ASD ISM — incremental change analysis

Release v2026.03.24 (2026-03-24) vs prior v2025.12.9 · 105 days · catalogue 1081 controls · NC-explicit era
ASD changes summary: ISM March 2026 changes (PDF)
9
Added
4
Substantive
9
Clarification
4
Editorial
6
Relocated
0
Scope changes
1
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET100
SECRET00
PROTECTED30
OFFICIAL: Sensitive03
Non-Classified010

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|POFFICIAL: SensitivePROTECTEDISM-2095 ISM-1400 ISM-1866

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (9)

ControlFootprintLocationStatement (excerpt)
ISM-2095OS|PGuidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from gra…
ISM-2096NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured to enforce separation between organisational and personal mobile applications and data.
ISM-2097NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured with always on VPN functionality.
ISM-2098NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured to prevent data transfers over Universal Serial Bus connections.
ISM-2099NC|OS|P|S|TSGuidelines for enterprise mobility › Connecting mobile devices to connected vehiclesMobile devices are not connected to the infotainment systems of connected vehicles.
ISM-2100NC|OS|P|S|TSGuidelines for enterprise mobility › Using mobile devices within or near connected vehiclesSensitive or classified data is not viewed on mobile devices within or near connected vehicles.
ISM-2101NC|OS|P|S|TSGuidelines for enterprise mobility › Using mobile devices within or near connected vehiclesSensitive or classified phone calls and conversations are not conducted within or near connected vehicles.
ISM-2102NC|OS|P|S|TSGuidelines for software development › Software artefactsExisting software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depen…
ISM-2103NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentOrganisational data generated, collected or processed by artificial intelligence applications is not used for training, fine-tuning or improving artif…

Substantive amendments (4)

ControlEdit distLocationStatement (excerpt)
ISM-18660.49Guidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from stor…
ISM-20280.36Guidelines for software development › Software artefactsAll software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (D…
ISM-14000.33Guidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separatio…
ISM-20260.26Guidelines for software development › Software artefactsAll software artefacts are scanned for malicious content before being imported into the authoritative source for software.

Clarifications (9)

ControlEdit distLocation
ISM-15260.23Guidelines for cyber security roles › Protecting systems and their resources
ISM-14820.23Guidelines for enterprise mobility › Organisation-owned mobile devices and desktop computers
ISM-00270.22Guidelines for cyber security roles › Protecting systems and their resources
ISM-19680.20Guidelines for cyber security roles › Protecting systems and their resources
ISM-18850.19Guidelines for communications infrastructure › Emanation security risk assessments
ISM-18880.12Guidelines for enterprise mobility › Maintaining mobile device security
ISM-16330.11Guidelines for cyber security roles › Protecting systems and their resources
ISM-08740.06Guidelines for enterprise mobility › Mobile devices and desktop computers accessing the internet
ISM-19900.05Guidelines for cryptography › Using post-quantum cryptographic algorithms

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-0246, ISM-0249, ISM-1137, ISM-1634

Relocated (6)

0 cross-chapter moves (listed) · 6 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (1)

ControlFootprintFormer locationStatement (excerpt)
ISM-1837NC|OS|P|S|TSGuidelines for system hardeningUser accounts are not configured with password never expires or password not required.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.