| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 43 | 0 |
| SECRET | 0 | 0 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 1 |
| Non-Classified | 0 | 42 |
| Footprint | Floor | Ceiling | Controls |
|---|---|---|---|
OS|P|S|TS | OFFICIAL: Sensitive | TOP SECRET | ISM-2112 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for cryptography | Cryptographic algorithms | 31 | ISM-1080 ISM-0471 ISM-0994 ISM-0472 ISM-1759 ISM-1629 ISM-1446 ISM-0474 ISM-1761 ISM-1762 ISM-0475 ISM-1763 ISM-1764 ISM-1990 ISM-1991 ISM-1992 ISM-1993 ISM-1994 ISM-1995 ISM-0476 ISM-1765 ISM-0477 ISM-1766 ISM-1767 ISM-1768 ISM-1769 ISM-1770 ISM-0479 ISM-2073 ISM-1917 ISM-1996 |
| Guidelines for cryptography | Cryptographic protocols | 2 | ISM-0469 ISM-0481 |
| Guidelines for information technology equipment | IT equipment maintenance or repairs | 6 | ISM-1079 ISM-0305 ISM-0307 ISM-0306 ISM-0310 ISM-1598 |
| Guidelines for security assurance | Security assessments | 13 | ISM-1807 ISM-1808 ISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1752 ISM-1703 ISM-1900 ISM-1921 ISM-2118 ISM-2119 |
| Guidelines for security assurance | Security monitoring | 22 | ISM-0580 ISM-1405 ISM-1983 ISM-1984 ISM-1985 ISM-1815 ISM-0988 ISM-0585 ISM-1959 ISM-0120 ISM-2116 ISM-2117 ISM-1986 ISM-1906 ISM-1907 ISM-0109 ISM-1987 ISM-1960 ISM-1961 ISM-1228 ISM-1988 ISM-1989 |
| Guidelines for system management | System maintenance | 28 | ISM-1143 ISM-0298 ISM-1876 ISM-1690 ISM-1691 ISM-1692 ISM-1901 ISM-1693 ISM-1877 ISM-1694 ISM-1695 ISM-1696 ISM-1902 ISM-1878 ISM-1751 ISM-1879 ISM-1697 ISM-1903 ISM-1904 ISM-0300 ISM-1905 ISM-1704 ISM-0304 ISM-1501 ISM-1753 ISM-1981 ISM-1982 ISM-1809 |
| Chapter | Section |
|---|---|
| Guidelines for cryptography | ASD-Approved Cryptographic Algorithms |
| Guidelines for cryptography | ASD-Approved Cryptographic Protocols |
| Guidelines for information technology equipment | IT equipment maintenance and repairs |
| Guidelines for system management | System patching |
| Guidelines for system monitoring | Event logging and monitoring |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for cryptography | Cryptographic fundamentals | High Assurance Cryptographic Equipment | 1 | ISM-1802 |
| Guidelines for enterprise mobility | Enterprise mobility | Privately owned mobile devices and desktop computers | 5 | ISM-1297 ISM-1400 ISM-1866 ISM-2095 ISM-0694 |
| Guidelines for enterprise mobility | Mobile device management | Encrypted communications | 2 | ISM-1085 ISM-2108 |
| Guidelines for enterprise mobility | Mobile device management | Encrypted storage | 2 | ISM-0869 ISM-1868 |
| Guidelines for media | Media usage | Encrypting media | 3 | ISM-1059 ISM-0459 ISM-2109 |
| Guidelines for personnel security | Cyber security awareness training | Posting personal information on online services | 3 | ISM-0821 ISM-1146 ISM-2107 |
| Guidelines for personnel security | Cyber security awareness training | Posting work-related information on online services | 4 | ISM-0820 ISM-2104 ISM-2105 ISM-2106 |
| Guidelines for software development | Artificial intelligence application development | Data collection, retention and use | 2 | ISM-2103 ISM-2123 |
| Guidelines for system hardening | User application hardening | Artificial intelligence applications | 3 | ISM-2112 ISM-2113 ISM-2114 |
| Guidelines for system hardening | User application hardening | Email clients | 1 | ISM-1748 |
| Guidelines for system hardening | User application hardening | Office productivity suites | 17 | ISM-1859 ISM-1667 ISM-1668 ISM-1669 ISM-1542 ISM-1823 ISM-1671 ISM-1488 ISM-1672 ISM-1673 ISM-1674 ISM-1890 ISM-1487 ISM-1675 ISM-1891 ISM-1676 ISM-1489 |
| Guidelines for system hardening | User application hardening | Portable Document Format applications | 3 | ISM-1670 ISM-1860 ISM-1824 |
| Guidelines for system hardening | User application hardening | Security products | 1 | ISM-1825 |
| Guidelines for system hardening | User application hardening | Web browsers | 4 | ISM-1486 ISM-1485 ISM-1412 ISM-1585 |
| Guidelines for system hardening | Virtualisation hardening | Functional separation between operating environments | 7 | ISM-1460 ISM-1604 ISM-1605 ISM-1606 ISM-1848 ISM-1607 ISM-1461 |
| Guidelines for system management | System administration | Software registers | 2 | ISM-1493 ISM-1643 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for cryptography | Cryptographic fundamentals | Approved High Assurance Cryptographic Equipment |
