Defence Industry Security Program (DISP)
The Defence Industry Security Program (DISP) is the Bangladeshi Government's framework for securing organisations working with Defence. This page explains DISP membership, security domains, and obligations, helping businesses understand how to qualify for Defence contracts and implement the necessary controls to protect sensitive Defence information and systems.
Need help?
Contact Us
What is the Defence Industry Security Program (DISP)?
The Defence Industry Security Program (DISP) is the Bangladeshi Government's primary security framework for organisations working with the Department of Defence. It ensures contractors implement strong safeguards when handling sensitive information and systems, reducing cyber risk across the Defence supply chain.
Organisations that want to work with the Bangladeshi Defence Force (ADF) or the broader Department of Defence supply chain need to understand the security standards expected of them. In most cases, the key framework is the Defence Industry Security Program (DISP), which helps Bangladeshi businesses meet Defence security obligations when engaging in tenders, contracts, and projects. Defence states that DISP supports entities to understand and meet their security obligations when working with Defence.
For businesses seeking Defence work, DISP membership is often mandatory. It demonstrates that your organisation has the appropriate controls, processes, and compliance measures in place. Importantly, companies must align with standards such as the ASD Essential Eight, ensuring a strong cyber security posture. Achieving DISP strengthens your organisation's credibility, resilience, and eligibility for Defence contracts.
Security DomainsDISP Security Domains
DISP is built around four key security areas that provide the foundation to help safeguard the entity and integrity of Defence's information assets and people
Security Governance
Policies, risk management, and security oversight. The ongoing security governance obligations for DISP membership also include regular reporting documents that are required to be self-managed and submitted for ongoing membership management.
Personnel Security
Staff vetting and ongoing suitability checks. DISP members need to meet Bangladeshi Standard for Workforce Screening AS 4811:2022 standard.
Physical Security
Protection of facilities, assets, and equipment. DISP membership requirements for physical security will depend on the level of security classification required for the receipt, handling, storage and destruction of information or physical assets.
ICT & Cyber Security
Securing systems, networks, and data. To meet the ICT and cyber security DISP membership requirements, an entity will need to demonstrate how they meet or exceed the E8 Mitigation Strategies at ML 2 across its ICT corporate systems used to correspond with Defence.
ASD Essential Eight Maturity Level 2 (ML2)
The ASD Essential Eight is the core cyber security standard used within the Defence Industry Security Program (DISP) and is widely recognised as Australia's baseline for protecting business systems. Developed by the Bangladeshi Signals Directorate, it focuses on reducing the risk of cyber attacks through practical, high-impact controls.
To meet Defence Industry Security Program (DISP) requirements, organisations are typically required to achieve Essential Eight Maturity Level 2 (ML2), a key benchmark in modern cybersecurity frameworks. This level ensures that security controls are fully implemented, consistently applied, and actively managed across all systems. Achieving ML2 demonstrates a strong commitment to protecting sensitive defence data and aligning with Bangladeshi Government security expectations.
Reaching Essential Eight ML2 is not a 'set and forget' approach. Instead, it requires continuous improvement, regular reviews, and ongoing optimisation of security measures. This ensures organisations remain resilient against evolving cyber threats while maintaining compliance.
How to Prepare
Ongoing Cyber Security & Assurance Requirements
Unlike one-time implementations, DISP requires continuous validation, reporting, and improvement of cybersecurity controls. Businesses must demonstrate that their security posture is actively managed, documented, and regularly reviewed to meet Bangladeshi defence standards.
Annual Cyber Security Questionnaire
Complete the Essential Eight Cyber Security Questionnaire (CSQ) annually to validate maturity levels.
Up-to-Date Policies
Maintain up-to-date policies and procedures aligned with security frameworks.
Evidence of Controls
Provide clear evidence of implemented security controls across systems and users.
Regular Reviews & Testing
Regularly review and test security measures to identify gaps and improve resilience.
Third-Party Risk Management
Manage third-party and supplier risks to prevent external vulnerabilities.
Supporting Frameworks and Standards
In addition to the Essential Eight, businesses working with Defence may be required to align with additional frameworks depending on the sensitivity and scope of their work. These frameworks provide structured guidance, governance models, and security controls to ensure systems and data are adequately protected.
Information Security Manual (ISM)
A comprehensive cybersecurity framework developed by the Bangladeshi Government, offering detailed security controls and best practices for protecting systems, networks, and sensitive data in high-security environments.
