ASD ISM — incremental change analysis

Release v2023.12.1 (2023-12-01) vs prior v2023.09.25 · 67 days · catalogue 904 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
33
Added
26
Substantive
33
Clarification
12
Editorial
11
Relocated
1
Scope changes
27
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET580
SECRET02
PROTECTED10
OFFICIAL: Sensitive04
Non-Classified053

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|POFFICIAL: SensitivePROTECTEDISM-0248
S|TSSECRETTOP SECRETISM-0249 ISM-1137
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-1884 ISM-1885 ISM-0246

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (33)

ControlFootprintLocationStatement (excerpt)
ISM-1880NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Reporting cyber security incidents to customers and the publicCyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
ISM-1881NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Reporting cyber security incidents to customers and the publicCyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discove…
ISM-1882NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services are chosen from suppliers that have demonstrated a commitment to transparency for their products and services…
ISM-1883NC|OS|P|S|TSGuidelines for Personnel Security › Privileged access to systemsPrivileged accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake …
ISM-1884OS|P|S|TSGuidelines for Communications Infrastructure › Emanation security doctrineEmanation security doctrine produced by ASD for the management of emanation security matters is complied with.
ISM-1885OS|P|S|TSGuidelines for Communications Infrastructure › Emanation security threat assessmentsRecommended actions contained within TEMPEST requirements statements issued for systems are implemented by system owners.
ISM-1886NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured to operate in a supervised (or equivalent) mode.
ISM-1887NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured with remote locate and wipe functionality.
ISM-1888NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured with secure lock screens.
ISM-1889NC|OS|P|S|TSGuidelines for System Hardening › Command ShellCommand line process creation events are centrally logged.
ISM-1890NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Office macrosMicrosoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.
ISM-1891NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Office macrosMicrosoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.
ISM-1892NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their or…
ISM-1893NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisatio…
ISM-1894NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication used for authenticating users of data repositories is phishing-resistant.
ISM-1895NC|OS|P|S|TSGuidelines for System Hardening › Single-factor authenticationSuccessful and unsuccessful single-factor authentication events are centrally logged.
ISM-1896NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsMemory integrity functionality is enabled.
ISM-1897NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsRemote Credential Guard functionality is enabled.
ISM-1898NC|OS|P|S|TSGuidelines for System Management › Separate privileged operating environmentsSecure Admin Workstations are used in the performance of administrative activities.
ISM-1899NC|OS|P|S|TSGuidelines for System Management › Administrative infrastructureNetwork devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.
ISM-1900NC|OS|P|S|TSGuidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
ISM-1901NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF …
ISM-1902NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-fa…
ISM-1903NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed …
ISM-1904NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed…
ISM-1905NC|OS|P|S|TSGuidelines for System Management › Cessation of supportOnline services that are no longer supported by vendors are removed.
ISM-1906NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
ISM-1907NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
ISM-1908NC|OS|P|S|TSGuidelines for Software Development › Reporting and resolving vulnerabilitiesVulnerabilities identified in applications are publicly disclosed (where appropriate to do so) by software developers in a timely manner.
ISM-1909NC|OS|P|S|TSGuidelines for Software Development › Reporting and resolving vulnerabilitiesIn resolving vulnerabilities, software developers perform root cause analysis and, to the greatest extent possible, seek to remediate entire vulnerabi…
ISM-1910NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesWeb API calls that facilitate modification of data, or access to data not authorised for release into the public domain, are centrally logged.
ISM-1911NC|OS|P|S|TSGuidelines for Software Development › Web application event loggingWeb application crashes and error messages are centrally logged.
ISM-1912NC|OS|P|S|TSGuidelines for Networking › Network documentationNetwork documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.