| Guidelines for cryptography | Cryptographic fundamentals | Encrypting data at rest |
| Guidelines for cryptography | Cryptographic fundamentals | Encrypting data in transit |
| Guidelines for cyber security incidents | Managing cyber security incidents | Access to sufficient data sources and tools |
| Guidelines for enterprise mobility | Enterprise mobility | Privately-owned mobile devices and desktop computers |
| Guidelines for enterprise mobility | Mobile device management | Data communications |
| Guidelines for enterprise mobility | Mobile device management | Data storage |
| Guidelines for personnel security | Cyber security awareness training | Posting personal information to online services |
| Guidelines for personnel security | Cyber security awareness training | Posting work information to online services |
| Guidelines for system hardening | User application hardening | Microsoft Office macros |
| Guidelines for system hardening | Virtualisation hardening | Functional separation between computing environments |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for software development | Software development fundamentals | 3 | 1 | 4 | 4 | 12 |
| Guidelines for system hardening | User application hardening | 5 | 3 | 1 | 0 | 9 |
| Guidelines for personnel security | Cyber security awareness training | 4 | 1 | 3 | 0 | 8 |
| Guidelines for system hardening | Server application hardening | 1 | 0 | 1 | 6 | 8 |
| Guidelines for system hardening | Virtualisation hardening | 0 | 4 | 3 | 0 | 7 |
| Guidelines for security assurance | Security monitoring | 2 | 2 | 1 | 1 | 6 |
| Guidelines for media | Media usage | 1 | 1 | 2 | 1 | 5 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | 0 | 0 | 4 | 1 | 5 |
| Guidelines for information technology equipment | IT equipment maintenance or repairs | 0 | 1 | 2 | 2 | 5 |
| Guidelines for networking | Network design and configuration | 0 | 2 | 2 | 1 | 5 |
| Guidelines for enterprise mobility | Enterprise mobility | 0 | 0 | 0 | 5 | 5 |
| Guidelines for physical security | Facilities and systems | 0 | 0 | 3 | 1 | 4 |
| Guidelines for enterprise mobility | Mobile device management | 1 | 0 | 2 | 0 | 3 |
| Guidelines for software development | Artificial intelligence application development | 1 | 0 | 2 | 0 | 3 |
| Guidelines for information technology equipment | IT equipment usage | 0 | 0 | 3 | 0 | 3 |
| Guidelines for system hardening | Operating system hardening | 0 | 0 | 2 | 1 | 3 |
| Guidelines for security assurance | Security assessments | 2 | 0 | 0 | 0 | 2 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | 0 | 2 | 0 | 0 | 2 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | 0 | 0 | 1 | 1 | 2 |
| Guidelines for communications infrastructure | Cabling infrastructure | 0 | 0 | 2 | 0 | 2 |
| Guidelines for cyber security roles | Chief information security officer | 0 | 1 | 1 | 0 | 2 |
| Guidelines for system hardening | Authentication hardening | 0 | 2 | 0 | 0 | 2 |
| Guidelines for information technology equipment | IT equipment sanitisation and destruction | 0 | 0 | 0 | 2 | 2 |
| Guidelines for database systems | Database servers | 0 | 1 | 0 | 1 | 2 |
| Guidelines for gateways | Content filtering | 0 | 0 | 0 | 2 | 2 |
| Guidelines for procurement and outsourcing | Cyber supply chain risk management | 0 | 0 | 0 | 2 | 2 |
| Guidelines for cyber security roles | Board of directors and executive committee | 0 | 0 | 0 | 2 | 2 |
| Guidelines for communications systems | Telephone systems | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cryptography | Cryptographic protocols | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cryptography | Secure Shell | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Wireless networks | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Video conferencing and Internet Protocol telephony | 0 | 0 | 1 | 0 | 1 |
| Guidelines for media | Media sanitisation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Multifunction devices | 0 | 0 | 0 | 1 | 1 |
| Guidelines for gateways | Gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cryptography | Cryptographic algorithms | 0 | 1 | 0 | 0 | 1 |
