| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 36 | 1 |
| SECRET | 1 | 3 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 0 |
| Non-Classified | 0 | 33 |
| Footprint | Floor | Ceiling | Controls |
|---|---|---|---|
TS | TOP SECRET | TOP SECRET | ISM-2019 |
S|TS | SECRET | TOP SECRET | ISM-2007 ISM-2008 ISM-2009 |
NC|OS|P|S | Non-Classified | SECRET | ISM-0100 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | 5 | ISM-0039 ISM-0047 ISM-1739 ISM-0888 ISM-1602 |
| Guidelines for cybersecurity documentation | System-specific cybersecurity documentation | 6 | ISM-0041 ISM-0043 ISM-0912 ISM-1163 ISM-1563 ISM-1564 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | 10 | ISM-1997 ISM-1998 ISM-1999 ISM-2000 ISM-2001 ISM-2002 ISM-2003 ISM-2004 ISM-2005 ISM-2006 |
| Guidelines for software development | Software development fundamentals | 37 | ISM-0400 ISM-1419 ISM-1420 ISM-1422 ISM-1816 ISM-0401 ISM-1780 ISM-1238 ISM-1922 ISM-1923 ISM-1924 ISM-1796 ISM-1797 ISM-1798 ISM-1730 ISM-1818 ISM-2013 ISM-1817 ISM-2014 ISM-1910 ISM-2015 ISM-1240 ISM-2016 ISM-1424 ISM-1275 ISM-1276 ISM-1278 ISM-1536 ISM-0402 ISM-1616 ISM-1755 ISM-1756 ISM-1717 ISM-1908 ISM-1754 ISM-1909 ISM-1911 |
| Chapter | Section |
|---|---|
| Guidelines for Security Documentation | Development and maintenance of security documentation |
| Guidelines for Security Documentation | System-specific security documentation |
| Guidelines for Software Development | Application development |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for database systems | Database servers | Segregation of development, testing, staging and production database servers | 1 | ISM-1273 |
| Guidelines for database systems | Databases | Segregation of development, testing, staging and production databases | 1 | ISM-1274 |
| Guidelines for gateways | Gateways | Border Gateway Protocol routing security | 2 | ISM-1783 ISM-2018 |
| Guidelines for networking | Network design and configuration | Encrypted Domain Name System Services | 1 | ISM-2017 |
| Guidelines for physical security | Facilities and systems | Bringing medical devices into facilities | 3 | ISM-2007 ISM-2008 ISM-2009 |
| Guidelines for system hardening | Authentication hardening | Screen locking | 1 | ISM-2012 |
| Guidelines for system hardening | Authentication hardening | Session locking | 1 | ISM-0428 |
| Guidelines for system hardening | Operating system hardening | Host-based intrusion detection and response | 2 | ISM-1341 ISM-1034 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for Database Systems | Database servers | Separation of development, testing and production database servers |
| Guidelines for Database Systems | Databases | Separation of development, testing and production databases |
| Guidelines for Gateways | Gateways | Border Gateway Protocol route security |
| Guidelines for Information Technology Equipment | IT equipment usage | IT equipment selection |
| Guidelines for Software Development | Web application development | Web application event logging |
| Guidelines for Software Development | Web application development | Web application input handling |
| Guidelines for Software Development | Web application development | Web application interaction with databases |
| Guidelines for Software Development | Web application development | Web browser-based controls |
| Guidelines for System Hardening | Authentication hardening | Session and screen locking |
| Guidelines for System Hardening | Operating system hardening | Host-based Intrusion Prevention System |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for software development | Software development fundamentals | 4 | 4 | 16 | 1 | 25 |
| Guidelines for cybersecurity roles | Chief information security officer | 0 | 0 | 2 | 12 | 14 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | 10 | 0 | 0 | 0 | 10 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | 0 | 0 | 1 | 8 | 9 |
| Guidelines for system monitoring | Event logging and monitoring | 0 | 0 | 0 | 8 | 8 |
| Guidelines for cybersecurity roles | System owners | 0 | 1 | 3 | 1 | 5 |
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | 0 | 0 | 1 | 3 | 4 |
| Guidelines for system hardening | Operating system hardening | 0 | 1 | 3 | 0 | 4 |
| Guidelines for physical security | Facilities and systems | 3 | 0 | 0 | 0 | 3 |
| Guidelines for system hardening | Server application hardening | 1 | 1 | 1 | 0 | 3 |
| Guidelines for system hardening | Authentication hardening | 2 | 1 | 0 | 0 | 3 |
| Guidelines for gateways | Gateways | 2 | 1 | 0 | 0 | 3 |
| Guidelines for procurement and outsourcing | Cyber supply chain risk management | 0 | 0 | 0 | 3 | 3 |
| Guidelines for cybersecurity documentation | System-specific cybersecurity documentation | 1 | 0 | 0 | 1 | 2 |
| Guidelines for networking | Network design and configuration | 1 | 0 | 1 | 0 | 2 |
| Guidelines for enterprise mobility | Mobile device usage | 0 | 0 | 2 | 0 | 2 |
| Guidelines for system hardening | User application hardening | 0 | 1 | 1 | 0 | 2 |
| Guidelines for database systems | Database servers | 0 | 1 | 1 | 0 | 2 |
