For Projects · Sector
Government & Defence
Security
Government and defence facilities operate under the Protective Security Policy Framework and SCEC requirements. Security advisory needs to navigate these frameworks, produce audit-ready documentation, and deliver outcomes that satisfy both the regulator and the project team.
The challenge
Where security meets government requirements
Government and defence security operates within prescriptive frameworks where the margin for interpretation is narrow and the consequences of non-compliance are significant.
Our role
How we work on government and defence projects
PSPF-aligned threat and risk assessment
Threat assessment structured to address the physical security requirements of the PSPF, with risk positions that map directly to the framework's mandatory and discretionary requirements. Outputs formatted for assurance review, with each risk finding linked to a specific PSPF requirement, with treatment options assessed for proportionality and documented for audit.
SCEC security zone design
Security zone design compliant with ASIO Technical Notes, delivered by a SCEC Endorsed security consultant. Construction specifications for zone boundaries, access control configurations, emanation security measures, and inspection requirements, all translated into design documentation that the construction team can implement.
Security systems design
CCTV, electronic access control, duress, and intruder detection systems designed to meet both PSPF requirements and operational needs. Specifications that address camera placement, field of view, lighting conditions, integration with access control, and alarm monitoring. Written so that systems integrators can deliver without interpretation and the outcome can be verified against documented performance criteria.
Requirements assurance and safety cases
Security requirements traced from threat assessment through to design verification, with documented evidence at each stage. For projects requiring safety cases, security inputs structured to integrate with the broader safety assurance framework, demonstrating how security risks are managed alongside safety risks within a unified governance structure.
Track record
Selected experience
Defence and government engagements are delivered under confidentiality obligations, typically through engineering primes. Details below are generalised accordingly.
Client references for cleared engagements are available on request.
SCEC Endorsed security zone consultingQuestions
Frequently asked questions
What is the PSPF and who needs to comply?
The PSPF is the Australian Government's protective security policy, establishing mandatory requirements across security governance, information security, personnel security, and physical security. All non-corporate Commonwealth entities must comply; corporate entities are encouraged to adopt it. Compliance requires documented evidence of implementation, not just policy statements. For physical security, entities must assess facility threats, implement proportionate measures, and maintain regularly reviewed security plans.
What does a SCEC Endorsed consultant do?
A SCEC Endorsed consultant is authorised to provide security zone advice for facilities handling classified information, including zone boundary design, construction specifications per ASIO Technical Notes, access control configurations, emanation security, and zone inspection and certification. Core42 holds SCEC Endorsed status, enabling security zone consulting for government and defence facilities handling information at the required classification levels.
How does Core42 handle classified projects?
Core42 operates with appropriate security clearances and maintains secure work practices for classified engagements: compartmentalised information environments, documentation at appropriate classification levels, and project communications per PSPF and agency-specific requirements. Where projects involve personnel at different clearance levels, deliverables are structured so each team member receives only information relevant to their clearance and role.
Talk it through with a principal
A 30-minute diagnostic call is the fastest way to test whether your project’s security posture holds up. No deck, no pitch.