ASD ISM — incremental change analysis

Release v2023.03.3 (2023-03-03) vs prior v2022.12.1 · 92 days · catalogue 877 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
33
Added
21
Substantive
18
Clarification
4
Editorial
50
Relocated
10
Scope changes
6
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET533
SECRET13
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified048

3 · Level-specific material changes

FootprintFloorCeilingControls
SSECRETSECRETISM-0187
TSTOP SECRETTOP SECRETISM-1821 ISM-0216 ISM-1116
S|TSSECRETTOP SECRETISM-0213 ISM-1105

4 · Change location by chapter

5 · Section / topic structure

New sections: 2 · Removed sections: 3 · New topics: 11 · Removed topics: 5. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for System HardeningServer application hardening29ISM-1826 ISM-1483 ISM-1246 ISM-1260 ISM-1247 ISM-1245 ISM-1249 ISM-1250 ISM-1827 ISM-1828 ISM-1829 ISM-1830 ISM-1831 ISM-1832 ISM-1833 ISM-1834 ISM-1835 ISM-1836 ISM-1837 ISM-1838 ISM-1839 ISM-1840 ISM-1841 ISM-1842 ISM-1843 ISM-1844 ISM-1620 ISM-1845 ISM-1846
Guidelines for System HardeningUser application hardening31ISM-0938 ISM-1467 ISM-1806 ISM-1412 ISM-1470 ISM-1235 ISM-1667 ISM-1668 ISM-1669 ISM-1542 ISM-1823 ISM-1486 ISM-1485 ISM-1666 ISM-1585 ISM-1670 ISM-1824 ISM-1601 ISM-1748 ISM-1825 ISM-1671 ISM-1488 ISM-1672 ISM-1673 ISM-1674 ISM-1487 ISM-1675 ISM-1676 ISM-1489 ISM-1677 ISM-1678

Removed sections

ChapterSection
Guidelines for Cyber Security IncidentsReporting cyber security incidents
Guidelines for Database SystemsDatabase management system software
Guidelines for System HardeningApplication hardening

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for Communications InfrastructureCabling infrastructureCommon cable bundles and conduits2ISM-0187 ISM-1821
Guidelines for Communications InfrastructureCabling infrastructureCommon cable reticulation systems1ISM-1114
Guidelines for Communications InfrastructureCabling infrastructureTerminating cables on patch panels1ISM-0213
Guidelines for Cyber Security IncidentsManaging cyber security incidentsReporting cyber security incidents1ISM-0123
Guidelines for Cyber Security IncidentsManaging cyber security incidentsReporting cyber security incidents to the ACSC1ISM-0140
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsEnacting incident response plans1ISM-1819
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsMaintaining the integrity of evidence1ISM-0138
Guidelines for Software DevelopmentApplication developmentApplication security testing2ISM-0402 ISM-1754
Guidelines for Software DevelopmentWeb application developmentOpen Web Application Security Projects3ISM-0971 ISM-1849 ISM-1850
Guidelines for System HardeningAuthentication hardeningChanging credentials2ISM-1590 ISM-1847
Guidelines for System HardeningAuthentication hardeningSetting credentials for local administrator accounts and service accounts3ISM-1685 ISM-1619 ISM-1795

Removed topics

ChapterSectionTopic
Guidelines for Communications InfrastructureCabling infrastructureCommon cable reticulation systems and conduits
Guidelines for Communications InfrastructureCabling infrastructureTerminating cable groups on patch panels
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsIntegrity of evidence
Guidelines for Software DevelopmentApplication developmentApplication testing and maintenance
Guidelines for Software DevelopmentWeb application developmentOpen Web Application Security Project

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for System HardeningServer application hardening2152129
Guidelines for Communications InfrastructureCabling infrastructure355013
Guidelines for System HardeningUser application hardening32117
Guidelines for Software DevelopmentWeb application development31206
Guidelines for System HardeningOperating system hardening01113
Guidelines for Cyber Security IncidentsResponding to cyber security incidents11002
Guidelines for System HardeningAuthentication hardening10102
Guidelines for System HardeningVirtualisation hardening10102
Guidelines for Software DevelopmentApplication development02002
Guidelines for System MonitoringEvent logging and monitoring01102
Guidelines for Database SystemsDatabases01102
Guidelines for Communications SystemsTelephone systems01001
Guidelines for Evaluated ProductsEvaluated product procurement00101
Guidelines for GatewaysContent filtering00101
Guidelines for Security DocumentationSystem-specific security documentation00101
Guidelines for Personnel SecurityAccess to systems and their resources01001
Guidelines for Procurement and OutsourcingCyber supply chain risk management00011

