ASD ISM — incremental change analysis

Release v2022.09.15 (2022-09-15) vs prior v2022.09.14 · 1 days · catalogue 837 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
19
Added
9
Substantive
12
Clarification
4
Editorial
42
Relocated
0
Scope changes
2
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET280
SECRET01
PROTECTED00
OFFICIAL: Sensitive01
Non-Classified026

3 · Level-specific material changes

FootprintFloorCeilingControls
S|TSSECRETTOP SECRETISM-1802
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-1482

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (19)

ControlFootprintLocationStatement (excerpt)
ISM-1784NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Incident management policyThe incident management policy, including the associated incident response plan, is exercised at least annually.
ISM-1785NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Supplier relationship managementA supplier relationship management policy is developed and implemented.
ISM-1786NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Supplier relationship managementAn approved supplier list is developed and implemented.
ISM-1787NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesApplications, ICT equipment and services are purchased from approved suppliers.
ISM-1788NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesMultiple potential suppliers are identified for the purchase of critical applications, ICT equipment and services.
ISM-1789NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesSufficient spares of critical ICT equipment is purchased and kept in reserve.
ISM-1790NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesApplications, ICT equipment and services are delivered in a manner that maintains their integrity.
ISM-1791NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesThe integrity of applications, ICT equipment and services are assessed as part of acceptance of products and services.
ISM-1792NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesThe authenticity of applications, ICT equipment and services are assessed as part of acceptance of products and services.
ISM-1793NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their managed services undergo a security assessment by an IRAP assessor at least every 24 months.
ISM-1794NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Contractual security requirementsNotification by service providers of significant changes to their own service provider arrangements is documented in contractual arrangements.
ISM-1795NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsCredentials for local administrator accounts and service accounts are a minimum of 30 characters.
ISM-1796NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentFiles containing executable content are digitally signed as part of application development.
ISM-1797NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentInstallers, patches and updates are digitally signed or provided with cryptographic checksums as part of application development.
ISM-1798NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentSecure configuration guidance is produced as part of application development.
ISM-1799NC|OS|P|S|TSGuidelines for Email › Domain-based Message Authentication, Reporting and ConformanceIncoming emails are rejected if they do not pass DMARC checks.
ISM-1800NC|OS|P|S|TSGuidelines for Networking › Flashing network devices with trusted firmware before first useNetwork devices are flashed with trusted firmware before they are used for the first time.
ISM-1801NC|OS|P|S|TSGuidelines for Networking › Regularly restarting network devicesNetwork devices are restarted on at least a monthly basis.
ISM-1802S|TSGuidelines for Cryptography › ASD-approved High Assurance Cryptographic EquipmentHACE does not process, store or communicate SECRET or TOP SECRET data until approved for use by ASD.

Substantive amendments (9)

ControlEdit distLocationStatement (excerpt)
ISM-14520.62Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesA supply chain risk assessment is performed for suppliers of applications, ICT equipment and services in order to assess the impact to a system’s secu…
ISM-14820.52Guidelines for Enterprise Mobility › Organisation-owned mobile devicesPersonnel accessing systems or data using an organisation-owned mobile device use an ASD-approved platform, a security configuration in accordance wit…
ISM-15680.44Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services are chosen from suppliers that have made a commitment to the security of their products and services.
ISM-15670.40Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesSuppliers identified as high risk by a cyber supply chain risk assessment are not used.
ISM-01410.38Guidelines for Procurement and Outsourcing › Contractual security requirementsThe requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are …
ISM-11830.36Guidelines for Email › Sender Policy FrameworkA hard fail SPF record is used when specifying authorised email servers (or lack thereof) for all domains (including subdomains).
ISM-16310.32Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services associated with systems are identified and understood.
ISM-17370.30Guidelines for Procurement and Outsourcing › Managed servicesA managed service register contains the following for each managed service: * managed service provider’s name * managed service’s name * purpose for u…
ISM-05760.28Guidelines for Cyber Security Incidents › Incident management policyAn incident management policy is developed and implemented.

Clarifications (12)

ControlEdit distLocation
ISM-15400.20Guidelines for Email › Domain-based Message Authentication, Reporting and Conformance
ISM-16320.20Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities
ISM-00720.20Guidelines for Procurement and Outsourcing › Contractual security requirements
ISM-16380.15Guidelines for Procurement and Outsourcing › Outsourced cloud services
ISM-08530.15Guidelines for System Hardening › Session termination
ISM-15890.13Guidelines for Email › Email server transport encryption
ISM-08610.13Guidelines for Email › DomainKeys Identified Mail
ISM-05670.13Guidelines for Email › Open relay email servers
ISM-05740.12Guidelines for Email › Sender Policy Framework
ISM-15020.09Guidelines for Email › Blocking suspicious emails
ISM-04600.08Guidelines for Cryptography › Encrypting data at rest
ISM-15690.05Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-0467, ISM-0499, ISM-0687, ISM-1400

Relocated (42)

24 cross-chapter moves (listed) · 18 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for OutsourcingGuidelines for Procurement and OutsourcingISM-0072 ISM-1073 ISM-1395 ISM-1451 ISM-1452 ISM-1529 ISM-1567 ISM-1568 ISM-1569 ISM-1570 ISM-1571 ISM-1572 ISM-1573 ISM-1574 ISM-1575 ISM-1576 ISM-1631 ISM-1632 ISM-1637 ISM-1638 ISM-1736 ISM-1737 ISM-1738
Guidelines for Cyber Security IncidentsGuidelines for Procurement and OutsourcingISM-0141

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (2)

ControlFootprintFormer locationStatement (excerpt)
ISM-1152NC|OS|P|S|TSGuidelines for EmailIncoming emails that fail SPF checks are blocked or marked in a manner that is visible to the recipients.
ISM-1433NC|OS|P|S|TSGuidelines for Cyber Security IncidentsService providers and their customers maintain 24/7 contact details for each other, including additional out-of-band contact details for when normal c…
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.