ASD ISM — incremental change analysis

Release v2026.09.4 (2026-09-04) vs prior v2026.06.18 · 78 days · catalogue 1143 controls · NC-explicit era
ASD changes summary: ISM September 2026 changes (PDF)
44
Added
14
Substantive
33
Clarification
55
Editorial
130
Relocated
0
Scope changes
2
Removed

1 · Change typology

2 · Classification footprint

Ceiling (highest level reached) / Floor (lowest level reached) — material changes

Levelas ceilingas floor
TOP SECRET580
SECRET00
PROTECTED00
OFFICIAL: Sensitive00
Non-Classified058

3 · Level-specific material changes

No level-specific material changes — every added/substantive control applies at all classifications (NC|OS|P|S|TS).

4 · Change location by chapter

5 · Section / topic structure

New sections: 4 · Removed sections: 3 · New topics: 17 · Removed topics: 11. Keyed on case/spelling-normalised chapter › section › topic, so cosmetic retitles do not appear here.

New sections

ChapterSectionControlsControl IDs
Guidelines for cryptographySecure/Multipurpose Internet Mail Extensions1ISM-0490
Guidelines for networkingWired networks5ISM-2163 ISM-2164 ISM-2165 ISM-2166 ISM-2167
Guidelines for system accessCredential management43ISM-1559 ISM-1560 ISM-1561 ISM-0421 ISM-1557 ISM-0422 ISM-1558 ISM-2078 ISM-2079 ISM-2080 ISM-2081 ISM-1593 ISM-1227 ISM-1594 ISM-1595 ISM-1596 ISM-1953 ISM-1685 ISM-1795 ISM-1954 ISM-1619 ISM-2141 ISM-2142 ISM-2143 ISM-1590 ISM-2144 ISM-1955 ISM-1847 ISM-1956 ISM-2145 ISM-2146 ISM-1597 ISM-1980 ISM-0418 ISM-1402 ISM-1957 ISM-1861 ISM-1686 ISM-1897 ISM-1749 ISM-1875 ISM-2147 ISM-2148
Guidelines for system accessIdentity and access management80ISM-1864 ISM-0432 ISM-0434 ISM-0435 ISM-1865 ISM-0408 ISM-0414 ISM-0415 ISM-1583 ISM-0420 ISM-2133 ISM-0405 ISM-1852 ISM-1566 ISM-0409 ISM-0411 ISM-1507 ISM-1508 ISM-1175 ISM-1883 ISM-1649 ISM-0445 ISM-1263 ISM-1509 ISM-1650 ISM-0446 ISM-0447 ISM-0407 ISM-2134 ISM-2135 ISM-0430 ISM-1591 ISM-1404 ISM-1648 ISM-1647 ISM-0441 ISM-0443 ISM-1610 ISM-1611 ISM-1612 ISM-1614 ISM-1615 ISM-1613 ISM-0078 ISM-0854 ISM-1546 ISM-2136 ISM-1603 ISM-1055 ISM-2076 ISM-2077 ISM-1504 ISM-1679 ISM-1680 ISM-1892 ISM-1893 ISM-1681 ISM-1919 ISM-1173 ISM-0974 ISM-1505 ISM-1401 ISM-1872 ISM-1873 ISM-1874 ISM-1682 ISM-1894 ISM-2011 ISM-1920 ISM-1683 ISM-0417 ISM-1895 ISM-1403 ISM-0428 ISM-2012 ISM-0853 ISM-2137 ISM-2138 ISM-2139 ISM-2140

Removed sections

ChapterSection
Guidelines for cryptographySecure/Multipurpose Internet Mail Extension
Guidelines for personnel securityAccess to systems and their resources
Guidelines for system hardeningAuthentication hardening

