ASD ISM — incremental change analysis

Release v2024.09.26 (2024-09-26) vs prior v2024.06.18 · 100 days · catalogue 953 controls · ALL-era (NC imputed)
ASD changes summary: ISM September 2024 changes (PDF)
40
Added
6
Substantive
8
Clarification
15
Editorial
6
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET460
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified046

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (40)

ControlFootprintLocationStatement (excerpt)
ISM-1926NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesMicrosoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their de…
ISM-1927NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesAccess to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to pr…
ISM-1928NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory servicesBackups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted, …
ISM-1929NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersLightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.
ISM-1930NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersPasswords are prevented from being stored in Group Policy Preferences.
ISM-1931NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services domain controllersSID Filtering is enabled for domain and forest trusts.
ISM-1932NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe number of service accounts configured with an SPN is minimised.
ISM-1933NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningService accounts configured with an SPN do not have DCSync permissions.
ISM-1934NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.
ISM-1935NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningComputer accounts are not configured for unconstrained delegation.
ISM-1936NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe sIDHistory attribute for user accounts is not used.
ISM-1937NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are checked at least weekly for the presence of the sIDHistory attribute.
ISM-1938NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningThe Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.
ISM-1939NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.
ISM-1940NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsService accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
ISM-1941NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsComputer accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
ISM-1942NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Domain Services security group membershipsThe Domain Computers security group is not a member of any privileged or highly-privileged security groups.
ISM-1943NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesStrong mapping between certificates and users is enforced.
ISM-1944NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesThe EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
ISM-1945NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesThe CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
ISM-1946NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesUnprivileged user accounts do not have write access to certificate templates.
ISM-1947NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesExtended Key Usages that enable user authentication are removed.
ISM-1948NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Certificate ServicesCA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.
ISM-1949NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Active Directory Federation ServicesMicrosoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.
ISM-1950NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectSoft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.
ISM-1951NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectHard match takeover is disabled for Microsoft Entra Connect servers.
ISM-1952NC|OS|P|S|TSGuidelines for System Hardening › Microsoft Entra ConnectPrivileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.
ISM-1953NC|OS|P|S|TSGuidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accountsCredentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.
ISM-1954NC|OS|P|S|TSGuidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accountsCredentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.
ISM-1955NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsCredentials for computer accounts are changed if: - they are compromised - they are suspected of being compromised - they have not been changed in the…
ISM-1956NC|OS|P|S|TSGuidelines for System Hardening › Changing credentialsMicrosoft AD FS token-signing and encryption certificates are changed twice in quick succession if: - they are compromised - they are suspected of bei…
ISM-1957NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsPrivate keys for Microsoft AD CS CA servers are protected by a hardware security module.
ISM-1958NC|OS|P|S|TSGuidelines for System Management › Separate privileged operating environmentsUser accounts with DCSync permissions cannot logon to unprivileged operating environments.
ISM-1959NC|OS|P|S|TSGuidelines for System Monitoring › Event log detailsTo the extent possible, event logs are captured and stored in a consistent and structured format.
ISM-1960NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.
ISM-1961NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.
ISM-1962NC|OS|P|S|TSGuidelines for Networking › Using the Server Message Block protocolSMB version 1 is not used on networks.
ISM-1963NC|OS|P|S|TSGuidelines for Networking › Network device event loggingSecurity-relevant events for internet-facing network devices are centrally logged.
ISM-1964NC|OS|P|S|TSGuidelines for Networking › Network device event loggingSecurity-relevant events for non-internet-facing network devices are centrally logged.
ISM-1965NC|OS|P|S|TSGuidelines for Gateways › Content checkingFiles imported or exported via gateways or CDSs undergo content checking.

Substantive amendments (6)

ControlEdit distLocationStatement (excerpt)
ISM-05820.98Guidelines for System Hardening › Operating system event loggingSecurity-relevant events for operating systems are centrally logged, including: - application and operating system crashes and error messages - change…
ISM-15370.79Guidelines for Database Systems › Database event loggingSecurity-relevant events for databases are centrally logged, including: - access or modification of particularly important content - addition of new u…
ISM-06340.74Guidelines for Gateways › Gateway event loggingSecurity-relevant events for gateways are centrally logged, including: - data packets and data flows permitted through gateways - data packets and dat…
ISM-09880.58Guidelines for System Monitoring › Centralised event logging facilityAn accurate and consistent time source is used for event logging.
ISM-18300.47Guidelines for System Hardening › Microsoft Active Directory servicesSecurity-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect serve…
ISM-18330.43Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardeningUser accounts are provisioned with the minimum privileges required.

Clarifications (8)

ControlEdit distLocation
ISM-18290.16Guidelines for System Hardening › Microsoft Active Directory Domain Services domain controllers
ISM-06700.15Guidelines for Gateways › Cross Domain Solution event logging
ISM-17170.13Guidelines for Software Development › Vulnerability disclosure program
ISM-17950.12Guidelines for System Hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
ISM-17350.11Guidelines for Media › Media that cannot be successfully sanitised
ISM-16500.09Guidelines for Personnel Security › Privileged access to systems
ISM-18420.08Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening
ISM-18430.06Guidelines for System Hardening › Microsoft Active Directory Domain Services account hardening

Editorial / grammatical (15)

Cosmetic edits (normalised edit distance < 0.05). ISM-0421, ISM-0445, ISM-0487, ISM-1175, ISM-1263, ISM-1590, ISM-1688, ISM-1689, ISM-1705, ISM-1706, ISM-1707, ISM-1812, ISM-1813, ISM-1814, ISM-1883

Relocated (6)

0 cross-chapter moves (listed) · 6 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (1 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.