| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 24 | 0 |
| SECRET | 0 | 0 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 0 |
| Non-Classified | 0 | 24 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for communications systems | Fax machines and services | 1 | ISM-2075 |
| Guidelines for communications systems | Multifunction devices | 7 | ISM-0588 ISM-0245 ISM-1854 ISM-0590 ISM-0589 ISM-1855 ISM-1036 |
| Chapter | Section |
|---|---|
| Guidelines for communications systems | Fax machines and multifunction devices |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for personnel security | Access to systems and their resources | General-purpose artificial intelligence usage policy | 1 | ISM-2074 |
| Guidelines for personnel security | Access to systems and their resources | Web usage policy | 1 | ISM-0258 |
| Guidelines for software development | Artificial intelligence application development | Artificial intelligence model poisoning | 3 | ISM-2086 ISM-2087 ISM-2088 |
| Guidelines for software development | Artificial intelligence application development | Excessive agency | 2 | ISM-2092 ISM-2093 |
| Guidelines for software development | Artificial intelligence application development | Prompt injection | 1 | ISM-1924 |
| Guidelines for software development | Artificial intelligence application development | Sensitive data exposure and improper output | 1 | ISM-2094 |
| Guidelines for software development | Artificial intelligence application development | Unbounded consumption | 3 | ISM-2089 ISM-2090 ISM-2091 |
| Guidelines for software development | Software development fundamentals | Cryptographic bill of materials | 2 | ISM-2082 ISM-2083 |
| Guidelines for system hardening | Authentication hardening | Password strength | 11 | ISM-1559 ISM-1560 ISM-1561 ISM-0421 ISM-1557 ISM-0422 ISM-1558 ISM-2078 ISM-2079 ISM-2080 ISM-2081 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for gateways | Web proxies | Web usage policy |
| Guidelines for information technology equipment | IT equipment sanitisation and destruction | Sanitising fax machines |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for system hardening | Authentication hardening | 6 | 1 | 9 | 3 | 19 |
| Guidelines for cyber security roles | Chief information security officer | 0 | 0 | 1 | 14 | 15 |
| Guidelines for software development | Artificial intelligence application development | 11 | 0 | 1 | 0 | 12 |
| Guidelines for system monitoring | Event logging and monitoring | 0 | 0 | 0 | 9 | 9 |
| Guidelines for cyber security incidents | Managing cyber security incidents | 0 | 0 | 1 | 8 | 9 |
| Guidelines for cyber security roles | Board of directors and executive committee | 0 | 0 | 0 | 9 | 9 |
| Guidelines for software development | Software development fundamentals | 2 | 1 | 0 | 3 | 6 |
| Guidelines for cyber security documentation | Development and maintenance of cyber security documentation | 0 | 0 | 0 | 4 | 4 |
| Guidelines for communications systems | Multifunction devices | 0 | 1 | 2 | 0 | 3 |
| Guidelines for cryptography | Secure Shell | 0 | 0 | 1 | 2 | 3 |
| Guidelines for personnel security | Cyber security awareness training | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | 0 | 0 | 0 | 2 | 2 |
| Guidelines for personnel security | Access to systems and their resources | 1 | 0 | 0 | 0 | 1 |
| Guidelines for communications systems | Fax machines and services | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | System owners | 0 | 0 | 0 | 1 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for system hardening | Authentication hardening | Password strength | 4 | 1 | 6 | 0 | 11 |
| Guidelines for system monitoring | Event logging and monitoring | Event log monitoring | 0 | 0 | 0 | 8 | 8 |
| Guidelines for system hardening | Authentication hardening | Changing credentials | 0 | 0 | 2 | 2 | 4 |
| Guidelines for cyber security roles | Board of directors and executive committee | Embedding cyber security | 0 | 0 | 0 | 4 | 4 |
| Guidelines for software development | Artificial intelligence application development | Secure artificial intelligence application development | 2 | 0 | 1 | 0 | 3 |
| Guidelines for software development | Artificial intelligence application development | Artificial intelligence model poisoning | 3 | 0 | 0 | 0 | 3 |
| Guidelines for software development | Artificial intelligence application development | Unbounded consumption | 3 | 0 | 0 | 0 | 3 |
| Guidelines for cyber security roles | Chief information security officer | Overseeing the cyber security program | 0 | 0 | 0 | 3 | 3 |
| Guidelines for cyber security roles | Board of directors and executive committee | Building cyber security expertise | 0 | 0 | 0 | 3 | 3 |
| Guidelines for software development | Software development fundamentals | Secure software development | 0 | 0 | 0 | 3 | 3 |
| Guidelines for system hardening | Authentication hardening | Insecure authentication methods | 2 | 0 | 0 | 0 | 2 |
| Guidelines for software development | Software development fundamentals | Cryptographic bill of materials | 2 | 0 | 0 | 0 | 2 |
| Guidelines for software development | Artificial intelligence application development | Excessive agency | 2 | 0 | 0 | 0 | 2 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Cyber security incident register | 0 | 0 | 1 | 1 | 2 |