New topics

ChapterSectionTopicControlsControl IDs
Guidelines for data transfersData transfersAccountability for data transfers1ISM-0661
Guidelines for gatewaysCross domain solutionsCross domain solution use1ISM-0610
Guidelines for networkingNetwork design and configuration802.1X authentication and key exchange2ISM-1321 ISM-1711
Guidelines for networkingNetwork design and configurationEvaluation of 802.1X implementations1ISM-1322
Guidelines for networkingNetwork design and configurationGenerating and issuing X.509 certificates for authentication3ISM-1323 ISM-1324 ISM-1327
Guidelines for networkingNetwork design and configurationNetwork device hardening2ISM-1304 ISM-2162
Guidelines for networkingNetwork design and configurationNetwork device integrity2ISM-1800 ISM-2161
Guidelines for networkingNetwork design and configurationRemote Authentication Dial-In User Service authentication1ISM-1454
Guidelines for personnel securityCyber security awareness trainingGeneral-purpose artificial intelligence usage policy1ISM-2074
Guidelines for personnel securityCyber security awareness trainingManaging requests to change banking details or transfer funds1ISM-1740
Guidelines for personnel securityCyber security awareness trainingManaging requests to modify user accounts1ISM-2071
Guidelines for personnel securityCyber security awareness trainingSynthetic impersonation1ISM-2126
Guidelines for personnel securityCyber security awareness trainingWeb usage policy1ISM-0258
Guidelines for security assuranceSecurity monitoringThreat hunting1ISM-2153
Guidelines for system hardeningOperating system hardeningWindows Management Instrumentation1ISM-2129
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Domain Services6ISM-1827 ISM-1929 ISM-1828 ISM-1829 ISM-1930 ISM-1931
Guidelines for system managementSystem administrationAdministrative tools2ISM-2149 ISM-2150

Removed topics

ChapterSectionTopic
Guidelines for data transfersData transfersUser responsibilities
Guidelines for gatewaysCross Domain SolutionsUser training
Guidelines for networkingNetwork design and configurationDefault user accounts and credentials for network devices
Guidelines for networkingNetwork design and configurationFlashing network devices with trusted firmware before first use
Guidelines for networkingWireless networks802.1X authentication
Guidelines for networkingWireless networksEvaluation of 802.1X authentication implementation
Guidelines for networkingWireless networksGenerating and issuing certificates for authentication
Guidelines for networkingWireless networksRemote Authentication Dial-In User Service authentication
Guidelines for personnel securityCyber security awareness trainingManaging and reporting suspicious changes to banking details or payment requests
Guidelines for personnel securityCyber security awareness trainingManaging and reporting suspicious requests to disclose or change user account details
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Domain Services domain controllers

Changes by section (this release)

ChapterSectionAddedSubstantiveClarificationEditorialTotal
Guidelines for system accessIdentity and access management8292039
Guidelines for system accessCredential management832114
Guidelines for system hardeningServer application hardening31149
Guidelines for system hardeningUser application hardening01179
Guidelines for system hardeningOperating system hardening31138
Guidelines for networkingNetwork design and configuration32218
Guidelines for procurement and outsourcingManaged services and cloud services20147
Guidelines for system managementSystem administration20327
Guidelines for software developmentSoftware development fundamentals20406
Guidelines for cyber security rolesSystem owners00156
Guidelines for networkingWired networks50005
Guidelines for software developmentArtificial intelligence application development40004
Guidelines for cyber security documentationSystem-specific cyber security documentation00033
Guidelines for cyber security incidentsResponding to cyber security incidents02103
Guidelines for personnel securityCyber security awareness training10102
Guidelines for system managementData backup and restoration20002
Guidelines for emailEmail usage01102
Guidelines for data transfersData transfers00022
Guidelines for security assuranceSecurity monitoring10001
Guidelines for cryptographySecure Shell01001
Guidelines for gatewaysCross domain solutions00101
Guidelines for database systemsDatabases00101
Guidelines for database systemsDatabase servers00011
Guidelines for cryptographyTransport Layer Security00101
Guidelines for system managementSystem maintenance00011
Guidelines for communications systemsMultifunction devices00101
Guidelines for gatewaysGateways00011
Guidelines for security assuranceSecurity assessments00101

