| Level | as ceiling | as floor |
|---|---|---|
| TOP SECRET | 58 | 0 |
| SECRET | 0 | 0 |
| PROTECTED | 0 | 0 |
| OFFICIAL: Sensitive | 0 | 0 |
| Non-Classified | 0 | 58 |
| Chapter | Section | Controls | Control IDs |
|---|---|---|---|
| Guidelines for cryptography | Secure/Multipurpose Internet Mail Extensions | 1 | ISM-0490 |
| Guidelines for networking | Wired networks | 5 | ISM-2163 ISM-2164 ISM-2165 ISM-2166 ISM-2167 |
| Guidelines for system access | Credential management | 43 | ISM-1559 ISM-1560 ISM-1561 ISM-0421 ISM-1557 ISM-0422 ISM-1558 ISM-2078 ISM-2079 ISM-2080 ISM-2081 ISM-1593 ISM-1227 ISM-1594 ISM-1595 ISM-1596 ISM-1953 ISM-1685 ISM-1795 ISM-1954 ISM-1619 ISM-2141 ISM-2142 ISM-2143 ISM-1590 ISM-2144 ISM-1955 ISM-1847 ISM-1956 ISM-2145 ISM-2146 ISM-1597 ISM-1980 ISM-0418 ISM-1402 ISM-1957 ISM-1861 ISM-1686 ISM-1897 ISM-1749 ISM-1875 ISM-2147 ISM-2148 |
| Guidelines for system access | Identity and access management | 80 | ISM-1864 ISM-0432 ISM-0434 ISM-0435 ISM-1865 ISM-0408 ISM-0414 ISM-0415 ISM-1583 ISM-0420 ISM-2133 ISM-0405 ISM-1852 ISM-1566 ISM-0409 ISM-0411 ISM-1507 ISM-1508 ISM-1175 ISM-1883 ISM-1649 ISM-0445 ISM-1263 ISM-1509 ISM-1650 ISM-0446 ISM-0447 ISM-0407 ISM-2134 ISM-2135 ISM-0430 ISM-1591 ISM-1404 ISM-1648 ISM-1647 ISM-0441 ISM-0443 ISM-1610 ISM-1611 ISM-1612 ISM-1614 ISM-1615 ISM-1613 ISM-0078 ISM-0854 ISM-1546 ISM-2136 ISM-1603 ISM-1055 ISM-2076 ISM-2077 ISM-1504 ISM-1679 ISM-1680 ISM-1892 ISM-1893 ISM-1681 ISM-1919 ISM-1173 ISM-0974 ISM-1505 ISM-1401 ISM-1872 ISM-1873 ISM-1874 ISM-1682 ISM-1894 ISM-2011 ISM-1920 ISM-1683 ISM-0417 ISM-1895 ISM-1403 ISM-0428 ISM-2012 ISM-0853 ISM-2137 ISM-2138 ISM-2139 ISM-2140 |
| Chapter | Section |
|---|---|
| Guidelines for cryptography | Secure/Multipurpose Internet Mail Extension |
| Guidelines for personnel security | Access to systems and their resources |
| Guidelines for system hardening | Authentication hardening |
| Chapter | Section | Topic | Controls | Control IDs |
|---|---|---|---|---|
| Guidelines for data transfers | Data transfers | Accountability for data transfers | 1 | ISM-0661 |
| Guidelines for gateways | Cross domain solutions | Cross domain solution use | 1 | ISM-0610 |
| Guidelines for networking | Network design and configuration | 802.1X authentication and key exchange | 2 | ISM-1321 ISM-1711 |
| Guidelines for networking | Network design and configuration | Evaluation of 802.1X implementations | 1 | ISM-1322 |
| Guidelines for networking | Network design and configuration | Generating and issuing X.509 certificates for authentication | 3 | ISM-1323 ISM-1324 ISM-1327 |
| Guidelines for networking | Network design and configuration | Network device hardening | 2 | ISM-1304 ISM-2162 |
| Guidelines for networking | Network design and configuration | Network device integrity | 2 | ISM-1800 ISM-2161 |
| Guidelines for networking | Network design and configuration | Remote Authentication Dial-In User Service authentication | 1 | ISM-1454 |
| Guidelines for personnel security | Cyber security awareness training | General-purpose artificial intelligence usage policy | 1 | ISM-2074 |
| Guidelines for personnel security | Cyber security awareness training | Managing requests to change banking details or transfer funds | 1 | ISM-1740 |
| Guidelines for personnel security | Cyber security awareness training | Managing requests to modify user accounts | 1 | ISM-2071 |
| Guidelines for personnel security | Cyber security awareness training | Synthetic impersonation | 1 | ISM-2126 |
| Guidelines for personnel security | Cyber security awareness training | Web usage policy | 1 | ISM-0258 |
| Guidelines for security assurance | Security monitoring | Threat hunting | 1 | ISM-2153 |
| Guidelines for system hardening | Operating system hardening | Windows Management Instrumentation | 1 | ISM-2129 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Domain Services | 6 | ISM-1827 ISM-1929 ISM-1828 ISM-1829 ISM-1930 ISM-1931 |
| Guidelines for system management | System administration | Administrative tools | 2 | ISM-2149 ISM-2150 |
| Chapter | Section | Topic |
|---|---|---|
| Guidelines for data transfers | Data transfers | User responsibilities |
| Guidelines for gateways | Cross Domain Solutions | User training |
| Guidelines for networking | Network design and configuration | Default user accounts and credentials for network devices |
