Australian Defence & government ICT
Cloud and Kubernetes platforms built against the Information Security Manual.
DDG Consulting is an Australian security engineering practice. We design and harden cloud and Kubernetes infrastructure to ISM controls, and prepare the assessment material and documentation a system needs before it can be authorised to operate. We run the same patterns in production ourselves — every control we recommend is one we operate.
At a glance
- Based
- Australia. Australian owned and operated.
- Focus
- Platform engineering, security observability, and ISM assessment and authorisation.
- Frameworks
- ISM · PSPF · DSPF · Essential Eight · ISO/IEC 27001
- Stack
- Kubernetes · FluxCD · Splunk · OpenTelemetry · Terraform · Ansible
- Engagement
- Fixed-scope projects, or ongoing advisory.
Reference platform
Evidence, not assertions.
Our own production environment is a GitOps-managed Kubernetes cluster engineered to ISM PROTECTED control patterns. The audit and logging pipeline below is running today — each stage is mapped to the ISM control it satisfies, and each is available as a deliverable on client systems.
OpenTelemetry Collector
Node-level agents and a cluster receiver capture workload logs, node and pod metrics, Kubernetes events, and the full API server audit trail.
TLS to Splunk HEC
Telemetry travels over HTTP Event Collector with TLS issued by an internal cert-manager CA. Certificate verification is enforced — no skipped checks.
Splunk Enterprise
Operator-managed Splunk with dedicated indexes separating application logs, metrics and API audit events. Seven-year audit retention with SHA-256 data-integrity hashing for tamper evidence.
SmartStore to S3
Warm and cold index data is offloaded to S3-compatible object storage, keeping long retention affordable without shortening the audit trail.
Least-privilege Splunk roles scope each user to only the indexes their duty requires. The audit trail is readable by the auditor role and no one else.
No day-to-day account can purge indexed events. Destructive capability sits behind a sealed breakglass account whose every use is itself logged.
FluxCD reconciles the cluster from a git repository. Secrets are SOPS-encrypted at rest in git; history doubles as the change record for assessment evidence.
Why it matters for authorisation. Assessors ask for evidence: where the logs go, who can touch them, how long they are kept, and how you would know if they were altered. A platform built this way answers those questions from configuration files rather than assurances — and the same pipeline, roles and retention policy can be stood up on your system as part of an engagement.
The ISM six-step process
Authorisation under the ISM follows a defined six-step lifecycle. The steps below set out which parts we can support and which part rests with your organisation.
Define the system
Establishing the system boundary, its classification, the data it handles and the environment it runs in.
Select controls
Identifying the ISM controls that apply at the target classification and determining how each relates to the architecture.
Implement controls
Building and configuring the platform so that the selected controls are in place, enforced and documented.
Assess controls
Self-assessment against the selected controls, remediation of identified gaps, and assembly of the supporting evidence.
Authorise the system
The authorising officer reviews the assessment, accepts the residual risk and grants authority to operate. This decision rests with your organisation.
Monitor the system
Ongoing monitoring, detection of configuration drift, and the reporting required to keep an authorisation current.
On step four. Where an independent security assessment is required, it must be carried out by an ASD-endorsed IRAP assessor. DDG Consulting is not an endorsed assessor and does not perform IRAP assessments. Our work is preparatory: identifying and closing gaps, writing the documentation, and assembling the evidence so the system is in a defensible state before the formal assessment begins.
Services
Platform engineering and system authorisation
The two are closely related in practice. A platform designed without reference to the ISM generally needs rework before it can be authorised, and documentation written separately from the build often fails to describe the system as it was actually deployed. We take on both so that the build and the paperwork stay consistent with each other.
Cloud and Kubernetes platform engineering
Design, build and hardening of production infrastructure, with ISM controls applied during the build rather than added afterwards. Delivered as declarative, version-controlled configuration your team can operate.
