Defence Industry Security Program

More efficient and effective DISP management today.

Mojo DISP is the Security Management System for DISP members — your register, your people, your facilities and your evidence, kept current and audit-ready inside your own Microsoft 365.

Built in Canberra by the team that delivered the first OFFICIAL and PROTECTED Microsoft 365 environments in the Australian Federal Government.

Runs in your Microsoft 365Reminders in Teams and OutlookCeiling up to PROTECTED
Security Governance register25 sections · 3 falling due
Clearances
2 revalidations due
next 21 days
Containers
Combination changed
B-204 · yesterday
Key muster
31 of 40 confirmed
round closes Fri
Travel
1 debrief owed
returned 4 days ago
Incidents
None open
last: 12 Aug
Audit trail
Verified end to end
23,061 entries
Export to Defence's workbook · 1 clickData location your tenant

Book a 25-minute demo and we'll walk you through Mojo DISP — a Security Management System built for DISP members.

Book a 25-minute demo
One system, not eleven spreadsheets

Everything DISP asks you to keep, in one place.

The register

One record per person, referenced everywhere

People, clearances, briefings, travel, facilities, containers, keys, combinations, assets, incidents, training, contracts — and the checks, declarations and evidence that keep them true. Updated once.

Built for Microsoft

Built for Microsoft. Built for Defence.

Runs on the Microsoft 365 you already pay for. Reminders and escalations arrive in Teams and Outlook, where your people already are. Your tenant, your data, your security boundary. Nothing leaves.

Programmed

Program the year. Then let it run.

Key musters, container checks, annual declarations, clearance revalidations — scheduled once, opened on their dates, chased in Teams and Outlook, closed when done.

Thirty days from spreadsheet to audit-ready

Deployed in a day. Programmed within a month.

Hour 1

See where you actually are

We walk how your security is managed today — wherever it lives — and name the gaps out loud.

Day 1

Deployed

Into your Microsoft 365. No new infrastructure, no new vendor to onboard.

Week 1

Running

Register live, officers appointed, your people declaring for themselves.

Day 30

Programmed

Your next twelve months of DISP activity is on its dates, and your Security Governance register exports into Defence's own workbook whenever you need it.

Why now

DISP membership isn't a certificate. It's a standing obligation.

You were assessed once. Since then you've hired people, lost people, moved a safe, changed a combination, sent someone overseas, had a near miss, and renewed a contract. Every one of those is a change to your register, and your register is the thing Defence looks at.

Most members are running it out of a spreadsheet, a shared drive and one person's memory. That works right up until it doesn't — and it stops working on exactly the day somebody asks you to prove it.

A register is a record. A Security Management System is what keeps it true.

The register says where you got to. The system is everything that gets you there and keeps you there: who is appointed and to what, what gets checked and how often, who was asked, what they answered, who never answered at all, what changed, who changed it, and what stands behind every one of those claims.

A spreadsheet can hold the first. It cannot be the second, and the second is what you're being assessed on.

25

mandated register sections you're expected to keep current

1

Security Officer, in most member companies, running the whole system

0

audit trail, if your register lives in a spreadsheet

The question isn't whether your register is accurate. It's whether you could demonstrate it was accurate last March.

The difference

Spreadsheets got you through the assessment. They won't get you through the next one.

Spreadsheets & SharePointGeneric GRC platformMojo DISP
What it isA record of where you got toA controls library you map yourselfA Security Management System, built for DISP
Register structureWhatever you builtGeneric controls, mapped by youBuilt to the DISP Member Security Register, section by section
Producing the register for DefenceRebuilt by hand each timeExported to a format you then reformatFills Defence's own issued workbook, on demand
Where the data livesWherever the file was savedVendor's cloudYour Microsoft 365 tenant
Who changed whatLast-modified-by, if you're luckyVendor's logTamper-evident, hash-chained audit trail
Getting declarations backEmail, then chasingEmail, then chasingAutomated rounds, reminders and escalation on timeframes you set
Where the reminder landsAn email you wroteThe vendor's portalTeams and Outlook, automatically
Your own processes and formsA new tabA generic templateA visual designer, with Defence-structured baselines included
Keeping it currentSomebody remembersSomebody remembersThe system asks, chases, escalates and records
LicensingFree, until it costs you a findingPer user, per monthContact us for pricing
Separation of dutiesHonour systemConfigurable, usually offEnforced server-side, on by default
Pricing

Contact us for pricing.

Talk to our team about your DISP membership level, headcount and requirements.

Your house, your rules

Your data never leaves your tenant.

Mojo DISP is a Power Platform application, so your Security Management System runs inside your own Microsoft 365. Your register, your people's details, your incident reports and your evidence sit in your Dataverse, under your tenant's identity, your conditional access and your retention policy.

There is no Mojo Up cloud. There is no copy of your register on our infrastructure. When your assessor asks where the data is, the answer is the same answer you already gave them about your email.

