ASD ISM — incremental change analysis

Release v2025.12.9 (2025-12-09) vs prior v2025.10.8 · 62 days · catalogue 1073 controls · NC-explicit era
ASD changes summary: ISM December 2025 changes (PDF)
21
Added
3
Substantive
15
Clarification
59
Editorial
16
Relocated
0
Scope changes
6
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET240
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified024

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Section / topic structure

New sections: 2 · Removed sections: 1 · New topics: 9 · Removed topics: 2. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for communications systemsFax machines and services1ISM-2075
Guidelines for communications systemsMultifunction devices7ISM-0588 ISM-0245 ISM-1854 ISM-0590 ISM-0589 ISM-1855 ISM-1036

Removed sections

ChapterSection
Guidelines for communications systemsFax machines and multifunction devices

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for personnel securityAccess to systems and their resourcesGeneral-purpose artificial intelligence usage policy1ISM-2074
Guidelines for personnel securityAccess to systems and their resourcesWeb usage policy1ISM-0258
Guidelines for software developmentArtificial intelligence application developmentArtificial intelligence model poisoning3ISM-2086 ISM-2087 ISM-2088
Guidelines for software developmentArtificial intelligence application developmentExcessive agency2ISM-2092 ISM-2093
Guidelines for software developmentArtificial intelligence application developmentPrompt injection1ISM-1924
Guidelines for software developmentArtificial intelligence application developmentSensitive data exposure and improper output1ISM-2094
Guidelines for software developmentArtificial intelligence application developmentUnbounded consumption3ISM-2089 ISM-2090 ISM-2091
Guidelines for software developmentSoftware development fundamentalsCryptographic bill of materials2ISM-2082 ISM-2083
Guidelines for system hardeningAuthentication hardeningPassword strength11ISM-1559 ISM-1560 ISM-1561 ISM-0421 ISM-1557 ISM-0422 ISM-1558 ISM-2078 ISM-2079 ISM-2080 ISM-2081

Removed topics

ChapterSectionTopic
Guidelines for gatewaysWeb proxiesWeb usage policy
Guidelines for information technology equipmentIT equipment sanitisation and destructionSanitising fax machines

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for system hardeningAuthentication hardening619319
Guidelines for cyber security rolesChief information security officer0011415
Guidelines for software developmentArtificial intelligence application development1101012
Guidelines for system monitoringEvent logging and monitoring00099
Guidelines for cyber security incidentsManaging cyber security incidents00189
Guidelines for cyber security rolesBoard of directors and executive committee00099
Guidelines for software developmentSoftware development fundamentals21036
Guidelines for cyber security documentationDevelopment and maintenance of cyber security documentation00044
Guidelines for communications systemsMultifunction devices01203
Guidelines for cryptographySecure Shell00123
Guidelines for personnel securityCyber security awareness training00022
Guidelines for cyber security incidentsResponding to cyber security incidents00022
Guidelines for personnel securityAccess to systems and their resources10001
Guidelines for communications systemsFax machines and services10001
Guidelines for cyber security documentationSystem-specific cyber security documentation00011
Guidelines for procurement and outsourcingManaged services and cloud services00011
Guidelines for cyber security rolesSystem owners00011