| Guidelines for cybersecurity incidents | Responding to cybersecurity incidents | 0 | 0 | 0 | 2 | 2 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | 0 | 0 | 0 | 1 | 1 |
| Guidelines for personnel security | Cybersecurity awareness training | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system management | System administration | 0 | 1 | 0 | 0 | 1 |
| Guidelines for database systems | Databases | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | Virtualisation hardening | 0 | 1 | 0 | 0 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for system monitoring | Event logging and monitoring | Event log monitoring | 0 | 0 | 0 | 8 | 8 |
| Guidelines for software development | Software development fundamentals | Network application programming interfaces | 3 | 0 | 3 | 0 | 6 |
| Guidelines for software development | Software development fundamentals | Secure software development | 0 | 2 | 4 | 0 | 6 |
| Guidelines for cybersecurity roles | System owners | Protecting systems and their resources | 0 | 1 | 3 | 1 | 5 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | Embedding cybersecurity | 4 | 0 | 0 | 0 | 4 |
| Guidelines for software development | Software development fundamentals | Software interaction with databases | 0 | 0 | 4 | 0 | 4 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | Building cybersecurity expertise | 3 | 0 | 0 | 0 | 3 |
| Guidelines for physical security | Facilities and systems | Bringing medical devices into facilities | 3 | 0 | 0 | 0 | 3 |
| Guidelines for cybersecurity roles | Chief information security officer | Overseeing the cybersecurity program | 0 | 0 | 0 | 3 | 3 |
| Guidelines for procurement and outsourcing | Cyber supply chain risk management | Cyber supply chain risk management activities | 0 | 0 | 0 | 3 | 3 |
| Guidelines for software development | Software development fundamentals | Software input handling | 1 | 1 | 0 | 0 | 2 |
| Guidelines for gateways | Gateways | Assessment of gateways | 1 | 1 | 0 | 0 | 2 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Cybersecurity incident register | 0 | 0 | 1 | 1 | 2 |
| Guidelines for software development | Software development fundamentals | Development, testing, staging and production environments | 0 | 0 | 2 | 0 | 2 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Cybersecurity incident management policy | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cybersecurity roles | Chief information security officer | Reporting on cybersecurity | 0 | 0 | 1 | 1 | 2 |
| Guidelines for cybersecurity roles | Chief information security officer | Coordinating cybersecurity | 0 | 0 | 1 | 1 | 2 |
| Guidelines for cybersecurity roles | Chief information security officer | Overseeing cybersecurity incident response activities | 0 | 0 | 0 | 2 | 2 |
| Guidelines for enterprise mobility | Mobile device usage | Using mobile devices in public spaces | 0 | 0 | 2 | 0 | 2 |
| Guidelines for system hardening | Operating system hardening | Host-based intrusion detection and response | 0 | 0 | 2 | 0 | 2 |
| Guidelines for software development | Software development fundamentals | Reporting and resolving vulnerabilities | 0 | 0 | 2 | 0 | 2 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Reporting cybersecurity incidents to customers and the public | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cybersecurity documentation | System-specific cybersecurity documentation | Change and configuration management plan | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | Championing a positive cybersecurity culture | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | Identifying critical business assets | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cybersecurity roles | Board of directors and executive committee | Planning for major cybersecurity incidents | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Domain Services account hardening | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system hardening | Authentication hardening | Multi-factor authentication | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system hardening | Authentication hardening | Screen locking | 1 | 0 | 0 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Encrypted Domain Name System Services | 1 | 0 | 0 | 0 | 1 |
| Guidelines for gateways | Gateways | Border Gateway Protocol routing security | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | Cybersecurity strategy | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity documentation | System-specific cybersecurity documentation | Cybersecurity incident response plan | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | Approval of cybersecurity documentation | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Access to sufficient data sources and tools | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Reporting cybersecurity incidents | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity incidents | Managing cybersecurity incidents | Reporting cybersecurity incidents to ASD | 0 | 0 | 0 | 1 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Contractual security requirements with service