| Guidelines for database systems | Databases | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system management | System administration | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Service continuity for online services | 0 | 0 | 1 | 0 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for system hardening | Virtualisation hardening | Functional separation between operating environments | 0 | 4 | 3 | 0 | 7 |
| Guidelines for software development | Software development fundamentals | Secure software development | 2 | 0 | 1 | 2 | 5 |
| Guidelines for software development | Software development fundamentals | Software security testing | 1 | 1 | 2 | 1 | 5 |
| Guidelines for enterprise mobility | Enterprise mobility | Privately owned mobile devices and desktop computers | 0 | 0 | 0 | 5 | 5 |
| Guidelines for personnel security | Cyber security awareness training | Posting work-related information on online services | 3 | 0 | 1 | 0 | 4 |
| Guidelines for system hardening | User application hardening | Hardening user application configurations | 2 | 2 | 0 | 0 | 4 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Domain Services security group memberships | 0 | 0 | 0 | 4 | 4 |
| Guidelines for personnel security | Cyber security awareness training | Posting personal information on online services | 1 | 1 | 1 | 0 | 3 |
| Guidelines for media | Media usage | Encrypting media | 1 | 1 | 1 | 0 | 3 |
| Guidelines for system hardening | User application hardening | Artificial intelligence applications | 3 | 0 | 0 | 0 | 3 |
| Guidelines for security assurance | Security monitoring | Event log monitoring | 2 | 1 | 0 | 0 | 3 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Contractual security requirements with service providers | 0 | 0 | 2 | 1 | 3 |
| Guidelines for information technology equipment | IT equipment maintenance or repairs | On-site maintenance or repairs | 0 | 1 | 1 | 1 | 3 |
| Guidelines for enterprise mobility | Mobile device management | Encrypted communications | 1 | 0 | 1 | 0 | 2 |
| Guidelines for system hardening | Server application hardening | Hardening server application configurations | 1 | 0 | 0 | 1 | 2 |
| Guidelines for security assurance | Security assessments | Vulnerability assessments and penetration tests | 2 | 0 | 0 | 0 | 2 |
| Guidelines for information technology equipment | IT equipment usage | IT equipment registers | 0 | 0 | 2 | 0 | 2 |
| Guidelines for system hardening | Operating system hardening | Application control | 0 | 0 | 2 | 0 | 2 |
| Guidelines for procurement and outsourcing | Cyber supply chain risk management | Cyber supply chain risk management activities | 0 | 0 | 0 | 2 | 2 |
| Guidelines for security assurance | Security monitoring | Centralised event logging facility | 0 | 1 | 0 | 1 | 2 |
| Guidelines for physical security | Facilities and systems | Bringing medical devices into facilities | 0 | 0 | 1 | 1 | 2 |
| Guidelines for software development | Artificial intelligence application development | Secure artificial intelligence application development | 0 | 0 | 2 | 0 | 2 |
| Guidelines for software development | Artificial intelligence application development | Data collection, retention and use | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | Cyber security incident response plan | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | Maintaining the integrity of evidence | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications infrastructure | Cabling infrastructure | Cable register | 0 | 0 | 1 | 0 | 1 |
| Guidelines for communications systems | Telephone systems | Cordless telephone systems | 0 | 0 | 1 | 0 | 1 |
| Guidelines for information technology equipment | IT equipment usage | Labelling IT equipment | 0 | 0 | 1 | 0 | 1 |
| Guidelines for information technology equipment | IT equipment maintenance or repairs | Off-site maintenance or repairs | 0 | 0 | 0 | 1 | 1 |
| Guidelines for media | Media usage | Labelling media | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Network design and configuration | Functional separation between servers | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cryptography | Cryptographic protocols | Using cryptographic protocols | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cryptography | Secure Shell | Configuring Secure Shell | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Wireless networks | Public wireless networks | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Video conferencing and Internet Protocol telephony | Traffic separation | 0 | 0 | 1 | 0 | 1 |
