Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States

    Compliance & Governance

    The frameworks Australian boards, insurers and regulators ask about — and the evidence that satisfies them.

    Compliance work fails for a predictable reason: the controls exist somewhere in the environment, but the evidence does not exist anywhere. An auditor asks how privileged access is reviewed and receives a description rather than an export. An insurer asks whether multi-factor authentication covers all remote access and receives a confident yes that nobody can substantiate. The articles in this topic are written to close that gap by treating evidence as a design requirement, not a reporting task.

    The Australian frameworks get the most coverage because they are the ones our clients are measured against. The ASD Essential Eight and its maturity levels underpin most local expectations. APRA CPS 234 governs information security for regulated financial entities and CPS 230 extends the same thinking to operational risk and service providers. The Information Security Manual and the Protective Security Policy Framework shape government and defence supply chains, with IRAP assessment sitting over the top for systems handling government data.

    International standards appear where clients are pulled into them: ISO/IEC 27001 for information security management, ISO/IEC 42001 for AI management systems, and HIPAA for our United States healthcare clients. The Privacy Act, the Notifiable Data Breaches scheme and the Security of Critical Infrastructure Act obligations round out the Australian picture.

    Practically, most of this maps onto Microsoft 365 and Azure configuration that can be exported on demand: conditional access policy state, device compliance, audit log retention, data loss prevention rules, sensitivity labels, backup and recovery test results, and access review outcomes. The articles here explain that mapping, and are honest about where a framework asks for something technology cannot supply — governance, board oversight, tested plans and documented decisions.

    All Compliance & Governance articles (6)

    Services on this topic

    Other topics

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.