| Guidelines for networking | Network design and configuration | Flashing network devices with trusted firmware before first use |
| Guidelines for networking | Wireless networks | 802.1X authentication |
| Guidelines for networking | Wireless networks | Evaluation of 802.1X authentication implementation |
| Guidelines for networking | Wireless networks | Generating and issuing certificates for authentication |
| Guidelines for networking | Wireless networks | Remote Authentication Dial-In User Service authentication |
| Guidelines for personnel security | Cyber security awareness training | Managing and reporting suspicious changes to banking details or payment requests |
| Guidelines for personnel security | Cyber security awareness training | Managing and reporting suspicious requests to disclose or change user account details |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Domain Services domain controllers |
| Chapter | Section | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|
| Guidelines for system access | Identity and access management | 8 | 2 | 9 | 20 | 39 |
| Guidelines for system access | Credential management | 8 | 3 | 2 | 1 | 14 |
| Guidelines for system hardening | Server application hardening | 3 | 1 | 1 | 4 | 9 |
| Guidelines for system hardening | User application hardening | 0 | 1 | 1 | 7 | 9 |
| Guidelines for system hardening | Operating system hardening | 3 | 1 | 1 | 3 | 8 |
| Guidelines for networking | Network design and configuration | 3 | 2 | 2 | 1 | 8 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | 2 | 0 | 1 | 4 | 7 |
| Guidelines for system management | System administration | 2 | 0 | 3 | 2 | 7 |
| Guidelines for software development | Software development fundamentals | 2 | 0 | 4 | 0 | 6 |
| Guidelines for cyber security roles | System owners | 0 | 0 | 1 | 5 | 6 |
| Guidelines for networking | Wired networks | 5 | 0 | 0 | 0 | 5 |
| Guidelines for software development | Artificial intelligence application development | 4 | 0 | 0 | 0 | 4 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | 0 | 0 | 0 | 3 | 3 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | 0 | 2 | 1 | 0 | 3 |
| Guidelines for personnel security | Cyber security awareness training | 1 | 0 | 1 | 0 | 2 |
| Guidelines for system management | Data backup and restoration | 2 | 0 | 0 | 0 | 2 |
| Guidelines for email | Email usage | 0 | 1 | 1 | 0 | 2 |
| Guidelines for data transfers | Data transfers | 0 | 0 | 0 | 2 | 2 |
| Guidelines for security assurance | Security monitoring | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cryptography | Secure Shell | 0 | 1 | 0 | 0 | 1 |
| Guidelines for gateways | Cross domain solutions | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Databases | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Database servers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cryptography | Transport Layer Security | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system management | System maintenance | 0 | 0 | 0 | 1 | 1 |
| Guidelines for communications systems | Multifunction devices | 0 | 0 | 1 | 0 | 1 |
| Guidelines for gateways | Gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for security assurance | Security assessments | 0 | 0 | 1 | 0 | 1 |
| Chapter | Section | Topic | Added | Substantive | Clarification | Editorial | Total |
|---|---|---|---|---|---|---|---|
| Guidelines for system access | Identity and access management | Multi-factor authentication | 0 | 0 | 2 | 13 | 15 |
| Guidelines for cyber security roles | System owners | Protecting systems and their resources | 0 | 0 | 1 | 5 | 6 |
| Guidelines for networking | Wired networks | Media Access Control Security | 5 | 0 | 0 | 0 | 5 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Certificate Services | 3 | 0 | 0 | 1 | 4 |
| Guidelines for system access | Identity and access management | Third-party application access and device code authentication | 4 | 0 | 0 | 0 | 4 |
| Guidelines for software development | Artificial intelligence application development | Excessive agency | 4 | 0 | 0 | 0 | 4 |
| Guidelines for system management | System administration | Separate privileged operating environments | 0 | 0 | 2 | 2 | 4 |
