ASD ISM — incremental change analysis

Release v2025.03.31 (2025-03-31) vs prior v2024.12.19 · 102 days · catalogue 1003 controls · NC-explicit era
ASD changes summary: ISM March 2025 changes (PDF)
24
Added
13
Substantive
33
Clarification
41
Editorial
49
Relocated
1
Scope changes
1
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET361
SECRET13
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified033

3 · Level-specific material changes

FootprintFloorCeilingControls
TSTOP SECRETTOP SECRETISM-2019
S|TSSECRETTOP SECRETISM-2007 ISM-2008 ISM-2009
NC|OS|P|SNon-ClassifiedSECRETISM-0100

4 · Change location by chapter

5 · Section / topic structure

New sections: 4 · Removed sections: 3 · New topics: 8 · Removed topics: 10. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentation5ISM-0039 ISM-0047 ISM-1739 ISM-0888 ISM-1602
Guidelines for cybersecurity documentationSystem-specific cybersecurity documentation6ISM-0041 ISM-0043 ISM-0912 ISM-1163 ISM-1563 ISM-1564
Guidelines for cybersecurity rolesBoard of directors and executive committee10ISM-1997 ISM-1998 ISM-1999 ISM-2000 ISM-2001 ISM-2002 ISM-2003 ISM-2004 ISM-2005 ISM-2006
Guidelines for software developmentSoftware development fundamentals37ISM-0400 ISM-1419 ISM-1420 ISM-1422 ISM-1816 ISM-0401 ISM-1780 ISM-1238 ISM-1922 ISM-1923 ISM-1924 ISM-1796 ISM-1797 ISM-1798 ISM-1730 ISM-1818 ISM-2013 ISM-1817 ISM-2014 ISM-1910 ISM-2015 ISM-1240 ISM-2016 ISM-1424 ISM-1275 ISM-1276 ISM-1278 ISM-1536 ISM-0402 ISM-1616 ISM-1755 ISM-1756 ISM-1717 ISM-1908 ISM-1754 ISM-1909 ISM-1911

Removed sections

ChapterSection
Guidelines for Security DocumentationDevelopment and maintenance of security documentation
Guidelines for Security DocumentationSystem-specific security documentation
Guidelines for Software DevelopmentApplication development

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for database systemsDatabase serversSegregation of development, testing, staging and production database servers1ISM-1273
Guidelines for database systemsDatabasesSegregation of development, testing, staging and production databases1ISM-1274
Guidelines for gatewaysGatewaysBorder Gateway Protocol routing security2ISM-1783 ISM-2018
Guidelines for networkingNetwork design and configurationEncrypted Domain Name System Services1ISM-2017
Guidelines for physical securityFacilities and systemsBringing medical devices into facilities3ISM-2007 ISM-2008 ISM-2009
Guidelines for system hardeningAuthentication hardeningScreen locking1ISM-2012
Guidelines for system hardeningAuthentication hardeningSession locking1ISM-0428
Guidelines for system hardeningOperating system hardeningHost-based intrusion detection and response2ISM-1341 ISM-1034

Removed topics

ChapterSectionTopic
Guidelines for Database SystemsDatabase serversSeparation of development, testing and production database servers
Guidelines for Database SystemsDatabasesSeparation of development, testing and production databases
Guidelines for GatewaysGatewaysBorder Gateway Protocol route security
Guidelines for Information Technology EquipmentIT equipment usageIT equipment selection
Guidelines for Software DevelopmentWeb application developmentWeb application event logging
Guidelines for Software DevelopmentWeb application developmentWeb application input handling
Guidelines for Software DevelopmentWeb application developmentWeb application interaction with databases
Guidelines for Software DevelopmentWeb application developmentWeb browser-based controls
Guidelines for System HardeningAuthentication hardeningSession and screen locking
Guidelines for System HardeningOperating system hardeningHost-based Intrusion Prevention System

