ASD ISM — incremental change analysis

Release v2022.12.1 (2022-12-01) vs prior v2022.09.15 · 77 days · catalogue 850 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
16
Added
31
Substantive
66
Clarification
9
Editorial
24
Relocated
1
Scope changes
3
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET470
SECRET02
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified045

3 · Level-specific material changes

FootprintFloorCeilingControls
S|TSSECRETTOP SECRETISM-0669 ISM-1776

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 8 · Removed topics: 7. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for Communications SystemsVideo conferencing and Internet Protocol telephonyDenial of service response plan2ISM-1019 ISM-1805
Guidelines for NetworkingNetwork design and configurationDefault accounts and credentials for network devices1ISM-1304
Guidelines for Procurement and OutsourcingCyber supply chain risk managementSourcing applications, ICT equipment and services3ISM-1787 ISM-1788 ISM-1789
Guidelines for Procurement and OutsourcingManaged services and cloud servicesContractual security requirements with service providers12ISM-1395 ISM-0072 ISM-1571 ISM-1738 ISM-1804 ISM-0141 ISM-1794 ISM-1451 ISM-1572 ISM-1573 ISM-1574 ISM-1575
Guidelines for Software DevelopmentWeb application developmentWeb application programming interfaces2ISM-1817 ISM-1818
Guidelines for System ManagementData backup and restorationBackup access4ISM-1812 ISM-1813 ISM-1705 ISM-1706
Guidelines for System ManagementData backup and restorationBackup modification and deletion3ISM-1814 ISM-1707 ISM-1708
Guidelines for System MonitoringEvent logging and monitoringCentralised event logging facility3ISM-1405 ISM-1815 ISM-0988

Removed topics

ChapterSectionTopic
Guidelines for Communications SystemsVideo conferencing and Internet Protocol telephonyDeveloping a denial of service response plan
Guidelines for NetworkingNetwork design and configurationDefault accounts for network devices
Guidelines for Procurement and OutsourcingCyber supply chain risk managementPurchasing of applications, ICT equipment and services
Guidelines for Procurement and OutsourcingManaged services and cloud servicesContractual security requirements
Guidelines for System HardeningAuthentication hardeningSetting credentials for service accounts
Guidelines for System ManagementData backup and restorationBackup access and modification
Guidelines for System MonitoringEvent logging and monitoringEvent logging facility

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for Procurement and OutsourcingManaged services and cloud services1013014
Guidelines for System ManagementData backup and restoration536014
Guidelines for System HardeningOperating system hardening052310
Guidelines for System HardeningAuthentication hardening03036
Guidelines for Personnel SecurityAccess to systems and their resources06006
Guidelines for Procurement and OutsourcingCyber supply chain risk management00516
Guidelines for System ManagementSystem patching30205
Guidelines for Cyber Security IncidentsManaging cyber security incidents12104
Guidelines for NetworkingNetwork design and configuration03104
Guidelines for Enterprise MobilityMobile device usage01214
Guidelines for System HardeningApplication hardening11013
Guidelines for System MonitoringEvent logging and monitoring10203
Guidelines for Software DevelopmentApplication development10203
Guidelines for Software DevelopmentWeb application development21003
Guidelines for Communications InfrastructureCabling infrastructure00303
Guidelines for Data TransfersData transfers01203
Guidelines for MediaMedia usage00303
Guidelines for Communications SystemsVideo conferencing and Internet Protocol telephony11002
Guidelines for GatewaysWeb proxies01102
Guidelines for ICT EquipmentICT equipment sanitisation and destruction00202
Guidelines for ICT EquipmentICT equipment usage00202
Guidelines for Cyber Security RolesChief Information Security Officer00202
Guidelines for Database SystemsDatabases01102
Guidelines for Security DocumentationDevelopment and maintenance of security documentation00101
Guidelines for System ManagementSystem administration00101
Guidelines for EmailEmail usage00101
Guidelines for MediaMedia sanitisation00101
Guidelines for MediaMedia destruction00101
Guidelines for MediaMedia disposal00101
Guidelines for CryptographyCryptographic fundamentals00101
Guidelines for Communications SystemsFax machines and multifunction devices00101
Guidelines for GatewaysWeb content filters00101
Guidelines for Communications SystemsTelephone systems00101
Guidelines for EmailEmail gateways and servers00101
Guidelines for Enterprise MobilityMobile device management00101
Guidelines for Physical SecurityFacilities and systems00101
Guidelines for ICT EquipmentICT equipment disposal00101
Guidelines for GatewaysGateways01001
Guidelines for GatewaysCross Domain Solutions01001

