| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 10 | 0 |
| SECRET | 0 | 1 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 0 |
| Non-Classified | 0 | 9 |
| Footprint | Floor | Ceiling | Controls |
|---|---|---|---|
S|TS | SECRET | TOP SECRET | ISM-1535 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for Information Technology Equipment | IT equipment disposal | 4 | ISM-1550 ISM-1217 ISM-0321 ISM-0316 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | 6 | ISM-1079 ISM-0305 ISM-0307 ISM-0306 ISM-0310 ISM-1598 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | 18 | ISM-0313 ISM-1741 ISM-0311 ISM-1742 ISM-1218 ISM-0312 ISM-0315 ISM-0317 ISM-1219 ISM-1220 ISM-1221 ISM-0318 ISM-1534 ISM-1076 ISM-1222 ISM-1223 ISM-1225 ISM-1226 |
| Guidelines for Information Technology Equipment | IT equipment usage | 10 | ISM-1551 ISM-1857 ISM-1913 ISM-1858 ISM-0336 ISM-1869 ISM-0294 ISM-0296 ISM-0293 ISM-1599 |
| Guidelines for Physical Security | IT equipment and media | 1 | ISM-0161 |
| Chapter | Section |
|---|---|
| Guidelines for ICT Equipment | ICT equipment disposal |
| Guidelines for ICT Equipment | ICT equipment maintenance and repairs |
| Guidelines for ICT Equipment | ICT equipment sanitisation and destruction |
| Guidelines for ICT Equipment | ICT equipment usage |
| Guidelines for Physical Security | ICT equipment and media |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for Communications Systems | Fax machines and multifunction devices | Simultaneously connecting multifunction devices to networks and digital telephone systems | 1 | ISM-0245 |
| Guidelines for Cryptography | Cryptographic fundamentals | Handling encrypted IT equipment and media | 1 | ISM-0462 |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | Insider threat mitigation program | 2 | ISM-1625 ISM-1626 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Delivery of applications, IT equipment, OT equipment and services | 3 | ISM-1790 ISM-1791 ISM-1792 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Sourcing applications, IT equipment, OT equipment and services | 3 | ISM-1787 ISM-1788 ISM-1789 |
| Guidelines for Procurement and Outsourcing | Managed services and cloud services | Access to systems, applications and data by service providers | 2 | ISM-1073 ISM-1576 |
| Guidelines for Software Development | Web application development | Secure web application design and development | 3 | ISM-0971 ISM-1849 ISM-1850 |
| Guidelines for System Management | System patching | Mitigating known vulnerabilities | 18 | ISM-1876 ISM-1690 ISM-1691 ISM-1692 ISM-1901 ISM-1693 ISM-1877 ISM-1694 ISM-1695 ISM-1696 ISM-1902 ISM-1878 ISM-1751 ISM-1879 ISM-1697 ISM-1903 ISM-1904 ISM-0300 |
| Guidelines for System Management | System patching | Scanning for unmitigated vulnerabilities | 11 | ISM-1807 ISM-1808 ISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1752 ISM-1703 ISM-1900 ISM-1921 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for Communications Systems | Fax machines and multifunction devices | Connecting multifunction devices to both networks and digital telephone systems |
| Guidelines for Cryptography | Cryptographic fundamentals | Handling encrypted ICT equipment and media |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | Trusted insider program |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Delivery of applications, ICT equipment and services |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Sourcing applications, ICT equipment and services |
| Guidelines for Procurement and Outsourcing | Managed services and cloud services | Access to systems and data by service providers |
| Guidelines for Software Development | Web application development | Open Web Application Security Projects |
| Guidelines for System Management | System patching | Scanning for missing patches or updates |
| Guidelines for System Management | System patching | When to patch vulnerabilities |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | 0 | 0 | 7 | 4 | 11 |
| Guidelines for Information Technology Equipment | IT equipment usage | 0 | 0 | 0 | 10 | 10 |
| Guidelines for System Management | System patching | 1 | 0 | 0 | 7 | 8 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | 0 | 0 | 0 | 7 | 7 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | 0 | 0 | 0 | 6 | 6 |
| Guidelines for Software Development | Application development | 3 | 0 | 0 | 1 | 4 |
| Guidelines for Information Technology Equipment | IT equipment disposal | 0 | 0 | 0 | 4 | 4 |
| Guidelines for Cyber Security Roles | Chief Information Security Officer | 1 | 0 | 2 | 0 | 3 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | 0 | 0 | 0 | 3 | 3 |
| Guidelines for Networking | Network design and configuration | 0 | 0 | 0 | 3 | 3 |
| Guidelines for System Hardening | Authentication hardening | 2 | 0 | 0 | 0 | 2 |
| Guidelines for Procurement and Outsourcing | Managed services and cloud services | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Networking | Wireless networks | 0 | 1 | 0 | 1 | 2 |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | 0 | 0 | 2 | 0 | 2 |
