| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 53 | 3 |
| SECRET | 1 | 3 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 0 |
| Non-Classified | 0 | 48 |
| Footprint | Floor | Ceiling | Controls |
|---|---|---|---|
S | SECRET | SECRET | ISM-0187 |
TS | TOP SECRET | TOP SECRET | ISM-1821 ISM-0216 ISM-1116 |
S|TS | SECRET | TOP SECRET | ISM-0213 ISM-1105 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for System Hardening | Server application hardening | 29 | ISM-1826 ISM-1483 ISM-1246 ISM-1260 ISM-1247 ISM-1245 ISM-1249 ISM-1250 ISM-1827 ISM-1828 ISM-1829 ISM-1830 ISM-1831 ISM-1832 ISM-1833 ISM-1834 ISM-1835 ISM-1836 ISM-1837 ISM-1838 ISM-1839 ISM-1840 ISM-1841 ISM-1842 ISM-1843 ISM-1844 ISM-1620 ISM-1845 ISM-1846 |
| Guidelines for System Hardening | User application hardening | 31 | ISM-0938 ISM-1467 ISM-1806 ISM-1412 ISM-1470 ISM-1235 ISM-1667 ISM-1668 ISM-1669 ISM-1542 ISM-1823 ISM-1486 ISM-1485 ISM-1666 ISM-1585 ISM-1670 ISM-1824 ISM-1601 ISM-1748 ISM-1825 ISM-1671 ISM-1488 ISM-1672 ISM-1673 ISM-1674 ISM-1487 ISM-1675 ISM-1676 ISM-1489 ISM-1677 ISM-1678 |
| Chapter | Section |
|---|---|
| Guidelines for Cyber Security Incidents | Reporting cyber security incidents |
| Guidelines for Database Systems | Database management system software |
| Guidelines for System Hardening | Application hardening |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for Communications Infrastructure | Cabling infrastructure | Common cable bundles and conduits | 2 | ISM-0187 ISM-1821 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Common cable reticulation systems | 1 | ISM-1114 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Terminating cables on patch panels | 1 | ISM-0213 |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | Reporting cyber security incidents | 1 | ISM-0123 |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | Reporting cyber security incidents to the ACSC | 1 | ISM-0140 |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | Enacting incident response plans | 1 | ISM-1819 |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | Maintaining the integrity of evidence | 1 | ISM-0138 |
| Guidelines for Software Development | Application development | Application security testing | 2 | ISM-0402 ISM-1754 |
| Guidelines for Software Development | Web application development | Open Web Application Security Projects | 3 | ISM-0971 ISM-1849 ISM-1850 |
| Guidelines for System Hardening | Authentication hardening | Changing credentials | 2 | ISM-1590 ISM-1847 |
| Guidelines for System Hardening | Authentication hardening | Setting credentials for local administrator accounts and service accounts | 3 | ISM-1685 ISM-1619 ISM-1795 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for Communications Infrastructure | Cabling infrastructure | Common cable reticulation systems and conduits |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Terminating cable groups on patch panels |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | Integrity of evidence |
| Guidelines for Software Development | Application development | Application testing and maintenance |
| Guidelines for Software Development | Web application development | Open Web Application Security Project |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for System Hardening | Server application hardening | 21 | 5 | 2 | 1 | 29 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | 3 | 5 | 5 | 0 | 13 |
| Guidelines for System Hardening | User application hardening | 3 | 2 | 1 | 1 | 7 |
| Guidelines for Software Development | Web application development | 3 | 1 | 2 | 0 | 6 |
| Guidelines for System Hardening | Operating system hardening | 0 | 1 | 1 | 1 | 3 |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | 1 | 1 | 0 | 0 | 2 |
| Guidelines for System Hardening | Authentication hardening | 1 | 0 | 1 | 0 | 2 |
| Guidelines for System Hardening | Virtualisation hardening | 1 | 0 | 1 | 0 | 2 |
| Guidelines for Software Development | Application development | 0 | 2 | 0 | 0 | 2 |
| Guidelines for System Monitoring | Event logging and monitoring | 0 | 1 | 1 | 0 | 2 |
| Guidelines for Database Systems | Databases | 0 | 1 | 1 | 0 | 2 |
| Guidelines for Communications Systems | Telephone systems | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Evaluated Products | Evaluated product procurement | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Gateways | Content filtering | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Security Documentation | System-specific security documentation | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Personnel Security | Access to systems and their resources | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | 0 | 0 | 0 | 1 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for System Hardening | Server application hardening | Microsoft Active Directory Domain Services account hardening | 13 | 0 | 0 | 0 | 13 |
| Guidelines for System Hardening | User application hardening | Hardening user application configurations | 3 | 1 | 1 | 1 | 6 |
| Guidelines for System Hardening | Server application hardening | Microsoft Active Directory Domain Services domain controllers | 5 | 0 | 0 | 0 | 5 |
| Guidelines for System Hardening | Server application hardening | Hardening server application configurations | 0 | 3 | 1 | 0 | 4 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Cable colours | 1 | 0 | 2 | 0 | 3 |
| Guidelines for System Hardening | Server application hardening | Microsoft Active Directory Domain Services security group memberships | 2 | 0 | 0 | 1 | 3 |