Changes by topic (this release)

ChapterSectionTopicAddedSubstantiveClarificationEditorialTotal
Guidelines for system accessIdentity and access managementMulti-factor authentication0021315
Guidelines for cyber security rolesSystem ownersProtecting systems and their resources00156
Guidelines for networkingWired networksMedia Access Control Security50005
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Certificate Services30014
Guidelines for system accessIdentity and access managementThird-party application access and device code authentication40004
Guidelines for software developmentArtificial intelligence application developmentExcessive agency40004
Guidelines for system managementSystem administrationSeparate privileged operating environments00224
Guidelines for system hardeningUser application hardeningOffice productivity suites00044
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory services01034
Guidelines for procurement and outsourcingManaged services and cloud servicesAccess to systems by service providers20103
Guidelines for system hardeningOperating system hardeningHardening operating system configurations20013
Guidelines for system accessCredential managementApplication and workload credentials30003
Guidelines for system accessCredential managementChanging credentials11013
Guidelines for system accessIdentity and access managementPrivileged access to systems00213
Guidelines for cyber security incidentsResponding to cyber security incidentsHandling and containing intrusions02103
Guidelines for networkingNetwork design and configurationGenerating and issuing X.509 certificates for authentication01113
Guidelines for system accessCredential managementSetting credentials for user accounts02103
Guidelines for system accessIdentity and access managementArtificial intelligence agent register20002
Guidelines for system accessCredential managementRevoking credentials20002
Guidelines for system accessCredential managementProtecting authentication artefacts20002
Guidelines for system managementSystem administrationAdministrative tools20002
Guidelines for system managementData backup and restorationBackup modification and deletion20002
Guidelines for software developmentSoftware development fundamentalsSoftware artefacts10102
Guidelines for emailEmail usageProtective marking tools01102
Guidelines for system hardeningOperating system hardeningApplication management00022
Guidelines for system accessIdentity and access managementUnprivileged access to systems by foreign nationals00022
Guidelines for system accessIdentity and access managementUser identification00202
Guidelines for system accessIdentity and access managementSuspension of access to systems00022
Guidelines for software developmentSoftware development fundamentalsSecure software development00202
Guidelines for personnel securityCyber security awareness trainingSynthetic impersonation10001
Guidelines for system hardeningOperating system hardeningWindows Management Instrumentation10001
Guidelines for system accessIdentity and access managementArtificial intelligence agent identification10001
Guidelines for system accessIdentity and access managementAuthenticating to systems10001
Guidelines for security assuranceSecurity monitoringThreat hunting10001
Guidelines for software developmentSoftware development fundamentalsBuild solution10001
Guidelines for networkingNetwork design and configurationNetworked management interfaces10001
Guidelines for networkingNetwork design and configurationNetwork device integrity10001
Guidelines for networkingNetwork design and configurationNetwork device hardening10001
