ASD ISM — incremental change analysis

Release v2025.03.31 (2025-03-31) vs prior v2024.12.19 · 102 days · catalogue 1003 controls · NC-explicit era
ASD changes summary: ISM March 2025 changes (PDF)
24
Added
13
Substantive
33
Clarification
41
Editorial
49
Relocated
1
Scope changes
1
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET361
SECRET13
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified033

3 · Level-specific material changes

FootprintFloorCeilingControls
TSTOP SECRETTOP SECRETISM-2019
S|TSSECRETTOP SECRETISM-2007 ISM-2008 ISM-2009
NC|OS|P|SNon-ClassifiedSECRETISM-0100

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (24)

ControlFootprintLocationStatement (excerpt)
ISM-0912NC|OS|P|S|TSGuidelines for cybersecurity documentation › Change and configuration management planSystems have a change and configuration management plan that includes: - what constitutes routine and urgent changes to the configuration of systems -…
ISM-1997NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee defines clear roles and responsibilities for cybersecurity both within the board of directors or executi…
ISM-1998NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee ensures that cybersecurity is integrated throughout all business functions within their organisation.
ISM-1999NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee ensures the cybersecurity strategy for their organisation is aligned with the overarching strategic dire…
ISM-2000NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee seeks regular briefings or reporting on the cybersecurity posture of their organisation, as well as the …
ISM-2001NC|OS|P|S|TSGuidelines for cybersecurity roles › Championing a positive cybersecurity cultureThe board of directors or executive committee champions a positive cybersecurity culture within their organisation, including through leading by examp…
ISM-2002NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee maintains a sufficient level of cybersecurity literacy to fulfil both their fiduciary duties and any leg…
ISM-2003NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee maintains awareness of key cybersecurity recruitment activities, retention rates for cybersecurity perso…
ISM-2004NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee supports the development of cybersecurity skills and experience for all personnel via internal and exter…
ISM-2005NC|OS|P|S|TSGuidelines for cybersecurity roles › Identifying critical business assetsThe board of directors or executive committee understands the business criticality of their organisation’s systems, applications and data, including a…
ISM-2006NC|OS|P|S|TSGuidelines for cybersecurity roles › Planning for major cybersecurity incidentsThe board of directors or executive committee plans for major cybersecurity incidents, including by participating in exercises, and understand their d…
ISM-2007S|TSGuidelines for physical security › Bringing medical devices into facilitiesAn authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.
ISM-2008S|TSGuidelines for physical security › Bringing medical devices into facilitiesMedical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Aus…
ISM-2009S|TSGuidelines for physical security › Bringing medical devices into facilitiesUnauthorised medical devices are not brought into SECRET and TOP SECRET areas.
ISM-2010NC|OS|P|S|TSGuidelines for system hardening › Microsoft Active Directory Domain Services account hardeningService accounts configured with an SPN use the Advanced Encryption Standard for encryption.
ISM-2011NC|OS|P|S|TSGuidelines for system hardening › Multi-factor authenticationWhen phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are dis…
ISM-2012NC|OS|P|S|TSGuidelines for system hardening › Screen lockingSystems are configured with a screen lock that: - activates after a maximum of 15 minutes of user inactivity, or when manually activated by users - co…
ISM-2013NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesAuthentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible ov…
ISM-2014NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesAuthentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into…
ISM-2015NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesNetwork API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible ov…
ISM-2016NC|OS|P|S|TSGuidelines for software development › Software input handlingValidation or sanitisation is performed on all input received over a local network by software.
ISM-2017NC|OS|P|S|TSGuidelines for networking › Encrypted Domain Name System ServicesDNS traffic is encrypted by clients and servers wherever supported.
ISM-2018NC|OS|P|S|TSGuidelines for gateways › Border Gateway Protocol routing securityRoutes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or depriori…
ISM-2019TSGuidelines for gateways › Assessment of gatewaysTOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the be…

Substantive amendments (13)

ControlEdit distLocationStatement (excerpt)
ISM-09380.95Guidelines for system hardening › User application selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-17430.95Guidelines for system hardening › Operating system selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-18260.93Guidelines for system hardening › Server application selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-16330.87Guidelines for cybersecurity roles › Protecting systems and their resourcesSystem owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality and security objectives for…
ISM-04010.87Guidelines for software development › Secure software developmentSecure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages o…
ISM-01000.65Guidelines for gateways › Assessment of gatewaysNon-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to …
ISM-04280.63Guidelines for system hardening › Session lockingServices are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall sessi…
ISM-12730.56Guidelines for database systems › Segregation of development, testing, staging and production database serversDatabase servers for development, testing, staging and production environments are segregated.
ISM-12110.55Guidelines for system management › System administration processes and proceduresSystem administrators perform system administration activities in accordance with the system’s change and configuration management plan.
ISM-14600.52Guidelines for system hardening › Functional separation between computing environmentsWhen using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism is from a vendor that has demonstrated …
ISM-17960.29Guidelines for software development › Secure software developmentFiles containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.
ISM-12400.28Guidelines for software development › Software input handlingValidation or sanitisation is performed on all input received over the internet by software.
ISM-14240.26Guidelines for software development › Web security policy response headersContent-Security-Policy, HSTS and X-Frame-Options are specified by web server software via security policy in response headers.

