ASD ISM — incremental change analysis

Release v2024.09.26 (2024-09-26) vs prior v2024.06.18 · 100 days · catalogue 953 controls · ALL-era (NC imputed)
ASD changes summary: ISM September 2024 changes (PDF)
40
Added
6
Substantive
8
Clarification
15
Editorial
6
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET460
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified046

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 9 · Removed topics: 2. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for GatewaysContent filteringContent checking1ISM-1965
Guidelines for NetworkingNetwork design and configurationNetwork device event logging2ISM-1963 ISM-1964
Guidelines for NetworkingNetwork design and configurationUsing the Server Message Block protocol1ISM-1962
Guidelines for NetworkingNetwork design and configurationUsing the Simple Network Management Protocol2ISM-1311 ISM-1312
Guidelines for System HardeningAuthentication hardeningSetting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts5ISM-1953 ISM-1685 ISM-1795 ISM-1954 ISM-1619
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Certificate Services6ISM-1943 ISM-1944 ISM-1945 ISM-1946 ISM-1947 ISM-1948
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Federation Services1ISM-1949
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory services4ISM-1926 ISM-1927 ISM-1928 ISM-1830
Guidelines for System HardeningServer application hardeningMicrosoft Entra Connect3ISM-1950 ISM-1951 ISM-1952

Removed topics

ChapterSectionTopic
Guidelines for NetworkingNetwork design and configurationUse of Simple Network Management Protocol
Guidelines for System HardeningAuthentication hardeningSetting credentials for break glass accounts, local administrator accounts and service accounts

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for System HardeningServer application hardening2723032
Guidelines for System HardeningAuthentication hardening50128
Guidelines for System ManagementData backup and restoration00066
Guidelines for Personnel SecurityAccess to systems and their resources00145
Guidelines for System MonitoringEvent logging and monitoring31004
Guidelines for System ManagementSystem administration10023
Guidelines for NetworkingNetwork design and configuration30003
Guidelines for GatewaysContent filtering10001
Guidelines for CryptographySecure Shell00011
Guidelines for System HardeningOperating system hardening01001
Guidelines for GatewaysGateways01001
Guidelines for GatewaysCross Domain Solutions00101
Guidelines for Database SystemsDatabases01001
Guidelines for Software DevelopmentApplication development00101
Guidelines for MediaMedia sanitisation00101

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services account hardening712010
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Certificate Services60006
Guidelines for Personnel SecurityAccess to systems and their resourcesPrivileged access to systems00145
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory services31004
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services domain controllers30104
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Domain Services security group memberships40004
Guidelines for System ManagementData backup and restorationBackup access00044
Guidelines for System HardeningServer application hardeningMicrosoft Entra Connect30003
Guidelines for System HardeningAuthentication hardeningSetting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts20103
Guidelines for System HardeningAuthentication hardeningChanging credentials20013
Guidelines for System ManagementSystem administrationSeparate privileged operating environments10023
Guidelines for System MonitoringEvent logging and monitoringEvent log monitoring20002
Guidelines for NetworkingNetwork design and configurationNetwork device event logging20002
Guidelines for System ManagementData backup and restorationBackup modification and deletion00022
Guidelines for System HardeningServer application hardeningMicrosoft Active Directory Federation Services10001
Guidelines for System HardeningAuthentication hardeningProtecting credentials10001
Guidelines for System MonitoringEvent logging and monitoringEvent log details10001
Guidelines for NetworkingNetwork design and configurationUsing the Server Message Block protocol10001
Guidelines for GatewaysContent filteringContent checking10001
Guidelines for System HardeningAuthentication hardeningSingle-factor authentication00011
Guidelines for CryptographySecure ShellAutomated remote access00011
Guidelines for System HardeningOperating system hardeningOperating system event logging01001
Guidelines for GatewaysGatewaysGateway event logging01001
Guidelines for GatewaysCross Domain SolutionsCross Domain Solution event logging00101
Guidelines for System MonitoringEvent logging and monitoringCentralised event logging facility01001
Guidelines for Database SystemsDatabasesDatabase event logging01001
Guidelines for Software DevelopmentApplication developmentVulnerability disclosure program00101
Guidelines for MediaMedia sanitisationMedia that cannot be successfully sanitised00101

6 · Control call-outs by category

Added — new controls (40)