| Guidelines for system hardening | User application hardening | Office productivity suites | 0 | 0 | 0 | 4 | 4 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory services | 0 | 1 | 0 | 3 | 4 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Access to systems by service providers | 2 | 0 | 1 | 0 | 3 |
| Guidelines for system hardening | Operating system hardening | Hardening operating system configurations | 2 | 0 | 0 | 1 | 3 |
| Guidelines for system access | Credential management | Application and workload credentials | 3 | 0 | 0 | 0 | 3 |
| Guidelines for system access | Credential management | Changing credentials | 1 | 1 | 0 | 1 | 3 |
| Guidelines for system access | Identity and access management | Privileged access to systems | 0 | 0 | 2 | 1 | 3 |
| Guidelines for cyber security incidents | Responding to cyber security incidents | Handling and containing intrusions | 0 | 2 | 1 | 0 | 3 |
| Guidelines for networking | Network design and configuration | Generating and issuing X.509 certificates for authentication | 0 | 1 | 1 | 1 | 3 |
| Guidelines for system access | Credential management | Setting credentials for user accounts | 0 | 2 | 1 | 0 | 3 |
| Guidelines for system access | Identity and access management | Artificial intelligence agent register | 2 | 0 | 0 | 0 | 2 |
| Guidelines for system access | Credential management | Revoking credentials | 2 | 0 | 0 | 0 | 2 |
| Guidelines for system access | Credential management | Protecting authentication artefacts | 2 | 0 | 0 | 0 | 2 |
| Guidelines for system management | System administration | Administrative tools | 2 | 0 | 0 | 0 | 2 |
| Guidelines for system management | Data backup and restoration | Backup modification and deletion | 2 | 0 | 0 | 0 | 2 |
| Guidelines for software development | Software development fundamentals | Software artefacts | 1 | 0 | 1 | 0 | 2 |
| Guidelines for email | Email usage | Protective marking tools | 0 | 1 | 1 | 0 | 2 |
| Guidelines for system hardening | Operating system hardening | Application management | 0 | 0 | 0 | 2 | 2 |
| Guidelines for system access | Identity and access management | Unprivileged access to systems by foreign nationals | 0 | 0 | 0 | 2 | 2 |
| Guidelines for system access | Identity and access management | User identification | 0 | 0 | 2 | 0 | 2 |
| Guidelines for system access | Identity and access management | Suspension of access to systems | 0 | 0 | 0 | 2 | 2 |
| Guidelines for software development | Software development fundamentals | Secure software development | 0 | 0 | 2 | 0 | 2 |
| Guidelines for personnel security | Cyber security awareness training | Synthetic impersonation | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system hardening | Operating system hardening | Windows Management Instrumentation | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system access | Identity and access management | Artificial intelligence agent identification | 1 | 0 | 0 | 0 | 1 |
| Guidelines for system access | Identity and access management | Authenticating to systems | 1 | 0 | 0 | 0 | 1 |
| Guidelines for security assurance | Security monitoring | Threat hunting | 1 | 0 | 0 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Build solution | 1 | 0 | 0 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Networked management interfaces | 1 | 0 | 0 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Network device integrity | 1 | 0 | 0 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Network device hardening | 1 | 0 | 0 | 0 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | System security plan | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system access | Identity and access management | Recording authorisation for personnel to access systems | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system access | Identity and access management | System access requirements | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system access | Identity and access management | Session locking | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system access | Identity and access management | Temporary access to systems | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cryptography | Secure Shell | SSH-agent | 0 | 1 | 0 | 0 | 1 |
| Guidelines for gateways | Cross domain solutions | Cross domain solution use | 0 | 0 | 1 | 0 | 1 |