| Guidelines for Security Documentation | System-specific security documentation | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Physical Security | IT equipment and media | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Systems | Telephone systems | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Infrastructure | Emanation security | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Evaluated Products | Evaluated product procurement | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Evaluated Products | Evaluated product usage | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Media | Media usage | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Cryptography | Cryptographic fundamentals | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Monitoring | Event logging and monitoring | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Gateways | Gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Hardening | Operating system hardening | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Data Transfers | Data transfers | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Email | Email gateways and servers | 0 | 0 | 1 | 0 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Cyber supply chain risk management activities | 0 | 0 | 1 | 4 | 5 |
| Guidelines for Software Development | Application development | Secure software design and development | 3 | 0 | 0 | 0 | 3 |
| Guidelines for System Management | System patching | Mitigating known vulnerabilities | 0 | 0 | 0 | 3 | 3 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | On-site maintenance and repairs | 0 | 0 | 0 | 3 | 3 |
| Guidelines for Information Technology Equipment | IT equipment disposal | Disposal of IT equipment | 0 | 0 | 0 | 3 | 3 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Sourcing applications, IT equipment, OT equipment and services | 0 | 0 | 3 | 0 | 3 |
| Guidelines for Procurement and Outsourcing | Cyber supply chain risk management | Delivery of applications, IT equipment, OT equipment and services | 0 | 0 | 3 | 0 | 3 |
| Guidelines for Cyber Security Roles | Chief Information Security Officer | Reporting on cyber security | 1 | 0 | 1 | 0 | 2 |
| Guidelines for System Hardening | Authentication hardening | Multi-factor authentication | 2 | 0 | 0 | 0 | 2 |
| Guidelines for System Management | System patching | Scanning for unmitigated vulnerabilities | 1 | 0 | 0 | 1 | 2 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | Sanitising IT equipment | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | Sanitising highly sensitive IT equipment | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Information Technology Equipment | IT equipment usage | IT equipment registers | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Procurement and Outsourcing | Managed services and cloud services | Access to systems, applications and data by service providers | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Networking | Wireless networks | Generating and issuing certificates for authentication | 0 | 1 | 0 | 1 | 2 |
| Guidelines for Cyber Security Incidents | Managing cyber security incidents | Insider threat mitigation program | 0 | 0 | 2 | 0 | 2 |
| Guidelines for System Management | System patching | Cessation of support | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Information Technology Equipment | IT equipment usage | Hardening IT equipment configurations | 0 | 0 | 0 | 2 | 2 |
| Guidelines for Security Documentation | System-specific security documentation | System security plan | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Physical Security | IT equipment and media | Securing IT equipment and media | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Fly lead installation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Systems | Telephone systems | Personnel awareness | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Infrastructure | Emanation security | Electromagnetic interference/electromagnetic compatibility standards | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Evaluated Products | Evaluated product procurement | Delivery of evaluated products | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Evaluated Products | Evaluated product usage | Using evaluated products | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | Classifying IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | Labelling IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | Labelling high assurance IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | Off-site maintenance and repairs | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | IT equipment sanitisation processes and procedures | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | Destroying high assurance IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Media | Media usage | Labelling media | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Software Development | Application development | Application security testing | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Cryptography | Cryptographic fundamentals | Handling encrypted IT equipment and media | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Networking | Network design and configuration | Network access controls | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Monitoring | Event logging and monitoring | Event log details | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Gateways | Gateways | Authenticating to networks accessed via gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Cyber Security Roles | Chief Information Security Officer | Providing cyber security leadership and guidance | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | Maintenance and repairs of high assurance IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Power reticulation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Communications Infrastructure | Cabling infrastructure | Cable colour non-conformance | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Hardening | Operating system hardening | Application control | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Networking | Network design and configuration | Functional separation between servers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for System Management | System patching | Software register | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Data Transfers | Data transfers | Data transfer processes and procedures | 0 | 1 | 0 | 0 | 1 |