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services account hardening1300013
Guidelines for System HardeningUser application hardeningHardening user application configurations31116
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services domain controllers50005
Guidelines for System HardeningServer application hardeningHardening server application configurations03104
Guidelines for Communications InfrastructureCabling infrastructureCable colours10203
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services security group memberships20013
Guidelines for Software DevelopmentWeb application developmentOpen Web Application Security Projects20103
Guidelines for Software DevelopmentWeb application developmentWeb application programming interfaces11103
Guidelines for Communications InfrastructureCabling infrastructurePhysical separation of cabinets and patch panels02103
Guidelines for Communications InfrastructureCabling infrastructureCommon cable bundles and conduits11002
Guidelines for System HardeningVirtualisation hardeningFunctional separation between computing environments10102
Guidelines for System MonitoringEvent logging and monitoringEvent log retention01102
Guidelines for System HardeningServer application hardeningRestricting privileges for server applications01102
Guidelines for Database SystemsDatabasesWeb application interaction with databases01102
Guidelines for System HardeningOperating system hardeningApplication control00112
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsEnacting incident response plans10001
Guidelines for Communications InfrastructureCabling infrastructureWall outlet box colours10001
Guidelines for System HardeningServer application hardeningServer application selection10001
Guidelines for System HardeningAuthentication hardeningChanging credentials10001
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsMaintaining the integrity of evidence01001
Guidelines for Communications InfrastructureCabling infrastructureTerminating cables on patch panels01001
Guidelines for Communications SystemsTelephone systemsCordless telephone systems01001
Guidelines for Evaluated ProductsEvaluated product procurementEvaluated product selection00101
Guidelines for Software DevelopmentApplication developmentSecure software design and development01001
Guidelines for Software DevelopmentApplication developmentApplication security testing01001
Guidelines for GatewaysContent filteringValidating file integrity00101
Guidelines for System HardeningUser application hardeningUser application selection01001
Guidelines for Communications InfrastructureCabling infrastructureTerminating cables in cabinets00101
Guidelines for Communications InfrastructureCabling infrastructureWall outlet boxes01001
Guidelines for Communications InfrastructureCabling infrastructureCommon cable reticulation systems00101
Guidelines for Security DocumentationSystem-specific security documentationContinuous monitoring plan00101
Guidelines for Personnel SecurityAccess to systems and their resourcesPrivileged access to systems01001
Guidelines for System HardeningServer application hardeningServer application releases01001
Guidelines for Procurement and OutsourcingCyber supply chain risk managementCyber supply chain risk management activities00011
Guidelines for System HardeningAuthentication hardeningMulti-factor authentication00101
Guidelines for System HardeningOperating system hardeningOperating system selection01001

6 · Control call-outs by category

Added — new controls (33)