| Guidelines for security assurance | Security monitoring | Security monitoring policy | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Coordinating cyber security | 0 | 1 | 0 | 0 | 1 |
| Guidelines for media | Media sanitisation | Treatment of volatile media following sanitisation | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Authentication hardening | Session termination | 0 | 1 | 0 | 0 | 1 |
| Guidelines for enterprise mobility | Mobile device management | Encrypted storage | 0 | 0 | 1 | 0 | 1 |
| Guidelines for communications systems | Multifunction devices | Observing multifunction device use | 0 | 0 | 0 | 1 | 1 |
| Guidelines for gateways | Gateways | Assessment of gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for information technology equipment | IT equipment sanitisation and destruction | Sanitising televisions and computer monitors | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cryptography | Cryptographic algorithms | Using cryptographic algorithms | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | Continuous monitoring plan | 0 | 1 | 0 | 0 | 1 |
| Guidelines for information technology equipment | IT equipment sanitisation and destruction | Sanitising printers and multifunction devices | 0 | 0 | 0 | 1 | 1 |
| Guidelines for database systems | Databases | Database register | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Database servers | Network environment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for database systems | Database servers | Communications between database servers and web servers | 0 | 1 | 0 | 0 | 1 |
| Guidelines for gateways | Content filtering | Archive files | 0 | 0 | 0 | 1 | 1 |
| Guidelines for gateways | Content filtering | Encrypted files | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Authentication hardening | User account lockouts | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | Operating system hardening | Antivirus application | 0 | 0 | 0 | 1 | 1 |
| Guidelines for software development | Software development fundamentals | Development, testing, staging and production environments | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Network design and configuration | Using Internet Protocol version 6 | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | User application releases | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system hardening | Server application hardening | Server application releases | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system management | System administration | Software registers | 0 | 0 | 1 | 0 | 1 |
| Guidelines for physical security | Facilities and systems | Bringing radio frequency and infrared devices into facilities | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Service continuity for online services | Capacity and availability planning and monitoring for online services | 0 | 0 | 1 | 0 | 1 |
| Guidelines for information technology equipment | IT equipment maintenance or repairs | Inspection of IT equipment following maintenance or repairs | 0 | 0 | 1 | 0 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Outsourced cloud services | 0 | 0 | 1 | 0 | 1 |
| Guidelines for communications infrastructure | Cabling infrastructure | Floor plan diagrams | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | User application hardening | Office productivity suites | 0 | 0 | 1 | 0 | 1 |
| Guidelines for media | Media usage | Removable media register | 0 | 0 | 1 | 0 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Managed services | 0 | 0 | 1 | 0 | 1 |
| Guidelines for personnel security | Cyber security awareness training | Managing and reporting suspicious changes to banking details or payment requests | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Network encryption | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Regularly restarting network devices | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory services | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security roles | Chief information security officer | Overseeing the cyber security program | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | Handling and containing malicious code infections | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security roles | Board of directors and executive committee | Identifying critical business assets | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security roles | Board of directors and executive committee | Planning for major cyber security incidents | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Network design and configuration | Encrypted Domain Name System Services | 0 | 1 | 0 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Software input handling | 0 | 0 | 1 | 0 | 1 |
