Australian Information Security Manual
ACSC Information Security Manual. Australian Government cybersecurity controls baseline.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit cyber.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Guidelines for communications infrastructure
| Code | Title |
|---|---|
| ISM-0181 | Cabling infrastructure is installed in accordance with relevant Australian Standards, as d |
| ISM-0187 | SECRET cables, when bundled together or run in conduit, are run exclusively in their own i |
| ISM-0194 | In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit |
| ISM-0195 | In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to |
| ISM-0198 | When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Orga |
| ISM-0201 | Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre |
| ISM-0206 | Cable labelling processes, and supporting cable labelling procedures, are developed, imple |
| ISM-0208 | A cable register contains the following for each cable: - cable identifier - cable colour |
| ISM-0211 | A cable register is developed, implemented, maintained and verified on a regular basis. |
| ISM-0213 | SECRET and TOP SECRET cables are terminated on their own individual patch panels. |
| ISM-0216 | TOP SECRET patch panels are installed in individual TOP SECRET cabinets. |
| ISM-0217 | Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabi |
| ISM-0218 | If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wa |
| ISM-0246 | When an emanation security risk assessment is required, it is sought as early as possible |
| ISM-0249 | System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployab |
| ISM-0250 | IT equipment meets industry and government standards relating to electromagnetic interfere |
| ISM-0926 | Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink |
| ISM-1095 | Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier. |
| ISM-1096 | Cables are labelled at each end with sufficient source and destination details to enable t |
| ISM-1098 | SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet wit |
| ISM-1100 | TOP SECRET cables are terminated in an individual TOP SECRET cabinet. |
| ISM-1101 | In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or c |
| ISM-1102 | Cable reticulation systems leading into cabinets are terminated as close as possible to th |
| ISM-1103 | In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms |
| ISM-1105 | SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables. |
| ISM-1107 | Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither s |
| ISM-1109 | Wall outlet box covers are clear plastic. |
| ISM-1111 | Fibre-optic cables are used for cabling infrastructure instead of copper cables. |
| ISM-1112 | Cables in non-TOP SECRET areas are inspectable every five metres or less. |
| ISM-1114 | Cable bundles or conduits sharing a common cable reticulation system have a dividing parti |
| ISM-1115 | Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit. |
| ISM-1116 | A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets. |
| ISM-1119 | Cables in TOP SECRET areas are fully inspectable for their entire length. |
| ISM-1122 | Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET ca |
| ISM-1123 | A power distribution board with a feed from an Uninterruptible Power Supply is used to pow |
| ISM-1130 | In shared facilities, cables are run in an enclosed cable reticulation system. |
| ISM-1133 | In shared facilities, TOP SECRET cables are not run in party walls. |
| ISM-1137 | System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD f |
| ISM-1164 | In shared facilities, conduits or the front covers of ducts, cable trays in floors and cei |
| ISM-1216 | SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appro |
| ISM-1639 | Building management cables are labelled with their purpose in black writing on a yellow ba |
| ISM-1640 | Cables for foreign systems installed in Australian facilities are labelled at inspection p |
| ISM-1645 | Floor plan diagrams are developed, implemented, maintained and verified on a regular basis |
| ISM-1646 | Floor plan diagrams contain the following: - cable paths (including ingress and egress poi |
| ISM-1718 | SECRET cables are coloured salmon pink. |
| ISM-1719 | TOP SECRET cables are coloured red. |
| ISM-1720 | SECRET wall outlet boxes are coloured salmon pink. |
| ISM-1721 | TOP SECRET wall outlet boxes are coloured red. |
| ISM-1820 | Cables for individual systems use a consistent colour. |
| ISM-1821 | TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their o |
| ISM-1822 | Wall outlet boxes for individual systems use a consistent colour. |
| ISM-1884 | Emanation security doctrine produced by ASD for the management of emanation security matte |
| ISM-1885 | Recommended actions contained within emanation security mitigation advice issued for syste |
Guidelines for communications systems
| Code | Title |
|---|---|
| ISM-0229 | Personnel are advised of the permitted sensitivity or classification of information that c |
| ISM-0230 | Personnel are advised of security risks posed by non-secure telephone systems in areas whe |