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for Procurement and OutsourcingManaged services and cloud servicesContractual security requirements with service providers1011012
Guidelines for System ManagementData backup and restorationBackup access21104
Guidelines for Personnel SecurityAccess to systems and their resourcesPrivileged access to systems04004
Guidelines for System HardeningOperating system hardeningApplication control01034
Guidelines for System ManagementData backup and restorationPerforming and retaining backups20103
Guidelines for System ManagementData backup and restorationBackup modification and deletion11103
Guidelines for Procurement and OutsourcingCyber supply chain risk managementSourcing applications, ICT equipment and services00213
Guidelines for Cyber Security IncidentsManaging cyber security incidentsCyber security incident register11002
Guidelines for Communications SystemsVideo conferencing and Internet Protocol telephonyDenial of service response plan11002
Guidelines for System ManagementSystem patchingScanning for missing patches or updates20002
Guidelines for System MonitoringEvent logging and monitoringCentralised event logging facility10102
Guidelines for Software DevelopmentWeb application developmentWeb application programming interfaces20002
Guidelines for System HardeningAuthentication hardeningProtecting credentials01012
Guidelines for Data TransfersData transfersData transfer processes and procedures00202
Guidelines for Enterprise MobilityMobile device usageAfter travelling overseas with mobile devices01012
Guidelines for System HardeningOperating system hardeningOperating system releases and versions01102
Guidelines for System ManagementData backup and restorationData backup and restoration processes and procedures00202
Guidelines for System HardeningOperating system hardeningPowerShell01102
Guidelines for System HardeningApplication hardeningMicrosoft Office macros01012
Guidelines for System HardeningAuthentication hardeningMulti-factor authentication01012
Guidelines for Software DevelopmentApplication developmentVulnerability disclosure program00202
Guidelines for Procurement and OutsourcingCyber supply chain risk managementSupplier relationship management00202
Guidelines for System HardeningApplication hardeningHardening application configurations10001
Guidelines for System ManagementSystem patchingCessation of support10001
Guidelines for Software DevelopmentApplication developmentDevelopment, testing and production environments10001
Guidelines for Security DocumentationDevelopment and maintenance of security documentationCyber security strategy00101
Guidelines for System ManagementSystem administrationSystem administration processes and procedures00101
Guidelines for Communications InfrastructureCabling infrastructureCable labelling processes and procedures00101
Guidelines for Communications InfrastructureCabling infrastructureCable register00101
Guidelines for GatewaysWeb proxiesWeb usage policy00101
Guidelines for EmailEmail usageEmail usage policy00101
Guidelines for ICT EquipmentICT equipment sanitisation and destructionICT equipment sanitisation processes and procedures00101
Guidelines for ICT EquipmentICT equipment usageICT equipment register00101
Guidelines for MediaMedia sanitisationMedia sanitisation processes and procedures00101
Guidelines for MediaMedia destructionMedia destruction processes and procedures00101
Guidelines for MediaMedia disposalMedia disposal processes and procedures00101
Guidelines for System HardeningOperating system hardeningHardening operating system configurations01001
Guidelines for System HardeningAuthentication hardeningSession and screen locking00011
Guidelines for CryptographyCryptographic fundamentalsCryptographic key management processes and procedures00101
Guidelines for NetworkingNetwork design and configurationNetwork documentation01001
