ASD ISM — incremental change analysis

Release v2024.03.5 (2024-03-05) vs prior v2023.12.1 · 95 days · catalogue 906 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
5
Added
1
Substantive
1
Clarification
1
Editorial
0
Relocated
0
Scope changes
3
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET60
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified06

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (5)

ControlFootprintLocationStatement (excerpt)
ISM-1913NC|OS|P|S|TSGuidelines for ICT Equipment › Hardening ICT equipment configurationsApproved configurations for ICT equipment are developed, implemented and maintained.
ISM-1914NC|OS|P|S|TSGuidelines for System Hardening › Hardening operating system configurationsApproved configurations for operating systems are developed, implemented and maintained.
ISM-1915NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsApproved configurations for user applications are developed, implemented and maintained.
ISM-1916NC|OS|P|S|TSGuidelines for System Hardening › Hardening server application configurationsApproved configurations for server applications are developed, implemented and maintained.
ISM-1917NC|OS|P|S|TSGuidelines for Cryptography › Planning for post-quantum cryptography standardsFuture cryptographic requirements and dependencies are considered during the transition to post-quantum cryptographic standards.

Substantive amendments (1)

ControlEdit distLocationStatement (excerpt)
ISM-09940.27Guidelines for Cryptography › Asymmetric/public key algorithmsECDH is used in preference to DH.

Clarifications (1)

ControlEdit distLocation
ISM-14460.14Guidelines for Cryptography › Using Elliptic Curve Cryptography

Editorial / grammatical (1)

Cosmetic edits (normalised edit distance < 0.05). ISM-1867

Relocated (0)

0 cross-chapter moves (listed) · 0 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (3)

ControlFootprintFormer locationStatement (excerpt)
ISM-0473OS|PGuidelines for CryptographyWhen using DSA for digital signatures, a modulus of at least 2048 bits is used.
ISM-1630OS|PGuidelines for CryptographyWhen using DSA for digital signatures, a modulus and associated parameters are generated according to FIPS 186-4.
ISM-1760S|TSGuidelines for CryptographyDSA is not used for digital signatures.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.