ASD ISM — incremental change analysis

Release v2023.12.1 (2023-12-01) vs prior v2023.09.25 · 67 days · catalogue 904 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
33
Added
26
Substantive
33
Clarification
12
Editorial
11
Relocated
1
Scope changes
27
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET580
SECRET02
PROTECTED10
OFFICIAL: Sensitive04
Non-Classified053

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|POFFICIAL: SensitivePROTECTEDISM-0248
S|TSSECRETTOP SECRETISM-0249 ISM-1137
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-1884 ISM-1885 ISM-0246

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 8 · Removed topics: 7. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for Communications InfrastructureEmanation securityEmanation security doctrine1ISM-1884
Guidelines for Communications InfrastructureEmanation securityEmanation security threat assessments5ISM-1137 ISM-0248 ISM-0249 ISM-0246 ISM-1885
Guidelines for Communications SystemsFax machines and multifunction devicesLogging multifunction device use1ISM-1855
Guidelines for Cyber Security IncidentsManaging cyber security incidentsReporting cyber security incidents to customers and the public2ISM-1880 ISM-1881
Guidelines for GatewaysGatewaysGateway event logging1ISM-0634
Guidelines for Software DevelopmentApplication developmentReporting and resolving vulnerabilities3ISM-1908 ISM-1754 ISM-1909
Guidelines for Software DevelopmentWeb application developmentWeb application interaction with databases4ISM-1275 ISM-1276 ISM-1278 ISM-1536
Guidelines for System HardeningOperating system hardeningCommand Shell1ISM-1889

Removed topics

ChapterSectionTopic
Guidelines for Communications InfrastructureEmanation securityEarly consideration of emanation security threats
Guidelines for Communications InfrastructureEmanation securityEmanation security threat assessments in Australia
Guidelines for Communications InfrastructureEmanation securityEmanation security threat assessments outside Australia
Guidelines for Communications SystemsFax machines and multifunction devicesAuditing multifunction device use
Guidelines for Database SystemsDatabasesWeb application interaction with databases
Guidelines for GatewaysGatewaysGateway event logging and alerting
Guidelines for Software DevelopmentApplication developmentResolving vulnerabilities

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for System ManagementSystem patching652417
Guidelines for System HardeningAuthentication hardening637016
Guidelines for Personnel SecurityAccess to systems and their resources1110012
Guidelines for System HardeningOperating system hardening14117
Guidelines for System HardeningUser application hardening23117
Guidelines for Communications InfrastructureEmanation security24006
Guidelines for System ManagementData backup and restoration01405
Guidelines for Enterprise MobilityMobile device management30104
Guidelines for System MonitoringEvent logging and monitoring21104
Guidelines for Software DevelopmentWeb application development21104
Guidelines for Cyber Security IncidentsManaging cyber security incidents20002
Guidelines for Procurement and OutsourcingCyber supply chain risk management10012
Guidelines for System ManagementSystem administration20002
Guidelines for Software DevelopmentApplication development20002
Guidelines for NetworkingNetwork design and configuration10012
Guidelines for GatewaysGateways00112
Guidelines for System HardeningServer application hardening01102
Guidelines for GatewaysWeb proxies00011
Guidelines for GatewaysCross Domain Solutions00101
Guidelines for Database SystemsDatabases00011
Guidelines for Enterprise MobilityMobile device usage01001
Guidelines for NetworkingWireless networks00101
Guidelines for Cyber Security IncidentsResponding to cyber security incidents00101
Guidelines for Communications SystemsFax machines and multifunction devices00011
Guidelines for ICT EquipmentICT equipment usage01001

