ASD ISM — incremental change analysis

Release v2023.09.21 (2023-09-21) vs prior v2023.08.3 · 49 days · catalogue 898 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
16
Added
19
Substantive
36
Clarification
33
Editorial
38
Relocated
2
Scope changes
1
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET320
SECRET03
PROTECTED30
OFFICIAL: Sensitive05
Non-Classified027

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|POFFICIAL: SensitivePROTECTEDISM-1866 ISM-1867 ISM-1400
S|TSSECRETTOP SECRETISM-1868 ISM-0687 ISM-1802
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-0249 ISM-1482

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (16)

ControlFootprintLocationStatement (excerpt)
ISM-1864NC|OS|P|S|TSGuidelines for Personnel Security › System usage policyA system usage policy is developed, implemented and maintained.
ISM-1865NC|OS|P|S|TSGuidelines for Personnel Security › System access requirementsPersonnel agree to abide by usage policies associated with a system and its resources before being granted access to the system and its resources.
ISM-1866OS|PGuidelines for Enterprise Mobility › Privately-owned mobile devices and desktop computersPersonnel accessing OFFICIAL: Sensitive or PROTECTED systems or data using privately-owned mobile devices or desktop computers are prevented from stor…
ISM-1867OS|PGuidelines for Enterprise Mobility › Approved mobile platformsMobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation agai…
ISM-1868S|TSGuidelines for Enterprise Mobility › Data storageSECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand by ASD.
ISM-1869NC|OS|P|S|TSGuidelines for ICT Equipment › ICT equipment registersA non-networked ICT equipment register is developed, implemented, maintained and verified on a regular basis.
ISM-1870NC|OS|P|S|TSGuidelines for System Hardening › Application controlApplication control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.
ISM-1871NC|OS|P|S|TSGuidelines for System Hardening › Application controlApplication control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clien…
ISM-1872NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication used for online services is phishing-resistant.
ISM-1873NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication provided for online customer services offers a phishing-resistant option.
ISM-1874NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication provided for online customer services is phishing-resistant.
ISM-1875NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsNetworks are scanned at least monthly to identify any credentials that are being stored in the clear.
ISM-1876NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are as…
ISM-1877NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices a…
ISM-1878NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of ICT equipment other than workstations, servers and network de…
ISM-1879NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in drivers and firmware are applied within 48 hours of release when vulnerabilities a…

Substantive amendments (19)

ControlEdit distLocationStatement (excerpt)
ISM-12990.89Guidelines for Enterprise Mobility › Personnel awarenessPersonnel are advised to take the following precautions when using mobile devices: - never leave mobile devices or removable media unattended, includi…
ISM-06870.73Guidelines for Enterprise Mobility › Approved mobile platformsMobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that have been issued an Approval for Use by ASD and are operated…
ISM-18020.73Guidelines for Cryptography › Approved High Assurance Cryptographic EquipmentHACE are issued an Approval for Use by ASD and operated in accordance with the latest version of their associated Australian Communications Security I…
ISM-18590.62Guidelines for System Hardening › Hardening user application configurationsOffice productivity suites are hardened using ASD and vendor hardening guidance.
ISM-04070.58Guidelines for Personnel Security › Recording authorisation for personnel to access systemsA secure record is maintained for the life of each system covering the following for each user: - their user identification - their signed agreement t…
ISM-14820.57Guidelines for Enterprise Mobility › Organisation-owned mobile devices and desktop computersPersonnel accessing systems or data using an organisation-owned mobile device or desktop computer are either prohibited from using it for personal pur…
ISM-12460.55Guidelines for System Hardening › Hardening server application configurationsServer applications are hardened using ASD and vendor hardening guidance.
ISM-14120.55Guidelines for System Hardening › Hardening user application configurationsWeb browsers are hardened using ASD and vendor hardening guidance.
ISM-11950.54Guidelines for Enterprise Mobility › Mobile device management policyMobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, versi…
ISM-18600.54Guidelines for System Hardening › Hardening user application configurationsPDF software is hardened using ASD and vendor hardening guidance.
ISM-16810.54Guidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used by default to authenticate users to online customer services that process, store or communicate sensitive data, ho…
ISM-14090.54Guidelines for System Hardening › Hardening operating system configurationsOperating systems are hardened using ASD and vendor hardening guidance.
ISM-02490.53Guidelines for Communications Infrastructure › Emanation security threat assessments outside AustraliaSystem owners deploying systems or military platforms overseas contact ASD for an emanation security threat assessment and implement any additional in…
ISM-18580.51Guidelines for ICT Equipment › Hardening ICT equipment configurationsICT equipment is hardened using ASD and vendor hardening guidance.
ISM-16960.47Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-fa…
ISM-16950.35Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-fa…
ISM-07200.32Guidelines for Cyber Security Roles › Communicating a cyber security vision and strategyThe CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber sec…
ISM-14000.28Guidelines for Enterprise Mobility › Privately-owned mobile devices and desktop computersPersonnel accessing OFFICIAL: Sensitive or PROTECTED systems or data using privately-owned mobile devices or desktop computers have enforced separatio…
ISM-04080.28Guidelines for System Hardening › Logon bannerSystems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.