| Guidelines for physical security | Facilities and systems | Bringing photographic and video recording devices into facilities | 0 | 0 | 1 | 0 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-2104 | NC|OS|P|S|TS | Guidelines for personnel security › Posting work-related information on online services | Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where … |
| ISM-2105 | NC|OS|P|S|TS | Guidelines for personnel security › Posting work-related information on online services | Personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such inf… |
| ISM-2106 | NC|OS|P|S|TS | Guidelines for personnel security › Posting work-related information on online services | Personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases… |
| ISM-2107 | NC|OS|P|S|TS | Guidelines for personnel security › Posting personal information on online services | Personnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services. |
| ISM-2108 | NC|OS|P|S|TS | Guidelines for enterprise mobility › Encrypted communications | Mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography. |
| ISM-2109 | NC|OS|P|S|TS | Guidelines for media › Encrypting media | Pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes. |
| ISM-2110 | NC|OS|P|S|TS | Guidelines for system hardening › Hardening user application configurations | User applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. |
| ISM-2111 | NC|OS|P|S|TS | Guidelines for system hardening › Hardening user application configurations | All temporary installation files created during user application installation processes are removed after user applications have been installed. |
| ISM-2112 | OS|P|S|TS | Guidelines for system hardening › Artificial intelligence applications | AI applications that process classified data have their ability to directly access external public data sources disabled. |
| ISM-2113 | NC|OS|P|S|TS | Guidelines for system hardening › Artificial intelligence applications | AI applications are configured to flag organisationally defined risky actions for human approval prior to their execution. |
| ISM-2114 | NC|OS|P|S|TS | Guidelines for system hardening › Artificial intelligence applications | Baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations. |
| ISM-2115 | NC|OS|P|S|TS | Guidelines for system hardening › Hardening server application configurations | Extensions for server applications are restricted to an organisation-approved set. |
| ISM-2116 | NC|OS|P|S|TS | Guidelines for security assurance › Event log monitoring | Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents. |
| ISM-2117 | NC|OS|P|S|TS | Guidelines for security assurance › Event log monitoring | Suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents. |
| ISM-2118 | NC|OS|P|S|TS | Guidelines for security assurance › Vulnerability assessments and penetration tests | Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant … |
| ISM-2119 | NC|OS|P|S|TS | Guidelines for security assurance › Vulnerability assessments and penetration tests | Suitable AI models are used to augment vulnerability assessments and penetration tests. |
| ISM-2120 | NC|OS|P|S|TS | Guidelines for software development › Secure software development | A secure software development policy is developed, implemented and maintained. |
| ISM-2121 | NC|OS|P|S|TS | Guidelines for software development › Secure software development | Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used. |
| ISM-2122 | NC|OS|P|S|TS | Guidelines for software development › Software security testing | Suitable AI models are used to augment software security testing. |
| ISM-2123 | NC|OS|P|S|TS | Guidelines for software development › Data collection, retention and use | All prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications. |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-1460 | 0.76 | Guidelines for system hardening › Functional separation between operating environments | When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has d… |