Guidelines for cyber security documentationSystem-specific cyber security documentationSystem security plan00011
Guidelines for system accessIdentity and access managementRecording authorisation for personnel to access systems00011
Guidelines for system accessIdentity and access managementSystem access requirements00011
Guidelines for system accessIdentity and access managementSession locking01001
Guidelines for system accessIdentity and access managementTemporary access to systems00101
Guidelines for cryptographySecure ShellSSH-agent01001
Guidelines for gatewaysCross domain solutionsCross domain solution use00101
Guidelines for data transfersData transfersAccountability for data transfers00011
Guidelines for data transfersData transfersAuthorising export of data00011
Guidelines for system hardeningOperating system hardeningApplication control01001
Guidelines for system accessIdentity and access managementSession termination00101
Guidelines for system managementSystem administrationSystem administration processes and procedures00101
Guidelines for database systemsDatabasesProtecting database contents00101
Guidelines for database systemsDatabase serversNetwork environment00011
Guidelines for networkingNetwork design and configuration802.1X authentication and key exchange00101
Guidelines for networkingNetwork design and configurationEvaluation of 802.1X implementations01001
Guidelines for cryptographyTransport Layer SecurityConfiguring Transport Layer Security00101
Guidelines for system hardeningOperating system hardeningOperating system releases and versions00101
Guidelines for software developmentSoftware development fundamentalsSoftware interaction with databases00101
Guidelines for cyber security documentationSystem-specific cyber security documentationSecurity assessment report00011
Guidelines for cyber security documentationSystem-specific cyber security documentationPlan of action and milestones00011
Guidelines for personnel securityCyber security awareness trainingProviding cyber security awareness training00101
Guidelines for system hardeningUser application hardeningWeb browsers00101
Guidelines for procurement and outsourcingManaged services and cloud servicesOutsourced cloud services00011
Guidelines for procurement and outsourcingManaged services and cloud servicesManaged services00011
Guidelines for system hardeningUser application hardeningEmail clients00011
Guidelines for system managementSystem maintenanceCessation of support00011
Guidelines for system hardeningUser application hardeningPortable Document Format applications00011
Guidelines for system hardeningUser application hardeningSecurity products00011
Guidelines for system accessIdentity and access managementUnprivileged access to systems00101
Guidelines for communications systemsMultifunction devicesAuthenticating to multifunction devices00101
Guidelines for system accessCredential managementProtecting credentials00101
Guidelines for system hardeningServer application hardeningMicrosoft Active Directory Domain Services account hardening00101
Guidelines for procurement and outsourcingManaged services and cloud servicesAssessment of managed service providers00011
Guidelines for procurement and outsourcingManaged services and cloud servicesAssessment of outsourced cloud service providers00011
Guidelines for system accessIdentity and access managementScreen locking01001
Guidelines for gatewaysGatewaysAssessment of gateways00011
Guidelines for system hardeningUser application hardeningArtificial intelligence applications01001
Guidelines for security assuranceSecurity assessmentsVulnerability assessments and penetration tests00101