Clarifications (36)

ControlEdit distLocation
ISM-15040.24Guidelines for System Hardening › Multi-factor authentication
ISM-16900.24Guidelines for System Management › When to patch vulnerabilities
ISM-16940.24Guidelines for System Management › When to patch vulnerabilities
ISM-04990.23Guidelines for Cryptography › Communications security doctrine
ISM-03700.20Guidelines for Media › Supervision of destruction
ISM-16920.19Guidelines for System Management › When to patch vulnerabilities
ISM-03720.19Guidelines for Media › Supervision of accountable material destruction
ISM-16970.19Guidelines for System Management › When to patch vulnerabilities
ISM-17020.18Guidelines for System Management › Scanning for missing patches or updates
ISM-16270.18Guidelines for Networking › Blocking anonymity network traffic
ISM-18610.16Guidelines for System Hardening › Protecting credentials
ISM-16790.15Guidelines for System Hardening › Multi-factor authentication
ISM-16820.15Guidelines for System Hardening › Multi-factor authentication
ISM-16800.14Guidelines for System Hardening › Multi-factor authentication
ISM-17510.13Guidelines for System Management › When to patch vulnerabilities
ISM-17010.12Guidelines for System Management › Scanning for missing patches or updates
ISM-05760.12Guidelines for Cyber Security Incidents › Cyber security incident management policy
ISM-17840.12Guidelines for Cyber Security Incidents › Cyber security incident management policy
ISM-06940.12Guidelines for Enterprise Mobility › Privately-owned mobile devices and desktop computers
ISM-12970.10Guidelines for Enterprise Mobility › Privately-owned mobile devices and desktop computers
ISM-05200.10Guidelines for Networking › Network access controls
ISM-16980.09Guidelines for System Management › Scanning for missing patches or updates
ISM-04600.08Guidelines for Cryptography › Encrypting data at rest
ISM-09260.07Guidelines for Communications Infrastructure › Cable colours
ISM-03000.07Guidelines for System Management › When to patch vulnerabilities
ISM-08740.07Guidelines for Enterprise Mobility › Connecting mobile devices and desktop computers to the internet
ISM-03060.07Guidelines for ICT Equipment › On-site maintenance and repairs
ISM-18190.06Guidelines for Cyber Security Incidents › Enacting cyber security incident response plans
ISM-11070.06Guidelines for Communications Infrastructure › Wall outlet box colours
ISM-08100.06Guidelines for Physical Security › Physical access to systems
ISM-12130.06Guidelines for Cyber Security Incidents › Handling and containing intrusions
ISM-15050.06Guidelines for System Hardening › Multi-factor authentication
ISM-11820.06Guidelines for Networking › Network access controls
ISM-03070.06Guidelines for ICT Equipment › On-site maintenance and repairs
ISM-17540.05Guidelines for Software Development › Resolving vulnerabilities
ISM-17040.05Guidelines for System Management › Cessation of support

Editorial / grammatical (33)

Cosmetic edits (normalised edit distance < 0.05). ISM-0043, ISM-0140, ISM-0247, ISM-0248, ISM-0286, ISM-0290, ISM-0296, ISM-0321, ISM-0336, ISM-0402, ISM-0445, ISM-0467, ISM-0597, ISM-0734, ISM-1053, ISM-1079, ISM-1088, ISM-1137, ISM-1163, ISM-1196, ISM-1198, ISM-1199, ISM-1200, ISM-1520, ISM-1530, ISM-1606, ISM-1691, ISM-1693, ISM-1699, ISM-1700, ISM-1703, ISM-1717, ISM-1752

Relocated (38)

0 cross-chapter moves (listed) · 38 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (2)

ControlDirectionFootprint before → afterLocation
ISM-0372widenedOS|P|S|TSNC|OS|P|S|TSSupervision of accountable material destruction
ISM-0373widenedOS|P|S|TSNC|OS|P|S|TSSupervision of accountable material destruction

Removed (1)

ControlFootprintFormer locationStatement (excerpt)
ISM-0979NC|OS|P|S|TSGuidelines for System HardeningLegal advice is sought on the exact wording of logon banners.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.