providers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for personnel security | Cybersecurity awareness training | Providing cybersecurity awareness training | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Operating system hardening | Hardening operating system configurations | 0 | 0 | 1 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Software security testing | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Authentication hardening | Session locking | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cybersecurity roles | Chief information security officer | Providing cybersecurity leadership and guidance | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity roles | Chief information security officer | Overseeing cybersecurity personnel | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity roles | Chief information security officer | Communicating a cybersecurity vision and strategy | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity roles | Chief information security officer | Receiving and managing a dedicated cybersecurity budget | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity roles | Chief information security officer | Overseeing cybersecurity awareness raising | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | Maintenance of cybersecurity documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | User application selection | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system management | System administration | System administration processes and procedures | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | Server application hardening | Hardening server application configurations | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Database servers | Network environment | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Database servers | Segregation of development, testing, staging and production database servers | 0 | 1 | 0 | 0 | 1 |
| Guidelines for database systems | Databases | Segregation of development, testing, staging and production databases | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Default user accounts and credentials for network devices | 0 | 0 | 1 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Web security policy response headers | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | Virtualisation hardening | Functional separation between computing environments | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cybersecurity documentation | Development and maintenance of cybersecurity documentation | Communication of cybersecurity documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Operating system hardening | Operating system selection | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | User application hardening | Hardening user application configurations | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cybersecurity incidents | Responding to cybersecurity incidents | Enacting cybersecurity incident response plans | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Server application hardening | Server application selection | 0 | 1 | 0 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Software event logging | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cybersecurity incidents | Responding to cybersecurity incidents | Handling and containing malicious code infections | 0 | 0 | 0 | 1 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-0912 | NC|OS|P|S|TS | Guidelines for cybersecurity documentation › Change and configuration management plan | Systems have a change and configuration management plan that includes: - what constitutes routine and urgent changes to the configuration of systems -… |
| ISM-1997 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Embedding cybersecurity | The board of directors or executive committee defines clear roles and responsibilities for cybersecurity both within the board of directors or executi… |
| ISM-1998 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Embedding cybersecurity | The board of directors or executive committee ensures that cybersecurity is integrated throughout all business functions within their organisation. |
| ISM-1999 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Embedding cybersecurity | The board of directors or executive committee ensures the cybersecurity strategy for their organisation is aligned with the overarching strategic dire… |
| ISM-2000 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Embedding cybersecurity | The board of directors or executive committee seeks regular briefings or reporting on the cybersecurity posture of their organisation, as well as the … |
| ISM-2001 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Championing a positive cybersecurity culture | The board of directors or executive committee champions a positive cybersecurity culture within their organisation, including through leading by examp… |
| ISM-2002 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Building cybersecurity expertise | The board of directors or executive committee maintains a sufficient level of cybersecurity literacy to fulfil both their fiduciary duties and any leg… |