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for system hardeningAuthentication hardeningPassword strength416011
Guidelines for system monitoringEvent logging and monitoringEvent log monitoring00088
Guidelines for system hardeningAuthentication hardeningChanging credentials00224
Guidelines for cyber security rolesBoard of directors and executive committeeEmbedding cyber security00044
Guidelines for software developmentArtificial intelligence application developmentSecure artificial intelligence application development20103
Guidelines for software developmentArtificial intelligence application developmentArtificial intelligence model poisoning30003
Guidelines for software developmentArtificial intelligence application developmentUnbounded consumption30003
Guidelines for cyber security rolesChief information security officerOverseeing the cyber security program00033
Guidelines for cyber security rolesBoard of directors and executive committeeBuilding cyber security expertise00033
Guidelines for software developmentSoftware development fundamentalsSecure software development00033
Guidelines for system hardeningAuthentication hardeningInsecure authentication methods20002
Guidelines for software developmentSoftware development fundamentalsCryptographic bill of materials20002
Guidelines for software developmentArtificial intelligence application developmentExcessive agency20002
Guidelines for cyber security incidentsManaging cyber security incidentsCyber security incident register00112
Guidelines for personnel securityCyber security awareness trainingProviding cyber security awareness training00022
Guidelines for cryptographySecure ShellAutomated remote access00022
Guidelines for cyber security incidentsManaging cyber security incidentsCyber security incident management policy00022
Guidelines for cyber security rolesChief information security officerOverseeing cyber security personnel00022
Guidelines for cyber security rolesChief information security officerReporting on cyber security00022
Guidelines for cyber security rolesChief information security officerCoordinating cyber security00112
Guidelines for cyber security rolesChief information security officerOverseeing cyber security incident response activities00022
Guidelines for cyber security incidentsManaging cyber security incidentsReporting cyber security incidents to customers and the public00022
Guidelines for personnel securityAccess to systems and their resourcesGeneral-purpose artificial intelligence usage policy10001
Guidelines for communications systemsFax machines and servicesSending and receiving fax messages10001
Guidelines for software developmentArtificial intelligence application developmentSensitive data exposure and improper output10001
Guidelines for cyber security documentationDevelopment and maintenance of cyber security documentationCyber security strategy00011
Guidelines for cyber security documentationSystem-specific cyber security documentationCyber security incident response plan00011
Guidelines for cyber security documentationDevelopment and maintenance of cyber security documentationApproval of cyber security documentation00011
Guidelines for cyber security incidentsManaging cyber security incidentsAccess to sufficient data sources and tools00011
Guidelines for cyber security incidentsManaging cyber security incidentsReporting cyber security incidents00011
Guidelines for cyber security incidentsManaging cyber security incidentsReporting cyber security incidents to ASD00011
Guidelines for procurement and outsourcingManaged services and cloud servicesContractual security requirements with service providers00011
Guidelines for communications systemsMultifunction devicesConnecting multifunction devices to digital telephone systems01001
Guidelines for system hardeningAuthentication hardeningSingle-factor authentication00011
Guidelines for system monitoringEvent logging and monitoringEvent log details00011
Guidelines for communications systemsMultifunction devicesMultifunction device usage policy00101
Guidelines for cyber security rolesChief information security officerProviding cyber security leadership and guidance00011
Guidelines for cyber security rolesChief information security officerCommunicating a cyber security vision and strategy00011
Guidelines for cyber security rolesChief information security officerReceiving and managing a dedicated cyber security budget00011
Guidelines for cyber security rolesChief information security officerOverseeing cyber security awareness training00011
Guidelines for cyber security documentationDevelopment and maintenance of cyber security documentationMaintenance of cyber security documentation00011
Guidelines for communications systemsMultifunction devicesObserving multifunction device use00101
Guidelines for cryptographySecure ShellAuthentication mechanisms00101
Guidelines for cyber security rolesSystem ownersProtecting systems and their resources00011
Guidelines for system hardeningAuthentication hardeningSetting credentials for user accounts00101
Guidelines for cyber security documentationDevelopment and maintenance of cyber security documentationCommunication of cyber security documentation00011
Guidelines for cyber security incidentsResponding to cyber security incidentsEnacting cyber security incident response plans00011
Guidelines for software developmentSoftware development fundamentalsSoftware event logging01001
Guidelines for cyber security incidentsResponding to cyber security incidentsHandling and containing malicious code infections00011
Guidelines for cyber security rolesBoard of directors and executive committeeChampioning a positive cyber security culture00011
Guidelines for cyber security rolesBoard of directors and executive committeePlanning for major cyber security incidents00011

6 · Control call-outs by category

Added — new controls (21)

ControlFootprintLocationStatement (excerpt)
ISM-2074NC|OS|P|S|TSGuidelines for personnel security › General-purpose artificial intelligence usage policyA general-purpose artificial intelligence usage policy is developed, implemented and maintained.
ISM-2075NC|OS|P|S|TSGuidelines for communications systems › Sending and receiving fax messagesFax machines, and online fax services, are not used for sending or receiving fax messages.
ISM-2076NC|OS|P|S|TSGuidelines for system hardening › Insecure authentication methodsSecurity questions are not used for authentication purposes.
ISM-2077NC|OS|P|S|TSGuidelines for system hardening › Insecure authentication methodsEmail is not used for out-of-band authentication purposes.
ISM-2078NC|OS|P|S|TSGuidelines for system hardening › Password strengthPasswords appearing in lists of commonly used passwords or lists of compromised passwords are not used.
ISM-2079NC|OS|P|S|TSGuidelines for system hardening › Password strengthMaximum length limits for passwords are not less than 64 characters.
ISM-2080NC|OS|P|S|TSGuidelines for system hardening › Password strengthPassword complexity requirements are not imposed for passwords.
ISM-2081NC|OS|P|S|TSGuidelines for system hardening › Password strengthAll ASCII printable characters are supported for passwords.
ISM-2082NC|OS|P|S|TSGuidelines for software development › Cryptographic bill of materialsIf a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such …
ISM-2083NC|OS|P|S|TSGuidelines for software development › Cryptographic bill of materialsA cryptographic bill of materials is produced and made available to consumers of software.
ISM-2084NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentArtificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics,…
ISM-2085NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentThe exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented.
ISM-2086NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningThe source and integrity of artificial intelligence models, structures and weights are verified.
ISM-2087NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningThe source and integrity of training data for artificial intelligence models is verified.
ISM-2088NC|OS|P|S|TSGuidelines for software development › Artificial intelligence model poisoningData validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models.
ISM-2089NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionArtificial intelligence model performance metrics are monitored and anomalies are investigated.
ISM-2090NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionRate limiting is applied to inference queries for artificial intelligence models.
ISM-2091NC|OS|P|S|TSGuidelines for software development › Unbounded consumptionResource limits are enforced for artificial intelligence models.
ISM-2092NC|OS|P|S|TSGuidelines for software development › Excessive agencyAccess control policies are implemented to enforce fine-grained permissions for artificial intelligence applications.
ISM-2093NC|OS|P|S|TSGuidelines for software development › Excessive agencyRole-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.
ISM-2094NC|OS|P|S|TSGuidelines for software development › Sensitive data exposure and improper outputContent filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output.