  • Your identity — Entra ID sign-in, your MFA, your conditional access.
  • Your boundary — no third-party data centre, no vendor-side copy, no egress.
  • Your classification — a configurable ceiling, up to PROTECTED, set by you.
Mojo DISP clearances register, with level, status, issue date and revalidation due
Capabilities

What a Security Management System has to do.

Seven things. Mojo DISP is built as those seven rather than as a feature list, which is why the parts fit together instead of sitting beside each other: record it, report it, run it, design how it runs, involve your people, evidence it, and control who may do what.

Record

Not a folder of spreadsheets. The register itself.

Twenty-five sections, structured the way the Member Security Register is structured — governance, personnel, physical security, ICT. A person is one record, referenced from every section they appear in, so a promotion, a clearance renewal or a departure is one edit rather than six.

A section that doesn't apply to you isn't hidden — it's recorded as not applicable, with who decided that and why. That's the difference between a register with a gap in it and a register with an answer in it.

Mojo DISP Member Security Register, section A1 record of sighting by commanders and managers
Report

It fills Defence's workbook. In one click. Not a lookalike.

Whenever you need it — an assessment, an annual return, an assessor's request — one click writes your Security Governance register into the issued workbook: the real one, with its columns, its headings and its protective marking band intact. Every export is recorded: who ran it, when, and what was in it.

An export that can't be completed doesn't hand you a half-filled spreadsheet. It stops and tells you what's missing, because a compliance document with rows silently dropped is worse than no document at all.

Mojo DISP forms list, including clearance, declaration, incident and briefing forms
Run

Program a year of audits in an afternoon.

This is the half a register can't do. Program the year — key musters, container inspections, annual declarations, clearance revalidations — and Mojo DISP opens each round on its date, asks the people it needs to ask, reminds the ones who haven't answered, escalates to the security team when they still haven't, and closes when it's done.

The timeframes are yours: every reminder, due date and escalation runs on an SLA you set once and change in one place. And nobody has to open a new system to be reminded — the nudge arrives as a Teams notification and an Outlook email, from the system, with a link straight to the thing being asked for.

  • 31 of 40 confirmed is three numbers, not one.
  • The people who answered, the people who were excused, and the people who could never be reached.
  • "Nothing is outstanding" and "nobody could be asked" are opposite answers.
Mojo DISP audits in flight, showing who accepted, who is awaiting review, and who has not answered
Design

Built on Defence's standards. Shaped by you.

Every DISP process in Mojo DISP — an incident, a clearance sponsorship, an overseas travel briefing and debrief, a combination change — runs on a workflow, and every declaration runs on a form. Both are yours to design, in a visual designer, with no code.

You don't start from a blank page. Mojo DISP ships with baseline processes and forms built from the Member Security Register and Defence's own workbook, and each baseline carries a locked spine: the steps a process must have for the register to stay true and the obligation to Defence to be discharged. You can add, reorder and branch around them. You can't remove them by accident.

A process is drafted by one person and published by another, and a published version is immutable — so a declaration made against it years from now is readable against the exact questions that were on screen. Changing the questions is a new version, deliberately.

Mojo DISP process designer canvas for Guard walk v1, with a published branching workflow
Involve

Stop transcribing other people's forms.

A Security Management System that only your Security Officer touches is one person's memory with a licence fee. Everyone in your company gets their own view — not your register, just the parts that are about them. They confirm the keys they hold, declare overseas travel, acknowledge a briefing, report an incident, and attach the signed document where one is needed.

They can see what they're being asked and nothing else. Not your assessment of them, not anybody else's clearance, not the register. That containment isn't a hidden screen — it's enforced in the platform, underneath the app.

Mojo DISP overseas travel declaration form, previewed as the person completing it
Evidence

The audit trail is the product.

Every create, update and deletion is written server-side, by the platform, not by the app — with the person, the moment, the record, the permission it relied on, and what actually changed. Each entry is cryptographically linked to the one before it, so the trail can be verified end to end and an altered entry can't hide.

Nobody edits it. Not an administrator, not us, not you. A mistake is corrected by a new entry that supersedes the old one, which is exactly what an assessor wants to see.

Refusals are recorded too. "Has anyone tried to do something they weren't allowed to do?" has an answer, and the answer isn't silence.

Mojo DISP audit trail with integrity verification result
Control

Roles that mean something.

CSO, CISO, Security Officer, Auditor, and everyone else. Each holds named permissions, and the app doesn't decide what you may do — the platform does, on every write, whether the request came from the app or from anywhere else.

Separation of duties is real: the person who drafts a process isn't the person who approves it, and where your company genuinely only has one officer, the exception is recorded as an exception rather than quietly permitted.

Delegation is time-bound and can never escalate. And when something has to be done outside the rules, break glass opens a reviewed window with a justification attached — not a switch somebody leaves on.

Mojo DISP security settings showing app users and the offices each person holds
Custody

Documents that can't quietly change.

Signed declarations, correspondence with Defence, briefing records, certificates. Every file is fingerprinted when it arrives and checked again every time it's read, so "this is the document we filed" is something you can demonstrate rather than assert.

Disposal is a two-step act with a reason on it, and the record of the file outlives the file.