Guidelines for Cyber Security IncidentsManaging cyber security incidentsIncident management policy01001
Guidelines for System MonitoringEvent logging and monitoringEvent logging policy00101
Guidelines for Communications SystemsFax machines and multifunction devicesFax machine and multifunction device usage policy00101
Guidelines for Data TransfersData transfersManual export of data01001
Guidelines for Enterprise MobilityMobile device usageMobile device emergency sanitisation processes and procedures00101
Guidelines for Cyber Security RolesChief Information Security OfficerDeveloping a cyber security communications strategy00101
Guidelines for Cyber Security RolesChief Information Security OfficerOverseeing cyber security awareness raising00101
Guidelines for GatewaysWeb content filtersUsing web content filters00101
Guidelines for Communications SystemsTelephone systemsTelephone system usage policy00101
Guidelines for Enterprise MobilityMobile device usageMobile device usage policy00101
Guidelines for System ManagementSystem patchingPatch management processes and procedures00101
Guidelines for EmailEmail gateways and serversEmail content filtering00101
Guidelines for Database SystemsDatabasesDatabase register00101
Guidelines for NetworkingNetwork design and configurationDefault accounts and credentials for network devices01001
Guidelines for NetworkingNetwork design and configurationUse of Simple Network Management Protocol00101
Guidelines for MediaMedia usageRemovable media usage policy00101
Guidelines for System ManagementSystem patchingSoftware register00101
Guidelines for System ManagementData backup and restorationDigital preservation policy00101
Guidelines for System ManagementData backup and restorationTesting restoration of backups01001
Guidelines for Enterprise MobilityMobile device managementMobile device management policy00101
Guidelines for Physical SecurityFacilities and systemsBringing Radio Frequency and infrared devices into facilities00101
Guidelines for MediaMedia usageMedia management policy00101
Guidelines for ICT EquipmentICT equipment disposalICT equipment disposal processes and procedures00101
Guidelines for ICT EquipmentICT equipment usageICT equipment management policy00101
Guidelines for System HardeningAuthentication hardeningSetting credentials for user accounts01001
Guidelines for Cyber Security IncidentsManaging cyber security incidentsTrusted insider program00101
Guidelines for Procurement and OutsourcingCyber supply chain risk managementCyber supply chain risk management activities00101
Guidelines for Procurement and OutsourcingManaged services and cloud servicesOutsourced cloud services00101
Guidelines for Communications InfrastructureCabling infrastructureFloor plan diagrams00101
Guidelines for MediaMedia usageRemovable media register00101
Guidelines for Personnel SecurityAccess to systems and their resourcesUnprivileged access to systems01001
Guidelines for Personnel SecurityAccess to systems and their resourcesEmergency access to systems01001
Guidelines for Procurement and OutsourcingManaged services and cloud servicesManaged services00101
Guidelines for ICT EquipmentICT equipment sanitisation and destructionICT equipment destruction processes and procedures00101
Guidelines for System HardeningOperating system hardeningOperating system event logging01001
Guidelines for Software DevelopmentWeb application developmentWeb application event logging01001
Guidelines for Database SystemsDatabasesDatabase event logging01001
Guidelines for GatewaysGatewaysGateway event logging and alerting01001
Guidelines for GatewaysCross Domain SolutionsCross Domain Solution event logging01001
Guidelines for GatewaysWeb proxiesWeb proxy event logging01001
Guidelines for NetworkingNetwork design and configurationProtective Domain Name System Services01001

