ASD ISM — incremental change analysis

Release v2024.03.5 (2024-03-05) vs prior v2023.12.1 · 95 days · catalogue 906 controls · ALL-era (NC imputed)
ASD changes summary: not available online (pre-June-2024 or errata release)
5
Added
1
Substantive
1
Clarification
1
Editorial
0
Relocated
0
Scope changes
3
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET60
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified06

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 1 · Removed topics: 1. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsPlanning for post-quantum cryptography standards1ISM-1917

Removed topics

ChapterSectionTopic
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing the Digital Signature Algorithm

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for CryptographyASD-Approved Cryptographic Algorithms11103
Guidelines for ICT EquipmentICT equipment usage10001
Guidelines for System HardeningOperating system hardening10001
Guidelines for System HardeningUser application hardening10001
Guidelines for System HardeningServer application hardening10001
Guidelines for Enterprise MobilityMobile device management00011

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for ICT EquipmentICT equipment usageHardening ICT equipment configurations10001
Guidelines for System HardeningOperating system hardeningHardening operating system configurations10001
Guidelines for System HardeningUser application hardeningHardening user application configurations10001
Guidelines for System HardeningServer application hardeningHardening server application configurations10001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsPlanning for post-quantum cryptography standards10001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsAsymmetric/public key algorithms01001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing Elliptic Curve Cryptography00101
Guidelines for Enterprise MobilityMobile device managementApproved mobile platforms00011

6 · Control call-outs by category

Added — new controls (5)

ControlFootprintLocationStatement (excerpt)
ISM-1913NC|OS|P|S|TSGuidelines for ICT Equipment › Hardening ICT equipment configurationsApproved configurations for ICT equipment are developed, implemented and maintained.
ISM-1914NC|OS|P|S|TSGuidelines for System Hardening › Hardening operating system configurationsApproved configurations for operating systems are developed, implemented and maintained.
ISM-1915NC|OS|P|S|TSGuidelines for System Hardening › Hardening user application configurationsApproved configurations for user applications are developed, implemented and maintained.
ISM-1916NC|OS|P|S|TSGuidelines for System Hardening › Hardening server application configurationsApproved configurations for server applications are developed, implemented and maintained.
ISM-1917NC|OS|P|S|TSGuidelines for Cryptography › Planning for post-quantum cryptography standardsFuture cryptographic requirements and dependencies are considered during the transition to post-quantum cryptographic standards.

Substantive amendments (1)

ControlEdit distLocationStatement (excerpt)
ISM-09940.27Guidelines for Cryptography › Asymmetric/public key algorithmsECDH is used in preference to DH.

Clarifications (1)

ControlEdit distLocation
ISM-14460.14Guidelines for Cryptography › Using Elliptic Curve Cryptography

Editorial / grammatical (1)

Cosmetic edits (normalised edit distance < 0.05). ISM-1867

Relocated (0)

0 cross-chapter moves (listed) · 0 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (3)

ControlFootprintFormer locationStatement (excerpt)
ISM-0473OS|PGuidelines for CryptographyWhen using DSA for digital signatures, a modulus of at least 2048 bits is used.
ISM-1630OS|PGuidelines for CryptographyWhen using DSA for digital signatures, a modulus and associated parameters are generated according to FIPS 186-4.
ISM-1760S|TSGuidelines for CryptographyDSA is not used for digital signatures.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.