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for software developmentSoftware development fundamentals4416125
Guidelines for cybersecurity rolesChief information security officer0021214
Guidelines for cybersecurity rolesBoard of directors and executive committee1000010
Guidelines for cybersecurity incidentsManaging cybersecurity incidents00189
Guidelines for system monitoringEvent logging and monitoring00088
Guidelines for cybersecurity rolesSystem owners01315
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentation00134
Guidelines for system hardeningOperating system hardening01304
Guidelines for physical securityFacilities and systems30003
Guidelines for system hardeningServer application hardening11103
Guidelines for system hardeningAuthentication hardening21003
Guidelines for gatewaysGateways21003
Guidelines for procurement and outsourcingCyber supply chain risk management00033
Guidelines for cybersecurity documentationSystem-specific cybersecurity documentation10012
Guidelines for networkingNetwork design and configuration10102
Guidelines for enterprise mobilityMobile device usage00202
Guidelines for system hardeningUser application hardening01102
Guidelines for database systemsDatabase servers01102
Guidelines for cybersecurity incidentsResponding to cybersecurity incidents00022
Guidelines for procurement and outsourcingManaged services and cloud services00011
Guidelines for personnel securityCybersecurity awareness training00011
Guidelines for system managementSystem administration01001
Guidelines for database systemsDatabases00101
Guidelines for system hardeningVirtualisation hardening01001

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for system monitoringEvent logging and monitoringEvent log monitoring00088
Guidelines for software developmentSoftware development fundamentalsNetwork application programming interfaces30306
Guidelines for software developmentSoftware development fundamentalsSecure software development02406
Guidelines for cybersecurity rolesSystem ownersProtecting systems and their resources01315
Guidelines for cybersecurity rolesBoard of directors and executive committeeEmbedding cybersecurity40004
Guidelines for software developmentSoftware development fundamentalsSoftware interaction with databases00404
Guidelines for cybersecurity rolesBoard of directors and executive committeeBuilding cybersecurity expertise30003
Guidelines for physical securityFacilities and systemsBringing medical devices into facilities30003
Guidelines for cybersecurity rolesChief information security officerOverseeing the cybersecurity program00033
Guidelines for procurement and outsourcingCyber supply chain risk managementCyber supply chain risk management activities00033
Guidelines for software developmentSoftware development fundamentalsSoftware input handling11002
Guidelines for gatewaysGatewaysAssessment of gateways11002
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsCybersecurity incident register00112
Guidelines for software developmentSoftware development fundamentalsDevelopment, testing, staging and production environments00202
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsCybersecurity incident management policy00022
Guidelines for cybersecurity rolesChief information security officerReporting on cybersecurity00112
Guidelines for cybersecurity rolesChief information security officerCoordinating cybersecurity00112
Guidelines for cybersecurity rolesChief information security officerOverseeing cybersecurity incident response activities00022
Guidelines for enterprise mobilityMobile device usageUsing mobile devices in public spaces00202
Guidelines for system hardeningOperating system hardeningHost-based intrusion detection and response00202
Guidelines for software developmentSoftware development fundamentalsReporting and resolving vulnerabilities00202
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsReporting cybersecurity incidents to customers and the public00022
Guidelines for cybersecurity documentationSystem-specific cybersecurity documentationChange and configuration management plan10001
Guidelines for cybersecurity rolesBoard of directors and executive committeeChampioning a positive cybersecurity culture10001