| ISM-1848 | 0.72 | Guidelines for system hardening › Functional separation between operating environments | When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating sys… |
| ISM-0043 | 0.57 | Guidelines for cyber security documentation › Cyber security incident response plan | Systems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types… |
| ISM-0306 | 0.49 | Guidelines for information technology equipment › On-site maintenance or repairs | If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: - h… |
| ISM-0120 | 0.49 | Guidelines for security assurance › Event log monitoring | Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security… |
| ISM-0853 | 0.48 | Guidelines for system hardening › Session termination | User sessions are terminated and workstations are restarted at least daily. |
| ISM-1403 | 0.45 | Guidelines for system hardening › User account lockouts | User accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon atte… |
| ISM-0469 | 0.41 | Guidelines for cryptography › Using cryptographic protocols | An AACP or high assurance cryptographic protocol is used when encrypting data in transit. |
| ISM-1235 | 0.39 | Guidelines for system hardening › Hardening user application configurations | Extensions for user applications are restricted to an organisation-approved set. |
| ISM-0725 | 0.38 | Guidelines for cyber security roles › Coordinating cyber security | The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber securit… |
| ISM-1467 | 0.38 | Guidelines for system hardening › User application releases | The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are… |
| ISM-1163 | 0.37 | Guidelines for cyber security documentation › Continuous monitoring plan | Systems have a continuous monitoring plan that includes: - conducting security assessment activities to identify vulnerabilities - analysing identifie… |
| ISM-1606 | 0.34 | Guidelines for system hardening › Functional separation between operating environments | When using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerab… |
| ISM-0385 | 0.34 | Guidelines for networking › Functional separation between servers | Servers maintain effective functional separation from each other. |
| ISM-1470 | 0.33 | Guidelines for system hardening › Hardening user application configurations | Unneeded user accounts, components, services and functionality of user applications are disabled or removed. |
| ISM-0821 | 0.33 | Guidelines for personnel security › Posting personal information on online services | Personnel are advised of security risks associated with posting personal information on online services. |
| ISM-1607 | 0.32 | Guidelines for system hardening › Functional separation between operating environments | When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is perform… |
| ISM-1059 | 0.30 | Guidelines for media › Encrypting media | All data stored on media is encrypted using ASD-approved cryptography. |
| ISM-1277 | 0.29 | Guidelines for database systems › Communications between database servers and web servers | Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography. |
| ISM-1984 | 0.29 | Guidelines for security assurance › Centralised event logging facility | Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography. |
| ISM-2061 | 0.27 | Guidelines for software development › Software security testing | Peer reviews are conducted on all critical and security-related software components. |
| ISM-1080 | 0.26 | Guidelines for cryptography › Using cryptographic algorithms | An AACA or high assurance cryptographic algorithm is used when encrypting data at rest. |
| ISM-2017 | 0.25 | Guidelines for networking › Encrypted Domain Name System Services | DNS traffic is encrypted by clients and servers using ASD-approved cryptography. |
| Control | Edit dist | Location |
|---|---|---|
| ISM-1582 | 0.24 | Guidelines for system hardening › Application control |
| ISM-1146 | 0.21 | Guidelines for personnel security › Posting personal information on online services |
| ISM-1781 | 0.20 | Guidelines for networking › Network encryption |
| ISM-1676 | 0.20 | Guidelines for system hardening › Office productivity suites |
| ISM-0869 | 0.19 | Guidelines for enterprise mobility › Encrypted storage |
| ISM-0211 | 0.18 | Guidelines for communications infrastructure › Cable register |