- GitOps delivery with FluxCD — the cluster reconciles from git, and git history becomes the auditable change record
- Secrets encrypted in the repository with SOPS and age, decrypted only in-cluster at deploy time
- Kubernetes hardening: RBAC, admission control, pod security standards and network policy, with policy-as-code enforcement via Kyverno
- Certificate automation with cert-manager — public TLS via Let's Encrypt DNS-01 and an internal CA for service-to-service encryption
- Bare-metal and edge patterns: K3s, MetalLB load balancing, ingress-nginx, automated DNS via external-dns
- Identity-aware ingress: OAuth single sign-on enforced in front of web workloads via oauth2-proxy
- Persistent storage with Longhorn distributed block storage and CSI volume snapshots
- Backup and disaster recovery with VolSync and Kopia — scheduled, encrypted, deduplicated backups with tested restoration procedures
- Node provisioning and SSH hardening automated with Ansible; AWS account structure, IAM and network segmentation through Terraform
- Automated dependency currency via Renovate, so patching is a pull request rather than a project
ISM assessment and authority to operate
Gap analysis, documentation and evidence for systems working towards authorisation at OFFICIAL, PROTECTED or above — grounded in operating these controls, not just writing about them.
- Gap analysis against the current quarterly ISM release at the target classification
- System Security Plan and the supporting control matrix, written from the system as deployed
- Security Risk Management Plan, risk register and residual risk statements
- Standard operating procedures — change management, incident response, patch management, backup and restore, access management, continuous monitoring, and logging and audit operations
- Evidence libraries mapped control by control, drawn from live configuration rather than screenshots
- Plan of Action and Milestones (POA&M) and remediation delivery where gaps are identified
- Continuous monitoring and annual reporting to maintain an existing authorisation
Security observability with Splunk
Design and deployment of Splunk Enterprise on Kubernetes via the Splunk Operator, fed by OpenTelemetry collectors over TLS. Index separation for logs, metrics and audit events, long-term retention with integrity controls, SmartStore tiering to object storage, and role models that enforce separation of duties — plus the dashboards and review procedures to make the data usable.
DISP readiness and Essential Eight uplift
DISP membership is assessed across governance, personnel, physical and ICT security, with Essential Eight Maturity Level 2 generally expected in the cyber domain. We work on the ICT and cyber requirements, and can identify where gaps remain in the other domains.
IRAP pre-assessment
An assessment of the system against ISM controls ahead of a formal engagement, followed by remediation of what is found and preparation of the evidence an assessor will request.
Engagements
How engagements work
Scope and pricing
Each engagement begins with a scoping discussion, followed by a written statement of work covering the controls in scope, the deliverables, the timeline and the price. If the work turns out to be larger than anticipated, that is raised before it is undertaken.
Handover
Infrastructure is delivered as version-controlled code with written runbooks, and documentation is provided in a format your own team can maintain. The intention is that the work can be taken over internally once it is complete.
Specialist work
Some work sits outside what we do, including independent IRAP assessment, physical security and legal advice. Where that applies we will say so early, and can help you brief the relevant specialist.
Background
Experience behind the work
- Certification
- ISO/IEC 27001:2022 Lead Auditor, covering information security management system design, implementation and audit programme management in line with ISO/IEC 17021-1 and ISO 19011.
- Sector
- Delivery on regulated Australian Defence programs, including security hardening of delivered systems, security risk assessment and gap analysis, and handling of controlled technical data under Australian and United States export control obligations.
- Platform and tooling
- Kubernetes and K3s, FluxCD, Kyverno, Helm, Terraform, Ansible and AWX, AWS and EKS, Splunk Enterprise and the Splunk Operator for Kubernetes, OpenTelemetry, Prometheus, Grafana and Loki, Longhorn, VolSync and Kopia, SOPS, Linux, Python and Bash.
- Security operations
- Incident response, threat hunting and vulnerability assessment, including forensic review of compromised data following cyber security incidents. Design and operation of audit logging pipelines with long-term retention, integrity controls and separation-of-duties role models.
DDG Consulting is not an ASD-endorsed IRAP assessor and does not perform IRAP assessments. Authorisation decisions and the acceptance of residual risk rest with your organisation's authorising officer. The reference platform describes DDG's own environment; ISM control references indicate the controls the implementation addresses, not a formal assessment outcome. References to Defence programs describe professional experience only; no client, program or system is identified.
Contact
Enquiries
A short description of the system, its target classification and your timeframe is enough to begin. Initial discussions are at no cost, and we will say if the work is not a fit.