ASD ISM — incremental change analysis

Release v2024.12.19 (2024-12-19) vs prior v2024.10.4 · 76 days · catalogue 980 controls · NC-explicit era
ASD changes summary: ISM December 2024 changes (PDF)
31
Added
9
Substantive
18
Clarification
21
Editorial
11
Relocated
0
Scope changes
4
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET314
SECRET40
PROTECTED20
OFFICIAL: Sensitive00
Non-Classified336

3 · Level-specific material changes

FootprintFloorCeilingControls
NCNon-ClassifiedNon-ClassifiedISM-1973 ISM-1974 ISM-1975
TSTOP SECRETTOP SECRETISM-1967 ISM-1968 ISM-1971 ISM-1972
NC|OS|PNon-ClassifiedPROTECTEDISM-0421 ISM-1559
NC|OS|P|SNon-ClassifiedSECRETISM-1112 ISM-1570 ISM-1636 ISM-1793

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 12 · Removed topics: 7. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsAsymmetric cryptographic algorithms1ISM-0994
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsPost-quantum traditional hybrid schemes1ISM-1996
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsTransitioning to post-quantum cryptography1ISM-1917
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing post-quantum cryptographic algorithms1ISM-1990
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing Secure Hashing Algorithms3ISM-1766 ISM-1767 ISM-1768
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing symmetric cryptographic algorithms3ISM-1769 ISM-1770 ISM-0479
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing the Module-Lattice-Based Digital Signature Algorithm4ISM-1991 ISM-1992 ISM-1993 ISM-1994
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing the Module-Lattice-Based Key Encapsulation Mechanism1ISM-1995
Guidelines for CryptographyInternet Protocol SecurityPseudorandom function1ISM-1772
Guidelines for NetworkingNetwork design and configurationDefault user accounts and credentials for network devices1ISM-1304
Guidelines for System HardeningAuthentication hardeningUser account lockouts1ISM-1403
Guidelines for System HardeningServer application hardeningServer application event logging2ISM-1978 ISM-1979

Removed topics

ChapterSectionTopic
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsAsymmetric/public key algorithms
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsPlanning for post-quantum cryptography standards
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing hashing algorithms
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing symmetric encryption algorithms
Guidelines for CryptographyInternet Protocol SecurityPseudorandom function algorithms
Guidelines for NetworkingNetwork design and configurationDefault accounts and credentials for network devices
Guidelines for System HardeningAuthentication hardeningAccount lockouts

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for CryptographyASD-Approved Cryptographic Algorithms716014
Guidelines for Physical SecurityFacilities and systems30418
Guidelines for System MonitoringEvent logging and monitoring71008
Guidelines for Enterprise MobilityMobile device usage00257
Guidelines for System HardeningServer application hardening20046
Guidelines for System HardeningOperating system hardening21025
Guidelines for System HardeningAuthentication hardening12025
Guidelines for System ManagementSystem patching20125
Guidelines for Cyber Security RolesSystem owners21104
Guidelines for Procurement and OutsourcingManaged services and cloud services22004
Guidelines for Communications InfrastructureCabling infrastructure01203
Guidelines for Cyber Security IncidentsResponding to cyber security incidents20002
Guidelines for NetworkingNetwork design and configuration00022
Guidelines for Enterprise MobilityEnterprise mobility00112
Guidelines for Cyber Security RolesChief Information Security Officer10001
Guidelines for Personnel SecurityCyber security awareness training00011
Guidelines for System HardeningVirtualisation hardening00101
Guidelines for System HardeningUser application hardening00011