Substantive amendments (26)

ControlEdit distLocationStatement (excerpt)
ISM-17020.74Guidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, …
ISM-15360.66Guidelines for Software Development › Web application interaction with databasesAll queries to databases from web applications that are initiated by users, and any resulting crash or error messages, are centrally logged.
ISM-18610.57Guidelines for System Hardening › Protecting credentialsLocal Security Authority protection functionality is enabled.
ISM-03040.53Guidelines for System Management › Cessation of supportApplications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security p…
ISM-16860.52Guidelines for System Hardening › Protecting credentialsCredential Guard functionality is enabled.
ISM-16970.51Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed …
ISM-02490.41Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployable capability, contact ASD for an emanation security threat …
ISM-18600.37Guidelines for System Hardening › Hardening user application configurationsPDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-02480.36Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying OFFICIAL: Sensitive or PROTECTED systems with radio frequency transmitters (including any wireless capabilities) that will be …
ISM-14120.36Guidelines for System Hardening › Hardening user application configurationsWeb browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-18580.36Guidelines for ICT Equipment › Hardening ICT equipment configurationsICT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-14090.35Guidelines for System Hardening › Hardening operating system configurationsOperating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-12460.34Guidelines for System Hardening › Hardening server application configurationsServer applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-02460.34Guidelines for Communications Infrastructure › Emanation security threat assessmentsWhen an emanation security threat assessment is required, it is sought as early as possible in a system’s life cycle.
ISM-16600.33Guidelines for System Hardening › Application controlAllowed and blocked application control events are centrally logged.
ISM-15550.33Guidelines for Enterprise Mobility › Before travelling overseas with mobile devicesBefore travelling overseas with mobile devices, personnel take the following actions: - record all details of the mobile devices being taken, such as …
ISM-18590.32Guidelines for System Hardening › Hardening user application configurationsOffice productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts o…
ISM-15110.32Guidelines for System Management › Performing and retaining backupsBackups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
ISM-11750.29Guidelines for Personnel Security › Privileged access to systemsPrivileged accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web service…
ISM-11370.28Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security threat assessment.
ISM-16590.28Guidelines for System Hardening › Application controlMicrosoft’s vulnerable driver blocklist is implemented.
ISM-18150.27Guidelines for System Monitoring › Centralised event logging facilityEvent logs are protected from unauthorised modification and deletion.
ISM-16900.27Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are a…
ISM-17510.27Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of ICT equipment other than workstations, servers and network de…
ISM-15040.27Guidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisatio…
ISM-16230.25Guidelines for System Hardening › PowerShellPowerShell module logging, script block logging and transcription events are centrally logged.

Clarifications (33)

ControlEdit distLocation
ISM-15440.23Guidelines for System Hardening › Application control
ISM-16940.19Guidelines for System Management › When to patch vulnerabilities
ISM-18730.19Guidelines for System Hardening › Multi-factor authentication
ISM-18110.19Guidelines for System Management › Performing and retaining backups
ISM-16470.19Guidelines for Personnel Security › Suspension of access to systems
ISM-16810.19Guidelines for System Hardening › Multi-factor authentication
ISM-18740.18Guidelines for System Hardening › Multi-factor authentication
ISM-18100.16Guidelines for System Management › Performing and retaining backups
ISM-16820.15Guidelines for System Hardening › Multi-factor authentication
ISM-15150.14Guidelines for System Management › Testing restoration of backups
ISM-17100.14Guidelines for Networking › Default settings
ISM-18720.14Guidelines for System Hardening › Multi-factor authentication
ISM-17080.13Guidelines for System Management › Backup modification and deletion
ISM-15070.13Guidelines for Personnel Security › Privileged access to systems
ISM-15090.12Guidelines for Personnel Security › Privileged access to systems
ISM-15660.12Guidelines for Personnel Security › Unprivileged access to systems
ISM-16130.12Guidelines for Personnel Security › Emergency access to systems
ISM-01090.11Guidelines for System Monitoring › Event log monitoring
ISM-17030.10Guidelines for System Management › Scanning for missing patches or updates
ISM-15080.10Guidelines for Personnel Security › Privileged access to systems
ISM-17160.09Guidelines for Personnel Security › Suspension of access to systems
ISM-18300.08Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers
ISM-08630.08Guidelines for Enterprise Mobility › Maintaining mobile device security
ISM-06700.08Guidelines for Gateways › Cross Domain Solution event logging
ISM-16500.08Guidelines for Personnel Security › Privileged access to systems
ISM-12760.08Guidelines for Software Development › Web application interaction with databases
ISM-18190.08Guidelines for Cyber Security Incidents › Enacting cyber security incident response plans
ISM-16480.08Guidelines for Personnel Security › Suspension of access to systems
ISM-14040.07Guidelines for Personnel Security › Suspension of access to systems
ISM-06290.07Guidelines for Gateways › System administration of gateways
ISM-16770.07Guidelines for System Hardening › Microsoft Office macros
ISM-16830.06Guidelines for System Hardening › Multi-factor authentication
ISM-15050.06Guidelines for System Hardening › Multi-factor authentication