ControlFootprintLocationStatement (excerpt)
ISM-1819NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Enacting incident response plansFollowing the identification of a cyber security incident, an organisation’s incident response plan is enacted.
ISM-1820NC|OS|P|S|TSGuidelines for Communications Infrastructure › Cable coloursCables for individual systems use a consistent colour.
ISM-1821TSGuidelines for Communications Infrastructure › Common cable bundles and conduitsTOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
ISM-1822NC|OS|P|S|TSGuidelines for Communications Infrastructure › Wall outlet box coloursWall outlet boxes for individual systems use a consistent colour.
ISM-1823NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsOffice productivity suite security settings cannot be changed by users.
ISM-1824NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsPDF software security settings cannot be changed by users.
ISM-1825NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsSecurity product security settings cannot be changed by users.
ISM-1826NC|OS|P|S|TSGuidelines for System Hardening › Server application selectionServer applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-sa…
ISM-1827NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersMicrosoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
ISM-1828NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersThe Print Spooler service is disabled on Microsoft AD DS domain controllers.
ISM-1829NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersPasswords and cpasswords are not used in Group Policy Preferences.
ISM-1830NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersSecurity-related events for Microsoft AD DS are logged.
ISM-1831NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersMicrosoft AD DS event logs are stored centrally.
ISM-1832NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningOnly service accounts and computer accounts are configured with Service Principal Names (SPNs).
ISM-1833NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningService accounts are provisioned with the minimum privileges required and are not members of the domain administrators group or similar highly privile…
ISM-1834NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningDuplicate SPNs do not exist within the domain.
ISM-1835NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningPrivileged user accounts are configured as sensitive and cannot be delegated.
ISM-1836NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts require Kerberos pre-authentication.
ISM-1837NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are not configured with password never expires or password not required.
ISM-1838NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe UserPassword attribute for user accounts is not used.
ISM-1839NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningAccount properties accessible by unprivileged users are not used to store passwords.
ISM-1840NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser account passwords do not use reversible encryption.
ISM-1841NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUnprivileged user accounts cannot add machines to the domain.
ISM-1842NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningDedicated service accounts are used to add machines to the domain.
ISM-1843NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts with unconstrained delegation are reviewed at least annually, and those without an associated Kerberos SPN or demonstrated business requ…
ISM-1844NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningComputer accounts that are not Microsoft AD SD domain controllers are not trusted for delegation to services.
ISM-1845NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsWhen a user account is disabled, it is removed from all security group memberships.
ISM-1846NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe Pre-Windows 2000 Compatible Access security group does not contain user accounts.
ISM-1847NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsCredentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft Active Di…
ISM-1848NC|OS|P|S|TSGuidelines for System Hardening › Functional separation between computing environmentsWhen using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism or underlying operating system is repla…
ISM-1849NC|OS|P|S|TSGuidelines for Software Development › Open Web Application Security ProjectsThe OWASP Top Ten Proactive Controls are used in the development of web applications.
ISM-1850NC|OS|P|S|TSGuidelines for Software Development › Open Web Application Security ProjectsThe OWASP Top 10 are mitigated in the development of web applications.
ISM-1851NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesThe OWASP API Security Top 10 are mitigated in the development of web APIs.

Substantive amendments (21)

ControlEdit distLocationStatement (excerpt)
ISM-04020.89Guidelines for Software Development › Application security testingApplications are comprehensively tested for security vulnerabilities, using both static application security testing and dynamic application security …
ISM-08590.74Guidelines for System Monitoring › Event log retentionEvent logs, excluding those for Domain Name System services and web proxies, are retained for at least seven years.
ISM-11050.73Guidelines for Communications Infrastructure › Wall outlet boxesSECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.
ISM-12460.68Guidelines for System Hardening › Hardening server application configurationsACSC or vendor hardening guidance for server applications is implemented.
ISM-12600.62Guidelines for System Hardening › Hardening server application configurationsDefault accounts or credentials for server applications, including for any pre-configured accounts, are changed.
ISM-12630.55Guidelines for Personnel Security › Privileged access to systemsUnique privileged accounts are used for administering individual server applications.
ISM-01870.50Guidelines for Communications Infrastructure › Common cable bundles and conduitsSECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
ISM-01380.47Guidelines for Cyber Security Incidents › Maintaining the integrity of evidenceThe integrity of evidence gathered during an investigation is maintained by investigators: * recording all of their actions * maintaining a proper cha…
ISM-02130.43Guidelines for Communications Infrastructure › Terminating cables on patch panelsSECRET and TOP SECRET cables are terminated on their own individual patch panels.
ISM-02160.43Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panelsTOP SECRET patch panels are installed in individual TOP SECRET cabinets.
ISM-14830.39Guidelines for System Hardening › Server application releasesThe latest release of internet-facing server applications are used.
ISM-09380.36Guidelines for System Hardening › User application selectionUser applications are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe…
ISM-12450.35Guidelines for System Hardening › Hardening server application configurationsAll temporary installation files and logs created during server application installation processes are removed after server applications have been ins…
ISM-11160.35Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panelsA visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
ISM-17430.34Guidelines for System Hardening › Operating system selectionOperating systems are chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe…
ISM-18180.33Guidelines for Software Development › Web application programming interfacesAuthentication and authorisation of clients is performed when clients call web APIs that facilitate modification of data.
ISM-12500.31Guidelines for System Hardening › Restricting privileges for server applicationsThe accounts under which server applications run have limited access to their underlying server’s file system.
ISM-17480.30Guidelines for System Hardening › Hardening user application configurationsEmail client security settings cannot be changed by users.
ISM-12760.30Guidelines for Database Systems › Web application interaction with databasesParameterised queries or stored procedures, instead of dynamically generated queries, are used for database interactions.
ISM-04010.28Guidelines for Software Development › Secure software design and developmentSecure-by-design and secure-by-default principles, use of memory-safe programming languages where possible, and secure programming practices are used …
ISM-02330.28Guidelines for Communications Systems › Cordless telephone systemsCordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted.