6 · Control call-outs by category

Added — new controls (44)

ControlFootprintLocationStatement (excerpt)
ISM-2124NC|OS|P|S|TSGuidelines for procurement and outsourcing › Access to systems by service providersAccess by a service provider to an organisation’s systems is restricted to remote management tools, source network addresses and time windows explicit…
ISM-2125NC|OS|P|S|TSGuidelines for procurement and outsourcing › Access to systems by service providersAll access to an organisation’s systems by a service provider is independently logged by the organisation in a manner that the service provider cannot…
ISM-2126NC|OS|P|S|TSGuidelines for personnel security › Synthetic impersonationPersonnel positively identify requestors using a pre-established authentication method or independent trusted communication channel before actioning r…
ISM-2127NC|OS|P|S|TSGuidelines for system hardening › Hardening operating system configurationsDigital signature verification functionality for drivers is enforced before they are loaded.
ISM-2128NC|OS|P|S|TSGuidelines for system hardening › Hardening operating system configurationsThe ability to install, load or modify kernel-mode code, including drivers, kernel modules and extensions, is limited to privileged users who require …
ISM-2129NC|OS|P|S|TSGuidelines for system hardening › Windows Management InstrumentationWMI activity, including the creation of permanent event subscriptions, is centrally logged.
ISM-2130NC|OS|P|S|TSGuidelines for system hardening › Microsoft Active Directory Certificate ServicesWeb-based enrolment interfaces for Microsoft AD CS servers are disabled unless required, and where enabled, are configured to require HTTPS and Extend…
ISM-2131NC|OS|P|S|TSGuidelines for system hardening › Microsoft Active Directory Certificate ServicesCertificate templates are reviewed at least every three months to identify and remediate misconfigurations that could enable privilege escalation or u…
ISM-2132NC|OS|P|S|TSGuidelines for system hardening › Microsoft Active Directory Certificate ServicesCertificate enrolment events, including successful and unsuccessful requests and changes to certificate templates or Microsoft AD CS configurations, a…
ISM-2133NC|OS|P|S|TSGuidelines for system access › Artificial intelligence agent identificationEach AI agent is assigned a unique identity that is distinct from the user accounts of personnel and the identities of other AI agents.
ISM-2134NC|OS|P|S|TSGuidelines for system access › Artificial intelligence agent registerAn AI agent register is developed, implemented, maintained and regularly verified.
ISM-2135NC|OS|P|S|TSGuidelines for system access › Artificial intelligence agent registerAn AI agent register contains the following for each AI agent: - its unique identifier - its owner and business purpose - the identities assigned to i…
ISM-2136NC|OS|P|S|TSGuidelines for system access › Authenticating to systemsRisk-based access decisions, informed by contextual signals, are enforced for access to systems and their resources.
ISM-2137NC|OS|P|S|TSGuidelines for system access › Third-party application access and device code authenticationHuman users are prevented from granting consent to third-party OAuth applications, with such consent granted only by an authorised administrator.
ISM-2138NC|OS|P|S|TSGuidelines for system access › Third-party application access and device code authenticationOAuth application consents, including their granted permissions, are reviewed at least every six months, with unused applications and excessive permis…
ISM-2139NC|OS|P|S|TSGuidelines for system access › Third-party application access and device code authenticationConsent grants, token issuance and token use for third-party OAuth applications are centrally logged.
ISM-2140NC|OS|P|S|TSGuidelines for system access › Third-party application access and device code authenticationThe OAuth device code authentication flow is disabled unless required, and where required, is restricted to authorised user accounts and managed devic…
ISM-2141NC|OS|P|S|TSGuidelines for system access › Application and workload credentialsApplications and workloads use short-lived dynamically issued credentials in preference to long-lived static credentials.
ISM-2142NC|OS|P|S|TSGuidelines for system access › Application and workload credentialsStatic credentials used by applications and workloads are centrally managed using a credential or secrets management solution.
ISM-2143NC|OS|P|S|TSGuidelines for system access › Application and workload credentialsApplications and workloads use unique credentials that are not shared with other applications or workloads, or across development, testing, staging an…