6 · Control call-outs by category

Added — new controls (16)

ControlFootprintLocationStatement (excerpt)
ISM-1803NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Cyber security incident registerA cyber security incident register contains the following for each cyber security incident: * the date the cyber security incident occurred * the date…
ISM-1804NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Contractual security requirements with service providersBreak clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.
ISM-1805NC|OS|P|S|TSGuidelines for Communications Systems › Denial of service response planA denial of service response plan for video conferencing and IP telephony services contains the following: * how to identify signs of a denial-of-serv…
ISM-1806NC|OS|P|S|TSGuidelines for System Hardening › Hardening application configurationsDefault accounts or credentials for applications, including for any pre-configured accounts, are changed.
ISM-1807NC|OS|P|S|TSGuidelines for System Management › Scanning for missing patches or updatesAn automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activitie…
ISM-1808NC|OS|P|S|TSGuidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
ISM-1809NC|OS|P|S|TSGuidelines for System Management › Cessation of supportWhen applications, operating systems, network devices or other ICT equipment that are no longer supported by vendors cannot be immediately removed or …
ISM-1810NC|OS|P|S|TSGuidelines for System Management › Performing and retaining backupsBackups of important data, software and configuration settings are synchronised to enable restoration to a common point in time.
ISM-1811NC|OS|P|S|TSGuidelines for System Management › Performing and retaining backupsBackups of important data, software and configuration settings are retained in a secure and resilient manner.
ISM-1812NC|OS|P|S|TSGuidelines for System Management › Backup accessUnprivileged accounts cannot access backups belonging to other accounts.
ISM-1813NC|OS|P|S|TSGuidelines for System Management › Backup accessUnprivileged accounts cannot access their own backups.
ISM-1814NC|OS|P|S|TSGuidelines for System Management › Backup modification and deletionUnprivileged accounts are prevented from modifying and deleting backups.
ISM-1815NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs stored within a centralised event logging facility are protected from unauthorised modification and deletion.
ISM-1816NC|OS|P|S|TSGuidelines for Software Development › Development, testing and production environmentsUnauthorised modification of the authoritative source for software is prevented.
ISM-1817NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesClients are authenticated when calling web APIs that facilitate access to data not authorised for release into the public domain.
ISM-1818NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesClients are authenticated when calling web APIs that facilitate modification of data.

Substantive amendments (31)