Mojo DISP inbox showing items waiting, overdue and due soon
Dashboards and reports

See what's overdue before anybody asks.

The dashboard leads with what is falling due — clearances to revalidate, containers overdue for a combination change, briefings owed before travel, rounds still waiting on people — drawn from the register itself, not from a spreadsheet somebody keeps beside it. Every officer arranges their own; an Auditor sees the compliance picture and never a name.

When you need it on paper, compose your own report from the same figures — a page for the board, a page for your assessor — and print it with the protective marking on it. The register export is Defence's workbook; this is yours.

Falling due

Everything the register says is owed

And when. Derived from the register, so it can never disagree with it.

Your own dashboard

Arranged by you

From forty-plus widgets, saved per person. An Auditor's view carries figures and no names.

Composed reports

Your figures, your page

With your marking band. Recorded when exported, like every other export.

Mojo DISP dashboard with items waiting on an answer and processes by definition
The five questions an assessor asks

An assessor doesn't ask to see your spreadsheet. They ask to see the system working.

"Show me your current register."

On screen, live, in Defence's own structure — not a file somebody has to go and find.

"When was this last checked?"

Every record carries its last sighting and what's falling due. The dashboard leads with what's overdue.

"Who changed this, and why?"

Named, timestamped, reason attached, cryptographically chained. Including the changes that were refused.

"How do you know your people were told?"

Declarations, with who was asked, who answered, who was excused, and who could never be reached.

"Prove nobody has more access than they need."

The permission model is the answer, and it's enforced beneath the app rather than in it.

Built to be assessed

Built against the ISM's guidelines for software development.

Your assessor will ask about the tool as well as the register. Mojo DISP is developed against the Information Security Manual's guidelines for software development, and we keep the evidence rather than the assertion: which controls are implemented, how each one is evidenced, and which are recorded as gaps with a plan against them.

An ISM compliance report for the app is available to customers and prospective customers, so your assessor can verify it rather than take our word for it.

Scales from Entry Level to Level 3

One Security Management System, three sizes of program.

Entry Level / Level 1

One officer, one site

Your register, your declarations, and Defence's workbook whenever it's asked for. Set up in a day, and the system does the chasing so your Security Officer can go back to their actual job.

Level 2

A security team, real audit exposure

Separation of duties, delegation while people are on leave, scheduled audit rounds across multiple sites, and evidence attached to every claim.

Level 3

Multiple facilities, containers, an armoury

Physical security registers, key and combination management, weapons and munitions, classified waste, visitor control — and one dashboard across all of it.

Questions

The ones we get asked on every call.

What do you mean by a "Security Management System"?

The whole of how your company's security is run and evidenced — not just the register. Who is appointed and to what. What gets checked, how often, and by whom. How your people are told things and how you know they were told. What changed, who changed it, and what stands behind it. Mojo DISP is that system in one place, with the DISP Member Security Register as the record it keeps.

Is Mojo DISP a Defence product, or endorsed by Defence?

No. Mojo DISP is a Mojo Up product, built to help members meet their own DISP obligations. Your membership, your assessment and your relationship with Defence remain yours.

Where does our data live?

In your own Microsoft 365 tenant, in your Dataverse environment, in the Australian region you choose. Mojo Up holds no copy.

Does it replace our existing security policies?

No. Your policies say what your company will do; the Security Management System is where you run it, keep the register, hold the evidence and show that those policies are actually being followed.

We already have a GRC platform. Why this?

Because a generic controls library isn't the Member Security Register, and mapping one to the other is a project you have to redo every time either one changes. A GRC platform tells you which controls exist. This runs the program.

How long does implementation take?

Deployed in a day. Migrated and live inside a month, depending on the state of your current register.

Can our people use it without a Microsoft 365 licence?

Talk to us on the call — participant access is licensed differently from officer access, and it depends on your tenant.

What classification can we hold in it?

The ceiling is a setting, up to PROTECTED, and it's yours to choose. What the platform underneath is accredited to hold is a matter for your own environment and your own assessor — we'll tell you plainly what is and isn't ours to certify.

Is the app itself assessed against the ISM?

It is built against the ISM's guidelines for software development, and we publish the position control by control — implemented with evidence, not applicable with a reason, or a recorded gap with a plan. Ask for the ISM compliance report and we'll send the current one. It is our statement about our software; your environment's accreditation remains yours and your assessor's.

Can we change the processes and forms?

Yes — that's the point of the designer. Baselines ship structured to the register and Defence's workbook, with the steps that can't be dropped locked in. Everything around them is yours to shape, and a published version is never edited in place, so what somebody declared against stays readable.

What happens to our data if we stop using it?

It was never anywhere else. It's in your tenant, in your tables, and it stays there.

Can we get it out?

Yes — into Defence's own workbook, into Excel, and into a report you compose yourself.

Start to collaborate

Book a demo. We'll show you how Mojo DISP works.

A 25-minute walkthrough of the Security Management System, or a conversation about how Mojo DISP fits your membership level. No slide deck.

Or email contactus@mojoup.com.au.