ISM-2144NC|OS|P|S|TSGuidelines for system access › Changing credentialsStatic credentials used by applications and workloads are changed if: - they are compromised or suspected of being compromised - they are discovered s…
ISM-2145NC|OS|P|S|TSGuidelines for system access › Revoking credentialsCredentials for user accounts are revoked when they are no longer required.
ISM-2146NC|OS|P|S|TSGuidelines for system access › Revoking credentialsStatic credentials used by applications and workloads are revoked when they are no longer required.
ISM-2147NC|OS|P|S|TSGuidelines for system access › Protecting authentication artefactsAuthentication tokens, session cookies and refresh tokens are cryptographically bound to the device on which they were issued.
ISM-2148NC|OS|P|S|TSGuidelines for system access › Protecting authentication artefactsActive sessions, refresh tokens and other authentication artefacts are revoked when credentials are reset or re-enrolled, when credentials are comprom…
ISM-2149NC|OS|P|S|TSGuidelines for system management › Administrative toolsA list of authorised RMM tools and remote access tools is developed, enforced and maintained.
ISM-2150NC|OS|P|S|TSGuidelines for system management › Administrative toolsNetwork connections for unauthorised RMM tools and remote access tools are blocked at gateways.
ISM-2151NC|OS|P|S|TSGuidelines for system management › Backup modification and deletionBackups are stored using a technically enforced immutability mechanism that prevents their modification or deletion for the duration of their retentio…
ISM-2152NC|OS|P|S|TSGuidelines for system management › Backup modification and deletionBackup infrastructure, including backup servers, repositories and management consoles, is segregated from production environments and uses a separate …
ISM-2153NC|OS|P|S|TSGuidelines for security assurance › Threat huntingThreat hunting activities, informed by current strategic and sector-specific cyber threat intelligence, are conducted at least every three months.
ISM-2154NC|OS|P|S|TSGuidelines for software development › Software artefactsSoftware artefact dependencies are pinned to approved versions in source code.
ISM-2155NC|OS|P|S|TSGuidelines for software development › Build solutionSoftware is built using reproducible build practices that enable independent verification that release artefacts were produced from the stated source …
ISM-2156NC|OS|P|S|TSGuidelines for software development › Excessive agencyAgentic AI applications are restricted to the minimum set of tools, functions and permissions required for their intended purpose.
ISM-2157NC|OS|P|S|TSGuidelines for software development › Excessive agencyTools invoked by agentic AI applications are subject to both the access controls of the invoking user and agent-specific, task-scoped authorisation, w…
ISM-2158NC|OS|P|S|TSGuidelines for software development › Excessive agencyExternal content retrieved by agentic AI applications is treated as untrusted data throughout processing, is clearly delimited from system instruction…
ISM-2159NC|OS|P|S|TSGuidelines for software development › Excessive agencyAll tool invocations, external requests and outputs generated by agentic AI applications are centrally logged with sufficient detail to support cyber …
ISM-2160NC|OS|P|S|TSGuidelines for networking › Networked management interfacesNetworked management interfaces for IT equipment are only accessible from a dedicated management network that is segregated from the wider network and…
ISM-2161NC|OS|P|S|TSGuidelines for networking › Network device integrityThe integrity of network device firmware and running configurations is verified against an approved known-good baseline following patching, on detecti…
ISM-2162NC|OS|P|S|TSGuidelines for networking › Network device hardeningUnneeded components, services and functionality of network devices are disabled or removed.
ISM-2163NC|OS|P|S|TSGuidelines for networking › Media Access Control SecurityWhen using MACsec, confidentiality protection mode is enabled using GCM-AES-128, GCM-AES-256, GCM-AES-XPN-128 or GCM-AES-XPN-256, preferably GCM-AES-2…
ISM-2164NC|OS|P|S|TSGuidelines for networking › Media Access Control SecurityA connectivity association lifetime of less than 24 hours (86400 seconds) is used for MACsec connections.
ISM-2165NC|OS|P|S|TSGuidelines for networking › Media Access Control SecurityWhen using EAP-TLS, each device performs a fresh EAP-TLS authentication each time a new Connectivity Association Key is required.
ISM-2166NC|OS|P|S|TSGuidelines for networking › Media Access Control SecurityA secure association lifetime of less than four hours (14400 seconds) is used for MACsec connections.
ISM-2167NC|OS|P|S|TSGuidelines for networking › Media Access Control SecurityThe use of a Pre-Shared Key as a fallback authentication method for MACsec is disabled.