Clarifications (33)

ControlEdit distLocation
ISM-16360.24Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-12710.23Guidelines for database systems › Network environment
ISM-16340.22Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-07250.22Guidelines for cybersecurity roles › Coordinating cybersecurity
ISM-19670.20Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-07180.18Guidelines for cybersecurity roles › Reporting on cybersecurity
ISM-13410.17Guidelines for system hardening › Host-based intrusion detection and response
ISM-19110.17Guidelines for software development › Software event logging
ISM-00470.17Guidelines for cybersecurity documentation › Approval of cybersecurity documentation
ISM-18180.16Guidelines for software development › Network application programming interfaces
ISM-14200.16Guidelines for software development › Development, testing, staging and production environments
ISM-17800.15Guidelines for software development › Secure software development
ISM-18030.14Guidelines for cybersecurity incidents › Cybersecurity incident register
ISM-19100.14Guidelines for software development › Network application programming interfaces
ISM-12380.14Guidelines for software development › Secure software development
ISM-12740.14Guidelines for database systems › Segregation of development, testing, staging and production databases
ISM-18170.12Guidelines for software development › Network application programming interfaces
ISM-17980.11Guidelines for software development › Secure software development
ISM-10340.11Guidelines for system hardening › Host-based intrusion detection and response
ISM-12750.10Guidelines for software development › Software interaction with databases
ISM-17540.09Guidelines for software development › Reporting and resolving vulnerabilities
ISM-12780.09Guidelines for software development › Software interaction with databases
ISM-13040.08Guidelines for networking › Default user accounts and credentials for network devices
ISM-03830.08Guidelines for system hardening › Hardening operating system configurations
ISM-18060.08Guidelines for system hardening › Hardening user application configurations
ISM-12600.08Guidelines for system hardening › Hardening server application configurations
ISM-15360.07Guidelines for software development › Software interaction with databases
ISM-12760.07Guidelines for software development › Software interaction with databases
ISM-17970.07Guidelines for software development › Secure software development
ISM-19080.07Guidelines for software development › Reporting and resolving vulnerabilities
ISM-04000.07Guidelines for software development › Development, testing, staging and production environments
ISM-08660.06Guidelines for enterprise mobility › Using mobile devices in public spaces
ISM-16440.06Guidelines for enterprise mobility › Using mobile devices in public spaces

Editorial / grammatical (41)

Cosmetic edits (normalised edit distance < 0.05). ISM-0039, ISM-0043, ISM-0109, ISM-0120, ISM-0123, ISM-0125, ISM-0140, ISM-0141, ISM-0252, ISM-0402, ISM-0576, ISM-0714, ISM-0717, ISM-0720, ISM-0724, ISM-0726, ISM-0732, ISM-0733, ISM-0735, ISM-0888, ISM-1228, ISM-1478, ISM-1526, ISM-1568, ISM-1602, ISM-1617, ISM-1618, ISM-1632, ISM-1784, ISM-1819, ISM-1880, ISM-1881, ISM-1882, ISM-1906, ISM-1907, ISM-1918, ISM-1960, ISM-1961, ISM-1970, ISM-1986, ISM-1987

Relocated (49)

49 cross-chapter moves (listed) · 0 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Security DocumentationGuidelines for cybersecurity documentationISM-0039 ISM-0041 ISM-0043 ISM-0047 ISM-0888 ISM-1163 ISM-1563 ISM-1564 ISM-1602 ISM-1739
Guidelines for Software DevelopmentGuidelines for software developmentISM-0400 ISM-0401 ISM-0402 ISM-1238 ISM-1240 ISM-1275 ISM-1276 ISM-1278 ISM-1419 ISM-1420 ISM-1422 ISM-1424 ISM-1536 ISM-1616 ISM-1717 ISM-1730 ISM-1754 ISM-1755 ISM-1756 ISM-1780 ISM-1796 ISM-1797 ISM-1798 ISM-1816 ISM-1817 ISM-1818 ISM-1908 ISM-1909 ISM-1910 ISM-1911 ISM-1922 ISM-1923 ISM-1924
Guidelines for System HardeningGuidelines for system hardeningISM-0428 ISM-1034 ISM-1341
Guidelines for Database SystemsGuidelines for database systemsISM-1273 ISM-1274
Guidelines for GatewaysGuidelines for gatewaysISM-1783

Scope / applicability changes (1)

ControlDirectionFootprint before → afterLocation
ISM-0100narrowedNC|OS|P|S|TSNC|OS|P|SAssessment of gateways

Removed (1)

ControlFootprintFormer locationStatement (excerpt)
ISM-1857NC|OS|P|S|TSGuidelines for Information Technology EquipmentIT equipment is chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe progr…
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.