ASD ISM — incremental change analysis

Release v2024.12.19 (2024-12-19) vs prior v2024.10.4 · 76 days · catalogue 980 controls · NC-explicit era
ASD changes summary: ISM December 2024 changes (PDF)
31
Added
9
Substantive
18
Clarification
21
Editorial
11
Relocated
0
Scope changes
4
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET314
SECRET40
PROTECTED20
OFFICIAL: Sensitive00
Non-Classified336

3 · Level-specific material changes

FootprintFloorCeilingControls
NCNon-ClassifiedNon-ClassifiedISM-1973 ISM-1974 ISM-1975
TSTOP SECRETTOP SECRETISM-1967 ISM-1968 ISM-1971 ISM-1972
NC|OS|PNon-ClassifiedPROTECTEDISM-0421 ISM-1559
NC|OS|P|SNon-ClassifiedSECRETISM-1112 ISM-1570 ISM-1636 ISM-1793

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (31)

ControlFootprintLocationStatement (excerpt)
ISM-1966NC|OS|P|S|TSGuidelines for Cyber Security Roles › Overseeing the cyber security programThe CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.
ISM-1967TSGuidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and …
ISM-1968TSGuidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners obtain authorisation to operate each TOP SECRET system, including each sensitive compartmented information system, from Director-General…
ISM-1969NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Handling and containing malicious code infectionsMalicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
ISM-1970NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Handling and containing malicious code infectionsMalicious code processed for cyber security incident response or research purposes is done so in a dedicated analysis environment that is segregated f…
ISM-1971TSGuidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security as…
ISM-1972TSGuidelines for Procurement and Outsourcing › Assessment of outsourced cloud service providersOutsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a securi…
ISM-1973NCGuidelines for Physical Security › Physical access to systemsNon-classified systems are secured in suitably secure facilities.
ISM-1974NCGuidelines for Physical Security › Physical access to servers, network devices and cryptographic equipmentNon-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
ISM-1975NCGuidelines for Physical Security › Physical access to servers, network devices and cryptographic equipmentNon-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.
ISM-1976NC|OS|P|S|TSGuidelines for System Hardening › Operating system event loggingSecurity-relevant events for Apple macOS operating systems are centrally logged.
ISM-1977NC|OS|P|S|TSGuidelines for System Hardening › Operating system event loggingSecurity-relevant events for Linux operating systems are centrally logged.
ISM-1978NC|OS|P|S|TSGuidelines for System Hardening › Server application event loggingSecurity-relevant events for server applications on internet-facing servers are centrally logged.
ISM-1979NC|OS|P|S|TSGuidelines for System Hardening › Server application event loggingSecurity-relevant events for server applications on non-internet-facing servers are centrally logged.
ISM-1980NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsCredential hint functionality is not used for systems.
ISM-1981NC|OS|P|S|TSGuidelines for System Management › Cessation of supportNon-internet-facing network devices that are no longer supported by vendors are replaced.
ISM-1982NC|OS|P|S|TSGuidelines for System Management › Cessation of supportNetworked IT equipment that is no longer supported by vendors is replaced.
ISM-1983NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs sent to a centralised event logging facility are done so as soon as possible after they occur.
ISM-1984NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs sent to a centralised event logging facility are encrypted in transit.
ISM-1985NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs are protected from unauthorised access.
ISM-1986NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from critical servers are analysed in a timely manner to detect cyber security events.
ISM-1987NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from security products are analysed in a timely manner to detect cyber security events.
ISM-1988NC|OS|P|S|TSGuidelines for System Monitoring › Event log retentionEvent logs are retained in a searchable manner for at least 12 months.
ISM-1989NC|OS|P|S|TSGuidelines for System Monitoring › Event log retentionEvent logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Admini…
ISM-1990NC|OS|P|S|TSGuidelines for Cryptography › Using post-quantum cryptographic algorithmsWhen using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS publications is preferred.
ISM-1991NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.
ISM-1992NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen using ML-DSA for digital signatures, the hedged variant is used whenever possible.
ISM-1993NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmPre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.
ISM-1994NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.
ISM-1995NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Key Encapsulation MechanismWhen using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.
ISM-1996NC|OS|P|S|TSGuidelines for Cryptography › Post-quantum traditional hybrid schemesWhen a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or bot…

Substantive amendments (9)

ControlEdit distLocationStatement (excerpt)
ISM-05820.76Guidelines for System Hardening › Operating system event loggingSecurity-relevant events for Microsoft Windows operating systems are centrally logged.
ISM-17930.63Guidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor …
ISM-19170.60Guidelines for Cryptography › Transitioning to post-quantum cryptographyThe development and procurement of new cryptographic equipment and software ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 an…
ISM-15700.60Guidelines for Procurement and Outsourcing › Assessment of outsourced cloud service providersOutsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, usin…
ISM-11120.44Guidelines for Communications Infrastructure › Cable inspectabilityCables in non-TOP SECRET areas are inspectable every five metres or less.
ISM-14050.43Guidelines for System Monitoring › Centralised event logging facilityA centralised event logging facility is implemented.
ISM-15590.38Guidelines for System Hardening › Multi-factor authenticationMemorised secrets used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
ISM-16360.30Guidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners ensure controls for each system and its operating environment undergo a security assessment by their organisation’s own assessors or Inf…
ISM-04210.30Guidelines for System Hardening › Single-factor authenticationPassphrases used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are at least 4 random words with a tota…

Clarifications (18)

ControlEdit distLocation
ISM-17530.23Guidelines for System Management › Cessation of support
ISM-14820.21Guidelines for Enterprise Mobility › Organisation-owned mobile devices and desktop computers
ISM-16070.20Guidelines for System Hardening › Functional separation between computing environments
ISM-00270.15Guidelines for Cyber Security Roles › Protecting systems and their resources
ISM-08130.11Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-04770.09Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-09260.09Guidelines for Communications Infrastructure › Cable colours
ISM-10740.08Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-11070.08Guidelines for Communications Infrastructure › Wall outlet box colours
ISM-15300.07Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-04760.06Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-17650.06Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-11990.06Guidelines for Enterprise Mobility › Using Bluetooth functionality
ISM-17660.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-17670.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-17680.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-08100.05Guidelines for Physical Security › Physical access to systems
ISM-11960.05Guidelines for Enterprise Mobility › Using Bluetooth functionality

Editorial / grammatical (21)

Cosmetic edits (normalised edit distance < 0.05). ISM-0380, ISM-0383, ISM-0418, ISM-0520, ISM-1053, ISM-1146, ISM-1198, ISM-1200, ISM-1247, ISM-1249, ISM-1250, ISM-1260, ISM-1304, ISM-1400, ISM-1403, ISM-1493, ISM-1554, ISM-1555, ISM-1556, ISM-1806, ISM-1809

Relocated (11)

0 cross-chapter moves (listed) · 11 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (4)

ControlFootprintFormer locationStatement (excerpt)
ISM-0248OS|PGuidelines for Communications InfrastructureSystem owners deploying OFFICIAL: Sensitive or PROTECTED systems with radio frequency transmitters (including any wireless capabilities) that will be …
ISM-0859NC|OS|P|S|TSGuidelines for System MonitoringEvent logs, excluding those for Domain Name System services and web proxies, are retained for at least seven years.
ISM-0991NC|OS|P|S|TSGuidelines for System MonitoringEvent logs for Domain Name System services and web proxies are retained for at least 18 months.
ISM-1677NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked Microsoft Office macro execution events are centrally logged.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.