| Guidelines for personnel security | Cyber security awareness training | Providing cyber security awareness training | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cryptography | Secure Shell | Automated remote access | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Cyber security incident management policy | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security roles | Chief information security officer | Overseeing cyber security personnel | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security roles | Chief information security officer | Reporting on cyber security | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security roles | Chief information security officer | Coordinating cyber security | 0 | 0 | 1 | 1 | 2 |
| Guidelines for cyber security roles | Chief information security officer | Overseeing cyber security incident response activities | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Reporting cyber security incidents to customers and the public | 0 | 0 | 0 | 2 | 2 |
| Guidelines for personnel security | Access to systems and their resources | General-purpose artificial intelligence usage policy | 1 | 0 | 0 | 0 | 1 |
| Guidelines for communications systems | Fax machines and services | Sending and receiving fax messages | 1 | 0 | 0 | 0 | 1 |
| Guidelines for software development | Artificial intelligence application development | Sensitive data exposure and improper output | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cyber security documentation | Development and maintenance of cyber security documentation | Cyber security strategy | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | Cyber security incident response plan | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security documentation | Development and maintenance of cyber security documentation | Approval of cyber security documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Access to sufficient data sources and tools | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Reporting cyber security incidents | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security incidents | Managing cyber security incidents | Reporting cyber security incidents to ASD | 0 | 0 | 0 | 1 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Contractual security requirements with service providers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Multifunction devices | Connecting multifunction devices to digital telephone systems | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | Authentication hardening | Single-factor authentication | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system monitoring | Event logging and monitoring | Event log details | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Multifunction devices | Multifunction device usage policy | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Providing cyber security leadership and guidance | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Communicating a cyber security vision and strategy | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Receiving and managing a dedicated cyber security budget | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Overseeing cyber security awareness training | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security documentation | Development and maintenance of cyber security documentation | Maintenance of cyber security documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Multifunction devices | Observing multifunction device use | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cryptography | Secure Shell | Authentication mechanisms | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security roles | System owners | Protecting systems and their resources | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Authentication hardening | Setting credentials for user accounts | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security documentation | Development and maintenance of cyber security documentation | Communication of cyber security documentation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | Enacting cyber security incident response plans | 0 | 0 | 0 | 1 | 1 |
| Guidelines for software development | Software development fundamentals | Software event logging | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | Handling and containing malicious code infections | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Board of directors and executive committee | Championing a positive cyber security culture | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Board of directors and executive committee | Planning for major cyber security incidents | 0 | 0 | 0 | 1 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-2074 | NC|OS|P|S|TS | Guidelines for personnel security › General-purpose artificial intelligence usage policy | A general-purpose artificial intelligence usage policy is developed, implemented and maintained. |
| ISM-2075 | NC|OS|P|S|TS | Guidelines for communications systems › Sending and receiving fax messages | Fax machines, and online fax services, are not used for sending or receiving fax messages. |
| ISM-2076 | NC|OS|P|S|TS | Guidelines for system hardening › Insecure authentication methods | Security questions are not used for authentication purposes. |
| ISM-2077 | NC|OS|P|S|TS | Guidelines for system hardening › Insecure authentication methods | Email is not used for out-of-band authentication purposes. |
| ISM-2078 | NC|OS|P|S|TS | Guidelines for system hardening › Password strength | Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used. |
| ISM-2079 | NC|OS|P|S|TS | Guidelines for system hardening › Password strength | Maximum length limits for passwords are not less than 64 characters. |
| ISM-2080 | NC|OS|P|S|TS | Guidelines for system hardening › Password strength | Password complexity requirements are not imposed for passwords. |
| ISM-2081 | NC|OS|P|S|TS | Guidelines for system hardening › Password strength | All ASCII printable characters are supported for passwords. |