ControlEdit distLocationStatement (excerpt)
ISM-01250.76Guidelines for Cyber Security Incidents › Cyber security incident registerA cyber security incident register is developed, implemented and maintained.
ISM-17760.74Guidelines for Gateways › Cross Domain Solution event loggingCDS event logs are stored centrally.
ISM-17750.71Guidelines for Gateways › Gateway event logging and alertingGateway event logs are stored centrally.
ISM-17580.70Guidelines for Database Systems › Database event loggingDatabase event logs are stored centrally.
ISM-17770.70Guidelines for Gateways › Web proxy event loggingWeb proxy event logs are stored centrally.
ISM-16650.69Guidelines for System Hardening › PowerShellPowerShell event logs are stored centrally.
ISM-17150.69Guidelines for Personnel Security › Emergency access to systemsBreak glass event logs are stored centrally.
ISM-17570.66Guidelines for Software Development › Web application event loggingWeb application event logs are stored centrally.
ISM-17470.66Guidelines for System Hardening › Operating system event loggingOperating system event logs are stored centrally.
ISM-16510.65Guidelines for Personnel Security › Privileged access to systemsPrivileged access event logs are stored centrally.
ISM-16630.64Guidelines for System Hardening › Application controlApplication control event logs are stored centrally.
ISM-17140.64Guidelines for Personnel Security › Unprivileged access to systemsUnprivileged access event logs are stored centrally.
ISM-05180.63Guidelines for Networking › Network documentationNetwork documentation is developed, implemented, maintained.
ISM-16780.63Guidelines for System Hardening › Microsoft Office macrosMicrosoft Office macro event logs are stored centrally.
ISM-16840.60Guidelines for System Hardening › Multi-factor authenticationMulti-factor authentication event logs are stored centrally.
ISM-16520.59Guidelines for Personnel Security › Privileged access to systemsPrivileged account and group management event logs are stored centrally.
ISM-10190.58Guidelines for Communications Systems › Denial of service response planA denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.
ISM-13040.51Guidelines for Networking › Default accounts and credentials for network devicesDefault accounts or credentials for network devices including for any pre-configured accounts, are changed.
ISM-04180.49Guidelines for System Hardening › Protecting credentialsCredentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.
ISM-15960.44Guidelines for System Hardening › Setting credentials for user accountsCredentials, in the form of memorised secrets, are not reused by users across different systems.
ISM-17080.39Guidelines for System Management › Backup modification and deletionPrivileged accounts (including backup administrator accounts) are prevented from modifying and deleting backups during their retention period.
ISM-17820.39Guidelines for Networking › Protective Domain Name System ServicesA protective DNS service is used to block access to known malicious domain names.
ISM-13000.36Guidelines for Enterprise Mobility › After travelling overseas with mobile devicesUpon returning from travelling overseas with mobile devices, personnel take the following actions: * sanitise and reset mobile devices, including all …
ISM-05760.35Guidelines for Cyber Security Incidents › Incident management policyAn incident management policy, and associated incident response plan, is developed, implemented and maintained.
ISM-14080.35Guidelines for System Hardening › Operating system releases and versionsWhere supported, 64-bit versions of operating systems are used.
ISM-15150.33Guidelines for System Management › Testing restoration of backupsRestoration of important data, software and configuration settings from backups to a common point of time is tested as part of disaster recovery exerc…
ISM-03830.29Guidelines for System Hardening › Hardening operating system configurationsDefault accounts or credentials for operating systems, including for any pre-configured accounts, are changed.
ISM-06690.29Guidelines for Data Transfers › Manual export of dataWhen manually exporting data from SECRET and TOP SECRET systems, digital signatures are validated and keyword checks are performed within all textual …
ISM-17050.29Guidelines for System Management › Backup accessPrivileged accounts (excluding backup administrator accounts) cannot access backups belonging to other accounts.
ISM-16500.28Guidelines for Personnel Security › Privileged access to systemsPrivileged account and group management events are logged.
ISM-15090.27Guidelines for Personnel Security › Privileged access to systemsPrivileged access events are logged.

Clarifications (66)

