ASD ISM — incremental change analysis

Release v2026.06.18 (2026-06-18) vs prior v2026.03.24 · 86 days · catalogue 1101 controls · NC-explicit era
ASD changes summary: ISM June 2026 changes (PDF)
20
Added
23
Substantive
44
Clarification
38
Editorial
149
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET430
SECRET00
PROTECTED00
OFFICIAL: Sensitive01
Non-Classified042

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-2112

4 · Change location by chapter

5 · Control call-outs by category

Added — new controls (20)

ControlFootprintLocationStatement (excerpt)
ISM-2104NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where …
ISM-2105NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such inf…
ISM-2106NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases…
ISM-2107NC|OS|P|S|TSGuidelines for personnel security › Posting personal information on online servicesPersonnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.
ISM-2108NC|OS|P|S|TSGuidelines for enterprise mobility › Encrypted communicationsMobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
ISM-2109NC|OS|P|S|TSGuidelines for media › Encrypting mediaPre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.
ISM-2110NC|OS|P|S|TSGuidelines for system hardening › Hardening user application configurationsUser applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-2111NC|OS|P|S|TSGuidelines for system hardening › Hardening user application configurationsAll temporary installation files created during user application installation processes are removed after user applications have been installed.
ISM-2112OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsAI applications that process classified data have their ability to directly access external public data sources disabled.
ISM-2113NC|OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsAI applications are configured to flag organisationally defined risky actions for human approval prior to their execution.
ISM-2114NC|OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsBaselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.
ISM-2115NC|OS|P|S|TSGuidelines for system hardening › Hardening server application configurationsExtensions for server applications are restricted to an organisation-approved set.
ISM-2116NC|OS|P|S|TSGuidelines for security assurance › Event log monitoringCyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.
ISM-2117NC|OS|P|S|TSGuidelines for security assurance › Event log monitoringSuitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.
ISM-2118NC|OS|P|S|TSGuidelines for security assurance › Vulnerability assessments and penetration testsVulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant …
ISM-2119NC|OS|P|S|TSGuidelines for security assurance › Vulnerability assessments and penetration testsSuitable AI models are used to augment vulnerability assessments and penetration tests.
ISM-2120NC|OS|P|S|TSGuidelines for software development › Secure software developmentA secure software development policy is developed, implemented and maintained.
ISM-2121NC|OS|P|S|TSGuidelines for software development › Secure software developmentSoftware developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.
ISM-2122NC|OS|P|S|TSGuidelines for software development › Software security testingSuitable AI models are used to augment software security testing.
ISM-2123NC|OS|P|S|TSGuidelines for software development › Data collection, retention and useAll prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.

Substantive amendments (23)

ControlEdit distLocationStatement (excerpt)
ISM-14600.76Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has d…
ISM-18480.72Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating sys…
ISM-00430.57Guidelines for cyber security documentation › Cyber security incident response planSystems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types…
ISM-03060.49Guidelines for information technology equipment › On-site maintenance or repairsIf an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: - h…
ISM-01200.49Guidelines for security assurance › Event log monitoringCyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security…
ISM-08530.48Guidelines for system hardening › Session terminationUser sessions are terminated and workstations are restarted at least daily.
ISM-14030.45Guidelines for system hardening › User account lockoutsUser accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon atte…
ISM-04690.41Guidelines for cryptography › Using cryptographic protocolsAn AACP or high assurance cryptographic protocol is used when encrypting data in transit.
ISM-12350.39Guidelines for system hardening › Hardening user application configurationsExtensions for user applications are restricted to an organisation-approved set.
ISM-07250.38Guidelines for cyber security roles › Coordinating cyber securityThe CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber securit…
ISM-14670.38Guidelines for system hardening › User application releasesThe latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are…
ISM-11630.37Guidelines for cyber security documentation › Continuous monitoring planSystems have a continuous monitoring plan that includes: - conducting security assessment activities to identify vulnerabilities - analysing identifie…
ISM-16060.34Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerab…
ISM-03850.34Guidelines for networking › Functional separation between serversServers maintain effective functional separation from each other.
ISM-14700.33Guidelines for system hardening › Hardening user application configurationsUnneeded user accounts, components, services and functionality of user applications are disabled or removed.
ISM-08210.33Guidelines for personnel security › Posting personal information on online servicesPersonnel are advised of security risks associated with posting personal information on online services.
ISM-16070.32Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is perform…
ISM-10590.30Guidelines for media › Encrypting mediaAll data stored on media is encrypted using ASD-approved cryptography.
ISM-12770.29Guidelines for database systems › Communications between database servers and web serversData communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.
ISM-19840.29Guidelines for security assurance › Centralised event logging facilityEvent logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.
ISM-20610.27Guidelines for software development › Software security testingPeer reviews are conducted on all critical and security-related software components.
ISM-10800.26Guidelines for cryptography › Using cryptographic algorithmsAn AACA or high assurance cryptographic algorithm is used when encrypting data at rest.
ISM-20170.25Guidelines for networking › Encrypted Domain Name System ServicesDNS traffic is encrypted by clients and servers using ASD-approved cryptography.