| Guidelines for data transfers | Data transfers | Accountability for data transfers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for data transfers | Data transfers | Authorising export of data | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | Operating system hardening | Application control | 0 | 1 | 0 | 0 | 1 |
| Guidelines for system access | Identity and access management | Session termination | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system management | System administration | System administration processes and procedures | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Databases | Protecting database contents | 0 | 0 | 1 | 0 | 1 |
| Guidelines for database systems | Database servers | Network environment | 0 | 0 | 0 | 1 | 1 |
| Guidelines for networking | Network design and configuration | 802.1X authentication and key exchange | 0 | 0 | 1 | 0 | 1 |
| Guidelines for networking | Network design and configuration | Evaluation of 802.1X implementations | 0 | 1 | 0 | 0 | 1 |
| Guidelines for cryptography | Transport Layer Security | Configuring Transport Layer Security | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | Operating system hardening | Operating system releases and versions | 0 | 0 | 1 | 0 | 1 |
| Guidelines for software development | Software development fundamentals | Software interaction with databases | 0 | 0 | 1 | 0 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | Security assessment report | 0 | 0 | 0 | 1 | 1 |
| Guidelines for cyber security documentation | System-specific cyber security documentation | Plan of action and milestones | 0 | 0 | 0 | 1 | 1 |
| Guidelines for personnel security | Cyber security awareness training | Providing cyber security awareness training | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | User application hardening | Web browsers | 0 | 0 | 1 | 0 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Outsourced cloud services | 0 | 0 | 0 | 1 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Managed services | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | Email clients | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system management | System maintenance | Cessation of support | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | Portable Document Format applications | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | Security products | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system access | Identity and access management | Unprivileged access to systems | 0 | 0 | 1 | 0 | 1 |
| Guidelines for communications systems | Multifunction devices | Authenticating to multifunction devices | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system access | Credential management | Protecting credentials | 0 | 0 | 1 | 0 | 1 |
| Guidelines for system hardening | Server application hardening | Microsoft Active Directory Domain Services account hardening | 0 | 0 | 1 | 0 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Assessment of managed service providers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for procurement and outsourcing | Managed services and cloud services | Assessment of outsourced cloud service providers | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system access | Identity and access management | Screen locking | 0 | 1 | 0 | 0 | 1 |
| Guidelines for gateways | Gateways | Assessment of gateways | 0 | 0 | 0 | 1 | 1 |
| Guidelines for system hardening | User application hardening | Artificial intelligence applications | 0 | 1 | 0 | 0 | 1 |
| Guidelines for security assurance | Security assessments | Vulnerability assessments and penetration tests | 0 | 0 | 1 | 0 | 1 |
| Control | Footprint | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-2124 | NC|OS|P|S|TS | Guidelines for procurement and outsourcing › Access to systems by service providers | Access by a service provider to an organisation’s systems is restricted to remote management tools, source network addresses and time windows explicit… |
| ISM-2125 | NC|OS|P|S|TS | Guidelines for procurement and outsourcing › Access to systems by service providers | All access to an organisation’s systems by a service provider is independently logged by the organisation in a manner that the service provider cannot… |
| ISM-2126 | NC|OS|P|S|TS | Guidelines for personnel security › Synthetic impersonation | Personnel positively identify requestors using a pre-established authentication method or independent trusted communication channel before actioning r… |
