ASD ISM — incremental change analysis

Release v2026.06.18 (2026-06-18) vs prior v2026.03.24 · 86 days · catalogue 1101 controls · NC-explicit era
ASD changes summary: ISM June 2026 changes (PDF)
20
Added
23
Substantive
44
Clarification
38
Editorial
149
Relocated
0
Scope changes
0
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET430
SECRET00
PROTECTED00
OFFICIAL: Sensitive01
Non-Classified042

3 · Level-specific material changes

FootprintFloorCeilingControls
OS|P|S|TSOFFICIAL: SensitiveTOP SECRETISM-2112

4 · Change location by chapter

5 · Section / topic structure

New sections: 6 · Removed sections: 5 · New topics: 16 · Removed topics: 11. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for cryptographyCryptographic algorithms31ISM-1080 ISM-0471 ISM-0994 ISM-0472 ISM-1759 ISM-1629 ISM-1446 ISM-0474 ISM-1761 ISM-1762 ISM-0475 ISM-1763 ISM-1764 ISM-1990 ISM-1991 ISM-1992 ISM-1993 ISM-1994 ISM-1995 ISM-0476 ISM-1765 ISM-0477 ISM-1766 ISM-1767 ISM-1768 ISM-1769 ISM-1770 ISM-0479 ISM-2073 ISM-1917 ISM-1996
Guidelines for cryptographyCryptographic protocols2ISM-0469 ISM-0481
Guidelines for information technology equipmentIT equipment maintenance or repairs6ISM-1079 ISM-0305 ISM-0307 ISM-0306 ISM-0310 ISM-1598
Guidelines for security assuranceSecurity assessments13ISM-1807 ISM-1808 ISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1752 ISM-1703 ISM-1900 ISM-1921 ISM-2118 ISM-2119
Guidelines for security assuranceSecurity monitoring22ISM-0580 ISM-1405 ISM-1983 ISM-1984 ISM-1985 ISM-1815 ISM-0988 ISM-0585 ISM-1959 ISM-0120 ISM-2116 ISM-2117 ISM-1986 ISM-1906 ISM-1907 ISM-0109 ISM-1987 ISM-1960 ISM-1961 ISM-1228 ISM-1988 ISM-1989
Guidelines for system managementSystem maintenance28ISM-1143 ISM-0298 ISM-1876 ISM-1690 ISM-1691 ISM-1692 ISM-1901 ISM-1693 ISM-1877 ISM-1694 ISM-1695 ISM-1696 ISM-1902 ISM-1878 ISM-1751 ISM-1879 ISM-1697 ISM-1903 ISM-1904 ISM-0300 ISM-1905 ISM-1704 ISM-0304 ISM-1501 ISM-1753 ISM-1981 ISM-1982 ISM-1809

Removed sections

ChapterSection
Guidelines for cryptographyASD-Approved Cryptographic Algorithms
Guidelines for cryptographyASD-Approved Cryptographic Protocols
Guidelines for information technology equipmentIT equipment maintenance and repairs
Guidelines for system managementSystem patching
Guidelines for system monitoringEvent logging and monitoring