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for Physical SecurityFacilities and systemsPhysical access to servers, network devices and cryptographic equipment20316
Guidelines for Cyber Security RolesSystem ownersProtecting systems and their resources21104
Guidelines for System ManagementSystem patchingCessation of support20114
Guidelines for System MonitoringEvent logging and monitoringCentralised event logging facility31004
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing the Module-Lattice-Based Digital Signature Algorithm40004
Guidelines for Enterprise MobilityMobile device usageUsing Bluetooth functionality00224
Guidelines for System HardeningOperating system hardeningOperating system event logging21003
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing Rivest-Shamir-Adleman00303
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing Secure Hashing Algorithms00303
Guidelines for Cyber Security IncidentsResponding to cyber security incidentsHandling and containing malicious code infections20002
Guidelines for Procurement and OutsourcingManaged services and cloud servicesAssessment of managed service providers11002
Guidelines for Procurement and OutsourcingManaged services and cloud servicesAssessment of outsourced cloud service providers11002
Guidelines for Physical SecurityFacilities and systemsPhysical access to systems10102
Guidelines for System HardeningServer application hardeningServer application event logging20002
Guidelines for System HardeningAuthentication hardeningProtecting credentials10012
Guidelines for System MonitoringEvent logging and monitoringEvent log monitoring20002
Guidelines for System MonitoringEvent logging and monitoringEvent log retention20002
Guidelines for System HardeningOperating system hardeningHardening operating system configurations00022
Guidelines for System HardeningServer application hardeningHardening server application configurations00022
Guidelines for System HardeningServer application hardeningRestricting privileges for server applications00022
Guidelines for Enterprise MobilityMobile device usageBefore travelling overseas with mobile devices00022
Guidelines for Cyber Security RolesChief Information Security OfficerOverseeing the cyber security program10001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing post-quantum cryptographic algorithms10001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsUsing the Module-Lattice-Based Key Encapsulation Mechanism10001
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsPost-quantum traditional hybrid schemes10001
Guidelines for System HardeningAuthentication hardeningSingle-factor authentication01001
Guidelines for NetworkingNetwork design and configurationNetwork access controls00011
Guidelines for Communications InfrastructureCabling infrastructureCable colours00101
Guidelines for Communications InfrastructureCabling infrastructureWall outlet box colours00101
Guidelines for Communications InfrastructureCabling infrastructureCable inspectability01001
Guidelines for Personnel SecurityCyber security awareness trainingPosting work information to online services00011
Guidelines for NetworkingNetwork design and configurationDefault user accounts and credentials for network devices00011
Guidelines for Enterprise MobilityEnterprise mobilityPrivately-owned mobile devices and desktop computers00011
Guidelines for System HardeningAuthentication hardeningUser account lockouts00011
Guidelines for Enterprise MobilityEnterprise mobilityOrganisation-owned mobile devices and desktop computers00101
Guidelines for System ManagementSystem patchingSoftware register00011
Guidelines for Enterprise MobilityMobile device usageAfter travelling overseas with mobile devices00011
Guidelines for System HardeningAuthentication hardeningMulti-factor authentication01001
Guidelines for System HardeningVirtualisation hardeningFunctional separation between computing environments00101
Guidelines for System HardeningUser application hardeningHardening user application configurations00011
Guidelines for CryptographyASD-Approved Cryptographic AlgorithmsTransitioning to post-quantum cryptography01001

6 · Control call-outs by category

Added — new controls (31)

ControlFootprintLocationStatement (excerpt)
ISM-1966NC|OS|P|S|TSGuidelines for Cyber Security Roles › Overseeing the cyber security programThe CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.
ISM-1967TSGuidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and …
ISM-1968TSGuidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners obtain authorisation to operate each TOP SECRET system, including each sensitive compartmented information system, from Director-General…
ISM-1969NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Handling and containing malicious code infectionsMalicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
ISM-1970NC|OS|P|S|TSGuidelines for Cyber Security Incidents › Handling and containing malicious code infectionsMalicious code processed for cyber security incident response or research purposes is done so in a dedicated analysis environment that is segregated f…
ISM-1971TSGuidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security as…
ISM-1972TSGuidelines for Procurement and Outsourcing › Assessment of outsourced cloud service providersOutsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a securi…
ISM-1973NCGuidelines for Physical Security › Physical access to systemsNon-classified systems are secured in suitably secure facilities.
ISM-1974NCGuidelines for Physical Security › Physical access to servers, network devices and cryptographic equipmentNon-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
ISM-1975NCGuidelines for Physical Security › Physical access to servers, network devices and cryptographic equipmentNon-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.
ISM-1976NC|OS|P|S|TSGuidelines for System Hardening › Operating system event loggingSecurity-relevant events for Apple macOS operating systems are centrally logged.
ISM-1977NC|OS|P|S|TSGuidelines for System Hardening › Operating system event loggingSecurity-relevant events for Linux operating systems are centrally logged.
ISM-1978NC|OS|P|S|TSGuidelines for System Hardening › Server application event loggingSecurity-relevant events for server applications on internet-facing servers are centrally logged.
ISM-1979NC|OS|P|S|TSGuidelines for System Hardening › Server application event loggingSecurity-relevant events for server applications on non-internet-facing servers are centrally logged.
ISM-1980NC|OS|P|S|TSGuidelines for System Hardening › Protecting credentialsCredential hint functionality is not used for systems.
ISM-1981NC|OS|P|S|TSGuidelines for System Management › Cessation of supportNon-internet-facing network devices that are no longer supported by vendors are replaced.
ISM-1982NC|OS|P|S|TSGuidelines for System Management › Cessation of supportNetworked IT equipment that is no longer supported by vendors is replaced.
ISM-1983NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs sent to a centralised event logging facility are done so as soon as possible after they occur.
ISM-1984NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs sent to a centralised event logging facility are encrypted in transit.
ISM-1985NC|OS|P|S|TSGuidelines for System Monitoring › Centralised event logging facilityEvent logs are protected from unauthorised access.
ISM-1986NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from critical servers are analysed in a timely manner to detect cyber security events.
ISM-1987NC|OS|P|S|TSGuidelines for System Monitoring › Event log monitoringEvent logs from security products are analysed in a timely manner to detect cyber security events.
ISM-1988NC|OS|P|S|TSGuidelines for System Monitoring › Event log retentionEvent logs are retained in a searchable manner for at least 12 months.
ISM-1989NC|OS|P|S|TSGuidelines for System Monitoring › Event log retentionEvent logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Admini…
ISM-1990NC|OS|P|S|TSGuidelines for Cryptography › Using post-quantum cryptographic algorithmsWhen using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS publications is preferred.
ISM-1991NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.
ISM-1992NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen using ML-DSA for digital signatures, the hedged variant is used whenever possible.
ISM-1993NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmPre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.
ISM-1994NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Digital Signature AlgorithmWhen the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.
ISM-1995NC|OS|P|S|TSGuidelines for Cryptography › Using the Module-Lattice-Based Key Encapsulation MechanismWhen using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.
ISM-1996NC|OS|P|S|TSGuidelines for Cryptography › Post-quantum traditional hybrid schemesWhen a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or bot…