| ISM-2127 | NC|OS|P|S|TS | Guidelines for system hardening › Hardening operating system configurations | Digital signature verification functionality for drivers is enforced before they are loaded. |
| ISM-2128 | NC|OS|P|S|TS | Guidelines for system hardening › Hardening operating system configurations | The ability to install, load or modify kernel-mode code, including drivers, kernel modules and extensions, is limited to privileged users who require … |
| ISM-2129 | NC|OS|P|S|TS | Guidelines for system hardening › Windows Management Instrumentation | WMI activity, including the creation of permanent event subscriptions, is centrally logged. |
| ISM-2130 | NC|OS|P|S|TS | Guidelines for system hardening › Microsoft Active Directory Certificate Services | Web-based enrolment interfaces for Microsoft AD CS servers are disabled unless required, and where enabled, are configured to require HTTPS and Extend… |
| ISM-2131 | NC|OS|P|S|TS | Guidelines for system hardening › Microsoft Active Directory Certificate Services | Certificate templates are reviewed at least every three months to identify and remediate misconfigurations that could enable privilege escalation or u… |
| ISM-2132 | NC|OS|P|S|TS | Guidelines for system hardening › Microsoft Active Directory Certificate Services | Certificate enrolment events, including successful and unsuccessful requests and changes to certificate templates or Microsoft AD CS configurations, a… |
| ISM-2133 | NC|OS|P|S|TS | Guidelines for system access › Artificial intelligence agent identification | Each AI agent is assigned a unique identity that is distinct from the user accounts of personnel and the identities of other AI agents. |
| ISM-2134 | NC|OS|P|S|TS | Guidelines for system access › Artificial intelligence agent register | An AI agent register is developed, implemented, maintained and regularly verified. |
| ISM-2135 | NC|OS|P|S|TS | Guidelines for system access › Artificial intelligence agent register | An AI agent register contains the following for each AI agent: - its unique identifier - its owner and business purpose - the identities assigned to i… |
| ISM-2136 | NC|OS|P|S|TS | Guidelines for system access › Authenticating to systems | Risk-based access decisions, informed by contextual signals, are enforced for access to systems and their resources. |
| ISM-2137 | NC|OS|P|S|TS | Guidelines for system access › Third-party application access and device code authentication | Human users are prevented from granting consent to third-party OAuth applications, with such consent granted only by an authorised administrator. |
| ISM-2138 | NC|OS|P|S|TS | Guidelines for system access › Third-party application access and device code authentication | OAuth application consents, including their granted permissions, are reviewed at least every six months, with unused applications and excessive permis… |
| ISM-2139 | NC|OS|P|S|TS | Guidelines for system access › Third-party application access and device code authentication | Consent grants, token issuance and token use for third-party OAuth applications are centrally logged. |
| ISM-2140 | NC|OS|P|S|TS | Guidelines for system access › Third-party application access and device code authentication | The OAuth device code authentication flow is disabled unless required, and where required, is restricted to authorised user accounts and managed devic… |
| ISM-2141 | NC|OS|P|S|TS | Guidelines for system access › Application and workload credentials | Applications and workloads use short-lived dynamically issued credentials in preference to long-lived static credentials. |
| ISM-2142 | NC|OS|P|S|TS | Guidelines for system access › Application and workload credentials | Static credentials used by applications and workloads are centrally managed using a credential or secrets management solution. |
| ISM-2143 | NC|OS|P|S|TS | Guidelines for system access › Application and workload credentials | Applications and workloads use unique credentials that are not shared with other applications or workloads, or across development, testing, staging an… |
| ISM-2144 | NC|OS|P|S|TS | Guidelines for system access › Changing credentials | Static credentials used by applications and workloads are changed if: - they are compromised or suspected of being compromised - they are discovered s… |
