ASD ISM — incremental change analysis

Release v2022.09.15 (2022-09-15) vs prior v2022.09.14 · 1 days · catalogue 837 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
19
Added
9
Substantive
12
Clarification
4
Editorial
42
Relocated
0
Scope changes
2
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET280
SECRET01
PROTECTED00
OFFICIAL: Sensitive01
Non-Classified026

3 · Level-specific material changes

FootprintFloorCeilingControls
S|TSSECRETTOP SECRETISM-1802
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-1482

4 · Change location by chapter

5 · Section / topic structure

New sections: 4 · Removed sections: 4 · New topics: 8 · Removed topics: 7. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for Cyber Security IncidentsResponding to cyber security incidents8ISM-0133 ISM-0917 ISM-0137 ISM-1609 ISM-1731 ISM-1732 ISM-1213 ISM-0138
Guidelines for Evaluated ProductsEvaluated product procurement3ISM-0280 ISM-0285 ISM-0286
Guidelines for Procurement and OutsourcingCyber supply chain risk management14ISM-1631 ISM-1452 ISM-1567 ISM-1568 ISM-1632 ISM-1569 ISM-1785 ISM-1786 ISM-1787 ISM-1788 ISM-1789 ISM-1790 ISM-1791 ISM-1792
Guidelines for Procurement and OutsourcingManaged services and cloud services20ISM-1736 ISM-1737 ISM-1793 ISM-1637 ISM-1638 ISM-1529 ISM-1570 ISM-1395 ISM-0072 ISM-0141 ISM-1571 ISM-1738 ISM-1794 ISM-1451 ISM-1572 ISM-1573 ISM-1574 ISM-1575 ISM-1073 ISM-1576

Removed sections

ChapterSection
Guidelines for Cyber Security IncidentsDetecting cyber security incidents
Guidelines for Evaluated ProductsEvaluated product acquisition
Guidelines for OutsourcingCyber supply chain risk management
Guidelines for OutsourcingManaged services and cloud services

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for CryptographyCryptographic fundamentalsASD-approved High Assurance Cryptographic Equipment2ISM-1802 ISM-0499
Guidelines for Cyber Security IncidentsManaging cyber security incidentsAccess to sufficient data sources and tools1ISM-0120
Guidelines for Cyber Security IncidentsManaging cyber security incidentsIncident management policy2ISM-0576 ISM-1784
Guidelines for Cyber Security IncidentsManaging cyber security incidentsTrusted insider program2ISM-1625 ISM-1626
Guidelines for Cyber Security RolesChief Information Security OfficerWorking with suppliers1ISM-0731
Guidelines for Enterprise MobilityMobile device managementASD-approved platforms1ISM-0687
Guidelines for NetworkingNetwork design and configurationFlashing network devices with trusted firmware before first use1ISM-1800
Guidelines for NetworkingNetwork design and configurationRegularly restarting network devices1ISM-1801

Removed topics

ChapterSectionTopic
Guidelines for CryptographyCryptographic fundamentalsHigh assurance cryptography
Guidelines for Cyber Security IncidentsManaging cyber security incidentsHandling and containing data spills
Guidelines for Cyber Security IncidentsManaging cyber security incidentsHandling and containing intrusions
Guidelines for Cyber Security IncidentsManaging cyber security incidentsHandling and containing malicious code infections
Guidelines for Cyber Security IncidentsManaging cyber security incidentsIntegrity of evidence
Guidelines for Cyber Security RolesChief Information Security OfficerWorking with suppliers and service providers
Guidelines for Enterprise MobilityMobile device managementApproval for use

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for Procurement and OutsourcingCyber supply chain risk management842014
Guidelines for EmailEmail gateways and servers11608
Guidelines for Procurement and OutsourcingManaged services and cloud services22206
Guidelines for CryptographyCryptographic fundamentals10124
Guidelines for Software DevelopmentApplication development30003
Guidelines for Enterprise MobilityMobile device management01023
Guidelines for Cyber Security IncidentsManaging cyber security incidents11002
Guidelines for System HardeningAuthentication hardening10102
Guidelines for NetworkingNetwork design and configuration20002

