ASD ISM — incremental change analysis

Release v2023.03.3 (2023-03-03) vs prior v2022.12.1 · 92 days · catalogue 877 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
33
Added
21
Substantive
18
Clarification
4
Editorial
50
Relocated
10
Scope changes
6
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET533
SECRET13
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified048

3 · Level-specific material changes

FootprintFloorCeilingControls
SSECRETSECRETISM-0187
TSTOP SECRETTOP SECRETISM-1821 ISM-0216 ISM-1116
S|TSSECRETTOP SECRETISM-0213 ISM-1105

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (33)

ControlFootprintLocationStatement (excerpt)
ISM-1819NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Enacting incident response plansFollowing the identification of a cyber security incident, an organisation’s incident response plan is enacted.
ISM-1820NC|OS|P|S|TSGuidelines for Communications Infrastructure › Cable coloursCables for individual systems use a consistent colour.
ISM-1821TSGuidelines for Communications Infrastructure › Common cable bundles and conduitsTOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
ISM-1822NC|OS|P|S|TSGuidelines for Communications Infrastructure › Wall outlet box coloursWall outlet boxes for individual systems use a consistent colour.
ISM-1823NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsOffice productivity suite security settings cannot be changed by users.
ISM-1824NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsPDF software security settings cannot be changed by users.
ISM-1825NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsSecurity product security settings cannot be changed by users.
ISM-1826NC|OS|P|S|TSGuidelines for System Hardening › Server application selectionServer applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-sa…
ISM-1827NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersMicrosoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
ISM-1828NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersThe Print Spooler service is disabled on Microsoft AD DS domain controllers.
ISM-1829NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersPasswords and cpasswords are not used in Group Policy Preferences.
ISM-1830NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersSecurity-related events for Microsoft AD DS are logged.
ISM-1831NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersMicrosoft AD DS event logs are stored centrally.
ISM-1832NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningOnly service accounts and computer accounts are configured with Service Principal Names (SPNs).
ISM-1833NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningService accounts are provisioned with the minimum privileges required and are not members of the domain administrators group or similar highly privile…
ISM-1834NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningDuplicate SPNs do not exist within the domain.
ISM-1835NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningPrivileged user accounts are configured as sensitive and cannot be delegated.
ISM-1836NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts require Kerberos pre-authentication.
ISM-1837NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are not configured with password never expires or password not required.
ISM-1838NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe UserPassword attribute for user accounts is not used.
ISM-1839NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningAccount properties accessible by unprivileged users are not used to store passwords.
ISM-1840NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser account passwords do not use reversible encryption.
ISM-1841NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUnprivileged user accounts cannot add machines to the domain.
ISM-1842NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningDedicated service accounts are used to add machines to the domain.
ISM-1843NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts with unconstrained delegation are reviewed at least annually, and those without an associated Kerberos SPN or demonstrated business requ…
ISM-1844NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningComputer accounts that are not Microsoft AD SD domain controllers are not trusted for delegation to services.
ISM-1845NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsWhen a user account is disabled, it is removed from all security group memberships.
ISM-1846NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe Pre-Windows 2000 Compatible Access security group does not contain user accounts.
ISM-1847NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsCredentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft Active Di…
ISM-1848NC|OS|P|S|TSGuidelines for System Hardening › Functional separation between computing environmentsWhen using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism or underlying operating system is repla…
ISM-1849NC|OS|P|S|TSGuidelines for Software Development › Open Web Application Security ProjectsThe OWASP Top Ten Proactive Controls are used in the development of web applications.
ISM-1850NC|OS|P|S|TSGuidelines for Software Development › Open Web Application Security ProjectsThe OWASP Top 10 are mitigated in the development of web applications.
ISM-1851NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesThe OWASP API Security Top 10 are mitigated in the development of web APIs.

Substantive amendments (21)

