ASD ISM — incremental change analysis

Release v2024.06.18 (2024-06-18) vs prior v2024.03.12 · 98 days · catalogue 913 controls · ALL-era (NC imputed)
ASD changes summary: ISM June 2024 changes (PDF)
7
Added
3
Substantive
15
Clarification
55
Editorial
82
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET100
SECRET01
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified09

3 · Level-specific material changes

FootprintFloorCeilingControls
S|TSSECRETTOP SECRETISM-1535

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (7)

ControlFootprintLocationStatement (excerpt)
ISM-1918NC|OS|P|S|TSGuidelines for Cyber Security Roles › Reporting on cyber securityThe CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters.
ISM-1919NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationWhen multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication p…
ISM-1920NC|OS|P|S|TSGuidelines for System Hardening › Multi-factor authenticationWhen multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that proce…
ISM-1921NC|OS|P|S|TSGuidelines for System Management › Scanning for unmitigated vulnerabilitiesThe likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.
ISM-1922NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentThe Open Worldwide Application Security Project (OWASP) Mobile Application Security Verification Standard is used in the development of mobile applica…
ISM-1923NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentThe OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications.
ISM-1924NC|OS|P|S|TSGuidelines for Software Development › Secure software design and developmentLarge language model applications evaluate the sentence perplexity of user prompts to detect and mitigate adversarial suffixes designed to assist in t…

Substantive amendments (3)

ControlEdit distLocationStatement (excerpt)
ISM-00410.62Guidelines for Security Documentation › System security planSystems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is …
ISM-13270.37Guidelines for Networking › Generating and issuing certificates for authenticationCertificates are protected by logical and physical access controls, encryption, and user authentication.
ISM-15350.33Guidelines for Data Transfers › Data transfer processes and proceduresProcesses, and supporting procedures, are developed, implemented and maintained to prevent AUSTEO, AGAO and REL data in textual and non-textual format…

Clarifications (15)

ControlEdit distLocation
ISM-07140.25Guidelines for Cyber Security Roles › Providing cyber security leadership and guidance
ISM-16250.19Guidelines for Cyber Security Incidents › Insider threat mitigation program
ISM-07180.18Guidelines for Cyber Security Roles › Reporting on cyber security
ISM-16260.13Guidelines for Cyber Security Incidents › Insider threat mitigation program
ISM-02860.11Guidelines for Evaluated Products › Delivery of evaluated products
ISM-17890.11Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services
ISM-17870.09Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services
ISM-16310.08Guidelines for Procurement and Outsourcing › Cyber supply chain risk management activities
ISM-03320.07Guidelines for Media › Labelling media
ISM-17900.07Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services
ISM-05850.07Guidelines for System Monitoring › Event log details
ISM-17880.07Guidelines for Procurement and Outsourcing › Sourcing applications, IT equipment, OT equipment and services
ISM-17910.06Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services
ISM-17920.06Guidelines for Procurement and Outsourcing › Delivery of applications, IT equipment, OT equipment and services
ISM-15890.06Guidelines for Email › Email server transport encryption

Editorial / grammatical (55)

Cosmetic edits (normalised edit distance < 0.05). ISM-0161, ISM-0218, ISM-0229, ISM-0250, ISM-0290, ISM-0293, ISM-0294, ISM-0296, ISM-0300, ISM-0305, ISM-0306, ISM-0307, ISM-0310, ISM-0311, ISM-0312, ISM-0313, ISM-0315, ISM-0316, ISM-0321, ISM-0336, ISM-0402, ISM-0462, ISM-0520, ISM-0622, ISM-1073, ISM-1079, ISM-1123, ISM-1216, ISM-1217, ISM-1218, ISM-1323, ISM-1452, ISM-1471, ISM-1479, ISM-1493, ISM-1550, ISM-1551, ISM-1568, ISM-1576, ISM-1598, ISM-1599, ISM-1632, ISM-1741, ISM-1742, ISM-1751, ISM-1752, ISM-1753, ISM-1809, ISM-1857, ISM-1858, ISM-1863, ISM-1869, ISM-1878, ISM-1882, ISM-1913

Relocated (82)

38 cross-chapter moves (listed) · 44 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for ICT EquipmentGuidelines for Information Technology EquipmentISM-0293 ISM-0294 ISM-0296 ISM-0305 ISM-0306 ISM-0307 ISM-0310 ISM-0311 ISM-0312 ISM-0313 ISM-0315 ISM-0316 ISM-0317 ISM-0318 ISM-0321 ISM-0336 ISM-1076 ISM-1079 ISM-1217 ISM-1218 ISM-1219 ISM-1220 ISM-1221 ISM-1222 ISM-1223 ISM-1225 ISM-1226 ISM-1534 ISM-1550 ISM-1551 ISM-1598 ISM-1599 ISM-1741 ISM-1742 ISM-1857 ISM-1858 ISM-1869 ISM-1913

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.