ASD ISM — control change analysis

OSCAL releases 2022-09-14 → 2026-06-18 · controls only · baseline v2022.09.14 (820 controls)

Introduction

The Australian Signals Directorate (ASD) / Australian Cyber Security Centre (ACSC) maintains the Information Security Manual (ISM). The ISM is a cyber security framework that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats.

ISMexplorer takes the outputs of the ISM publication and change management process, specifically the OSCAL releases, and provides an analysis of the changes both over a long period as well as between versions.

The content in ISMexplorer is updated when ISM itself is updated, typically quarterly.

24
Releases analysed
17 / 7
Substantive / errata
+281
Catalogue growth
342
New controls added
61
Controls removed
185
Substantive edits

Longitudinal overview

Change typology per release
Classification footprint of material changes
Level-specific material changes (full-scope excluded)

Releases

Click a release to open its incremental report. Errata / format-only rows are dimmed — no content change. Counts are controls; sub-rate = (added + substantive) ÷ catalogue size.
ReleaseDateTypeAddedSubstClarifEditRelocScopeSizeSub-rate
v2026.06.182026-06-18substantive20234438149011010.039
v2026.03.242026-03-24substantive94946010810.012
v2025.12.92025-12-09substantive213155916010730.022
v2025.10.82025-10-08errata/format-only00000010580.000
v2025.09.152025-09-15errata/format-only00000010580.000
v2025.09.102025-09-10substantive51657010580.006
v2025.07.162025-07-16substantive519551620010530.057
v2025.03.312025-03-31substantive2413334149110030.037
v2024.12.192024-12-19substantive31918211109800.041
v2024.10.42024-10-04errata/format-only0000009530.000
v2024.09.262024-09-26substantive406815609530.048
v2024.06.182024-06-18substantive7315558209130.011
v2024.03.122024-03-12errata/format-only0000009060.000
v2024.03.52024-03-05substantive5111009060.007
v2023.12.12023-12-01substantive332633121119040.065
v2023.09.252023-09-25errata/format-only0000008980.000
v2023.09.212023-09-21substantive161936333828980.039
v2023.08.32023-08-03errata/format-only0000008830.000
v2023.06.292023-06-29substantive1272231308830.021
v2023.04.122023-04-12substantive0010008770.000
v2023.03.52023-03-05errata/format-only0000008770.000
v2023.03.32023-03-03substantive332118450108770.062
v2022.12.12022-12-01substantive16316692418500.055
v2022.09.152022-09-15substantive1991244208370.034

About

ISMexplorer is an analytical tool and publication by Baden Hughes, an independent security and compliance engineer. You can contact him via: hello@ismexplorer.org or signup to our low-volume announcements list.

Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.