| ISM-2145 | NC|OS|P|S|TS | Guidelines for system access › Revoking credentials | Credentials for user accounts are revoked when they are no longer required. |
| ISM-2146 | NC|OS|P|S|TS | Guidelines for system access › Revoking credentials | Static credentials used by applications and workloads are revoked when they are no longer required. |
| ISM-2147 | NC|OS|P|S|TS | Guidelines for system access › Protecting authentication artefacts | Authentication tokens, session cookies and refresh tokens are cryptographically bound to the device on which they were issued. |
| ISM-2148 | NC|OS|P|S|TS | Guidelines for system access › Protecting authentication artefacts | Active sessions, refresh tokens and other authentication artefacts are revoked when credentials are reset or re-enrolled, when credentials are comprom… |
| ISM-2149 | NC|OS|P|S|TS | Guidelines for system management › Administrative tools | A list of authorised RMM tools and remote access tools is developed, enforced and maintained. |
| ISM-2150 | NC|OS|P|S|TS | Guidelines for system management › Administrative tools | Network connections for unauthorised RMM tools and remote access tools are blocked at gateways. |
| ISM-2151 | NC|OS|P|S|TS | Guidelines for system management › Backup modification and deletion | Backups are stored using a technically enforced immutability mechanism that prevents their modification or deletion for the duration of their retentio… |
| ISM-2152 | NC|OS|P|S|TS | Guidelines for system management › Backup modification and deletion | Backup infrastructure, including backup servers, repositories and management consoles, is segregated from production environments and uses a separate … |
| ISM-2153 | NC|OS|P|S|TS | Guidelines for security assurance › Threat hunting | Threat hunting activities, informed by current strategic and sector-specific cyber threat intelligence, are conducted at least every three months. |
| ISM-2154 | NC|OS|P|S|TS | Guidelines for software development › Software artefacts | Software artefact dependencies are pinned to approved versions in source code. |
| ISM-2155 | NC|OS|P|S|TS | Guidelines for software development › Build solution | Software is built using reproducible build practices that enable independent verification that release artefacts were produced from the stated source … |
| ISM-2156 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | Agentic AI applications are restricted to the minimum set of tools, functions and permissions required for their intended purpose. |
| ISM-2157 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | Tools invoked by agentic AI applications are subject to both the access controls of the invoking user and agent-specific, task-scoped authorisation, w… |
| ISM-2158 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | External content retrieved by agentic AI applications is treated as untrusted data throughout processing, is clearly delimited from system instruction… |
| ISM-2159 | NC|OS|P|S|TS | Guidelines for software development › Excessive agency | All tool invocations, external requests and outputs generated by agentic AI applications are centrally logged with sufficient detail to support cyber … |
| ISM-2160 | NC|OS|P|S|TS | Guidelines for networking › Networked management interfaces | Networked management interfaces for IT equipment are only accessible from a dedicated management network that is segregated from the wider network and… |
| ISM-2161 | NC|OS|P|S|TS | Guidelines for networking › Network device integrity | The integrity of network device firmware and running configurations is verified against an approved known-good baseline following patching, on detecti… |
| ISM-2162 | NC|OS|P|S|TS | Guidelines for networking › Network device hardening | Unneeded components, services and functionality of network devices are disabled or removed. |
| ISM-2163 | NC|OS|P|S|TS | Guidelines for networking › Media Access Control Security | When using MACsec, confidentiality protection mode is enabled using GCM-AES-128, GCM-AES-256, GCM-AES-XPN-128 or GCM-AES-XPN-256, preferably GCM-AES-2… |
| ISM-2164 | NC|OS|P|S|TS | Guidelines for networking › Media Access Control Security | A connectivity association lifetime of less than 24 hours (86400 seconds) is used for MACsec connections. |