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for cryptographyCryptographic fundamentalsHigh Assurance Cryptographic Equipment1ISM-1802
Guidelines for enterprise mobilityEnterprise mobilityPrivately owned mobile devices and desktop computers5ISM-1297 ISM-1400 ISM-1866 ISM-2095 ISM-0694
Guidelines for enterprise mobilityMobile device managementEncrypted communications2ISM-1085 ISM-2108
Guidelines for enterprise mobilityMobile device managementEncrypted storage2ISM-0869 ISM-1868
Guidelines for mediaMedia usageEncrypting media3ISM-1059 ISM-0459 ISM-2109
Guidelines for personnel securityCyber security awareness trainingPosting personal information on online services3ISM-0821 ISM-1146 ISM-2107
Guidelines for personnel securityCyber security awareness trainingPosting work-related information on online services4ISM-0820 ISM-2104 ISM-2105 ISM-2106
Guidelines for software developmentArtificial intelligence application developmentData collection, retention and use2ISM-2103 ISM-2123
Guidelines for system hardeningUser application hardeningArtificial intelligence applications3ISM-2112 ISM-2113 ISM-2114
Guidelines for system hardeningUser application hardeningEmail clients1ISM-1748
Guidelines for system hardeningUser application hardeningOffice productivity suites17ISM-1859 ISM-1667 ISM-1668 ISM-1669 ISM-1542 ISM-1823 ISM-1671 ISM-1488 ISM-1672 ISM-1673 ISM-1674 ISM-1890 ISM-1487 ISM-1675 ISM-1891 ISM-1676 ISM-1489
Guidelines for system hardeningUser application hardeningPortable Document Format applications3ISM-1670 ISM-1860 ISM-1824
Guidelines for system hardeningUser application hardeningSecurity products1ISM-1825
Guidelines for system hardeningUser application hardeningWeb browsers4ISM-1486 ISM-1485 ISM-1412 ISM-1585
Guidelines for system hardeningVirtualisation hardeningFunctional separation between operating environments7ISM-1460 ISM-1604 ISM-1605 ISM-1606 ISM-1848 ISM-1607 ISM-1461
Guidelines for system managementSystem administrationSoftware registers2ISM-1493 ISM-1643

Removed topics

ChapterSectionTopic
Guidelines for cryptographyCryptographic fundamentalsApproved High Assurance Cryptographic Equipment
Guidelines for cryptographyCryptographic fundamentalsEncrypting data at rest
Guidelines for cryptographyCryptographic fundamentalsEncrypting data in transit
Guidelines for cyber security incidentsManaging cyber security incidentsAccess to sufficient data sources and tools
Guidelines for enterprise mobilityEnterprise mobilityPrivately-owned mobile devices and desktop computers
Guidelines for enterprise mobilityMobile device managementData communications
Guidelines for enterprise mobilityMobile device managementData storage
Guidelines for personnel securityCyber security awareness trainingPosting personal information to online services
Guidelines for personnel securityCyber security awareness trainingPosting work information to online services
Guidelines for system hardeningUser application hardeningMicrosoft Office macros
Guidelines for system hardeningVirtualisation hardeningFunctional separation between computing environments

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for software developmentSoftware development fundamentals314412
Guidelines for system hardeningUser application hardening53109
Guidelines for personnel securityCyber security awareness training41308
Guidelines for system hardeningServer application hardening10168
Guidelines for system hardeningVirtualisation hardening04307
Guidelines for security assuranceSecurity monitoring22116
Guidelines for mediaMedia usage11215
Guidelines for procurement and outsourcingManaged services and cloud services00415
Guidelines for information technology equipmentIT equipment maintenance or repairs01225
Guidelines for networkingNetwork design and configuration02215
Guidelines for enterprise mobilityEnterprise mobility00055
Guidelines for physical securityFacilities and systems00314
Guidelines for enterprise mobilityMobile device management10203
Guidelines for software developmentArtificial intelligence application development10203
Guidelines for information technology equipmentIT equipment usage00303
Guidelines for system hardeningOperating system hardening00213
Guidelines for security assuranceSecurity assessments20002
Guidelines for cyber security documentationSystem-specific cyber security documentation02002
Guidelines for cyber security incidentsResponding to cyber security incidents00112
Guidelines for communications infrastructureCabling infrastructure00202
Guidelines for cyber security rolesChief information security officer01102
Guidelines for system hardeningAuthentication hardening02002
Guidelines for information technology equipmentIT equipment sanitisation and destruction00022
Guidelines for database systemsDatabase servers01012
Guidelines for gatewaysContent filtering00022
Guidelines for procurement and outsourcingCyber supply chain risk management00022
Guidelines for cyber security rolesBoard of directors and executive committee00022
Guidelines for communications systemsTelephone systems00101
Guidelines for cryptographyCryptographic protocols01001
Guidelines for cryptographySecure Shell00011
Guidelines for networkingWireless networks00011
Guidelines for communications systemsVideo conferencing and Internet Protocol telephony00101
Guidelines for mediaMedia sanitisation00011
Guidelines for communications systemsMultifunction devices00011
Guidelines for gatewaysGateways00011
Guidelines for cryptographyCryptographic algorithms01001
Guidelines for database systemsDatabases00101
Guidelines for system managementSystem administration00101
Guidelines for networkingService continuity for online services00101