| Guidelines for Information Technology Equipment | IT equipment disposal | IT equipment disposal processes and procedures | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | IT equipment management policy | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Email | Email gateways and servers | Email server transport encryption | 0 | 0 | 1 | 0 | 1 |
| Guidelines for Information Technology Equipment | IT equipment maintenance and repairs | Inspection of IT equipment following maintenance and repairs | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | Handling IT equipment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment sanitisation and destruction | IT equipment destruction processes and procedures | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Information Technology Equipment | IT equipment usage | IT equipment selection | 0 | 0 | 0 | 1 | 1 |
| Guidelines for Networking | Network design and configuration | Networked management interfaces | 0 | 0 | 0 | 1 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-1918 | NC|OS|P|S|TS | Guidelines for Cyber Security Roles › Reporting on cyber security | The CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters. |
| ISM-1919 | NC|OS|P|S|TS | Guidelines for System Hardening › Multi-factor authentication | When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication p… |
| ISM-1920 | NC|OS|P|S|TS | Guidelines for System Hardening › Multi-factor authentication | When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that proce… |
| ISM-1921 | NC|OS|P|S|TS | Guidelines for System Management › Scanning for unmitigated vulnerabilities | The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities. |
| ISM-1922 | NC|OS|P|S|TS | Guidelines for Software Development › Secure software design and development | The Open Worldwide Application Security Project (OWASP) Mobile Application Security Verification Standard is used in the development of mobile applica… |
| ISM-1923 | NC|OS|P|S|TS | Guidelines for Software Development › Secure software design and development | The OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications. |
| ISM-1924 | NC|OS|P|S|TS | Guidelines for Software Development › Secure software design and development | Large language model applications evaluate the sentence perplexity of user prompts to detect and mitigate adversarial suffixes designed to assist in t… |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-0041 | 0.62 | Guidelines for Security Documentation › System security plan | Systems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is … |
| ISM-1327 | 0.37 | Guidelines for Networking › Generating and issuing certificates for authentication | Certificates are protected by logical and physical access controls, encryption, and user authentication. |
| ISM-1535 | 0.33 | Guidelines for Data Transfers › Data transfer processes and procedures | Processes, and supporting procedures, are developed, implemented and maintained to prevent AUSTEO, AGAO and REL data in textual and non-textual format… |
| Control | Edit dist | Location |
|---|---|---|
| ISM-0714 | 0.25 | Guidelines for Cyber Security Roles › Providing cyber security leadership and guidance |
| ISM-1625 | 0.19 | Guidelines for Cyber Security Incidents › Insider threat mitigation program |
| ISM-0718 | 0.18 | Guidelines for Cyber Security Roles › Reporting on cyber security |
| ISM-1626 | 0.13 | Guidelines for Cyber Security Incidents › Insider threat mitigation program |
| ISM-0286 | 0.11 | Guidelines for Evaluated Products › Delivery of evaluated products |
| ISM-1789 | 0.11 | Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services |
| ISM-1787 | 0.09 | Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services |
| ISM-1631 | 0.08 | Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities |
| ISM-0332 | 0.07 | Guidelines for Media › Labelling media |
| ISM-1790 | 0.07 | Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services |
| ISM-0585 | 0.07 | Guidelines for System Monitoring › Event log details |
| ISM-1788 | 0.07 | Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services |
| ISM-1791 | 0.06 | Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services |
| ISM-1792 | 0.06 | Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services |
| ISM-1589 | 0.06 | Guidelines for Email › Email server transport encryption |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for ICT Equipment | Guidelines for Information Technology Equipment | ISM-0293 ISM-0294 ISM-0296 ISM-0305 ISM-0306 ISM-0307 ISM-0310 ISM-0311 ISM-0312 ISM-0313 ISM-0315 ISM-0316 ISM-0317 ISM-0318 ISM-0321 ISM-0336 ISM-1076 ISM-1079 ISM-1217 ISM-1218 ISM-1219 ISM-1220 ISM-1221 ISM-1222 ISM-1223 ISM-1225 ISM-1226 ISM-1534 ISM-1550 ISM-1551 ISM-1598 ISM-1599 ISM-1741 ISM-1742 ISM-1857 ISM-1858 ISM-1869 ISM-1913 |
revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.