Substantive amendments (9)

ControlEdit distLocationStatement (excerpt)
ISM-05820.76Guidelines for System Hardening › Operating system event loggingSecurity-relevant events for Microsoft Windows operating systems are centrally logged.
ISM-17930.63Guidelines for Procurement and Outsourcing › Assessment of managed service providersManaged service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor …
ISM-19170.60Guidelines for Cryptography › Transitioning to post-quantum cryptographyThe development and procurement of new cryptographic equipment and software ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 an…
ISM-15700.60Guidelines for Procurement and Outsourcing › Assessment of outsourced cloud service providersOutsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, usin…
ISM-11120.44Guidelines for Communications Infrastructure › Cable inspectabilityCables in non-TOP SECRET areas are inspectable every five metres or less.
ISM-14050.43Guidelines for System Monitoring › Centralised event logging facilityA centralised event logging facility is implemented.
ISM-15590.38Guidelines for System Hardening › Multi-factor authenticationMemorised secrets used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
ISM-16360.30Guidelines for Cyber Security Roles › Protecting systems and their resourcesSystem owners ensure controls for each system and its operating environment undergo a security assessment by their organisation’s own assessors or Inf…
ISM-04210.30Guidelines for System Hardening › Single-factor authenticationPassphrases used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are at least 4 random words with a tota…

Clarifications (18)

ControlEdit distLocation
ISM-17530.23Guidelines for System Management › Cessation of support
ISM-14820.21Guidelines for Enterprise Mobility › Organisation-owned mobile devices and desktop computers
ISM-16070.20Guidelines for System Hardening › Functional separation between computing environments
ISM-00270.15Guidelines for Cyber Security Roles › Protecting systems and their resources
ISM-08130.11Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-04770.09Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-09260.09Guidelines for Communications Infrastructure › Cable colours
ISM-10740.08Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-11070.08Guidelines for Communications Infrastructure › Wall outlet box colours
ISM-15300.07Guidelines for Physical Security › Physical access to servers, network devices and cryptographic equipment
ISM-04760.06Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-17650.06Guidelines for Cryptography › Using Rivest-Shamir-Adleman
ISM-11990.06Guidelines for Enterprise Mobility › Using Bluetooth functionality
ISM-17660.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-17670.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-17680.06Guidelines for Cryptography › Using Secure Hashing Algorithms
ISM-08100.05Guidelines for Physical Security › Physical access to systems
ISM-11960.05Guidelines for Enterprise Mobility › Using Bluetooth functionality

Editorial / grammatical (21)

Cosmetic edits (normalised edit distance < 0.05). ISM-0380, ISM-0383, ISM-0418, ISM-0520, ISM-1053, ISM-1146, ISM-1198, ISM-1200, ISM-1247, ISM-1249, ISM-1250, ISM-1260, ISM-1304, ISM-1400, ISM-1403, ISM-1493, ISM-1554, ISM-1555, ISM-1556, ISM-1806, ISM-1809

Relocated (11)

0 cross-chapter moves (listed) · 11 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (4)

ControlFootprintFormer locationStatement (excerpt)
ISM-0248OS|PGuidelines for Communications InfrastructureSystem owners deploying OFFICIAL: Sensitive or PROTECTED systems with radio frequency transmitters (including any wireless capabilities) that will be …
ISM-0859NC|OS|P|S|TSGuidelines for System MonitoringEvent logs, excluding those for Domain Name System services and web proxies, are retained for at least seven years.
ISM-0991NC|OS|P|S|TSGuidelines for System MonitoringEvent logs for Domain Name System services and web proxies are retained for at least 18 months.
ISM-1677NC|OS|P|S|TSGuidelines for System HardeningAllowed and blocked Microsoft Office macro execution events are centrally logged.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.