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for System HardeningAuthentication hardeningMulti-factor authentication317011
Guidelines for System ManagementSystem patchingWhen to patch vulnerabilities431210
Guidelines for Personnel SecurityAccess to systems and their resourcesPrivileged access to systems11406
Guidelines for Communications InfrastructureEmanation securityEmanation security threat assessments14005
Guidelines for Enterprise MobilityMobile device managementMaintaining mobile device security30104
Guidelines for System HardeningUser application hardeningMicrosoft Office macros20114
Guidelines for System HardeningAuthentication hardeningProtecting credentials22004
Guidelines for System ManagementSystem patchingScanning for missing patches or updates11114
Guidelines for Personnel SecurityAccess to systems and their resourcesSuspension of access to systems00404
Guidelines for System ManagementSystem patchingCessation of support11013
Guidelines for System MonitoringEvent logging and monitoringEvent log monitoring20103
Guidelines for System HardeningUser application hardeningHardening user application configurations03003
Guidelines for System ManagementData backup and restorationPerforming and retaining backups01203
Guidelines for System HardeningOperating system hardeningApplication control02103
Guidelines for Cyber Security IncidentsManaging cyber security incidentsReporting cyber security incidents to customers and the public20002
Guidelines for Procurement and OutsourcingCyber supply chain risk managementCyber supply chain risk management activities10012
Guidelines for Software DevelopmentApplication developmentReporting and resolving vulnerabilities20002
Guidelines for NetworkingNetwork design and configurationNetwork documentation10012
Guidelines for Software DevelopmentWeb application developmentWeb application interaction with databases01102
Guidelines for Communications InfrastructureEmanation securityEmanation security doctrine10001
Guidelines for System HardeningOperating system hardeningCommand Shell10001
Guidelines for System HardeningAuthentication hardeningSingle-factor authentication10001
Guidelines for System ManagementSystem administrationSeparate privileged operating environments10001
Guidelines for System ManagementSystem administrationAdministrative infrastructure10001
Guidelines for Software DevelopmentWeb application developmentWeb application programming interfaces10001
Guidelines for Software DevelopmentWeb application developmentWeb application event logging10001
Guidelines for GatewaysWeb proxiesWeb proxy event logging00011
Guidelines for System HardeningOperating system hardeningOperating system event logging00011
Guidelines for GatewaysGatewaysSystem administration of gateways00101
Guidelines for GatewaysGatewaysGateway event logging00011
Guidelines for GatewaysCross Domain SolutionsCross Domain Solution event logging00101
Guidelines for System HardeningServer application hardeningHardening server application configurations01001
Guidelines for System HardeningOperating system hardeningHardening operating system configurations01001
Guidelines for System ManagementData backup and restorationTesting restoration of backups00101
Guidelines for Database SystemsDatabasesDatabase event logging00011
Guidelines for Enterprise MobilityMobile device usageBefore travelling overseas with mobile devices01001
Guidelines for Personnel SecurityAccess to systems and their resourcesUnprivileged access to systems00101
Guidelines for Personnel SecurityAccess to systems and their resourcesEmergency access to systems00101
Guidelines for System HardeningOperating system hardeningPowerShell01001
Guidelines for System ManagementData backup and restorationBackup modification and deletion00101
Guidelines for NetworkingWireless networksDefault settings00101
Guidelines for System MonitoringEvent logging and monitoringCentralised event logging facility01001
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsEnacting cyber security incident response plans00101
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services domain controllers00101
Guidelines for Communications SystemsFax machines and multifunction devicesLogging multifunction device use00011
Guidelines for ICT EquipmentICT equipment usageHardening ICT equipment configurations01001

6 · Control call-outs by category

Added — new controls (33)