| ISM-2082 | NC|OS|P|S|TS | Guidelines for software development › Cryptographic bill of materials | If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such … |
| ISM-2083 | NC|OS|P|S|TS | Guidelines for software development › Cryptographic bill of materials | A cryptographic bill of materials is produced and made available to consumers of software. |
| ISM-2084 | NC|OS|P|S|TS | Guidelines for software development › Secure artificial intelligence application development | Artificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics,… |
| ISM-2085 | NC|OS|P|S|TS | Guidelines for software development › Secure artificial intelligence application development | The exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented. |
| ISM-2086 | NC|OS|P|S|TS | Guidelines for software development › Artificial intelligence model poisoning | The source and integrity of artificial intelligence models, structures and weights are verified. |
| ISM-2087 | NC|OS|P|S|TS | Guidelines for software development › Artificial intelligence model poisoning | The source and integrity of training data for artificial intelligence models is verified. |
| ISM-2088 | NC|OS|P|S|TS | Guidelines for software development › Artificial intelligence model poisoning | Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models. |
| ISM-2089 | NC|OS|P|S|TS | Guidelines for software development › Unbounded consumption | Artificial intelligence model performance metrics are monitored and anomalies are investigated. |
| ISM-2090 | NC|OS|P|S|TS | Guidelines for software development › Unbounded consumption | Rate limiting is applied to inference queries for artificial intelligence models. |
| ISM-2091 | NC|OS|P|S|TS | Guidelines for software development › Unbounded consumption | Resource limits are enforced for artificial intelligence models. |
| ISM-2092 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | Access control policies are implemented to enforce fine-grained permissions for artificial intelligence applications. |
| ISM-2093 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | Role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data. |
| ISM-2094 | NC|OS|P|S|TS | Guidelines for software development › Sensitive data exposure and improper output | Content filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output. |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-1558 | 0.96 | Guidelines for system hardening › Password strength | Passwords using a sequence of words for single-factor authentication are not constructed using: - a list of categorised words - a real sentence in a n… |
| ISM-0245 | 0.70 | Guidelines for communications systems › Connecting multifunction devices to digital telephone systems | MFDs are not connected to digital telephone systems. |
| ISM-1911 | 0.28 | Guidelines for software development › Software event logging | Security-relevant usage, error messages and crashes for software are centrally logged. |
| Control | Edit dist | Location |
|---|---|---|
| ISM-1596 | 0.22 | Guidelines for system hardening › Setting credentials for user accounts |
| ISM-0725 | 0.22 | Guidelines for cyber security roles › Coordinating cyber security |
| ISM-1557 | 0.21 | Guidelines for system hardening › Password strength |
| ISM-0422 | 0.20 | Guidelines for system hardening › Password strength |
| ISM-0421 | 0.15 | Guidelines for system hardening › Password strength |
| ISM-1803 | 0.14 | Guidelines for cyber security incidents › Cyber security incident register |
| ISM-1036 | 0.13 | Guidelines for communications systems › Observing multifunction device use |
| ISM-1956 | 0.12 | Guidelines for system hardening › Changing credentials |
| ISM-0588 | 0.11 | Guidelines for communications systems › Multifunction device usage policy |
| ISM-1560 | 0.09 | Guidelines for system hardening › Password strength |
| ISM-1561 | 0.09 | Guidelines for system hardening › Password strength |
| ISM-1590 | 0.08 | Guidelines for system hardening › Changing credentials |
| ISM-2072 | 0.07 | Guidelines for software development › Secure artificial intelligence application development |
| ISM-1559 | 0.06 | Guidelines for system hardening › Password strength |
| ISM-1449 | 0.06 | Guidelines for cryptography › Authentication mechanisms |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for gateways | Guidelines for personnel security | ISM-0258 |
| Control | Footprint | Former location | Statement (excerpt) |
|---|---|---|---|
| ISM-0241 | NC|OS|P|S|TS | Guidelines for communications systems | When sending fax messages, the fax message is encrypted to an appropriate level to be communicated over unsecured telecommunications infrastructure. |
| ISM-1075 | NC|OS|P|S|TS | Guidelines for communications systems | The sender of a fax message makes arrangements for the receiver to collect the fax message as soon as possible after it is sent and for the receiver t… |
| ISM-1092 | NC|OS|P|S|TS | Guidelines for communications systems | Separate fax machines or MFDs are used for sending sensitive or classified fax messages and all other fax messages. |
| ISM-1225 | NC|OS|P|S|TS | Guidelines for information technology equipment | The paper tray of the fax machine is removed, and a fax message with a minimum length of four pages is transmitted, before the paper tray is re-instal… |
| ISM-1226 | NC|OS|P|S|TS | Guidelines for information technology equipment | Fax machines are checked to ensure no pages are trapped in the paper path due to a paper jam. |
| ISM-1923 | NC|OS|P|S|TS | Guidelines for software development | The OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications. |
revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.