| Guidelines for Software Development | Web application development | Open Web Application Security Projects | 2 | 0 | 1 | 0 | 3 |
| Guidelines for Software Development | Web application development | Web application programming interfaces | 1 | 1 | 1 | 0 | 3 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Physical separation of cabinets and patch panels | 0 | 2 | 1 | 0 | 3 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Common cable bundles and conduits | 1 | 1 | 0 | 0 | 2 |
| Guidelines for System Hardening | Virtualisation hardening | Functional separation between computing environments | 1 | 0 | 1 | 0 | 2 |
| Guidelines for System Monitoring | Event logging and monitoring | Event log retention | 0 | 1 | 1 | 0 | 2 |
| Guidelines for System Hardening | Server application hardening | Restricting privileges for server applications | 0 | 1 | 1 | 0 | 2 |
| Guidelines for Database Systems | Databases | Web application interaction with databases | 0 | 1 | 1 | 0 | 2 |
| Guidelines for System Hardening | Operating system hardening | Application control | 0 | 0 | 1 | 1 | 2 |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | Enacting incident response plans | 1 | 0 | 0 | 0 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Wall outlet box colours | 1 | 0 | 0 | 0 | 1 |
| Guidelines for System Hardening | Server application hardening | Server application selection | 1 | 0 | 0 | 0 | 1 |
| Guidelines for System Hardening | Authentication hardening | Changing credentials | 1 | 0 | 0 | 0 | 1 |
| Guidelines for Cyber Security Incidents | Responding to cyber security incidents | Maintaining the integrity of evidence | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Terminating cables on patch panels | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Communications Systems | Telephone systems | Cordless telephone systems | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Evaluated Products | Evaluated product procurement | Evaluated product selection | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Software Development | Application development | Secure software design and development | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Software Development | Application development | Application security testing | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Gateways | Content filtering | Validating file integrity | 0 | 0 | 1 | 0 | 1 |
| Guidelines for System Hardening | User application hardening | User application selection | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Terminating cables in cabinets | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Wall outlet boxes | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Common cable reticulation systems | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Security Documentation | System-specific security documentation | Continuous monitoring plan | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Personnel Security | Access to systems and their resources | Privileged access to systems | 0 | 1 | 0 | 0 | 1 |
| Guidelines for System Hardening | Server application hardening | Server application releases | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Cyber supply chain risk management activities | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Hardening | Authentication hardening | Multi-factor authentication | 0 | 0 | 1 | 0 | 1 |
| Guidelines for System Hardening | Operating system hardening | Operating system selection | 0 | 1 | 0 | 0 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-1819 | NC|OS|P|S|TS | Guidelines for Cyber Security Incidents › Enacting incident response plans | Following the identification of a cyber security incident, an organisation’s incident response plan is enacted. |
| ISM-1820 | NC|OS|P|S|TS | Guidelines for Communications Infrastructure › Cable colours | Cables for individual systems use a consistent colour. |
| ISM-1821 | TS | Guidelines for Communications Infrastructure › Common cable bundles and conduits | TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit. |
| ISM-1822 | NC|OS|P|S|TS | Guidelines for Communications Infrastructure › Wall outlet box colours | Wall outlet boxes for individual systems use a consistent colour. |
| ISM-1823 | NC|OS|P|S|TS | Guidelines for System Hardening › Hardening user application configurations | Office productivity suite security settings cannot be changed by users. |
| ISM-1824 | NC|OS|P|S|TS | Guidelines for System Hardening › Hardening user application configurations | PDF software security settings cannot be changed by users. |
| ISM-1825 | NC|OS|P|S|TS | Guidelines for System Hardening › Hardening user application configurations | Security product security settings cannot be changed by users. |
| ISM-1826 | NC|OS|P|S|TS | Guidelines for System Hardening › Server application selection | Server applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-sa… |
| ISM-1827 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers | Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems. |
| ISM-1828 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers | The Print Spooler service is disabled on Microsoft AD DS domain controllers. |
| ISM-1829 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers | Passwords and cpasswords are not used in Group Policy Preferences. |
| ISM-1830 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers | Security-related events for Microsoft AD DS are logged. |
| ISM-1831 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers | Microsoft AD DS event logs are stored centrally. |
| ISM-1832 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Only service accounts and computer accounts are configured with Service Principal Names (SPNs). |