ControlEdit distLocationStatement (excerpt)
ISM-04020.89Guidelines for Software Development › Application security testingApplications are comprehensively tested for security vulnerabilities, using both static application security testing and dynamic application security …
ISM-08590.74Guidelines for System Monitoring › Event log retentionEvent logs, excluding those for Domain Name System services and web proxies, are retained for at least seven years.
ISM-11050.73Guidelines for Communications Infrastructure › Wall outlet boxesSECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.
ISM-12460.68Guidelines for System Hardening › Hardening server application configurationsACSC or vendor hardening guidance for server applications is implemented.
ISM-12600.62Guidelines for System Hardening › Hardening server application configurationsDefault accounts or credentials for server applications, including for any pre-configured accounts, are changed.
ISM-12630.55Guidelines for Personnel Security › Privileged access to systemsUnique privileged accounts are used for administering individual server applications.
ISM-01870.50Guidelines for Communications Infrastructure › Common cable bundles and conduitsSECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
ISM-01380.47Guidelines for Cyber Security Incidents › Maintaining the integrity of evidenceThe integrity of evidence gathered during an investigation is maintained by investigators: * recording all of their actions * maintaining a proper cha…
ISM-02130.43Guidelines for Communications Infrastructure › Terminating cables on patch panelsSECRET and TOP SECRET cables are terminated on their own individual patch panels.
ISM-02160.43Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panelsTOP SECRET patch panels are installed in individual TOP SECRET cabinets.
ISM-14830.39Guidelines for System Hardening › Server application releasesThe latest release of internet-facing server applications are used.
ISM-09380.36Guidelines for System Hardening › User application selectionUser applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe…
ISM-12450.35Guidelines for System Hardening › Hardening server application configurationsAll temporary installation files and logs created during server application installation processes are removed after server applications have been ins…
ISM-11160.35Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panelsA visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
ISM-17430.34Guidelines for System Hardening › Operating system selectionOperating systems are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe…
ISM-18180.33Guidelines for Software Development › Web application programming interfacesAuthentication and authorisation of clients is performed when clients call web APIs that facilitate modification of data.
ISM-12500.31Guidelines for System Hardening › Restricting privileges for server applicationsThe accounts under which server applications run have limited access to their underlying server’s file system.
ISM-17480.30Guidelines for System Hardening › Hardening user application configurationsEmail client security settings cannot be changed by users.
ISM-12760.30Guidelines for Database Systems › Web application interaction with databasesParameterised queries or stored procedures, instead of dynamically generated queries, are used for database interactions.
ISM-04010.28Guidelines for Software Development › Secure software design and developmentSecure-by-design and secure-by-default principles, use of memory-safe programming languages where possible, and secure programming practices are used …
ISM-02330.28Guidelines for Communications Systems › Cordless telephone systemsCordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted.

Clarifications (18)

ControlEdit distLocation
ISM-14600.25Guidelines for System Hardening › Functional separation between computing environments
ISM-15850.23Guidelines for System Hardening › Hardening user application configurations
ISM-18170.23Guidelines for Software Development › Web application programming interfaces
ISM-16820.23Guidelines for System Hardening › Multi-factor authentication
ISM-13920.23Guidelines for System Hardening › Application control
ISM-10980.22Guidelines for Communications Infrastructure › Terminating cables in cabinets
ISM-09910.20Guidelines for System Monitoring › Event log retention
ISM-11140.16Guidelines for Communications Infrastructure › Common cable reticulation systems
ISM-11630.15Guidelines for Security Documentation › Continuous monitoring plan
ISM-12470.14Guidelines for System Hardening › Hardening server application configurations
ISM-12490.14Guidelines for System Hardening › Restricting privileges for server applications
ISM-02800.12Guidelines for Evaluated Products › Evaluated product selection
ISM-09710.11Guidelines for Software Development › Open Web Application Security Projects
ISM-17190.10Guidelines for Communications Infrastructure › Cable colours
ISM-02170.10Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panels
ISM-17180.09Guidelines for Communications Infrastructure › Cable colours
ISM-06770.06Guidelines for Gateways › Validating file integrity
ISM-12780.06Guidelines for Database Systems › Web application interaction with databases

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-1568, ISM-1620, ISM-1746, ISM-1806

Relocated (50)

7 cross-chapter moves (listed) · 43 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Database SystemsGuidelines for System HardeningISM-1245 ISM-1246 ISM-1247 ISM-1249 ISM-1250 ISM-1260
Guidelines for Database SystemsGuidelines for Personnel SecurityISM-1263

Scope / applicability changes (10)

ControlDirectionFootprint before → afterLocation
ISM-0187narrowedS|TSSCommon cable bundles and conduits
ISM-0213narrowedNC|OS|P|S|TSS|TSTerminating cables on patch panels
ISM-0216narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-0217narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-1098narrowedNC|OS|P|S|TSSTerminating cables in cabinets
ISM-1101widenedOS|P|S|TSNC|OS|P|S|TSConnecting cable reticulation systems to cabinets
ISM-1103widenedOS|P|S|TSNC|OS|P|S|TSConnecting cable reticulation systems to cabinets
ISM-1105narrowedNC|OS|P|S|TSS|TSWall outlet boxes
ISM-1116narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-1119widenedOS|P|S|TSNC|OS|P|S|TSCable inspectability

Removed (6)

ControlFootprintFormer locationStatement (excerpt)
ISM-0189NC|OS|P|S|TSGuidelines for Communications InfrastructureCables only carry a single cable group, unless each cable group belongs to a different subunit.
ISM-1104NC|OS|P|S|TSGuidelines for Communications InfrastructureWall outlet boxes have connectors on opposite sides of the wall outlet box if the cable group contains cables belonging to different systems.
ISM-1251NC|OS|P|S|TSGuidelines for Database SystemsThe ability of DBMS software to read local files from its database server is disabled.
ISM-1261NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrator accounts are not shared across different databases.
ISM-1262NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrators have unique and identifiable accounts.
ISM-1264NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrator access is restricted to defined roles rather than accounts with default administrative permissions or all permissions.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.