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for Procurement and OutsourcingCyber supply chain risk managementCyber supply chain risk management activities04206
Guidelines for Procurement and OutsourcingCyber supply chain risk managementPurchasing of applications, ICT equipment and services30003
Guidelines for Procurement and OutsourcingCyber supply chain risk managementDelivery of applications, ICT equipment and services30003
Guidelines for Procurement and OutsourcingManaged services and cloud servicesContractual security requirements11103
Guidelines for Software DevelopmentApplication developmentSecure software design and development30003
Guidelines for Cyber Security IncidentsManaging cyber security incidentsIncident management policy11002
Guidelines for Procurement and OutsourcingCyber supply chain risk managementSupplier relationship management20002
Guidelines for EmailEmail gateways and serversDomain-based Message Authentication, Reporting and Conformance10102
Guidelines for CryptographyCryptographic fundamentalsASD-approved High Assurance Cryptographic Equipment10012
Guidelines for EmailEmail gateways and serversSender Policy Framework01102
Guidelines for Procurement and OutsourcingManaged services and cloud servicesAssessment of managed service providers10001
Guidelines for System HardeningAuthentication hardeningProtecting credentials10001
Guidelines for NetworkingNetwork design and configurationFlashing network devices with trusted firmware before first use10001
Guidelines for NetworkingNetwork design and configurationRegularly restarting network devices10001
Guidelines for CryptographyCryptographic fundamentalsEncrypting data at rest00101
Guidelines for CryptographyCryptographic fundamentalsEncrypting data in transit00011
Guidelines for EmailEmail gateways and serversOpen relay email servers00101
Guidelines for Enterprise MobilityMobile device managementASD-approved platforms00011
Guidelines for System HardeningAuthentication hardeningSession termination00101
Guidelines for EmailEmail gateways and serversDomainKeys Identified Mail00101
Guidelines for Enterprise MobilityMobile device managementPrivately-owned mobile devices00011
Guidelines for Enterprise MobilityMobile device managementOrganisation-owned mobile devices01001
Guidelines for EmailEmail gateways and serversBlocking suspicious emails00101
Guidelines for EmailEmail gateways and serversEmail server transport encryption00101
Guidelines for Procurement and OutsourcingManaged services and cloud servicesOutsourced cloud services00101
Guidelines for Procurement and OutsourcingManaged services and cloud servicesManaged services01001

6 · Control call-outs by category

Added — new controls (19)

ControlFootprintLocationStatement (excerpt)
ISM-1784NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Incident management policyThe incident management policy, including the associated incident response plan, is exercised at least annually.
ISM-1785NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Supplier relationship managementA supplier relationship management policy is developed and implemented.
ISM-1786NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Supplier relationship managementAn approved supplier list is developed and implemented.
ISM-1787NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesApplications, ICT equipment and services are purchased from approved suppliers.
ISM-1788NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesMultiple potential suppliers are identified for the purchase of critical applications, ICT equipment and services.
ISM-1789NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Purchasing of applications, ICT equipment and servicesSufficient spares of critical ICT equipment is purchased and kept in reserve.
ISM-1790NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesApplications, ICT equipment and services are delivered in a manner that maintains their integrity.
ISM-1791NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesThe integrity of applications, ICT equipment and services are assessed as part of acceptance of products and services.
ISM-1792NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Delivery of applications, ICT equipment and servicesThe authenticity of applications, ICT equipment and services are assessed as part of acceptance of products and services.
ISM-1793NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their managed services undergo a security assessment by an IRAP assessor at least every 24 months.
ISM-1794NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Contractual security requirementsNotification by service providers of significant changes to their own service provider arrangements is documented in contractual arrangements.
ISM-1795NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsCredentials for local administrator accounts and service accounts are a minimum of 30 characters.
ISM-1796NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentFiles containing executable content are digitally signed as part of application development.
ISM-1797NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentInstallers, patches and updates are digitally signed or provided with cryptographic checksums as part of application development.
ISM-1798NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentSecure configuration guidance is produced as part of application development.
ISM-1799NC|OS|P|S|TSGuidelines for Email › Domain-based Message Authentication, Reporting and ConformanceIncoming emails are rejected if they do not pass DMARC checks.
ISM-1800NC|OS|P|S|TSGuidelines for Networking › Flashing network devices with trusted firmware before first useNetwork devices are flashed with trusted firmware before they are used for the first time.
ISM-1801NC|OS|P|S|TSGuidelines for Networking › Regularly restarting network devicesNetwork devices are restarted on at least a monthly basis.
ISM-1802S|TSGuidelines for Cryptography › ASD-approved High Assurance Cryptographic EquipmentHACE does not process, store or communicate SECRET or TOP SECRET data until approved for use by ASD.