Guidelines for cybersecurity rolesBoard of directors and executive committeeIdentifying critical business assets10001
Guidelines for cybersecurity rolesBoard of directors and executive committeePlanning for major cybersecurity incidents10001
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Domain Services account hardening10001
Guidelines for system hardeningAuthentication hardeningMulti-factor authentication10001
Guidelines for system hardeningAuthentication hardeningScreen locking10001
Guidelines for networkingNetwork design and configurationEncrypted Domain Name System Services10001
Guidelines for gatewaysGatewaysBorder Gateway Protocol routing security10001
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentationCybersecurity strategy00011
Guidelines for cybersecurity documentationSystem-specific cybersecurity documentationCybersecurity incident response plan00011
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentationApproval of cybersecurity documentation00101
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsAccess to sufficient data sources and tools00011
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsReporting cybersecurity incidents00011
Guidelines for cybersecurity incidentsManaging cybersecurity incidentsReporting cybersecurity incidents to ASD00011
Guidelines for procurement and outsourcingManaged services and cloud servicesContractual security requirements with service providers00011
Guidelines for personnel securityCybersecurity awareness trainingProviding cybersecurity awareness training00011
Guidelines for system hardeningOperating system hardeningHardening operating system configurations00101
Guidelines for software developmentSoftware development fundamentalsSoftware security testing00011
Guidelines for system hardeningAuthentication hardeningSession locking01001
Guidelines for cybersecurity rolesChief information security officerProviding cybersecurity leadership and guidance00011
Guidelines for cybersecurity rolesChief information security officerOverseeing cybersecurity personnel00011
Guidelines for cybersecurity rolesChief information security officerCommunicating a cybersecurity vision and strategy00011
Guidelines for cybersecurity rolesChief information security officerReceiving and managing a dedicated cybersecurity budget00011
Guidelines for cybersecurity rolesChief information security officerOverseeing cybersecurity awareness raising00011
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentationMaintenance of cybersecurity documentation00011
Guidelines for system hardeningUser application hardeningUser application selection01001
Guidelines for system managementSystem administrationSystem administration processes and procedures01001
Guidelines for system hardeningServer application hardeningHardening server application configurations00101
Guidelines for database systemsDatabase serversNetwork environment00101
Guidelines for database systemsDatabase serversSegregation of development, testing, staging and production database servers01001
Guidelines for database systemsDatabasesSegregation of development, testing, staging and production databases00101
Guidelines for networkingNetwork design and configurationDefault user accounts and credentials for network devices00101
Guidelines for software developmentSoftware development fundamentalsWeb security policy response headers01001
Guidelines for system hardeningVirtualisation hardeningFunctional separation between computing environments01001
Guidelines for cybersecurity documentationDevelopment and maintenance of cybersecurity documentationCommunication of cybersecurity documentation00011
Guidelines for system hardeningOperating system hardeningOperating system selection01001
Guidelines for system hardeningUser application hardeningHardening user application configurations00101
Guidelines for cybersecurity incidentsResponding to cybersecurity incidentsEnacting cybersecurity incident response plans00011
Guidelines for system hardeningServer application hardeningServer application selection01001
Guidelines for software developmentSoftware development fundamentalsSoftware event logging00101
Guidelines for cybersecurity incidentsResponding to cybersecurity incidentsHandling and containing malicious code infections00011