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for system hardeningVirtualisation hardeningFunctional separation between operating environments04307
Guidelines for software developmentSoftware development fundamentalsSecure software development20125
Guidelines for software developmentSoftware development fundamentalsSoftware security testing11215
Guidelines for enterprise mobilityEnterprise mobilityPrivately owned mobile devices and desktop computers00055
Guidelines for personnel securityCyber security awareness trainingPosting work-related information on online services30104
Guidelines for system hardeningUser application hardeningHardening user application configurations22004
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Domain Services security group memberships00044
Guidelines for personnel securityCyber security awareness trainingPosting personal information on online services11103
Guidelines for mediaMedia usageEncrypting media11103
Guidelines for system hardeningUser application hardeningArtificial intelligence applications30003
Guidelines for security assuranceSecurity monitoringEvent log monitoring21003
Guidelines for procurement and outsourcingManaged services and cloud servicesContractual security requirements with service providers00213
Guidelines for information technology equipmentIT equipment maintenance or repairsOn-site maintenance or repairs01113
Guidelines for enterprise mobilityMobile device managementEncrypted communications10102
Guidelines for system hardeningServer application hardeningHardening server application configurations10012
Guidelines for security assuranceSecurity assessmentsVulnerability assessments and penetration tests20002
Guidelines for information technology equipmentIT equipment usageIT equipment registers00202
Guidelines for system hardeningOperating system hardeningApplication control00202
Guidelines for procurement and outsourcingCyber supply chain risk managementCyber supply chain risk management activities00022
Guidelines for security assuranceSecurity monitoringCentralised event logging facility01012
Guidelines for physical securityFacilities and systemsBringing medical devices into facilities00112
Guidelines for software developmentArtificial intelligence application developmentSecure artificial intelligence application development00202
Guidelines for software developmentArtificial intelligence application developmentData collection, retention and use10001
Guidelines for cyber security documentationSystem-specific cyber security documentationCyber security incident response plan01001
Guidelines for cyber security incidentsResponding to cyber security incidentsMaintaining the integrity of evidence00011
Guidelines for communications infrastructureCabling infrastructureCable register00101
Guidelines for communications systemsTelephone systemsCordless telephone systems00101
Guidelines for information technology equipmentIT equipment usageLabelling IT equipment00101
Guidelines for information technology equipmentIT equipment maintenance or repairsOff-site maintenance or repairs00011
Guidelines for mediaMedia usageLabelling media00011
Guidelines for networkingNetwork design and configurationFunctional separation between servers01001
Guidelines for cryptographyCryptographic protocolsUsing cryptographic protocols01001
Guidelines for cryptographySecure ShellConfiguring Secure Shell00011
Guidelines for networkingWireless networksPublic wireless networks00011
Guidelines for communications systemsVideo conferencing and Internet Protocol telephonyTraffic separation00101
Guidelines for security assuranceSecurity monitoringSecurity monitoring policy00101
Guidelines for cyber security rolesChief information security officerCoordinating cyber security01001
Guidelines for mediaMedia sanitisationTreatment of volatile media following sanitisation00011
Guidelines for system hardeningAuthentication hardeningSession termination01001
Guidelines for enterprise mobilityMobile device managementEncrypted storage00101
Guidelines for communications systemsMultifunction devicesObserving multifunction device use00011
Guidelines for gatewaysGatewaysAssessment of gateways00011
Guidelines for information technology equipmentIT equipment sanitisation and destructionSanitising televisions and computer monitors00011
Guidelines for cryptographyCryptographic algorithmsUsing cryptographic algorithms01001
Guidelines for cyber security documentationSystem-specific cyber security documentationContinuous monitoring plan01001
Guidelines for information technology equipmentIT equipment sanitisation and destructionSanitising printers and multifunction devices00011
Guidelines for database systemsDatabasesDatabase register00101
Guidelines for database systemsDatabase serversNetwork environment00011
Guidelines for database systemsDatabase serversCommunications between database servers and web servers01001
Guidelines for gatewaysContent filteringArchive files00011
Guidelines for gatewaysContent filteringEncrypted files00011
Guidelines for system hardeningAuthentication hardeningUser account lockouts01001
Guidelines for system hardeningOperating system hardeningAntivirus application00011
Guidelines for software developmentSoftware development fundamentalsDevelopment, testing, staging and production environments00011
Guidelines for networkingNetwork design and configurationUsing Internet Protocol version 600011
Guidelines for system hardeningUser application hardeningUser application releases01001
Guidelines for system hardeningServer application hardeningServer application releases00011
Guidelines for system managementSystem administrationSoftware registers00101
Guidelines for physical securityFacilities and systemsBringing radio frequency and infrared devices into facilities00101
Guidelines for networkingService continuity for online servicesCapacity and availability planning and monitoring for online services00101
Guidelines for information technology equipmentIT equipment maintenance or repairsInspection of IT equipment following maintenance or repairs00101
Guidelines for procurement and outsourcingManaged services and cloud servicesOutsourced cloud services00101
Guidelines for communications infrastructureCabling infrastructureFloor plan diagrams00101
Guidelines for system hardeningUser application hardeningOffice productivity suites00101
Guidelines for mediaMedia usageRemovable media register00101
Guidelines for procurement and outsourcingManaged services and cloud servicesManaged services00101
Guidelines for personnel securityCyber security awareness trainingManaging and reporting suspicious changes to banking details or payment requests00101
Guidelines for networkingNetwork design and configurationNetwork encryption00101
Guidelines for networkingNetwork design and configurationRegularly restarting network devices00101
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory services00101
Guidelines for cyber security rolesChief information security officerOverseeing the cyber security program00101
Guidelines for cyber security incidentsResponding to cyber security incidentsHandling and containing malicious code infections00101
Guidelines for cyber security rolesBoard of directors and executive committeeIdentifying critical business assets00011
Guidelines for cyber security rolesBoard of directors and executive committeePlanning for major cyber security incidents00011
Guidelines for networkingNetwork design and configurationEncrypted Domain Name System Services01001
Guidelines for software developmentSoftware development fundamentalsSoftware input handling00101
Guidelines for physical securityFacilities and systemsBringing photographic and video recording devices into facilities00101