Substantive amendments (14)

ControlEdit distLocationStatement (excerpt)
ISM-12130.77Guidelines for cyber security incidents › Handling and containing intrusionsFollowing intrusion remediation activities, enhanced monitoring is conducted until there is sufficient evidence-based confidence that malicious actors…
ISM-20120.61Guidelines for system access › Screen lockingSystems are configured with a screen lock that: - activates after a maximum of 15 minutes of human user inactivity, or when manually activated - conce…
ISM-15930.58Guidelines for system access › Setting credentials for user accountsHuman users provide sufficient evidence to verify their identity when first requesting credentials, when requesting the reset of any credentials, when…
ISM-17320.58Guidelines for cyber security incidents › Handling and containing intrusionsIntrusion remediation activities are coordinated and sequenced to minimise opportunities for re-compromise of a system while balancing operational ris…
ISM-08460.57Guidelines for system hardening › Application controlUsers cannot disable or bypass application control, and are not exempted from application control, except when using local administrator accounts or b…
ISM-04890.48Guidelines for cryptography › SSH-agentWhen SSH-agent or similar key caching applications are used, cached private keys have a maximum lifetime of four hours and, where applicable, screen l…
ISM-04280.47Guidelines for system access › Session lockingServices are configured with a session lock that: - activates after a maximum of 15 minutes of human user inactivity, a maximum of 12 hours of overall…
ISM-19280.46Guidelines for system hardening › Microsoft Active Directory servicesBackups of Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted usin…
ISM-21130.41Guidelines for system hardening › Artificial intelligence applicationsAI applications are configured to require human approval before executing sensitive or high-impact actions.
ISM-15940.40Guidelines for system access › Setting credentials for user accountsCredentials for human users are provided via a secure communications channel or, if not possible, split into two parts with one part provided to the h…
ISM-10890.32Guidelines for email › Protective marking toolsWhen replying to or forwarding emails, protective marking tools do not allow the selection of protective markings lower than previously used.
ISM-13230.28Guidelines for networking › Generating and issuing X.509 certificates for authenticationX.509 certificates are required for devices and human users authenticating to networks using 802.1X.
ISM-15900.28Guidelines for system access › Changing credentialsCredentials for user accounts are changed if: - they are compromised or suspected of being compromised - they are discovered stored on systems in the …
ISM-13220.28Guidelines for networking › Evaluation of 802.1X implementationsEvaluated supplicants, authenticators and authentication servers are used for 802.1X authentication implementations.

Clarifications (33)

ControlEdit distLocation
ISM-15650.24Guidelines for personnel security › Providing cyber security awareness training
ISM-13270.23Guidelines for networking › Generating and issuing X.509 certificates for authentication
ISM-17310.22Guidelines for cyber security incidents › Handling and containing intrusions
ISM-13210.18Guidelines for networking › 802.1X authentication and key exchange
ISM-13720.17Guidelines for cryptography › Configuring Transport Layer Security
ISM-12110.17Guidelines for system management › System administration processes and procedures
ISM-14080.16Guidelines for system hardening › Operating system releases and versions
ISM-15760.14Guidelines for procurement and outsourcing › Access to systems by service providers
ISM-15360.12Guidelines for software development › Software interaction with databases
ISM-14010.11Guidelines for system access › Multi-factor authentication
ISM-15080.10Guidelines for system access › Privileged access to systems
ISM-18520.10Guidelines for system access › Unprivileged access to systems
ISM-20300.09Guidelines for software development › Software artefacts
ISM-08530.09Guidelines for system access › Session termination
ISM-20470.09Guidelines for software development › Secure software development
ISM-18830.08Guidelines for system access › Privileged access to systems
ISM-12550.07Guidelines for database systems › Protecting database contents
ISM-16880.07Guidelines for system management › Separate privileged operating environments
ISM-19340.07Guidelines for system hardening › Microsoft Active Directory Domain Services account hardening
ISM-04150.07Guidelines for system access › User identification
ISM-19580.06Guidelines for system management › Separate privileged operating environments
ISM-21180.06Guidelines for security assurance › Vulnerability assessments and penetration tests
ISM-20110.06Guidelines for system access › Multi-factor authentication
ISM-06100.06Guidelines for gateways › Cross domain solution use
ISM-18750.05Guidelines for system access › Protecting credentials
ISM-20380.05Guidelines for software development › Secure software development
ISM-16350.05Guidelines for cyber security roles › Protecting systems and their resources
ISM-04410.05Guidelines for system access › Temporary access to systems
ISM-18540.05Guidelines for communications systems › Authenticating to multifunction devices
ISM-15950.05Guidelines for system access › Setting credentials for user accounts
ISM-02720.05Guidelines for email › Protective marking tools
ISM-04140.05Guidelines for system access › User identification
ISM-15850.05Guidelines for system hardening › Web browsers

