The requirements found in these four categories of the NSW CSP assessment relate to security management activities that are also found (albeit worded differently) in the industry standard for information security management systems (ISMS); ISO/IEC 27001.
In case you didn’t already know that, clause 3.1 specifically calls out the requirement for NSW government departments and agencies to have an ISMS based on ISO/IEC 27001. Although certification isn’t always required – sometimes an annual, independent review or audit will suffice.
For us, there’s a lot of overlap between the NSW CSP requirements and those found inside ISO/IEC 27001. Perhaps there is some value in calling out 20 or so requirements for reporting purposes.
The augmentation of reporting with an assessment against the ‘ASD Essential 8’ is quite useful though, as it cuts straight to technical maturity, which can sometimes be vague in ISO/IEC 27001!