Substantive amendments (3)

ControlEdit distLocationStatement (excerpt)
ISM-15580.96Guidelines for system hardening › Password strengthPasswords using a sequence of words for single-factor authentication are not constructed using: - a list of categorised words - a real sentence in a n…
ISM-02450.70Guidelines for communications systems › Connecting multifunction devices to digital telephone systemsMFDs are not connected to digital telephone systems.
ISM-19110.28Guidelines for software development › Software event loggingSecurity-relevant usage, error messages and crashes for software are centrally logged.

Clarifications (15)

ControlEdit distLocation
ISM-15960.22Guidelines for system hardening › Setting credentials for user accounts
ISM-07250.22Guidelines for cyber security roles › Coordinating cyber security
ISM-15570.21Guidelines for system hardening › Password strength
ISM-04220.20Guidelines for system hardening › Password strength
ISM-04210.15Guidelines for system hardening › Password strength
ISM-18030.14Guidelines for cyber security incidents › Cyber security incident register
ISM-10360.13Guidelines for communications systems › Observing multifunction device use
ISM-19560.12Guidelines for system hardening › Changing credentials
ISM-05880.11Guidelines for communications systems › Multifunction device usage policy
ISM-15600.09Guidelines for system hardening › Password strength
ISM-15610.09Guidelines for system hardening › Password strength
ISM-15900.08Guidelines for system hardening › Changing credentials
ISM-20720.07Guidelines for software development › Secure artificial intelligence application development
ISM-15590.06Guidelines for system hardening › Password strength
ISM-14490.06Guidelines for cryptography › Authentication mechanisms

Editorial / grammatical (59)

Cosmetic edits (normalised edit distance < 0.05). ISM-0039, ISM-0043, ISM-0047, ISM-0109, ISM-0120, ISM-0123, ISM-0125, ISM-0140, ISM-0141, ISM-0252, ISM-0417, ISM-0487, ISM-0488, ISM-0576, ISM-0585, ISM-0714, ISM-0717, ISM-0718, ISM-0720, ISM-0724, ISM-0726, ISM-0732, ISM-0733, ISM-0735, ISM-0888, ISM-1228, ISM-1478, ISM-1526, ISM-1602, ISM-1617, ISM-1618, ISM-1784, ISM-1819, ISM-1847, ISM-1880, ISM-1881, ISM-1906, ISM-1907, ISM-1918, ISM-1955, ISM-1960, ISM-1961, ISM-1970, ISM-1986, ISM-1987, ISM-1997, ISM-1998, ISM-1999, ISM-2000, ISM-2001, ISM-2002, ISM-2003, ISM-2004, ISM-2006, ISM-2020, ISM-2022, ISM-2037, ISM-2038, ISM-2051

Relocated (16)

1 cross-chapter moves (listed) · 15 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for gatewaysGuidelines for personnel securityISM-0258

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (6)

ControlFootprintFormer locationStatement (excerpt)
ISM-0241NC|OS|P|S|TSGuidelines for communications systemsWhen sending fax messages, the fax message is encrypted to an appropriate level to be communicated over unsecured telecommunications infrastructure.
ISM-1075NC|OS|P|S|TSGuidelines for communications systemsThe sender of a fax message makes arrangements for the receiver to collect the fax message as soon as possible after it is sent and for the receiver t…
ISM-1092NC|OS|P|S|TSGuidelines for communications systemsSeparate fax machines or MFDs are used for sending sensitive or classified fax messages and all other fax messages.
ISM-1225NC|OS|P|S|TSGuidelines for information technology equipmentThe paper tray of the fax machine is removed, and a fax message with a minimum length of four pages is transmitted, before the paper tray is re-instal…
ISM-1226NC|OS|P|S|TSGuidelines for information technology equipmentFax machines are checked to ensure no pages are trapped in the paper path due to a paper jam.
ISM-1923NC|OS|P|S|TSGuidelines for software developmentThe OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.