Clarifications (18)

ControlEdit distLocation
ISM-14600.25Guidelines for System Hardening › Functional separation between computing environments
ISM-15850.23Guidelines for System Hardening › Hardening user application configurations
ISM-18170.23Guidelines for Software Development › Web application programming interfaces
ISM-16820.23Guidelines for System Hardening › Multi-factor authentication
ISM-13920.23Guidelines for System Hardening › Application control
ISM-10980.22Guidelines for Communications Infrastructure › Terminating cables in cabinets
ISM-09910.20Guidelines for System Monitoring › Event log retention
ISM-11140.16Guidelines for Communications Infrastructure › Common cable reticulation systems
ISM-11630.15Guidelines for Security Documentation › Continuous monitoring plan
ISM-12470.14Guidelines for System Hardening › Hardening server application configurations
ISM-12490.14Guidelines for System Hardening › Restricting privileges for server applications
ISM-02800.12Guidelines for Evaluated Products › Evaluated product selection
ISM-09710.11Guidelines for Software Development › Open Web Application Security Projects
ISM-17190.10Guidelines for Communications Infrastructure › Cable colours
ISM-02170.10Guidelines for Communications Infrastructure › Physical separation of cabinets and patch panels
ISM-17180.09Guidelines for Communications Infrastructure › Cable colours
ISM-06770.06Guidelines for Gateways › Validating file integrity
ISM-12780.06Guidelines for Database Systems › Web application interaction with databases

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-1568, ISM-1620, ISM-1746, ISM-1806

Relocated (50)

7 cross-chapter moves (listed) · 43 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Database SystemsGuidelines for System HardeningISM-1245 ISM-1246 ISM-1247 ISM-1249 ISM-1250 ISM-1260
Guidelines for Database SystemsGuidelines for Personnel SecurityISM-1263

Scope / applicability changes (10)

ControlDirectionFootprint before → afterLocation
ISM-0187narrowedS|TSSCommon cable bundles and conduits
ISM-0213narrowedNC|OS|P|S|TSS|TSTerminating cables on patch panels
ISM-0216narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-0217narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-1098narrowedNC|OS|P|S|TSSTerminating cables in cabinets
ISM-1101widenedOS|P|S|TSNC|OS|P|S|TSConnecting cable reticulation systems to cabinets
ISM-1103widenedOS|P|S|TSNC|OS|P|S|TSConnecting cable reticulation systems to cabinets
ISM-1105narrowedNC|OS|P|S|TSS|TSWall outlet boxes
ISM-1116narrowedOS|P|S|TSTSPhysical separation of cabinets and patch panels
ISM-1119widenedOS|P|S|TSNC|OS|P|S|TSCable inspectability

Removed (6)

ControlFootprintFormer locationStatement (excerpt)
ISM-0189NC|OS|P|S|TSGuidelines for Communications InfrastructureCables only carry a single cable group, unless each cable group belongs to a different subunit.
ISM-1104NC|OS|P|S|TSGuidelines for Communications InfrastructureWall outlet boxes have connectors on opposite sides of the wall outlet box if the cable group contains cables belonging to different systems.
ISM-1251NC|OS|P|S|TSGuidelines for Database SystemsThe ability of DBMS software to read local files from its database server is disabled.
ISM-1261NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrator accounts are not shared across different databases.
ISM-1262NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrators have unique and identifiable accounts.
ISM-1264NC|OS|P|S|TSGuidelines for Database SystemsDatabase administrator access is restricted to defined roles rather than accounts with default administrative permissions or all permissions.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.