| ISM-1833 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Service accounts are provisioned with the minimum privileges required and are not members of the domain administrators group or similar highly privile… |
| ISM-1834 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Duplicate SPNs do not exist within the domain. |
| ISM-1835 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Privileged user accounts are configured as sensitive and cannot be delegated. |
| ISM-1836 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | User accounts require Kerberos pre-authentication. |
| ISM-1837 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | User accounts are not configured with password never expires or password not required. |
| ISM-1838 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | The UserPassword attribute for user accounts is not used. |
| ISM-1839 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Account properties accessible by unprivileged users are not used to store passwords. |
| ISM-1840 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | User account passwords do not use reversible encryption. |
| ISM-1841 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Unprivileged user accounts cannot add machines to the domain. |
| ISM-1842 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Dedicated service accounts are used to add machines to the domain. |
| ISM-1843 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | User accounts with unconstrained delegation are reviewed at least annually, and those without an associated Kerberos SPN or demonstrated business requ… |
| ISM-1844 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening | Computer accounts that are not Microsoft AD SD domain controllers are not trusted for delegation to services. |
| ISM-1845 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services security group memberships | When a user account is disabled, it is removed from all security group memberships. |
| ISM-1846 | NC|OS|P|S|TS | Guidelines for System Hardening › Microsoft Active Directory Domain Services security group memberships | The Pre-Windows 2000 Compatible Access security group does not contain user accounts. |
| ISM-1847 | NC|OS|P|S|TS | Guidelines for System Hardening › Changing credentials | Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft Active Di… |
| ISM-1848 | NC|OS|P|S|TS | Guidelines for System Hardening › Functional separation between computing environments | When using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism or underlying operating system is repla… |
| ISM-1849 | NC|OS|P|S|TS | Guidelines for Software Development › Open Web Application Security Projects | The OWASP Top Ten Proactive Controls are used in the development of web applications. |
| ISM-1850 | NC|OS|P|S|TS | Guidelines for Software Development › Open Web Application Security Projects | The OWASP Top 10 are mitigated in the development of web applications. |
| ISM-1851 | NC|OS|P|S|TS | Guidelines for Software Development › Web application programming interfaces | The OWASP API Security Top 10 are mitigated in the development of web APIs. |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-0402 | 0.89 | Guidelines for Software Development › Application security testing | Applications are comprehensively tested for security vulnerabilities, using both static application security testing and dynamic application security … |
| ISM-0859 | 0.74 | Guidelines for System Monitoring › Event log retention | Event logs, excluding those for Domain Name System services and web proxies, are retained for at least seven years. |
| ISM-1105 | 0.73 | Guidelines for Communications Infrastructure › Wall outlet boxes | SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables. |
| ISM-1246 | 0.68 | Guidelines for System Hardening › Hardening server application configurations | ACSC or vendor hardening guidance for server applications is implemented. |
| ISM-1260 | 0.62 | Guidelines for System Hardening › Hardening server application configurations | Default accounts or credentials for server applications, including for any pre-configured accounts, are changed. |
| ISM-1263 | 0.55 | Guidelines for Personnel Security › Privileged access to systems | Unique privileged accounts are used for administering individual server applications. |
| ISM-0187 | 0.50 | Guidelines for Communications Infrastructure › Common cable bundles and conduits | SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit. |
| ISM-0138 | 0.47 | Guidelines for Cyber Security Incidents › Maintaining the integrity of evidence | The integrity of evidence gathered during an investigation is maintained by investigators: * recording all of their actions * maintaining a proper cha… |
| ISM-0213 | 0.43 | Guidelines for Communications Infrastructure › Terminating cables on patch panels | SECRET and TOP SECRET cables are terminated on their own individual patch panels. |
| ISM-0216 | 0.43 | Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panels | TOP SECRET patch panels are installed in individual TOP SECRET cabinets. |
| ISM-1483 | 0.39 | Guidelines for System Hardening › Server application releases | The latest release of internet-facing server applications are used. |
| ISM-0938 | 0.36 | Guidelines for System Hardening › User application selection | User applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe… |
| ISM-1245 | 0.35 | Guidelines for System Hardening › Hardening server application configurations | All temporary installation files and logs created during server application installation processes are removed after server applications have been ins… |