ControlFootprintLocationStatement (excerpt)
ISM-1880NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Reporting cyber security incidents to customers and the publicCyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
ISM-1881NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Reporting cyber security incidents to customers and the publicCyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discove…
ISM-1882NC|OS|P|S|TSGuidelines for Procurement and Outsourcing › Cyber supply chain risk management activitiesApplications, ICT equipment and services are chosen from suppliers that have demonstrated a commitment to transparency for their products and services…
ISM-1883NC|OS|P|S|TSGuidelines for Personnel Security › Privileged access to systemsPrivileged accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake …
ISM-1884OS|P|S|TSGuidelines for Communications Infrastructure › Emanation security doctrineEmanation security doctrine produced by ASD for the management of emanation security matters is complied with.
ISM-1885OS|P|S|TSGuidelines for Communications Infrastructure › Emanation security threat assessmentsRecommended actions contained within TEMPEST requirements statements issued for systems are implemented by system owners.
ISM-1886NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured to operate in a supervised (or equivalent) mode.
ISM-1887NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured with remote locate and wipe functionality.
ISM-1888NC|OS|P|S|TSGuidelines for Enterprise Mobility › Maintaining mobile device securityMobile devices are configured with secure lock screens.
ISM-1889NC|OS|P|S|TSGuidelines for System Hardening › Command ShellCommand line process creation events are centrally logged.
ISM-1890NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Office macrosMicrosoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.
ISM-1891NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Office macrosMicrosoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.
ISM-1892NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their or…
ISM-1893NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisatio…
ISM-1894NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationMulti-factor authentication used for authenticating users of data repositories is phishing-resistant.
ISM-1895NC|OS|P|S|TSGuidelines for System Hardening › Single-factor authenticationSuccessful and unsuccessful single-factor authentication events are centrally logged.
ISM-1896NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsMemory integrity functionality is enabled.
ISM-1897NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsRemote Credential Guard functionality is enabled.
ISM-1898NC|OS|P|S|TSGuidelines for System Management › Separate privileged operating environmentsSecure Admin Workstations are used in the performance of administrative activities.
ISM-1899NC|OS|P|S|TSGuidelines for System Management › Administrative infrastructureNetwork devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.
ISM-1900NC|OS|P|S|TSGuidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
ISM-1901NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF …
ISM-1902NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-fa…
ISM-1903NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed …
ISM-1904NC|OS|P|S|TSGuidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed…
ISM-1905NC|OS|P|S|TSGuidelines for System Management › Cessation of supportOnline services that are no longer supported by vendors are removed.
ISM-1906NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
ISM-1907NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
ISM-1908NC|OS|P|S|TSGuidelines for Software Development › Reporting and resolving vulnerabilitiesVulnerabilities identified in applications are publicly disclosed (where appropriate to do so) by software developers in a timely manner.
ISM-1909NC|OS|P|S|TSGuidelines for Software Development › Reporting and resolving vulnerabilitiesIn resolving vulnerabilities, software developers perform root cause analysis and, to the greatest extent possible, seek to remediate entire vulnerabi…
ISM-1910NC|OS|P|S|TSGuidelines for Software Development › Web application programming interfacesWeb API calls that facilitate modification of data, or access to data not authorised for release into the public domain, are centrally logged.
ISM-1911NC|OS|P|S|TSGuidelines for Software Development › Web application event loggingWeb application crashes and error messages are centrally logged.
ISM-1912NC|OS|P|S|TSGuidelines for Networking › Network documentationNetwork documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.

Substantive amendments (26)