6 · Control call-outs by category

Added — new controls (24)

ControlFootprintLocationStatement (excerpt)
ISM-0912NC|OS|P|S|TSGuidelines for cybersecurity documentation › Change and configuration management planSystems have a change and configuration management plan that includes: - what constitutes routine and urgent changes to the configuration of systems -…
ISM-1997NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee defines clear roles and responsibilities for cybersecurity both within the board of directors or executi…
ISM-1998NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee ensures that cybersecurity is integrated throughout all business functions within their organisation.
ISM-1999NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee ensures the cybersecurity strategy for their organisation is aligned with the overarching strategic dire…
ISM-2000NC|OS|P|S|TSGuidelines for cybersecurity roles › Embedding cybersecurityThe board of directors or executive committee seeks regular briefings or reporting on the cybersecurity posture of their organisation, as well as the …
ISM-2001NC|OS|P|S|TSGuidelines for cybersecurity roles › Championing a positive cybersecurity cultureThe board of directors or executive committee champions a positive cybersecurity culture within their organisation, including through leading by examp…
ISM-2002NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee maintains a sufficient level of cybersecurity literacy to fulfil both their fiduciary duties and any leg…
ISM-2003NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee maintains awareness of key cybersecurity recruitment activities, retention rates for cybersecurity perso…
ISM-2004NC|OS|P|S|TSGuidelines for cybersecurity roles › Building cybersecurity expertiseThe board of directors or executive committee supports the development of cybersecurity skills and experience for all personnel via internal and exter…
ISM-2005NC|OS|P|S|TSGuidelines for cybersecurity roles › Identifying critical business assetsThe board of directors or executive committee understands the business criticality of their organisation’s systems, applications and data, including a…
ISM-2006NC|OS|P|S|TSGuidelines for cybersecurity roles › Planning for major cybersecurity incidentsThe board of directors or executive committee plans for major cybersecurity incidents, including by participating in exercises, and understand their d…
ISM-2007S|TSGuidelines for physical security › Bringing medical devices into facilitiesAn authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.
ISM-2008S|TSGuidelines for physical security › Bringing medical devices into facilitiesMedical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Aus…
ISM-2009S|TSGuidelines for physical security › Bringing medical devices into facilitiesUnauthorised medical devices are not brought into SECRET and TOP SECRET areas.
ISM-2010NC|OS|P|S|TSGuidelines for system hardening › Microsoft Active Directory Domain Services account hardeningService accounts configured with an SPN use the Advanced Encryption Standard for encryption.
ISM-2011NC|OS|P|S|TSGuidelines for system hardening › Multi-factor authenticationWhen phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are dis…
ISM-2012NC|OS|P|S|TSGuidelines for system hardening › Screen lockingSystems are configured with a screen lock that: - activates after a maximum of 15 minutes of user inactivity, or when manually activated by users - co…
ISM-2013NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesAuthentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible ov…
ISM-2014NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesAuthentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into…
ISM-2015NC|OS|P|S|TSGuidelines for software development › Network application programming interfacesNetwork API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible ov…
ISM-2016NC|OS|P|S|TSGuidelines for software development › Software input handlingValidation or sanitisation is performed on all input received over a local network by software.
ISM-2017NC|OS|P|S|TSGuidelines for networking › Encrypted Domain Name System ServicesDNS traffic is encrypted by clients and servers wherever supported.
ISM-2018NC|OS|P|S|TSGuidelines for gateways › Border Gateway Protocol routing securityRoutes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or depriori…
ISM-2019TSGuidelines for gateways › Assessment of gatewaysTOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the be…

Substantive amendments (13)

ControlEdit distLocationStatement (excerpt)
ISM-09380.95Guidelines for system hardening › User application selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-17430.95Guidelines for system hardening › Operating system selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-18260.93Guidelines for system hardening › Server application selectionVendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices…
ISM-16330.87Guidelines for cybersecurity roles › Protecting systems and their resourcesSystem owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality and security objectives for…
ISM-04010.87Guidelines for software development › Secure software developmentSecure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages o…
ISM-01000.65Guidelines for gateways › Assessment of gatewaysNon-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to …
ISM-04280.63Guidelines for system hardening › Session lockingServices are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall sessi…
ISM-12730.56Guidelines for database systems › Segregation of development, testing, staging and production database serversDatabase servers for development, testing, staging and production environments are segregated.
ISM-12110.55Guidelines for system management › System administration processes and proceduresSystem administrators perform system administration activities in accordance with the system’s change and configuration management plan.
ISM-14600.52Guidelines for system hardening › Functional separation between computing environmentsWhen using a software-based isolation mechanism to share a physical server’s hardware, the isolation mechanism is from a vendor that has demonstrated …
ISM-17960.29Guidelines for software development › Secure software developmentFiles containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.
ISM-12400.28Guidelines for software development › Software input handlingValidation or sanitisation is performed on all input received over the internet by software.
ISM-14240.26Guidelines for software development › Web security policy response headersContent-Security-Policy, HSTS and X-Frame-Options are specified by web server software via security policy in response headers.

Clarifications (33)

