Securing the Australian Government Software Supply Chain: JFrog Completes Protected Level IRAP Assessment
Blog post from JFrog
JFrog reports that its entire software supply chain platform has undergone an IRAP assessment at Australia’s Protected classification level by ASD-endorsed assessor CyberCX against the Information Security Manual. The company emphasizes that IRAP is an independent assessment rather than a certification, with individual government agencies using the resulting report to make their own Authority to Operate decisions. It argues that supply chain security has become a governance and national-resilience concern as risks increasingly arise from dependencies, binaries, container images, and AI models. The assessment covers JFrog’s end-to-end platform capabilities, including open-source ingestion, artifact management, vulnerability scanning, policy controls, signed distribution, and runtime monitoring, across AWS, Azure, and Google Cloud sovereign Australian regions. JFrog says the assessment can help Australian public-sector and regulated organizations reduce duplicated control reviews, support faster procurement and ATO processes, and maintain hosting flexibility while meeting Australian government security and sovereignty requirements.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.