ControlEdit distLocationStatement (excerpt)
ISM-17020.74Guidelines for System Management › Scanning for missing patches or updatesA vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, …
ISM-15360.66Guidelines for Software Development › Web application interaction with databasesAll queries to databases from web applications that are initiated by users, and any resulting crash or error messages, are centrally logged.
ISM-18610.57Guidelines for System Hardening › Protecting credentialsLocal Security Authority protection functionality is enabled.
ISM-03040.53Guidelines for System Management › Cessation of supportApplications other than office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security p…
ISM-16860.52Guidelines for System Hardening › Protecting credentialsCredential Guard functionality is enabled.
ISM-16970.51Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed …
ISM-02490.41Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployable capability, contact ASD for an emanation security threat …
ISM-18600.37Guidelines for System Hardening › Hardening user application configurationsPDF software is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-02480.36Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying OFFICIAL: Sensitive or PROTECTED systems with radio frequency transmitters (including any wireless capabilities) that will be …
ISM-14120.36Guidelines for System Hardening › Hardening user application configurationsWeb browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-18580.36Guidelines for ICT Equipment › Hardening ICT equipment configurationsICT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-14090.35Guidelines for System Hardening › Hardening operating system configurationsOperating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-12460.34Guidelines for System Hardening › Hardening server application configurationsServer applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-02460.34Guidelines for Communications Infrastructure › Emanation security threat assessmentsWhen an emanation security threat assessment is required, it is sought as early as possible in a system’s life cycle.
ISM-16600.33Guidelines for System Hardening › Application controlAllowed and blocked application control events are centrally logged.
ISM-15550.33Guidelines for Enterprise Mobility › Before travelling overseas with mobile devicesBefore travelling overseas with mobile devices, personnel take the following actions: - record all details of the mobile devices being taken, such as …
ISM-18590.32Guidelines for System Hardening › Hardening user application configurationsOffice productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts o…
ISM-15110.32Guidelines for System Management › Performing and retaining backupsBackups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
ISM-11750.29Guidelines for Personnel Security › Privileged access to systemsPrivileged accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web service…
ISM-11370.28Guidelines for Communications Infrastructure › Emanation security threat assessmentsSystem owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security threat assessment.
ISM-16590.28Guidelines for System Hardening › Application controlMicrosoft’s vulnerable driver blocklist is implemented.
ISM-18150.27Guidelines for System Monitoring › Centralised event logging facilityEvent logs are protected from unauthorised modification and deletion.
ISM-16900.27Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are a…
ISM-17510.27Guidelines for System Management › When to patch vulnerabilitiesPatches, updates or other vendor mitigations for vulnerabilities in operating systems of ICT equipment other than workstations, servers and network de…
ISM-15040.27Guidelines for System Hardening › Multi-factor authenticationMulti-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisatio…
ISM-16230.25Guidelines for System Hardening › PowerShellPowerShell module logging, script block logging and transcription events are centrally logged.

Clarifications (33)

ControlEdit distLocation
ISM-15440.23Guidelines for System Hardening › Application control
ISM-16940.19Guidelines for System Management › When to patch vulnerabilities
ISM-18730.19Guidelines for System Hardening › Multi-factor authentication
ISM-18110.19Guidelines for System Management › Performing and retaining backups
ISM-16470.19Guidelines for Personnel Security › Suspension of access to systems
ISM-16810.19Guidelines for System Hardening › Multi-factor authentication
ISM-18740.18Guidelines for System Hardening › Multi-factor authentication
ISM-18100.16Guidelines for System Management › Performing and retaining backups
ISM-16820.15Guidelines for System Hardening › Multi-factor authentication
ISM-15150.14Guidelines for System Management › Testing restoration of backups
ISM-17100.14Guidelines for Networking › Default settings
ISM-18720.14Guidelines for System Hardening › Multi-factor authentication
ISM-17080.13Guidelines for System Management › Backup modification and deletion
ISM-15070.13Guidelines for Personnel Security › Privileged access to systems
ISM-15090.12Guidelines for Personnel Security › Privileged access to systems
ISM-15660.12Guidelines for Personnel Security › Unprivileged access to systems
ISM-16130.12Guidelines for Personnel Security › Emergency access to systems
ISM-01090.11Guidelines for System Monitoring › Event log monitoring
ISM-17030.10Guidelines for System Management › Scanning for missing patches or updates
ISM-15080.10Guidelines for Personnel Security › Privileged access to systems
ISM-17160.09Guidelines for Personnel Security › Suspension of access to systems
ISM-18300.08Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers
ISM-08630.08Guidelines for Enterprise Mobility › Maintaining mobile device security
ISM-06700.08Guidelines for Gateways › Cross Domain Solution event logging
ISM-16500.08Guidelines for Personnel Security › Privileged access to systems
ISM-12760.08Guidelines for Software Development › Web application interaction with databases
ISM-18190.08Guidelines for Cyber Security Incidents › Enacting cyber security incident response plans
ISM-16480.08Guidelines for Personnel Security › Suspension of access to systems
ISM-14040.07Guidelines for Personnel Security › Suspension of access to systems
ISM-06290.07Guidelines for Gateways › System administration of gateways
ISM-16770.07Guidelines for System Hardening › Microsoft Office macros
ISM-16830.06Guidelines for System Hardening › Multi-factor authentication
ISM-15050.06Guidelines for System Hardening › Multi-factor authentication