ControlEdit distLocation
ISM-16360.24Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-12710.23Guidelines for database systems › Network environment
ISM-16340.22Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-07250.22Guidelines for cybersecurity roles › Coordinating cybersecurity
ISM-19670.20Guidelines for cybersecurity roles › Protecting systems and their resources
ISM-07180.18Guidelines for cybersecurity roles › Reporting on cybersecurity
ISM-13410.17Guidelines for system hardening › Host-based intrusion detection and response
ISM-19110.17Guidelines for software development › Software event logging
ISM-00470.17Guidelines for cybersecurity documentation › Approval of cybersecurity documentation
ISM-18180.16Guidelines for software development › Network application programming interfaces
ISM-14200.16Guidelines for software development › Development, testing, staging and production environments
ISM-17800.15Guidelines for software development › Secure software development
ISM-18030.14Guidelines for cybersecurity incidents › Cybersecurity incident register
ISM-19100.14Guidelines for software development › Network application programming interfaces
ISM-12380.14Guidelines for software development › Secure software development
ISM-12740.14Guidelines for database systems › Segregation of development, testing, staging and production databases
ISM-18170.12Guidelines for software development › Network application programming interfaces
ISM-17980.11Guidelines for software development › Secure software development
ISM-10340.11Guidelines for system hardening › Host-based intrusion detection and response
ISM-12750.10Guidelines for software development › Software interaction with databases
ISM-17540.09Guidelines for software development › Reporting and resolving vulnerabilities
ISM-12780.09Guidelines for software development › Software interaction with databases
ISM-13040.08Guidelines for networking › Default user accounts and credentials for network devices
ISM-03830.08Guidelines for system hardening › Hardening operating system configurations
ISM-18060.08Guidelines for system hardening › Hardening user application configurations
ISM-12600.08Guidelines for system hardening › Hardening server application configurations
ISM-15360.07Guidelines for software development › Software interaction with databases
ISM-12760.07Guidelines for software development › Software interaction with databases
ISM-17970.07Guidelines for software development › Secure software development
ISM-19080.07Guidelines for software development › Reporting and resolving vulnerabilities
ISM-04000.07Guidelines for software development › Development, testing, staging and production environments
ISM-08660.06Guidelines for enterprise mobility › Using mobile devices in public spaces
ISM-16440.06Guidelines for enterprise mobility › Using mobile devices in public spaces

Editorial / grammatical (41)

Cosmetic edits (normalised edit distance < 0.05). ISM-0039, ISM-0043, ISM-0109, ISM-0120, ISM-0123, ISM-0125, ISM-0140, ISM-0141, ISM-0252, ISM-0402, ISM-0576, ISM-0714, ISM-0717, ISM-0720, ISM-0724, ISM-0726, ISM-0732, ISM-0733, ISM-0735, ISM-0888, ISM-1228, ISM-1478, ISM-1526, ISM-1568, ISM-1602, ISM-1617, ISM-1618, ISM-1632, ISM-1784, ISM-1819, ISM-1880, ISM-1881, ISM-1882, ISM-1906, ISM-1907, ISM-1918, ISM-1960, ISM-1961, ISM-1970, ISM-1986, ISM-1987

Relocated (49)

49 cross-chapter moves (listed) · 0 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for Security DocumentationGuidelines for cybersecurity documentationISM-0039 ISM-0041 ISM-0043 ISM-0047 ISM-0888 ISM-1163 ISM-1563 ISM-1564 ISM-1602 ISM-1739
Guidelines for Software DevelopmentGuidelines for software developmentISM-0400 ISM-0401 ISM-0402 ISM-1238 ISM-1240 ISM-1275 ISM-1276 ISM-1278 ISM-1419 ISM-1420 ISM-1422 ISM-1424 ISM-1536 ISM-1616 ISM-1717 ISM-1730 ISM-1754 ISM-1755 ISM-1756 ISM-1780 ISM-1796 ISM-1797 ISM-1798 ISM-1816 ISM-1817 ISM-1818 ISM-1908 ISM-1909 ISM-1910 ISM-1911 ISM-1922 ISM-1923 ISM-1924
Guidelines for System HardeningGuidelines for system hardeningISM-0428 ISM-1034 ISM-1341
Guidelines for Database SystemsGuidelines for database systemsISM-1273 ISM-1274
Guidelines for GatewaysGuidelines for gatewaysISM-1783

Scope / applicability changes (1)

ControlDirectionFootprint before → afterLocation
ISM-0100narrowedNC|OS|P|S|TSNC|OS|P|SAssessment of gateways

Removed (1)

ControlFootprintFormer locationStatement (excerpt)
ISM-1857NC|OS|P|S|TSGuidelines for Information Technology EquipmentIT equipment is chosen from vendors that have demonstrated a commitment to secure-by-design and secure-by-default principles, use of memory-safe progr…
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.