| ISM-2165 | NC|OS|P|S|TS | Guidelines for networking › Media Access Control Security | When using EAP-TLS, each device performs a fresh EAP-TLS authentication each time a new Connectivity Association Key is required. |
| ISM-2166 | NC|OS|P|S|TS | Guidelines for networking › Media Access Control Security | A secure association lifetime of less than four hours (14400 seconds) is used for MACsec connections. |
| ISM-2167 | NC|OS|P|S|TS | Guidelines for networking › Media Access Control Security | The use of a Pre-Shared Key as a fallback authentication method for MACsec is disabled. |
| Control | Edit dist | Location | Statement (excerpt) |
|---|---|---|---|
| ISM-1213 | 0.77 | Guidelines for cyber security incidents › Handling and containing intrusions | Following intrusion remediation activities, enhanced monitoring is conducted until there is sufficient evidence-based confidence that malicious actors… |
| ISM-2012 | 0.61 | Guidelines for system access › Screen locking | Systems are configured with a screen lock that: - activates after a maximum of 15 minutes of human user inactivity, or when manually activated - conce… |
| ISM-1593 | 0.58 | Guidelines for system access › Setting credentials for user accounts | Human users provide sufficient evidence to verify their identity when first requesting credentials, when requesting the reset of any credentials, when… |
| ISM-1732 | 0.58 | Guidelines for cyber security incidents › Handling and containing intrusions | Intrusion remediation activities are coordinated and sequenced to minimise opportunities for re-compromise of a system while balancing operational ris… |
| ISM-0846 | 0.57 | Guidelines for system hardening › Application control | Users cannot disable or bypass application control, and are not exempted from application control, except when using local administrator accounts or b… |
| ISM-0489 | 0.48 | Guidelines for cryptography › SSH-agent | When SSH-agent or similar key caching applications are used, cached private keys have a maximum lifetime of four hours and, where applicable, screen l… |
| ISM-0428 | 0.47 | Guidelines for system access › Session locking | Services are configured with a session lock that: - activates after a maximum of 15 minutes of human user inactivity, a maximum of 12 hours of overall… |
| ISM-1928 | 0.46 | Guidelines for system hardening › Microsoft Active Directory services | Backups of Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted usin… |
| ISM-2113 | 0.41 | Guidelines for system hardening › Artificial intelligence applications | AI applications are configured to require human approval before executing sensitive or high-impact actions. |
| ISM-1594 | 0.40 | Guidelines for system access › Setting credentials for user accounts | Credentials for human users are provided via a secure communications channel or, if not possible, split into two parts with one part provided to the h… |
| ISM-1089 | 0.32 | Guidelines for email › Protective marking tools | When replying to or forwarding emails, protective marking tools do not allow the selection of protective markings lower than previously used. |
| ISM-1323 | 0.28 | Guidelines for networking › Generating and issuing X.509 certificates for authentication | X.509 certificates are required for devices and human users authenticating to networks using 802.1X. |
| ISM-1590 | 0.28 | Guidelines for system access › Changing credentials | Credentials for user accounts are changed if: - they are compromised or suspected of being compromised - they are discovered stored on systems in the … |
| ISM-1322 | 0.28 | Guidelines for networking › Evaluation of 802.1X implementations | Evaluated supplicants, authenticators and authentication servers are used for 802.1X authentication implementations. |
| Control | Edit dist | Location |
|---|---|---|
| ISM-1565 | 0.24 | Guidelines for personnel security › Providing cyber security awareness training |
| ISM-1327 | 0.23 | Guidelines for networking › Generating and issuing X.509 certificates for authentication |
| ISM-1731 | 0.22 | Guidelines for cyber security incidents › Handling and containing intrusions |
| ISM-1321 | 0.18 | Guidelines for networking › 802.1X authentication and key exchange |
| ISM-1372 | 0.17 | Guidelines for cryptography › Configuring Transport Layer Security |
