ASD ISM — incremental change analysis

Release v2025.09.10 (2025-09-10) vs prior v2025.07.16 · 56 days · catalogue 1058 controls · NC-explicit era
ASD changes summary: ISM September 2025 changes (PDF)
5
Added
1
Substantive
6
Clarification
5
Editorial
7
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET60
SECRET02
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified04

3 · Level-specific material changes

FootprintFloorCeilingControls
S|TSSECRETTOP SECRETISM-2069 ISM-2070

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (5)

ControlFootprintLocationStatement (excerpt)
ISM-2069S|TSGuidelines for physical security › Bringing photographic and video recording devices into facilitiesAn authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a…
ISM-2070S|TSGuidelines for physical security › Bringing photographic and video recording devices into facilitiesUnauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas.
ISM-2071NC|OS|P|S|TSGuidelines for personnel security › Managing and reporting suspicious requests to disclose or change user account detailsPersonnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.
ISM-2072NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentArtificial intelligence models are stored in a file format that does not allow arbitrary code execution.
ISM-2073NC|OS|P|S|TSGuidelines for cryptography › Transitioning to post-quantum cryptographyA post-quantum cryptography transition plan is developed, implemented and maintained.

Substantive amendments (1)

ControlEdit distLocationStatement (excerpt)
ISM-19240.93Guidelines for software development › Secure artificial intelligence application developmentGenerative artificial intelligence applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to illicit uninte…

Clarifications (6)

ControlEdit distLocation
ISM-04570.13Guidelines for cryptography › Cryptographic implementation assurance
ISM-04550.11Guidelines for cryptography › Data recovery
ISM-04650.09Guidelines for cryptography › Cryptographic implementation assurance
ISM-04810.09Guidelines for cryptography › Using ASD-Approved Cryptographic Protocols
ISM-04710.08Guidelines for cryptography › Using ASD-Approved Cryptographic Algorithms
ISM-06650.06Guidelines for data transfers › Authorising export of data

Editorial / grammatical (5)

Cosmetic edits (normalised edit distance < 0.05). ISM-0664, ISM-0675, ISM-1657, ISM-1917, ISM-2029

Relocated (7)

0 cross-chapter moves (listed) · 7 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.