6 · Control call-outs by category

Added — new controls (20)

ControlFootprintLocationStatement (excerpt)
ISM-2104NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where …
ISM-2105NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such inf…
ISM-2106NC|OS|P|S|TSGuidelines for personnel security › Posting work-related information on online servicesPersonnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases…
ISM-2107NC|OS|P|S|TSGuidelines for personnel security › Posting personal information on online servicesPersonnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.
ISM-2108NC|OS|P|S|TSGuidelines for enterprise mobility › Encrypted communicationsMobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
ISM-2109NC|OS|P|S|TSGuidelines for media › Encrypting mediaPre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.
ISM-2110NC|OS|P|S|TSGuidelines for system hardening › Hardening user application configurationsUser applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
ISM-2111NC|OS|P|S|TSGuidelines for system hardening › Hardening user application configurationsAll temporary installation files created during user application installation processes are removed after user applications have been installed.
ISM-2112OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsAI applications that process classified data have their ability to directly access external public data sources disabled.
ISM-2113NC|OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsAI applications are configured to flag organisationally defined risky actions for human approval prior to their execution.
ISM-2114NC|OS|P|S|TSGuidelines for system hardening › Artificial intelligence applicationsBaselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.
ISM-2115NC|OS|P|S|TSGuidelines for system hardening › Hardening server application configurationsExtensions for server applications are restricted to an organisation-approved set.
ISM-2116NC|OS|P|S|TSGuidelines for security assurance › Event log monitoringCyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.
ISM-2117NC|OS|P|S|TSGuidelines for security assurance › Event log monitoringSuitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.
ISM-2118NC|OS|P|S|TSGuidelines for security assurance › Vulnerability assessments and penetration testsVulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant …
ISM-2119NC|OS|P|S|TSGuidelines for security assurance › Vulnerability assessments and penetration testsSuitable AI models are used to augment vulnerability assessments and penetration tests.
ISM-2120NC|OS|P|S|TSGuidelines for software development › Secure software developmentA secure software development policy is developed, implemented and maintained.
ISM-2121NC|OS|P|S|TSGuidelines for software development › Secure software developmentSoftware developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.
ISM-2122NC|OS|P|S|TSGuidelines for software development › Software security testingSuitable AI models are used to augment software security testing.
ISM-2123NC|OS|P|S|TSGuidelines for software development › Data collection, retention and useAll prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.