| ISM-2003 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Building cybersecurity expertise | The board of directors or executive committee maintains awareness of key cybersecurity recruitment activities, retention rates for cybersecurity perso… |
| ISM-2004 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Building cybersecurity expertise | The board of directors or executive committee supports the development of cybersecurity skills and experience for all personnel via internal and exter… |
| ISM-2005 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Identifying critical business assets | The board of directors or executive committee understands the business criticality of their organisation’s systems, applications and data, including a… |
| ISM-2006 | NC|OS|P|S|TS | Guidelines for cybersecurity roles › Planning for major cybersecurity incidents | The board of directors or executive committee plans for major cybersecurity incidents, including by participating in exercises, and understand their d… |
| ISM-2007 | S|TS | Guidelines for physical security › Bringing medical devices into facilities | An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis. |
| ISM-2008 | S|TS | Guidelines for physical security › Bringing medical devices into facilities | Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Aus… |
| ISM-2009 | S|TS | Guidelines for physical security › Bringing medical devices into facilities | Unauthorised medical devices are not brought into SECRET and TOP SECRET areas. |
| ISM-2010 | NC|OS|P|S|TS | Guidelines for system hardening › Microsoft Active Directory Domain Services account hardening | Service accounts configured with an SPN use the Advanced Encryption Standard for encryption. |
| ISM-2011 | NC|OS|P|S|TS | Guidelines for system hardening › Multi-factor authentication | When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are dis… |
| ISM-2012 | NC|OS|P|S|TS | Guidelines for system hardening › Screen locking | Systems are configured with a screen lock that: - activates after a maximum of 15 minutes of user inactivity, or when manually activated by users - co… |
| ISM-2013 | NC|OS|P|S|TS | Guidelines for software development › Network application programming interfaces | Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible ov… |
| ISM-2014 | NC|OS|P|S|TS | Guidelines for software development › Network application programming interfaces | Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into… |
| ISM-2015 | NC|OS|P|S|TS | Guidelines for software development › Network application programming interfaces | Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible ov… |
| ISM-2016 | NC|OS|P|S|TS | Guidelines for software development › Software input handling | Validation or sanitisation is performed on all input received over a local network by software. |
| ISM-2017 | NC|OS|P|S|TS | Guidelines for networking › Encrypted Domain Name System Services | DNS traffic is encrypted by clients and servers wherever supported. |
| ISM-2018 | NC|OS|P|S|TS | Guidelines for gateways › Border Gateway Protocol routing security | Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or depriori… |
| ISM-2019 | TS | Guidelines for gateways › Assessment of gateways | TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the be… |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-0938 | 0.95 | Guidelines for system hardening › User application selection | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices… |
| ISM-1743 | 0.95 | Guidelines for system hardening › Operating system selection | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices… |
| ISM-1826 | 0.93 | Guidelines for system hardening › Server application selection | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices… |
| ISM-1633 | 0.87 | Guidelines for cybersecurity roles › Protecting systems and their resources | System owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality and security objectives for… |
| ISM-0401 | 0.87 | Guidelines for software development › Secure software development | Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages o… |
| ISM-0100 | 0.65 | Guidelines for gateways › Assessment of gateways | Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to … |
| ISM-0428 | 0.63 | Guidelines for system hardening › Session locking | Services are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall sessi… |
| ISM-1273 | 0.56 | Guidelines for database systems › Segregation of development, testing, staging and production database servers | Database servers for development, testing, staging and production environments are segregated. |
| ISM-1211 | 0.55 | Guidelines for system management › System administration processes and procedures | System administrators perform system administration activities in accordance with the system’s change and configuration management plan. |
| ISM-1460 | 0.52 | Guidelines for system hardening › Functional separation between computing environments | When using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism is from a vendor that has demonstrated … |