Editorial / grammatical (55)

Cosmetic edits (normalised edit distance < 0.05). ISM-0009, ISM-0041, ISM-0382, ISM-0407, ISM-0408, ISM-0409, ISM-0411, ISM-0430, ISM-0445, ISM-0661, ISM-0665, ISM-0974, ISM-1173, ISM-1270, ISM-1324, ISM-1380, ISM-1487, ISM-1489, ISM-1491, ISM-1504, ISM-1505, ISM-1526, ISM-1563, ISM-1564, ISM-1591, ISM-1592, ISM-1634, ISM-1636, ISM-1638, ISM-1671, ISM-1679, ISM-1680, ISM-1682, ISM-1689, ISM-1737, ISM-1748, ISM-1809, ISM-1823, ISM-1824, ISM-1825, ISM-1830, ISM-1847, ISM-1872, ISM-1892, ISM-1893, ISM-1894, ISM-1919, ISM-1920, ISM-1926, ISM-1927, ISM-1948, ISM-1967, ISM-1971, ISM-1972, ISM-2019

Relocated (130)

107 cross-chapter moves (listed) · 23 intra-chapter section/topic reshuffles (count only).
From chapterTo chapterControls
Guidelines for personnel securityGuidelines for system accessISM-0078 ISM-0405 ISM-0407 ISM-0409 ISM-0411 ISM-0414 ISM-0415 ISM-0420 ISM-0430 ISM-0432 ISM-0434 ISM-0435 ISM-0441 ISM-0443 ISM-0445 ISM-0446 ISM-0447 ISM-0854 ISM-1175 ISM-1263 ISM-1404 ISM-1507 ISM-1508 ISM-1509 ISM-1566 ISM-1583 ISM-1591 ISM-1610 ISM-1611 ISM-1612 ISM-1613 ISM-1614 ISM-1615 ISM-1647 ISM-1648 ISM-1649 ISM-1650 ISM-1852 ISM-1864 ISM-1865 ISM-1883
Guidelines for system hardeningGuidelines for system accessISM-0408 ISM-0417 ISM-0418 ISM-0421 ISM-0422 ISM-0428 ISM-0853 ISM-0974 ISM-1055 ISM-1173 ISM-1227 ISM-1401 ISM-1402 ISM-1403 ISM-1504 ISM-1505 ISM-1546 ISM-1557 ISM-1558 ISM-1559 ISM-1560 ISM-1561 ISM-1590 ISM-1593 ISM-1594 ISM-1595 ISM-1596 ISM-1597 ISM-1603 ISM-1619 ISM-1679 ISM-1680 ISM-1681 ISM-1682 ISM-1683 ISM-1685 ISM-1686 ISM-1749 ISM-1795 ISM-1847 ISM-1861 ISM-1872 ISM-1873 ISM-1874 ISM-1875 ISM-1892 ISM-1893 ISM-1894 ISM-1895 ISM-1897 ISM-1919 ISM-1920 ISM-1953 ISM-1954 ISM-1955 ISM-1956 ISM-1957 ISM-1980 ISM-2011 ISM-2012 ISM-2076 ISM-2077 ISM-2078 ISM-2079 ISM-2080 ISM-2081

Scope / applicability changes (0)

No control changed its classification reach this release.

Removed (2)

ControlFootprintFormer locationStatement (excerpt)
ISM-0521NC|OS|P|S|TSGuidelines for networkingIPv6 functionality is disabled in dual-stack network devices unless it is being used.
ISM-1448NC|OS|P|S|TSGuidelines for cryptographyWhen using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.
Method. Controls only (ISM-principles excluded). A content modification requires ASD's native revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.
Generated by ISMexplorer v1.0.3 — longitudinal and per-release analysis of ASD Information Security Manual control changes.