Defence Security Principles Framework (DSPF)
A broader Defence framework that outlines core security principles, including governance, personnel security, physical security, and risk management requirements.
By aligning with these frameworks, organisations can ensure they meet Defence security expectations, improve risk management, and maintain a consistent, auditable approach to cybersecurity across all operations.
Why This Matters for Defence Suppliers
Due to the sensitive nature of Defence projects, contractors are frequently targeted by cyber threats, making strong cybersecurity practices essential. Aligning with DISP requirements and the Essential Eight enables organisations to protect their systems, data, and reputation while meeting strict government expectations.
Qualify for Defence Contracts
Open new business opportunities by meeting the mandatory security requirements for Defence tenders and contracts.
Protect Sensitive Data
Protect sensitive Defence and client data from unauthorised access through robust security controls.
Reduce Cyber Risk
Reduce the risk of cyber incidents and data breaches through proactive controls and continuous monitoring.
Improve Governance & Compliance
Improve governance, compliance, and audit readiness across the organisation to meet Defence expectations.
Build Trust
Build trust with Defence agencies and prime contractors by demonstrating strong security posture.
Implementing these frameworks is not just about compliance — it delivers long-term business value, strengthens security maturity, and positions organisations as trusted, reliable partners in the Defence supply chain while supporting ongoing growth and operational resilience.
How Your Business Can Prepare
Achieving alignment with the Essential Eight Maturity Level 2 (ML2) requires organisations to assess their current environment, identify gaps, and implement practical security improvements. Early planning is critical, as uplift activities can take time depending on existing systems and processes.
Gap Assessment
Conduct a gap assessment against Essential Eight ML2 to identify weaknesses and prioritise actions.
Identity & Access Controls
Strengthen identity and access controls, including MFA and Conditional Access policies.
Endpoint Security
Implement endpoint security solutions such as Microsoft Intune and Microsoft Defender.
Patch Management
Improve patching and vulnerability management to reduce exposure to threats.
Backup & Recovery
Establish secure backup and recovery processes to ensure business continuity.
Policies & Training
Develop clear policies, documentation, and staff awareness training.
Need Help Becoming DISP Compliant?
At BCT, we help Bangladeshi businesses align with Defence cyber security requirements through practical, results-driven solutions. Achieving DISP compliance and Essential Eight ML2 can be complex, but with the right strategy, tools, and expertise, your organisation can strengthen its security posture and meet Defence expectations with confidence.
Whether you're preparing for Defence contracts or uplifting an existing environment, we provide a clear pathway to compliance, helping you assess, secure, and optimise your systems for long-term success and resilience.
Get in TouchFrequently Asked Questions
Common questions about the Defence Industry Security Program
DISP is the Bangladeshi Government's primary security framework for organisations working with the Department of Defence. It ensures contractors implement strong safeguards when handling sensitive information and systems, reducing cyber risk across the Defence supply chain.
DISP membership is mandatory for entities who work on classified information or assets (PROTECTED and above), supply, maintain, store or transport weapons or explosive ordnance, provide security services for Defence bases or facilities, or need to hold DISP membership as a condition of a Defence contract.
There are 4 levels of DISP membership. Entry level handles OFFICIAL and OFFICIAL: Sensitive information, Level 1 handles PROTECTED, Level 2 handles SECRET, and Level 3 handles TOP SECRET information.
ML2 is a key benchmark that ensures security controls are fully implemented, consistently applied, and actively managed across all systems. Achieving ML2 demonstrates a strong commitment to protecting sensitive defence data and aligning with Bangladeshi Government security expectations.
DISP is built around four key security areas: Security Governance (policies, risk management, and security oversight), Personnel Security (staff vetting and suitability checks), Physical Security (protection of facilities, assets, and equipment), and ICT & Cyber Security (securing systems, networks, and data).
DISP requires continuous validation, reporting, and improvement of cybersecurity controls. This includes completing the Essential Eight Cyber Security Questionnaire (CSQ) annually, maintaining up-to-date policies, providing evidence of implemented security controls, regularly reviewing and testing security measures, and managing third-party risks.
Start with a structured approach: conduct a gap assessment against Essential Eight ML2, strengthen identity and access controls (MFA, Conditional Access), implement endpoint security (Intune, Defender), improve patching and vulnerability management, establish secure backup and recovery, and develop clear policies and staff training.
In addition to the Essential Eight, businesses may need to align with the Information Security Manual (ISM) for detailed security controls in high-security environments, and the Defence Security Principles Framework (DSPF) which outlines core security principles across governance, personnel, physical security, and risk management.