The Department of Defence has rolled out a critical update to the Defence Industry Security Program (DISP), specifically targeting cyber assurance standards. The revised Control 16.1 now mandates that all Entry Level and Level 1 members implement multi-factor authentication (MFA) and endpoint detection and response (EDR) solutions across their networks.
Previously, these requirements were only enforced for higher membership levels. The shift reflects the growing threat landscape, where smaller supply chain partners are increasingly targeted by state-sponsored actors as entry points into larger defence networks.
'The perimeter has dissolved,' stated the Head of Defence Security. 'Every node in the supply chain must be a fortress.' Members have been given a 6-month grace period to achieve compliance, after which non-compliant entities risk suspension from the program.