ControlEdit distLocation
ISM-14070.23Guidelines for System Hardening › Operating system releases and versions
ISM-17060.22Guidelines for System Management › Backup access
ISM-00720.21Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-12340.20Guidelines for Email › Email content filtering
ISM-15430.20Guidelines for Physical Security › Bringing Radio Frequency and infrared devices into facilities
ISM-14930.19Guidelines for System Management › Software register
ISM-02580.19Guidelines for Gateways › Web usage policy
ISM-14050.18Guidelines for System Monitoring › Centralised event logging facility
ISM-17070.18Guidelines for System Management › Backup modification and deletion
ISM-02640.18Guidelines for Email › Email usage policy
ISM-17940.17Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-05800.17Guidelines for System Monitoring › Event logging policy
ISM-00390.16Guidelines for Security Documentation › Cyber security strategy
ISM-15490.16Guidelines for Media › Media management policy
ISM-16250.16Guidelines for Cyber Security Incidents › Trusted insider program
ISM-17860.16Guidelines for Procurement and Outsourcing › Supplier relationship management
ISM-02110.16Guidelines for Communications Infrastructure › Cable register
ISM-16310.16Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities
ISM-10820.16Guidelines for Enterprise Mobility › Mobile device usage policy
ISM-12430.15Guidelines for Database Systems › Database register
ISM-15100.15Guidelines for System Management › Digital preservation policy
ISM-16450.15Guidelines for Communications Infrastructure › Floor plan diagrams
ISM-13590.15Guidelines for Media › Removable media usage policy
ISM-10780.15Guidelines for Communications Systems › Telephone system usage policy
ISM-15330.14Guidelines for Enterprise Mobility › Mobile device management policy
ISM-17550.14Guidelines for Software Development › Vulnerability disclosure program
ISM-03360.14Guidelines for ICT Equipment › ICT equipment register
ISM-05880.14Guidelines for Communications Systems › Fax machine and multifunction device usage policy
ISM-15510.14Guidelines for ICT Equipment › ICT equipment management policy
ISM-17130.14Guidelines for Media › Removable media register
ISM-17360.14Guidelines for Procurement and Outsourcing › Managed services
ISM-14510.13Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-17850.13Guidelines for Procurement and Outsourcing › Supplier relationship management
ISM-16370.13Guidelines for Procurement and Outsourcing › Outsourced cloud services
ISM-13110.12Guidelines for Networking › Use of Simple Network Management Protocol
ISM-13950.12Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-07350.12Guidelines for Cyber Security Roles › Overseeing cyber security awareness raising
ISM-09630.11Guidelines for Gateways › Using web content filters
ISM-15110.11Guidelines for System Management › Performing and retaining backups
ISM-15710.10Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-15470.10Guidelines for System Management › Data backup and restoration processes and procedures
ISM-15350.10Guidelines for Data Transfers › Data transfer processes and procedures
ISM-06630.10Guidelines for Data Transfers › Data transfer processes and procedures
ISM-03740.10Guidelines for Media › Media disposal processes and procedures
ISM-15730.10Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-02060.09Guidelines for Communications Infrastructure › Cable labelling processes and procedures
ISM-11430.09Guidelines for System Management › Patch management processes and procedures
ISM-15480.09Guidelines for System Management › Data backup and restoration processes and procedures
ISM-03630.09Guidelines for Media › Media destruction processes and procedures
ISM-03480.09Guidelines for Media › Media sanitisation processes and procedures
ISM-00420.08Guidelines for System Management › System administration processes and procedures
ISM-15500.08Guidelines for ICT Equipment › ICT equipment disposal processes and procedures
ISM-15720.08Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-17560.08Guidelines for Software Development › Vulnerability disclosure program
ISM-17410.08Guidelines for ICT Equipment › ICT equipment destruction processes and procedures
ISM-03130.08Guidelines for ICT Equipment › ICT equipment sanitisation processes and procedures
ISM-17880.08Guidelines for Procurement and Outsourcing › Sourcing applications, ICT equipment and services
ISM-05070.08Guidelines for Cryptography › Cryptographic key management processes and procedures
ISM-15750.08Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-17380.08Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-17890.07Guidelines for Procurement and Outsourcing › Sourcing applications, ICT equipment and services
ISM-07010.07Guidelines for Enterprise Mobility › Mobile device emergency sanitisation processes and procedures
ISM-15740.06Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-07200.06Guidelines for Cyber Security Roles › Developing a cyber security communications strategy
ISM-16640.06Guidelines for System Hardening › PowerShell
ISM-01410.05Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers

Editorial / grammatical (9)

Cosmetic edits (normalised edit distance < 0.05). ISM-0428, ISM-1556, ISM-1660, ISM-1661, ISM-1662, ISM-1677, ISM-1683, ISM-1685, ISM-1787

Relocated (24)

0 cross-chapter moves (listed) · 24 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (1)

ControlDirectionFootprint before → afterLocation
ISM-1776narrowedNC|OS|P|S|TSS|TSCross Domain Solution event logging

Removed (3)

ControlFootprintFormer locationStatement (excerpt)
ISM-0658S|TSGuidelines for Data TransfersWhen manually importing data to SECRET and TOP SECRET systems, the data undergoes data formatting checks.
ISM-1709NC|OS|P|S|TSGuidelines for NetworkingDefault accounts and credentials of wireless access points are changed.
ISM-1744NC|OS|P|S|TSGuidelines for System HardeningThe latest release, or the previous release, of operating systems are used for other ICT equipment.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.