Editorial / grammatical (12)

Cosmetic edits (normalised edit distance < 0.05). ISM-0261, ISM-0518, ISM-0582, ISM-0634, ISM-1487, ISM-1537, ISM-1632, ISM-1695, ISM-1704, ISM-1752, ISM-1855, ISM-1879

Relocated (11)

3 cross-chapter moves (listed) · 8 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Database SystemsGuidelines for Software DevelopmentISM-1275 ISM-1276 ISM-1278

Scope / applicability changes (1)

ControlDirectionFootprint before → afterLocation
ISM-0249narrowedOS|P|S|TSS|TSEmanation security threat assessments

Removed (27)

ControlFootprintFormer locationStatement (excerpt)
ISM-0247S|TSGuidelines for Communications InfrastructureSystem owners deploying SECRET or TOP SECRET systems with Radio Frequency transmitters inside or co-located with their facility contact ASD for an ema…
ISM-1381NC|OS|P|S|TSGuidelines for System ManagementOnly privileged operating environments can communicate with jump servers.
ISM-1388NC|OS|P|S|TSGuidelines for System ManagementOnly jump servers can communicate with assets requiring administrative activities to be performed.
ISM-1651NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access event logs are stored centrally.
ISM-1652NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged account and group management event logs are stored centrally.
ISM-1653NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged service accounts are prevented from accessing the internet, email and web services.
ISM-1661NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked execution events on internet-facing servers are logged.
ISM-1662NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked execution events on non-internet-facing servers are logged.
ISM-1663NC|OS|P|S|TSGuidelines for System HardeningApplication control event logs are stored centrally.
ISM-1664NC|OS|P|S|TSGuidelines for System HardeningBlocked PowerShell script execution events are logged.
ISM-1665NC|OS|P|S|TSGuidelines for System HardeningPowerShell event logs are stored centrally.
ISM-1666NC|OS|P|S|TSGuidelines for System HardeningInternet Explorer 11 does not process content from the internet.
ISM-1678NC|OS|P|S|TSGuidelines for System HardeningMicrosoft Office macro event logs are stored centrally.
ISM-1684NC|OS|P|S|TSGuidelines for System HardeningMulti-factor authentication event logs are stored centrally.
ISM-1714NC|OS|P|S|TSGuidelines for Personnel SecurityUnprivileged access event logs are stored centrally.
ISM-1715NC|OS|P|S|TSGuidelines for Personnel SecurityBreak glass event logs are stored centrally.
ISM-1733NC|OS|P|S|TSGuidelines for Personnel SecurityRequests for privileged access to data repositories are validated when first requested.
ISM-1734NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access to data repositories is automatically disabled after 12 months unless revalidated.
ISM-1747NC|OS|P|S|TSGuidelines for System HardeningOperating system event logs are stored centrally.
ISM-1757NC|OS|P|S|TSGuidelines for Software DevelopmentWeb application event logs are stored centrally.
ISM-1758NC|OS|P|S|TSGuidelines for Database SystemsDatabase event logs are stored centrally.
ISM-1775NC|OS|P|S|TSGuidelines for GatewaysGateway event logs are stored centrally.
ISM-1776S|TSGuidelines for GatewaysCDS event logs are stored centrally.
ISM-1777NC|OS|P|S|TSGuidelines for GatewaysWeb proxy event logs are stored centrally.
ISM-1831NC|OS|P|S|TSGuidelines for System HardeningMicrosoft AD DS event logs are stored centrally.
ISM-1853NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access to data repositories is limited to only what is required for users and services to undertake their duties.
ISM-1856NC|OS|P|S|TSGuidelines for Communications SystemsMFD event logs are stored centrally.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.