ControlFootprintLocationStatement (excerpt)
ISM-1926NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesMicrosoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their de…
ISM-1927NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesAccess to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to pr…
ISM-1928NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesBackups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted, …
ISM-1929NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersLightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.
ISM-1930NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersPasswords are prevented from being stored in Group Policy Preferences.
ISM-1931NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersSID Filtering is enabled for domain and forest trusts.
ISM-1932NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe number of service accounts configured with an SPN is minimised.
ISM-1933NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningService accounts configured with an SPN do not have DCSync permissions.
ISM-1934NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.
ISM-1935NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningComputer accounts are not configured for unconstrained delegation.
ISM-1936NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe sIDHistory attribute for user accounts is not used.
ISM-1937NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are checked at least weekly for the presence of the sIDHistory attribute.
ISM-1938NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.
ISM-1939NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.
ISM-1940NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsService accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
ISM-1941NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsComputer accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
ISM-1942NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe Domain Computers security group is not a member of any privileged or highly-privileged security groups.
ISM-1943NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesStrong mapping between certificates and users is enforced.
ISM-1944NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesThe EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
ISM-1945NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesThe CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
ISM-1946NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesUnprivileged user accounts do not have write access to certificate templates.
ISM-1947NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesExtended Key Usages that enable user authentication are removed.
ISM-1948NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesCA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.
ISM-1949NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Federation ServicesMicrosoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.
ISM-1950NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectSoft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.
ISM-1951NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectHard match takeover is disabled for Microsoft Entra Connect servers.
ISM-1952NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectPrivileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.
ISM-1953NC|OS|P|S|TSGuidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accountsCredentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.
ISM-1954NC|OS|P|S|TSGuidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accountsCredentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.
ISM-1955NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsCredentials for computer accounts are changed if: - they are compromised - they are suspected of being compromised - they have not been changed in the…
ISM-1956NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsMicrosoft AD FS token-signing and encryption certificates are changed twice in quick succession if: - they are compromised - they are suspected of bei…
ISM-1957NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsPrivate keys for Microsoft AD CS CA servers are protected by a hardware security module.
ISM-1958NC|OS|P|S|TSGuidelines for System Management › Separate privileged operating environmentsUser accounts with DCSync permissions cannot logon to unprivileged operating environments.
ISM-1959NC|OS|P|S|TSGuidelines for System Monitoring › Event log detailsTo the extent possible, event logs are captured and stored in a consistent and structured format.
ISM-1960NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.
ISM-1961NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.
ISM-1962NC|OS|P|S|TSGuidelines for Networking › Using the Server Message Block protocolSMB version 1 is not used on networks.
ISM-1963NC|OS|P|S|TSGuidelines for Networking › Network device event loggingSecurity-relevant events for internet-facing network devices are centrally logged.
ISM-1964NC|OS|P|S|TSGuidelines for Networking › Network device event loggingSecurity-relevant events for non-internet-facing network devices are centrally logged.
ISM-1965NC|OS|P|S|TSGuidelines for Gateways › Content checkingFiles imported or exported via gateways or CDSs undergo content checking.

Substantive amendments (6)

ControlEdit distLocationStatement (excerpt)
ISM-05820.98Guidelines for System Hardening › Operating system event loggingSecurity-relevant events for operating systems are centrally logged, including: - application and operating system crashes and error messages - change…
ISM-15370.79Guidelines for Database Systems › Database event loggingSecurity-relevant events for databases are centrally logged, including: - access or modification of particularly important content - addition of new u…
ISM-06340.74Guidelines for Gateways › Gateway event loggingSecurity-relevant events for gateways are centrally logged, including: - data packets and data flows permitted through gateways - data packets and dat…
ISM-09880.58Guidelines for System Monitoring › Centralised event logging facilityAn accurate and consistent time source is used for event logging.
ISM-18300.47Guidelines for System Hardening › Microsoft Active Directory servicesSecurity-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect serve…
ISM-18330.43Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are provisioned with the minimum privileges required.

Clarifications (8)

ControlEdit distLocation
ISM-18290.16Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers
ISM-06700.15Guidelines for Gateways › Cross Domain Solution event logging
ISM-17170.13Guidelines for Software Development › Vulnerability disclosure program
ISM-17950.12Guidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
ISM-17350.11Guidelines for Media › Media that cannot be successfully sanitised
ISM-16500.09Guidelines for Personnel Security › Privileged access to systems
ISM-18420.08Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening
ISM-18430.06Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening

Editorial / grammatical (15)

Cosmetic edits (normalised edit distance < 0.05). ISM-0421, ISM-0445, ISM-0487, ISM-1175, ISM-1263, ISM-1590, ISM-1688, ISM-1689, ISM-1705, ISM-1706, ISM-1707, ISM-1812, ISM-1813, ISM-1814, ISM-1883

Relocated (6)

0 cross-chapter moves (listed) · 6 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.