Clarifications (44)

ControlEdit distLocation
ISM-15820.24Guidelines for system hardening › Application control
ISM-11460.21Guidelines for personnel security › Posting personal information on online services
ISM-17810.20Guidelines for networking › Network encryption
ISM-16760.20Guidelines for system hardening › Office productivity suites
ISM-08690.19Guidelines for enterprise mobility › Encrypted storage
ISM-02110.18Guidelines for communications infrastructure › Cable register
ISM-20850.17Guidelines for software development › Secure artificial intelligence application development
ISM-05800.17Guidelines for security assurance › Security monitoring policy
ISM-20530.17Guidelines for software development › Secure software development
ISM-12430.17Guidelines for database systems › Database register
ISM-16450.17Guidelines for communications infrastructure › Floor plan diagrams
ISM-16050.16Guidelines for system hardening › Functional separation between operating environments
ISM-14610.16Guidelines for system hardening › Functional separation between operating environments
ISM-17130.16Guidelines for media › Removable media register
ISM-17360.16Guidelines for procurement and outsourcing › Managed services
ISM-03360.15Guidelines for information technology equipment › IT equipment registers
ISM-16370.14Guidelines for procurement and outsourcing › Outsourced cloud services
ISM-18690.14Guidelines for information technology equipment › IT equipment registers
ISM-17380.13Guidelines for procurement and outsourcing › Contractual security requirements with service providers
ISM-10850.13Guidelines for enterprise mobility › Encrypted communications
ISM-20620.13Guidelines for software development › Software security testing
ISM-19660.12Guidelines for cyber security roles › Overseeing the cyber security program
ISM-16040.11Guidelines for system hardening › Functional separation between operating environments
ISM-15980.11Guidelines for information technology equipment › Inspection of IT equipment following maintenance or repairs
ISM-20570.11Guidelines for software development › Software input handling
ISM-20070.11Guidelines for physical security › Bringing medical devices into facilities
ISM-04590.11Guidelines for media › Encrypting media
ISM-15430.11Guidelines for physical security › Bringing radio frequency and infrared devices into facilities
ISM-02330.11Guidelines for communications systems › Cordless telephone systems
ISM-18010.10Guidelines for networking › Regularly restarting network devices
ISM-20840.10Guidelines for software development › Secure artificial intelligence application development
ISM-05490.10Guidelines for communications systems › Traffic separation
ISM-14930.09Guidelines for system management › Software registers
ISM-17400.09Guidelines for personnel security › Managing and reporting suspicious changes to banking details or payment requests
ISM-20690.09Guidelines for physical security › Bringing photographic and video recording devices into facilities
ISM-00720.09Guidelines for procurement and outsourcing › Contractual security requirements with service providers
ISM-04020.07Guidelines for software development › Software security testing
ISM-08460.07Guidelines for system hardening › Application control
ISM-19700.07Guidelines for cyber security incidents › Handling and containing malicious code infections
ISM-15790.07Guidelines for networking › Capacity and availability planning and monitoring for online services
ISM-19280.07Guidelines for system hardening › Microsoft Active Directory services
ISM-03070.06Guidelines for information technology equipment › On-site maintenance or repairs
ISM-08200.06Guidelines for personnel security › Posting work-related information on online services
ISM-02940.06Guidelines for information technology equipment › Labelling IT equipment

Editorial / grammatical (38)

Cosmetic edits (normalised edit distance < 0.05). ISM-0138, ISM-0305, ISM-0310, ISM-0332, ISM-0484, ISM-0536, ISM-0694, ISM-0835, ISM-1036, ISM-1037, ISM-1076, ISM-1219, ISM-1245, ISM-1272, ISM-1289, ISM-1293, ISM-1297, ISM-1400, ISM-1417, ISM-1419, ISM-1429, ISM-1452, ISM-1483, ISM-1569, ISM-1574, ISM-1866, ISM-1939, ISM-1940, ISM-1941, ISM-1942, ISM-1983, ISM-2005, ISM-2006, ISM-2008, ISM-2035, ISM-2037, ISM-2060, ISM-2095

Relocated (149)

32 cross-chapter moves (listed) · 117 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for system monitoringGuidelines for security assuranceISM-0109 ISM-0580 ISM-0585 ISM-0988 ISM-1228 ISM-1405 ISM-1815 ISM-1906 ISM-1907 ISM-1959 ISM-1960 ISM-1961 ISM-1983 ISM-1984 ISM-1985 ISM-1986 ISM-1987 ISM-1988 ISM-1989
Guidelines for cyber security incidentsGuidelines for security assuranceISM-0120
Guidelines for cryptographyGuidelines for mediaISM-0459
Guidelines for system managementGuidelines for security assuranceISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1703 ISM-1752 ISM-1807 ISM-1808 ISM-1900 ISM-1921

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (13 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.