| ISM-1116 | 0.35 | Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panels | A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets. |
| ISM-1743 | 0.34 | Guidelines for System Hardening › Operating system selection | Operating systems are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe… |
| ISM-1818 | 0.33 | Guidelines for Software Development › Web application programming interfaces | Authentication and authorisation of clients is performed when clients call web APIs that facilitate modification of data. |
| ISM-1250 | 0.31 | Guidelines for System Hardening › Restricting privileges for server applications | The accounts under which server applications run have limited access to their underlying server’s file system. |
| ISM-1748 | 0.30 | Guidelines for System Hardening › Hardening user application configurations | Email client security settings cannot be changed by users. |
| ISM-1276 | 0.30 | Guidelines for Database Systems › Web application interaction with databases | Parameterised queries or stored procedures, instead of dynamically generated queries, are used for database interactions. |
| ISM-0401 | 0.28 | Guidelines for Software Development › Secure software design and development | Secure-by-design and secure-by-default principles, use of memory-safe programming languages where possible, and secure programming practices are used … |
| ISM-0233 | 0.28 | Guidelines for Communications Systems › Cordless telephone systems | Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted. |
| Control | Edit dist | Location |
|---|---|---|
| ISM-1460 | 0.25 | Guidelines for System Hardening › Functional separation between computing environments |
| ISM-1585 | 0.23 | Guidelines for System Hardening › Hardening user application configurations |
| ISM-1817 | 0.23 | Guidelines for Software Development › Web application programming interfaces |
| ISM-1682 | 0.23 | Guidelines for System Hardening › Multi-factor authentication |
| ISM-1392 | 0.23 | Guidelines for System Hardening › Application control |
| ISM-1098 | 0.22 | Guidelines for Communications Infrastructure › Terminating cables in cabinets |
| ISM-0991 | 0.20 | Guidelines for System Monitoring › Event log retention |
| ISM-1114 | 0.16 | Guidelines for Communications Infrastructure › Common cable reticulation systems |
| ISM-1163 | 0.15 | Guidelines for Security Documentation › Continuous monitoring plan |
| ISM-1247 | 0.14 | Guidelines for System Hardening › Hardening server application configurations |
| ISM-1249 | 0.14 | Guidelines for System Hardening › Restricting privileges for server applications |
| ISM-0280 | 0.12 | Guidelines for Evaluated Products › Evaluated product selection |
| ISM-0971 | 0.11 | Guidelines for Software Development › Open Web Application Security Projects |
| ISM-1719 | 0.10 | Guidelines for Communications Infrastructure › Cable colours |
| ISM-0217 | 0.10 | Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panels |
| ISM-1718 | 0.09 | Guidelines for Communications Infrastructure › Cable colours |
| ISM-0677 | 0.06 | Guidelines for Gateways › Validating file integrity |
| ISM-1278 | 0.06 | Guidelines for Database Systems › Web application interaction with databases |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for Database Systems | Guidelines for System Hardening | ISM-1245 ISM-1246 ISM-1247 ISM-1249 ISM-1250 ISM-1260 |
| Guidelines for Database Systems | Guidelines for Personnel Security | ISM-1263 |
| Control | Direction | Footprint before → after | Location |
|---|---|---|---|
| ISM-0187 | narrowed | S|TS → S | Common cable bundles and conduits |
| ISM-0213 | narrowed | NC|OS|P|S|TS → S|TS | Terminating cables on patch panels |
| ISM-0216 | narrowed | OS|P|S|TS → TS | Physical separation of cabinets and patch panels |
| ISM-0217 | narrowed | OS|P|S|TS → TS | Physical separation of cabinets and patch panels |
| ISM-1098 | narrowed | NC|OS|P|S|TS → S | Terminating cables in cabinets |
| ISM-1101 | widened | OS|P|S|TS → NC|OS|P|S|TS | Connecting cable reticulation systems to cabinets |
| ISM-1103 | widened | OS|P|S|TS → NC|OS|P|S|TS | Connecting cable reticulation systems to cabinets |
| ISM-1105 | narrowed | NC|OS|P|S|TS → S|TS | Wall outlet boxes |
| ISM-1116 | narrowed | OS|P|S|TS → TS | Physical separation of cabinets and patch panels |
| ISM-1119 | widened | OS|P|S|TS → NC|OS|P|S|TS | Cable inspectability |
| Control | Footprint | Former location | Statement (excerpt) |
|---|---|---|---|
| ISM-0189 | NC|OS|P|S|TS | Guidelines for Communications Infrastructure | Cables only carry a single cable group, unless each cable group belongs to a different subunit. |
| ISM-1104 | NC|OS|P|S|TS | Guidelines for Communications Infrastructure | Wall outlet boxes have connectors on opposite sides of the wall outlet box if the cable group contains cables belonging to different systems. |
| ISM-1251 | NC|OS|P|S|TS | Guidelines for Database Systems | The ability of DBMS software to read local files from its database server is disabled. |
| ISM-1261 | NC|OS|P|S|TS | Guidelines for Database Systems | Database administrator accounts are not shared across different databases. |
| ISM-1262 | NC|OS|P|S|TS | Guidelines for Database Systems | Database administrators have unique and identifiable accounts. |
| ISM-1264 | NC|OS|P|S|TS | Guidelines for Database Systems | Database administrator access is restricted to defined roles rather than accounts with default administrative permissions or all permissions. |
revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.