Substantive amendments (23)

ControlEdit distLocationStatement (excerpt)
ISM-14600.76Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has d…
ISM-18480.72Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating sys…
ISM-00430.57Guidelines for cyber security documentation › Cyber security incident response planSystems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types…
ISM-03060.49Guidelines for information technology equipment › On-site maintenance or repairsIf an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: - h…
ISM-01200.49Guidelines for security assurance › Event log monitoringCyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security…
ISM-08530.48Guidelines for system hardening › Session terminationUser sessions are terminated and workstations are restarted at least daily.
ISM-14030.45Guidelines for system hardening › User account lockoutsUser accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon atte…
ISM-04690.41Guidelines for cryptography › Using cryptographic protocolsAn AACP or high assurance cryptographic protocol is used when encrypting data in transit.
ISM-12350.39Guidelines for system hardening › Hardening user application configurationsExtensions for user applications are restricted to an organisation-approved set.
ISM-07250.38Guidelines for cyber security roles › Coordinating cyber securityThe CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber securit…
ISM-14670.38Guidelines for system hardening › User application releasesThe latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are…
ISM-11630.37Guidelines for cyber security documentation › Continuous monitoring planSystems have a continuous monitoring plan that includes: - conducting security assessment activities to identify vulnerabilities - analysing identifie…
ISM-16060.34Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerab…
ISM-03850.34Guidelines for networking › Functional separation between serversServers maintain effective functional separation from each other.
ISM-14700.33Guidelines for system hardening › Hardening user application configurationsUnneeded user accounts, components, services and functionality of user applications are disabled or removed.
ISM-08210.33Guidelines for personnel security › Posting personal information on online servicesPersonnel are advised of security risks associated with posting personal information on online services.
ISM-16070.32Guidelines for system hardening › Functional separation between operating environmentsWhen using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is perform…
ISM-10590.30Guidelines for media › Encrypting mediaAll data stored on media is encrypted using ASD-approved cryptography.
ISM-12770.29Guidelines for database systems › Communications between database servers and web serversData communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.
ISM-19840.29Guidelines for security assurance › Centralised event logging facilityEvent logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.
ISM-20610.27Guidelines for software development › Software security testingPeer reviews are conducted on all critical and security-related software components.
ISM-10800.26Guidelines for cryptography › Using cryptographic algorithmsAn AACA or high assurance cryptographic algorithm is used when encrypting data at rest.
ISM-20170.25Guidelines for networking › Encrypted Domain Name System ServicesDNS traffic is encrypted by clients and servers using ASD-approved cryptography.

Clarifications (44)

