ASD ISM — incremental change analysis

Release v2025.12.9 (2025-12-09) vs prior v2025.10.8 · 62 days · catalogue 1073 controls · NC-explicit era
ASD changes summary: ISM December 2025 changes (PDF)
21
Added
3
Substantive
15
Clarification
59
Editorial
16
Relocated
0
Scope changes
6
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET240
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified024

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (21)

ControlFootprintLocationStatement (excerpt)
ISM-2074NC|OS|P|S|TSGuidelines for personnel security › General-purpose artificial intelligence usage policyA general-purpose artificial intelligence usage policy is developed, implemented and maintained.
ISM-2075NC|OS|P|S|TSGuidelines for communications systems › Sending and receiving fax messagesFax machines, and online fax services, are not used for sending or receiving fax messages.
ISM-2076NC|OS|P|S|TSGuidelines for system hardening › Insecure authentication methodsSecurity questions are not used for authentication purposes.
ISM-2077NC|OS|P|S|TSGuidelines for system hardening › Insecure authentication methodsEmail is not used for out-of-band authentication purposes.
ISM-2078NC|OS|P|S|TSGuidelines for system hardening › Password strengthPasswords appearing in lists of commonly used passwords or lists of compromised passwords are not used.
ISM-2079NC|OS|P|S|TSGuidelines for system hardening › Password strengthMaximum length limits for passwords are not less than 64 characters.
ISM-2080NC|OS|P|S|TSGuidelines for system hardening › Password strengthPassword complexity requirements are not imposed for passwords.
ISM-2081NC|OS|P|S|TSGuidelines for system hardening › Password strengthAll ASCII printable characters are supported for passwords.
ISM-2082NC|OS|P|S|TSGuidelines for software development › Cryptographic bill of materialsIf a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such …
ISM-2083NC|OS|P|S|TSGuidelines for software development › Cryptographic bill of materialsA cryptographic bill of materials is produced and made available to consumers of software.
ISM-2084NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentArtificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics,…
ISM-2085NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentThe exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented.
ISM-2086NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningThe source and integrity of artificial intelligence models, structures and weights are verified.
ISM-2087NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningThe source and integrity of training data for artificial intelligence models is verified.
ISM-2088NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningData validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models.
ISM-2089NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionArtificial intelligence model performance metrics are monitored and anomalies are investigated.
ISM-2090NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionRate limiting is applied to inference queries for artificial intelligence models.
ISM-2091NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionResource limits are enforced for artificial intelligence models.
ISM-2092NC|OS|P|S|TSGuidelines for software development › Excessive agencyAccess control policies are implemented to enforce fine-grained permissions for artificial intelligence applications.
ISM-2093NC|OS|P|S|TSGuidelines for software development › Excessive agencyRole-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.
ISM-2094NC|OS|P|S|TSGuidelines for software development › Sensitive data exposure and improper outputContent filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output.

Substantive amendments (3)

ControlEdit distLocationStatement (excerpt)
ISM-15580.96Guidelines for system hardening › Password strengthPasswords using a sequence of words for single-factor authentication are not constructed using: - a list of categorised words - a real sentence in a n…
ISM-02450.70Guidelines for communications systems › Connecting multifunction devices to digital telephone systemsMFDs are not connected to digital telephone systems.
ISM-19110.28Guidelines for software development › Software event loggingSecurity-relevant usage, error messages and crashes for software are centrally logged.

Clarifications (15)

ControlEdit distLocation
ISM-15960.22Guidelines for system hardening › Setting credentials for user accounts
ISM-07250.22Guidelines for cyber security roles › Coordinating cyber security
ISM-15570.21Guidelines for system hardening › Password strength
ISM-04220.20Guidelines for system hardening › Password strength
ISM-04210.15Guidelines for system hardening › Password strength
ISM-18030.14Guidelines for cyber security incidents › Cyber security incident register
ISM-10360.13Guidelines for communications systems › Observing multifunction device use
ISM-19560.12Guidelines for system hardening › Changing credentials
ISM-05880.11Guidelines for communications systems › Multifunction device usage policy
ISM-15600.09Guidelines for system hardening › Password strength
ISM-15610.09Guidelines for system hardening › Password strength
ISM-15900.08Guidelines for system hardening › Changing credentials
ISM-20720.07Guidelines for software development › Secure artificial intelligence application development
ISM-15590.06Guidelines for system hardening › Password strength
ISM-14490.06Guidelines for cryptography › Authentication mechanisms

Editorial / grammatical (59)

Cosmetic edits (normalised edit distance < 0.05). ISM-0039, ISM-0043, ISM-0047, ISM-0109, ISM-0120, ISM-0123, ISM-0125, ISM-0140, ISM-0141, ISM-0252, ISM-0417, ISM-0487, ISM-0488, ISM-0576, ISM-0585, ISM-0714, ISM-0717, ISM-0718, ISM-0720, ISM-0724, ISM-0726, ISM-0732, ISM-0733, ISM-0735, ISM-0888, ISM-1228, ISM-1478, ISM-1526, ISM-1602, ISM-1617, ISM-1618, ISM-1784, ISM-1819, ISM-1847, ISM-1880, ISM-1881, ISM-1906, ISM-1907, ISM-1918, ISM-1955, ISM-1960, ISM-1961, ISM-1970, ISM-1986, ISM-1987, ISM-1997, ISM-1998, ISM-1999, ISM-2000, ISM-2001, ISM-2002, ISM-2003, ISM-2004, ISM-2006, ISM-2020, ISM-2022, ISM-2037, ISM-2038, ISM-2051

Relocated (16)

1 cross-chapter moves (listed) · 15 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for gatewaysGuidelines for personnel securityISM-0258

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (6)

ControlFootprintFormer locationStatement (excerpt)
ISM-0241NC|OS|P|S|TSGuidelines for communications systemsWhen sending fax messages, the fax message is encrypted to an appropriate level to be communicated over unsecured telecommunications infrastructure.
ISM-1075NC|OS|P|S|TSGuidelines for communications systemsThe sender of a fax message makes arrangements for the receiver to collect the fax message as soon as possible after it is sent and for the receiver t…
ISM-1092NC|OS|P|S|TSGuidelines for communications systemsSeparate fax machines or MFDs are used for sending sensitive or classified fax messages and all other fax messages.
ISM-1225NC|OS|P|S|TSGuidelines for information technology equipmentThe paper tray of the fax machine is removed, and a fax message with a minimum length of four pages is transmitted, before the paper tray is re-instal…
ISM-1226NC|OS|P|S|TSGuidelines for information technology equipmentFax machines are checked to ensure no pages are trapped in the paper path due to a paper jam.
ISM-1923NC|OS|P|S|TSGuidelines for software developmentThe OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.