| ISM-2085 | 0.17 | Guidelines for software development › Secure artificial intelligence application development |
| ISM-0580 | 0.17 | Guidelines for security assurance › Security monitoring policy |
| ISM-2053 | 0.17 | Guidelines for software development › Secure software development |
| ISM-1243 | 0.17 | Guidelines for database systems › Database register |
| ISM-1645 | 0.17 | Guidelines for communications infrastructure › Floor plan diagrams |
| ISM-1605 | 0.16 | Guidelines for system hardening › Functional separation between operating environments |
| ISM-1461 | 0.16 | Guidelines for system hardening › Functional separation between operating environments |
| ISM-1713 | 0.16 | Guidelines for media › Removable media register |
| ISM-1736 | 0.16 | Guidelines for procurement and outsourcing › Managed services |
| ISM-0336 | 0.15 | Guidelines for information technology equipment › IT equipment registers |
| ISM-1637 | 0.14 | Guidelines for procurement and outsourcing › Outsourced cloud services |
| ISM-1869 | 0.14 | Guidelines for information technology equipment › IT equipment registers |
| ISM-1738 | 0.13 | Guidelines for procurement and outsourcing › Contractual security requirements with service providers |
| ISM-1085 | 0.13 | Guidelines for enterprise mobility › Encrypted communications |
| ISM-2062 | 0.13 | Guidelines for software development › Software security testing |
| ISM-1966 | 0.12 | Guidelines for cyber security roles › Overseeing the cyber security program |
| ISM-1604 | 0.11 | Guidelines for system hardening › Functional separation between operating environments |
| ISM-1598 | 0.11 | Guidelines for information technology equipment › Inspection of IT equipment following maintenance or repairs |
| ISM-2057 | 0.11 | Guidelines for software development › Software input handling |
| ISM-2007 | 0.11 | Guidelines for physical security › Bringing medical devices into facilities |
| ISM-0459 | 0.11 | Guidelines for media › Encrypting media |
| ISM-1543 | 0.11 | Guidelines for physical security › Bringing radio frequency and infrared devices into facilities |
| ISM-0233 | 0.11 | Guidelines for communications systems › Cordless telephone systems |
| ISM-1801 | 0.10 | Guidelines for networking › Regularly restarting network devices |
| ISM-2084 | 0.10 | Guidelines for software development › Secure artificial intelligence application development |
| ISM-0549 | 0.10 | Guidelines for communications systems › Traffic separation |
| ISM-1493 | 0.09 | Guidelines for system management › Software registers |
| ISM-1740 | 0.09 | Guidelines for personnel security › Managing and reporting suspicious changes to banking details or payment requests |
| ISM-2069 | 0.09 | Guidelines for physical security › Bringing photographic and video recording devices into facilities |
| ISM-0072 | 0.09 | Guidelines for procurement and outsourcing › Contractual security requirements with service providers |
| ISM-0402 | 0.07 | Guidelines for software development › Software security testing |
| ISM-0846 | 0.07 | Guidelines for system hardening › Application control |
| ISM-1970 | 0.07 | Guidelines for cyber security incidents › Handling and containing malicious code infections |
| ISM-1579 | 0.07 | Guidelines for networking › Capacity and availability planning and monitoring for online services |
| ISM-1928 | 0.07 | Guidelines for system hardening › Microsoft Active Directory services |
| ISM-0307 | 0.06 | Guidelines for information technology equipment › On-site maintenance or repairs |
| ISM-0820 | 0.06 | Guidelines for personnel security › Posting work-related information on online services |
| ISM-0294 | 0.06 | Guidelines for information technology equipment › Labelling IT equipment |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for system monitoring | Guidelines for security assurance | ISM-0109 ISM-0580 ISM-0585 ISM-0988 ISM-1228 ISM-1405 ISM-1815 ISM-1906 ISM-1907 ISM-1959 ISM-1960 ISM-1961 ISM-1983 ISM-1984 ISM-1985 ISM-1986 ISM-1987 ISM-1988 ISM-1989 |
| Guidelines for cyber security incidents | Guidelines for security assurance | ISM-0120 |
| Guidelines for cryptography | Guidelines for media | ISM-0459 |
| Guidelines for system management | Guidelines for security assurance | ISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1703 ISM-1752 ISM-1807 ISM-1808 ISM-1900 ISM-1921 |
revision/updated stamp to move (13 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.