ASD ISM — incremental change analysis

Release v2026.03.24 (2026-03-24) vs prior v2025.12.9 · 105 days · catalogue 1081 controls · NC-explicit era
ASD changes summary: ISM March 2026 changes (PDF)
9
Added
4
Substantive
9
Clarification
4
Editorial
6
Relocated
0
Scope changes
1
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET100
SECRET00
PROTECTED30
OFFICIAL: Sensitive03
Non-Classified010

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|POFFICIAL: SensitivePROTECTEDISM-2095 ISM-1400 ISM-1866

4 · Change location by chapter

5 · Section / topic structure

New sections: 0 · Removed sections: 0 · New topics: 4 · Removed topics: 2. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for communications infrastructureEmanation securityEmanation security risk assessments4ISM-1137 ISM-0249 ISM-0246 ISM-1885
Guidelines for enterprise mobilityEnterprise mobilityMobile devices and desktop computers accessing the internet2ISM-0874 ISM-0705
Guidelines for enterprise mobilityMobile device usageConnecting mobile devices to connected vehicles1ISM-2099
Guidelines for enterprise mobilityMobile device usageUsing mobile devices within or near connected vehicles2ISM-2100 ISM-2101

Removed topics

ChapterSectionTopic
Guidelines for communications infrastructureEmanation securityEmanation security threat assessments
Guidelines for enterprise mobilityEnterprise mobilityConnecting mobile devices and desktop computers to the internet

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for enterprise mobilityEnterprise mobility12205
Guidelines for cyber security rolesSystem owners00415
Guidelines for enterprise mobilityMobile device management30104
Guidelines for communications infrastructureEmanation security00134
Guidelines for enterprise mobilityMobile device usage30003
Guidelines for software developmentSoftware development fundamentals12003
Guidelines for software developmentArtificial intelligence application development10001
Guidelines for cryptographyASD-Approved Cryptographic Algorithms00101

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for cyber security rolesSystem ownersProtecting systems and their resources00415
Guidelines for enterprise mobilityMobile device managementMaintaining mobile device security30104
Guidelines for communications infrastructureEmanation securityEmanation security risk assessments00134
Guidelines for enterprise mobilityEnterprise mobilityPrivately-owned mobile devices and desktop computers12003
Guidelines for software developmentSoftware development fundamentalsSoftware artefacts12003
Guidelines for enterprise mobilityMobile device usageUsing mobile devices within or near connected vehicles20002
Guidelines for enterprise mobilityMobile device usageConnecting mobile devices to connected vehicles10001
Guidelines for software developmentArtificial intelligence application developmentSecure artificial intelligence application development10001
Guidelines for enterprise mobilityEnterprise mobilityMobile devices and desktop computers accessing the internet00101
Guidelines for enterprise mobilityEnterprise mobilityOrganisation-owned mobile devices and desktop computers00101
Guidelines for cryptographyASD-Approved Cryptographic AlgorithmsUsing post-quantum cryptographic algorithms00101

6 · Control call-outs by category

Added — new controls (9)

ControlFootprintLocationStatement (excerpt)
ISM-2095OS|PGuidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from gra…
ISM-2096NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured to enforce separation between organisational and personal mobile applications and data.
ISM-2097NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured with always on VPN functionality.
ISM-2098NC|OS|P|S|TSGuidelines for enterprise mobility › Maintaining mobile device securityMobile devices are configured to prevent data transfers over Universal Serial Bus connections.
ISM-2099NC|OS|P|S|TSGuidelines for enterprise mobility › Connecting mobile devices to connected vehiclesMobile devices are not connected to the infotainment systems of connected vehicles.
ISM-2100NC|OS|P|S|TSGuidelines for enterprise mobility › Using mobile devices within or near connected vehiclesSensitive or classified data is not viewed on mobile devices within or near connected vehicles.
ISM-2101NC|OS|P|S|TSGuidelines for enterprise mobility › Using mobile devices within or near connected vehiclesSensitive or classified phone calls and conversations are not conducted within or near connected vehicles.
ISM-2102NC|OS|P|S|TSGuidelines for software development › Software artefactsExisting software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depen…
ISM-2103NC|OS|P|S|TSGuidelines for software development › Secure artificial intelligence application developmentOrganisational data generated, collected or processed by artificial intelligence applications is not used for training, fine-tuning or improving artif…

Substantive amendments (4)

ControlEdit distLocationStatement (excerpt)
ISM-18660.49Guidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from stor…
ISM-20280.36Guidelines for software development › Software artefactsAll software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (D…
ISM-14000.33Guidelines for enterprise mobility › Privately-owned mobile devices and desktop computersPersonnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separatio…
ISM-20260.26Guidelines for software development › Software artefactsAll software artefacts are scanned for malicious content before being imported into the authoritative source for software.

Clarifications (9)

ControlEdit distLocation
ISM-15260.23Guidelines for cyber security roles › Protecting systems and their resources
ISM-14820.23Guidelines for enterprise mobility › Organisation-owned mobile devices and desktop computers
ISM-00270.22Guidelines for cyber security roles › Protecting systems and their resources
ISM-19680.20Guidelines for cyber security roles › Protecting systems and their resources
ISM-18850.19Guidelines for communications infrastructure › Emanation security risk assessments
ISM-18880.12Guidelines for enterprise mobility › Maintaining mobile device security
ISM-16330.11Guidelines for cyber security roles › Protecting systems and their resources
ISM-08740.06Guidelines for enterprise mobility › Mobile devices and desktop computers accessing the internet
ISM-19900.05Guidelines for cryptography › Using post-quantum cryptographic algorithms

Editorial / grammatical (4)

Cosmetic edits (normalised edit distance < 0.05). ISM-0246, ISM-0249, ISM-1137, ISM-1634

Relocated (6)

0 cross-chapter moves (listed) · 6 intra-chapter section/topic reshuffles (count only).

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (1)

ControlFootprintFormer locationStatement (excerpt)
ISM-1837NC|OS|P|S|TSGuidelines for system hardeningUser accounts are not configured with password never expires or password not required.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (0 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.