ASD ISM — incremental change analysis

Release v2023.06.29 (2023-06-29) vs prior v2023.04.12 · 78 days · catalogue 883 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
12
Added
7
Substantive
22
Clarification
3
Editorial
13
Relocated
0
Scope changes
6
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET190
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified019

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (12)

ControlFootprintLocationStatement (excerpt)
ISM-1852NC|OS|P|S|TSGuidelines for Personnel Security › Unprivileged access to systemsUnprivileged access to systems, applications and data repositories is limited to only what is required for users and services to undertake their dutie…
ISM-1853NC|OS|P|S|TSGuidelines for Personnel Security › Privileged access to systemsPrivileged access to data repositories is limited to only what is required for users and services to undertake their duties.
ISM-1854NC|OS|P|S|TSGuidelines for Communications Systems › Authenticating to multifunction devicesUsers authenticate to MFDs before they can print, scan or copy documents.
ISM-1855NC|OS|P|S|TSGuidelines for Communications Systems › Auditing multifunction device useUse of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are logged.
ISM-1856NC|OS|P|S|TSGuidelines for Communications Systems › Auditing multifunction device useMFD event logs are stored centrally.
ISM-1857NC|OS|P|S|TSGuidelines for ICT Equipment › ICT equipment selectionICT equipment is chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe prog…
ISM-1858NC|OS|P|S|TSGuidelines for ICT Equipment › Hardening ICT equipment configurationsACSC and vendor hardening guidance for ICT equipment is implemented.
ISM-1859NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsACSC or vendor hardening guidance for office productivity suites is implemented.
ISM-1860NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsACSC or vendor hardening guidance for PDF software is implemented.
ISM-1861NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsProtective Process Light for LSASS is enabled with a UEFI lock.
ISM-1862NC|OS|P|S|TSGuidelines for Software Development › Web application firewallsIf using a WAF, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to th…
ISM-1863NC|OS|P|S|TSGuidelines for Networking › Networked management interfacesNetworked management interfaces for ICT equipment are not directly exposed to the internet.

Substantive amendments (7)

ControlEdit distLocationStatement (excerpt)
ISM-05900.76Guidelines for Communications Systems › Authenticating to multifunction devicesAuthentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.
ISM-14310.63Guidelines for Networking › Denial-of-service attack mitigation strategiesDenial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: * their capacity to withstand denial-of-servi…
ISM-16930.54Guidelines for System Management › When to patch security vulnerabilitiesPatches, updates or vendor mitigations for security vulnerabilities in applications other than office productivity suites, web browsers and their exte…
ISM-14090.44Guidelines for System Hardening › Hardening operating system configurationsACSC and vendor hardening guidance for operating systems is implemented.
ISM-17000.38Guidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner is used at least fortnightly to identify missing patches or updates for security vulnerabilities in applications other than of…
ISM-01400.35Guidelines for Cyber Security Incidents › Reporting cyber security incidents to the ACSCCyber security incidents are reported to the ACSC as soon as possible after they occur or are discovered.
ISM-11630.25Guidelines for Security Documentation › Continuous monitoring planSystems have a continuous monitoring plan that includes: * conducting vulnerability scans for systems at least fortnightly * conducting vulnerability …

Clarifications (22)

ControlEdit distLocation
ISM-15790.23Guidelines for Networking › Capacity and availability planning and monitoring for online services
ISM-02890.23Guidelines for Evaluated Products › Using evaluated products
ISM-05890.23Guidelines for Communications Systems › Scanning and copying documents on multifunction devices
ISM-02900.22Guidelines for Evaluated Products › Using evaluated products
ISM-14120.21Guidelines for System Hardening › Hardening user application configurations
ISM-14030.20Guidelines for System Hardening › Account lockouts
ISM-15720.19Guidelines for Procurement and Outsourcing › Contractual security requirements with service providers
ISM-17520.16Guidelines for System Management › Scanning for missing patches or updates
ISM-14360.15Guidelines for Networking › Denial-of-service attack mitigation strategies
ISM-17510.14Guidelines for System Management › When to patch security vulnerabilities
ISM-10260.12Guidelines for Email › DomainKeys Identified Mail
ISM-13850.11Guidelines for System Management › Administrative infrastructure
ISM-17950.10Guidelines for System Hardening › Setting credentials for break glass accounts, local administrator accounts and service accounts
ISM-16850.09Guidelines for System Hardening › Setting credentials for break glass accounts, local administrator accounts and service accounts
ISM-15900.08Guidelines for System Hardening › Changing credentials
ISM-05740.08Guidelines for Email › Sender Policy Framework
ISM-15810.07Guidelines for Networking › Capacity and availability planning and monitoring for online services
ISM-11830.07Guidelines for Email › Sender Policy Framework
ISM-15400.07Guidelines for Email › Domain-based Message Authentication, Reporting and Conformance
ISM-16810.06Guidelines for System Hardening › Multi-factor authentication
ISM-06650.05Guidelines for Data Transfers › Authorising export of data
ISM-01230.05Guidelines for Cyber Security Incidents › Reporting cyber security incidents

Editorial / grammatical (3)

Cosmetic edits (normalised edit distance < 0.05). ISM-0142, ISM-1246, ISM-1432

Relocated (13)

0 cross-chapter moves (listed) · 13 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (6)

ControlFootprintFormer locationStatement (excerpt)
ISM-0292S|TSGuidelines for Evaluated ProductsHigh assurance ICT equipment is always operated in an evaluated configuration.
ISM-1435NC|OS|P|S|TSGuidelines for NetworkingAvailability monitoring with real-time alerting is implemented for online services to detect denial-of-service attacks and measure their impact.
ISM-1441NC|OS|P|S|TSGuidelines for NetworkingWhere a requirement for high availability exists for online services, a denial of service mitigation service is used.
ISM-1458NC|OS|P|S|TSGuidelines for NetworkingThe functionality and quality of online services, how to maintain such functionality, and what functionality can be lived without during a denial-of-s…
ISM-1518NC|OS|P|S|TSGuidelines for NetworkingA static version of a website is pre-prepared that requires minimal processing and bandwidth in order to facilitate at least a basic level of service …
ISM-1578NC|OS|P|S|TSGuidelines for NetworkingAn organisation is notified by cloud service providers of any change to configured regions or availability zones for online services.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.