| ISM-1796 | 0.29 | Guidelines for software development › Secure software development | Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development. |
| ISM-1240 | 0.28 | Guidelines for software development › Software input handling | Validation or sanitisation is performed on all input received over the internet by software. |
| ISM-1424 | 0.26 | Guidelines for software development › Web security policy response headers | Content-Security-Policy, HSTS and X-Frame-Options are specified by web server software via security policy in response headers. |
| Control | Edit dist | Location |
|---|---|---|
| ISM-1636 | 0.24 | Guidelines for cybersecurity roles › Protecting systems and their resources |
| ISM-1271 | 0.23 | Guidelines for database systems › Network environment |
| ISM-1634 | 0.22 | Guidelines for cybersecurity roles › Protecting systems and their resources |
| ISM-0725 | 0.22 | Guidelines for cybersecurity roles › Coordinating cybersecurity |
| ISM-1967 | 0.20 | Guidelines for cybersecurity roles › Protecting systems and their resources |
| ISM-0718 | 0.18 | Guidelines for cybersecurity roles › Reporting on cybersecurity |
| ISM-1341 | 0.17 | Guidelines for system hardening › Host-based intrusion detection and response |
| ISM-1911 | 0.17 | Guidelines for software development › Software event logging |
| ISM-0047 | 0.17 | Guidelines for cybersecurity documentation › Approval of cybersecurity documentation |
| ISM-1818 | 0.16 | Guidelines for software development › Network application programming interfaces |
| ISM-1420 | 0.16 | Guidelines for software development › Development, testing, staging and production environments |
| ISM-1780 | 0.15 | Guidelines for software development › Secure software development |
| ISM-1803 | 0.14 | Guidelines for cybersecurity incidents › Cybersecurity incident register |
| ISM-1910 | 0.14 | Guidelines for software development › Network application programming interfaces |
| ISM-1238 | 0.14 | Guidelines for software development › Secure software development |
| ISM-1274 | 0.14 | Guidelines for database systems › Segregation of development, testing, staging and production databases |
| ISM-1817 | 0.12 | Guidelines for software development › Network application programming interfaces |
| ISM-1798 | 0.11 | Guidelines for software development › Secure software development |
| ISM-1034 | 0.11 | Guidelines for system hardening › Host-based intrusion detection and response |
| ISM-1275 | 0.10 | Guidelines for software development › Software interaction with databases |
| ISM-1754 | 0.09 | Guidelines for software development › Reporting and resolving vulnerabilities |
| ISM-1278 | 0.09 | Guidelines for software development › Software interaction with databases |
| ISM-1304 | 0.08 | Guidelines for networking › Default user accounts and credentials for network devices |
| ISM-0383 | 0.08 | Guidelines for system hardening › Hardening operating system configurations |
| ISM-1806 | 0.08 | Guidelines for system hardening › Hardening user application configurations |
| ISM-1260 | 0.08 | Guidelines for system hardening › Hardening server application configurations |
| ISM-1536 | 0.07 | Guidelines for software development › Software interaction with databases |
| ISM-1276 | 0.07 | Guidelines for software development › Software interaction with databases |
| ISM-1797 | 0.07 | Guidelines for software development › Secure software development |
| ISM-1908 | 0.07 | Guidelines for software development › Reporting and resolving vulnerabilities |
| ISM-0400 | 0.07 | Guidelines for software development › Development, testing, staging and production environments |
| ISM-0866 | 0.06 | Guidelines for enterprise mobility › Using mobile devices in public spaces |
| ISM-1644 | 0.06 | Guidelines for enterprise mobility › Using mobile devices in public spaces |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for Security Documentation | Guidelines for cybersecurity documentation | ISM-0039 ISM-0041 ISM-0043 ISM-0047 ISM-0888 ISM-1163 ISM-1563 ISM-1564 ISM-1602 ISM-1739 |
| Guidelines for Software Development | Guidelines for software development | ISM-0400 ISM-0401 ISM-0402 ISM-1238 ISM-1240 ISM-1275 ISM-1276 ISM-1278 ISM-1419 ISM-1420 ISM-1422 ISM-1424 ISM-1536 ISM-1616 ISM-1717 ISM-1730 ISM-1754 ISM-1755 ISM-1756 ISM-1780 ISM-1796 ISM-1797 ISM-1798 ISM-1816 ISM-1817 ISM-1818 ISM-1908 ISM-1909 ISM-1910 ISM-1911 ISM-1922 ISM-1923 ISM-1924 |
| Guidelines for System Hardening | Guidelines for system hardening | ISM-0428 ISM-1034 ISM-1341 |
| Guidelines for Database Systems | Guidelines for database systems | ISM-1273 ISM-1274 |
| Guidelines for Gateways | Guidelines for gateways | ISM-1783 |
| Control | Direction | Footprint before → after | Location |
|---|---|---|---|
| ISM-0100 | narrowed | NC|OS|P|S|TS → NC|OS|P|S | Assessment of gateways |
| Control | Footprint | Former location | Statement (excerpt) |
|---|---|---|---|
| ISM-1857 | NC|OS|P|S|TS | Guidelines for Information Technology Equipment | IT equipment is chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe progr… |
revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.