| ISM-1211 | 0.17 | Guidelines for system management › System administration processes and procedures |
| ISM-1408 | 0.16 | Guidelines for system hardening › Operating system releases and versions |
| ISM-1576 | 0.14 | Guidelines for procurement and outsourcing › Access to systems by service providers |
| ISM-1536 | 0.12 | Guidelines for software development › Software interaction with databases |
| ISM-1401 | 0.11 | Guidelines for system access › Multi-factor authentication |
| ISM-1508 | 0.10 | Guidelines for system access › Privileged access to systems |
| ISM-1852 | 0.10 | Guidelines for system access › Unprivileged access to systems |
| ISM-2030 | 0.09 | Guidelines for software development › Software artefacts |
| ISM-0853 | 0.09 | Guidelines for system access › Session termination |
| ISM-2047 | 0.09 | Guidelines for software development › Secure software development |
| ISM-1883 | 0.08 | Guidelines for system access › Privileged access to systems |
| ISM-1255 | 0.07 | Guidelines for database systems › Protecting database contents |
| ISM-1688 | 0.07 | Guidelines for system management › Separate privileged operating environments |
| ISM-1934 | 0.07 | Guidelines for system hardening › Microsoft Active Directory Domain Services account hardening |
| ISM-0415 | 0.07 | Guidelines for system access › User identification |
| ISM-1958 | 0.06 | Guidelines for system management › Separate privileged operating environments |
| ISM-2118 | 0.06 | Guidelines for security assurance › Vulnerability assessments and penetration tests |
| ISM-2011 | 0.06 | Guidelines for system access › Multi-factor authentication |
| ISM-0610 | 0.06 | Guidelines for gateways › Cross domain solution use |
| ISM-1875 | 0.05 | Guidelines for system access › Protecting credentials |
| ISM-2038 | 0.05 | Guidelines for software development › Secure software development |
| ISM-1635 | 0.05 | Guidelines for cyber security roles › Protecting systems and their resources |
| ISM-0441 | 0.05 | Guidelines for system access › Temporary access to systems |
| ISM-1854 | 0.05 | Guidelines for communications systems › Authenticating to multifunction devices |
| ISM-1595 | 0.05 | Guidelines for system access › Setting credentials for user accounts |
| ISM-0272 | 0.05 | Guidelines for email › Protective marking tools |
| ISM-0414 | 0.05 | Guidelines for system access › User identification |
| ISM-1585 | 0.05 | Guidelines for system hardening › Web browsers |
| From chapter | To chapter | Controls |
|---|---|---|
| Guidelines for personnel security | Guidelines for system access | ISM-0078 ISM-0405 ISM-0407 ISM-0409 ISM-0411 ISM-0414 ISM-0415 ISM-0420 ISM-0430 ISM-0432 ISM-0434 ISM-0435 ISM-0441 ISM-0443 ISM-0445 ISM-0446 ISM-0447 ISM-0854 ISM-1175 ISM-1263 ISM-1404 ISM-1507 ISM-1508 ISM-1509 ISM-1566 ISM-1583 ISM-1591 ISM-1610 ISM-1611 ISM-1612 ISM-1613 ISM-1614 ISM-1615 ISM-1647 ISM-1648 ISM-1649 ISM-1650 ISM-1852 ISM-1864 ISM-1865 ISM-1883 |
| Guidelines for system hardening | Guidelines for system access | ISM-0408 ISM-0417 ISM-0418 ISM-0421 ISM-0422 ISM-0428 ISM-0853 ISM-0974 ISM-1055 ISM-1173 ISM-1227 ISM-1401 ISM-1402 ISM-1403 ISM-1504 ISM-1505 ISM-1546 ISM-1557 ISM-1558 ISM-1559 ISM-1560 ISM-1561 ISM-1590 ISM-1593 ISM-1594 ISM-1595 ISM-1596 ISM-1597 ISM-1603 ISM-1619 ISM-1679 ISM-1680 ISM-1681 ISM-1682 ISM-1683 ISM-1685 ISM-1686 ISM-1749 ISM-1795 ISM-1847 ISM-1861 ISM-1872 ISM-1873 ISM-1874 ISM-1875 ISM-1892 ISM-1893 ISM-1894 ISM-1895 ISM-1897 ISM-1919 ISM-1920 ISM-1953 ISM-1954 ISM-1955 ISM-1956 ISM-1957 ISM-1980 ISM-2011 ISM-2012 ISM-2076 ISM-2077 ISM-2078 ISM-2079 ISM-2080 ISM-2081 |
| Control | Footprint | Former location | Statement (excerpt) |
|---|---|---|---|
| ISM-0521 | NC|OS|P|S|TS | Guidelines for networking | IPv6 functionality is disabled in dual-stack network devices unless it is being used. |
| ISM-1448 | NC|OS|P|S|TS | Guidelines for cryptography | When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used. |
revision/updated stamp to move (2 prose-only re-renders excluded as format noise). Relocation compares case/spelling-normalised chapter›section›topic paths. Nature = normalised edit distance (editorial <0.05, clarification <0.25, substantive ≥0.25 — uncalibrated). Footprints normalised across schemes (O→OS, ALL→NC|OS|P|S|TS); pre-Dec-2024 NC imputed.