Substantive amendments (9)

ControlEdit distLocationStatement (excerpt)
ISM-14520.62Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesA supply chain risk assessment is performed for suppliers of applications, ICT equipment and services in order to assess the impact to a system’s secu…
ISM-14820.52Guidelines for Enterprise Mobility › Organisation-owned mobile devicesPersonnel accessing systems or data using an organisation-owned mobile device use an ASD-approved platform, a security configuration in accordance wit…
ISM-15680.44Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services are chosen from suppliers that have made a commitment to the security of their products and services.
ISM-15670.40Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesSuppliers identified as high risk by a cyber supply chain risk assessment are not used.
ISM-01410.38Guidelines for Procurement and Outsourcing › Contractual security requirementsThe requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are …
ISM-11830.36Guidelines for Email › Sender Policy FrameworkA hard fail SPF record is used when specifying authorised email servers (or lack thereof) for all domains (including subdomains).
ISM-16310.32Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services associated with systems are identified and understood.
ISM-17370.30Guidelines for Procurement and Outsourcing › Managed servicesA managed service register contains the following for each managed service: * managed service provider’s name * managed service’s name * purpose for u…
ISM-05760.28Guidelines for Cyber Security Incidents › Incident management policyAn incident management policy is developed and implemented.

Clarifications (12)

ControlEdit distLocation
ISM-15400.20Guidelines for Email › Domain-based Message Authentication, Reporting and Conformance
ISM-16320.20Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities
ISM-00720.20Guidelines for Procurement and Outsourcing › Contractual security requirements
ISM-16380.15Guidelines for Procurement and Outsourcing › Outsourced cloud services
ISM-08530.15Guidelines for System Hardening › Session termination
ISM-15890.13Guidelines for Email › Email server transport encryption
ISM-08610.13Guidelines for Email › DomainKeys Identified Mail
ISM-05670.13Guidelines for Email › Open relay email servers
ISM-05740.12Guidelines for Email › Sender Policy Framework
ISM-15020.09Guidelines for Email › Blocking suspicious emails
ISM-04600.08Guidelines for Cryptography › Encrypting data at rest
ISM-15690.05Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-0467, ISM-0499, ISM-0687, ISM-1400

Relocated (42)

24 cross-chapter moves (listed) · 18 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for OutsourcingGuidelines for Procurement and OutsourcingISM-0072 ISM-1073 ISM-1395 ISM-1451 ISM-1452 ISM-1529 ISM-1567 ISM-1568 ISM-1569 ISM-1570 ISM-1571 ISM-1572 ISM-1573 ISM-1574 ISM-1575 ISM-1576 ISM-1631 ISM-1632 ISM-1637 ISM-1638 ISM-1736 ISM-1737 ISM-1738
Guidelines for Cyber Security IncidentsGuidelines for Procurement and OutsourcingISM-0141

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (2)

ControlFootprintFormer locationStatement (excerpt)
ISM-1152NC|OS|P|S|TSGuidelines for EmailIncoming emails that fail SPF checks are blocked or marked in a manner that is visible to the recipients.
ISM-1433NC|OS|P|S|TSGuidelines for Cyber Security IncidentsService providers and their customers maintain 24/7 contact details for each other, including additional out-of-band contact details for when normal c…
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.