Editorial / grammatical (12)

Cosmetic edits (normalised edit distance < 0.05). ISM-0261, ISM-0518, ISM-0582, ISM-0634, ISM-1487, ISM-1537, ISM-1632, ISM-1695, ISM-1704, ISM-1752, ISM-1855, ISM-1879

Relocated (11)

3 cross-chapter moves (listed) · 8 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Database SystemsGuidelines for Software DevelopmentISM-1275 ISM-1276 ISM-1278

Scope / applicability changes (1)

ControlDirectionFootprint before → afterLocation
ISM-0249narrowedOS|P|S|TSS|TSEmanation security threat assessments

Removed (27)

ControlFootprintFormer locationStatement (excerpt)
ISM-0247S|TSGuidelines for Communications InfrastructureSystem owners deploying SECRET or TOP SECRET systems with Radio Frequency transmitters inside or co-located with their facility contact ASD for an ema…
ISM-1381NC|OS|P|S|TSGuidelines for System ManagementOnly privileged operating environments can communicate with jump servers.
ISM-1388NC|OS|P|S|TSGuidelines for System ManagementOnly jump servers can communicate with assets requiring administrative activities to be performed.
ISM-1651NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access event logs are stored centrally.
ISM-1652NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged account and group management event logs are stored centrally.
ISM-1653NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged service accounts are prevented from accessing the internet, email and web services.
ISM-1661NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked execution events on internet-facing servers are logged.
ISM-1662NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked execution events on non-internet-facing servers are logged.
ISM-1663NC|OS|P|S|TSGuidelines for System HardeningApplication control event logs are stored centrally.
ISM-1664NC|OS|P|S|TSGuidelines for System HardeningBlocked PowerShell script execution events are logged.
ISM-1665NC|OS|P|S|TSGuidelines for System HardeningPowerShell event logs are stored centrally.
ISM-1666NC|OS|P|S|TSGuidelines for System HardeningInternet Explorer 11 does not process content from the internet.
ISM-1678NC|OS|P|S|TSGuidelines for System HardeningMicrosoft Office macro event logs are stored centrally.
ISM-1684NC|OS|P|S|TSGuidelines for System HardeningMulti-factor authentication event logs are stored centrally.
ISM-1714NC|OS|P|S|TSGuidelines for Personnel SecurityUnprivileged access event logs are stored centrally.
ISM-1715NC|OS|P|S|TSGuidelines for Personnel SecurityBreak glass event logs are stored centrally.
ISM-1733NC|OS|P|S|TSGuidelines for Personnel SecurityRequests for privileged access to data repositories are validated when first requested.
ISM-1734NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access to data repositories is automatically disabled after 12 months unless revalidated.
ISM-1747NC|OS|P|S|TSGuidelines for System HardeningOperating system event logs are stored centrally.
ISM-1757NC|OS|P|S|TSGuidelines for Software DevelopmentWeb application event logs are stored centrally.
ISM-1758NC|OS|P|S|TSGuidelines for Database SystemsDatabase event logs are stored centrally.
ISM-1775NC|OS|P|S|TSGuidelines for GatewaysGateway event logs are stored centrally.
ISM-1776S|TSGuidelines for GatewaysCDS event logs are stored centrally.
ISM-1777NC|OS|P|S|TSGuidelines for GatewaysWeb proxy event logs are stored centrally.
ISM-1831NC|OS|P|S|TSGuidelines for System HardeningMicrosoft AD DS event logs are stored centrally.
ISM-1853NC|OS|P|S|TSGuidelines for Personnel SecurityPrivileged access to data repositories is limited to only what is required for users and services to undertake their duties.
ISM-1856NC|OS|P|S|TSGuidelines for Communications SystemsMFD event logs are stored centrally.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.