ControlEdit distLocation
ISM-15820.24Guidelines for system hardening › Application control
ISM-11460.21Guidelines for personnel security › Posting personal information on online services
ISM-17810.20Guidelines for networking › Network encryption
ISM-16760.20Guidelines for system hardening › Office productivity suites
ISM-08690.19Guidelines for enterprise mobility › Encrypted storage
ISM-02110.18Guidelines for communications infrastructure › Cable register
ISM-20850.17Guidelines for software development › Secure artificial intelligence application development
ISM-05800.17Guidelines for security assurance › Security monitoring policy
ISM-20530.17Guidelines for software development › Secure software development
ISM-12430.17Guidelines for database systems › Database register
ISM-16450.17Guidelines for communications infrastructure › Floor plan diagrams
ISM-16050.16Guidelines for system hardening › Functional separation between operating environments
ISM-14610.16Guidelines for system hardening › Functional separation between operating environments
ISM-17130.16Guidelines for media › Removable media register
ISM-17360.16Guidelines for procurement and outsourcing › Managed services
ISM-03360.15Guidelines for information technology equipment › IT equipment registers
ISM-16370.14Guidelines for procurement and outsourcing › Outsourced cloud services
ISM-18690.14Guidelines for information technology equipment › IT equipment registers
ISM-17380.13Guidelines for procurement and outsourcing › Contractual security requirements with service providers
ISM-10850.13Guidelines for enterprise mobility › Encrypted communications
ISM-20620.13Guidelines for software development › Software security testing
ISM-19660.12Guidelines for cyber security roles › Overseeing the cyber security program
ISM-16040.11Guidelines for system hardening › Functional separation between operating environments
ISM-15980.11Guidelines for information technology equipment › Inspection of IT equipment following maintenance or repairs
ISM-20570.11Guidelines for software development › Software input handling
ISM-20070.11Guidelines for physical security › Bringing medical devices into facilities
ISM-04590.11Guidelines for media › Encrypting media
ISM-15430.11Guidelines for physical security › Bringing radio frequency and infrared devices into facilities
ISM-02330.11Guidelines for communications systems › Cordless telephone systems
ISM-18010.10Guidelines for networking › Regularly restarting network devices
ISM-20840.10Guidelines for software development › Secure artificial intelligence application development
ISM-05490.10Guidelines for communications systems › Traffic separation
ISM-14930.09Guidelines for system management › Software registers
ISM-17400.09Guidelines for personnel security › Managing and reporting suspicious changes to banking details or payment requests
ISM-20690.09Guidelines for physical security › Bringing photographic and video recording devices into facilities
ISM-00720.09Guidelines for procurement and outsourcing › Contractual security requirements with service providers
ISM-04020.07Guidelines for software development › Software security testing
ISM-08460.07Guidelines for system hardening › Application control
ISM-19700.07Guidelines for cyber security incidents › Handling and containing malicious code infections
ISM-15790.07Guidelines for networking › Capacity and availability planning and monitoring for online services
ISM-19280.07Guidelines for system hardening › Microsoft Active Directory services
ISM-03070.06Guidelines for information technology equipment › On-site maintenance or repairs
ISM-08200.06Guidelines for personnel security › Posting work-related information on online services
ISM-02940.06Guidelines for information technology equipment › Labelling IT equipment

Editorial / grammatical (38)

Cosmetic edits (normalised edit distance < 0.05). ISM-0138, ISM-0305, ISM-0310, ISM-0332, ISM-0484, ISM-0536, ISM-0694, ISM-0835, ISM-1036, ISM-1037, ISM-1076, ISM-1219, ISM-1245, ISM-1272, ISM-1289, ISM-1293, ISM-1297, ISM-1400, ISM-1417, ISM-1419, ISM-1429, ISM-1452, ISM-1483, ISM-1569, ISM-1574, ISM-1866, ISM-1939, ISM-1940, ISM-1941, ISM-1942, ISM-1983, ISM-2005, ISM-2006, ISM-2008, ISM-2035, ISM-2037, ISM-2060, ISM-2095

Relocated (149)

32 cross-chapter moves (listed) · 117 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for system monitoringGuidelines for security assuranceISM-0109 ISM-0580 ISM-0585 ISM-0988 ISM-1228 ISM-1405 ISM-1815 ISM-1906 ISM-1907 ISM-1959 ISM-1960 ISM-1961 ISM-1983 ISM-1984 ISM-1985 ISM-1986 ISM-1987 ISM-1988 ISM-1989
Guidelines for cyber security incidentsGuidelines for security assuranceISM-0120
Guidelines for cryptographyGuidelines for mediaISM-0459
Guidelines for system managementGuidelines for security assuranceISM-1698 ISM-1699 ISM-1700 ISM-1701 ISM-1702 ISM-1703 ISM-1752 ISM-1807 ISM-1808 ISM-1900 ISM-1921

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (0)

None.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (13 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.0 — longitudinal and per-release analysis of ASD Information Security Manual control changes.