| ISM-0231 | When using cryptographic equipment to permit different levels of conversation for differen |
| ISM-0232 | Telephone systems used for sensitive or classified conversations encrypt all traffic that |
| ISM-0233 | Cordless telephone handsets and headsets are not used for sensitive or classified conversa |
| ISM-0235 | Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone s |
| ISM-0236 | Off-hook audio protection features are used on telephone systems in areas where background |
| ISM-0245 | MFDs are not connected to digital telephone systems. |
| ISM-0546 | When video conferencing or IP telephony traffic passes through a gateway containing a fire |
| ISM-0547 | Video conferencing and IP telephony calls are conducted using a secure real-time transport |
| ISM-0548 | Video conferencing and IP telephony calls are established using a secure session initiatio |
| ISM-0549 | Video conferencing and IP telephony traffic is separated physically or logically from othe |
| ISM-0551 | IP telephony is configured such that: - IP phones authenticate themselves to the call cont |
| ISM-0553 | Authentication and authorisation is used for all actions on a video conferencing network, |
| ISM-0554 | An encrypted and non-replayable two-way authentication scheme is used for call authenticat |
| ISM-0555 | Authentication and authorisation is used for all actions on an IP telephony network, inclu |
| ISM-0556 | Workstations are not connected to video conferencing units or IP phones unless the worksta |
| ISM-0558 | IP phones used in public areas do not have the ability to access data networks, voicemail |
| ISM-0559 | Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET |
| ISM-0588 | An MFD usage policy is developed, implemented and maintained. |
| ISM-0589 | MFDs are not used to scan or copy documents above the sensitivity or classification of net |
| ISM-0590 | Authentication measures for MFDs are the same strength as those used for workstations on n |
| ISM-0931 | In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to |
| ISM-1014 | Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversation |
| ISM-1019 | A denial of service response plan for video conferencing and IP telephony services is deve |
| ISM-1036 | MFDs are located in areas where their use can be observed. |
| ISM-1078 | A telephone system usage policy is developed, implemented and maintained. |
| ISM-1450 | Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SE |
| ISM-1562 | Video conferencing and IP telephony infrastructure is hardened. |
| ISM-1805 | A denial of service response plan for video conferencing and IP telephony services contain |
| ISM-1854 | Users authenticate to MFDs before they can print, scan or copy documents. |
| ISM-1855 | Use of MFDs for printing, scanning and copying purposes, including the capture of shadow c |
| ISM-2075 | Fax machines, and online fax services, are not used for sending or receiving fax messages. |
Guidelines for cryptography
| Code | Title |
|---|---|
| ISM-0142 | The compromise or suspected compromise of cryptographic equipment or associated keying mat |
| ISM-0455 | Where practical, cryptographic equipment, applications and libraries provide a means of da |
| ISM-0457 | Cryptographic equipment, applications or libraries that have completed a Common Criteria e |
| ISM-0459 | Full disk encryption, or partial encryption where access controls will only allow writing |
| ISM-0460 | HACE is used when encrypting media that contains SECRET or TOP SECRET data. |
| ISM-0462 | When a user authenticates to the encryption functionality of IT equipment or media, it is |
| ISM-0465 | Cryptographic equipment, applications or libraries that have completed a Common Criteria e |
| ISM-0467 | HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently s |
| ISM-0469 | An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is |
| ISM-0471 | Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, |
| ISM-0472 | When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is |
| ISM-0474 | When using ECDH for agreeing on encryption session keys, a base point order and key size o |
| ISM-0475 | When using ECDSA for digital signatures, a base point order and key size of at least 224 b |
| ISM-0476 | When using RSA for digital signatures, and transporting encryption session keys (and simil |
| ISM-0477 | When using RSA for digital signatures, and for transporting encryption session keys (and s |
| ISM-0479 | Symmetric cryptographic algorithms are not used in Electronic Codebook Mode. |
| ISM-0481 | Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, |
| ISM-0484 | The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress x |
| ISM-0485 | Public key-based authentication is used for SSH connections. |
| ISM-0487 | When using logins without a password for SSH connections, the following are disabled: - ac |
| ISM-0488 | If using remote access without the use of a password for SSH connections, the 'forced comm |
| ISM-0489 | When SSH-agent or similar key caching applications are used, it is limited to workstations |
| ISM-0490 | Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections. |
| ISM-0494 | Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel |
| ISM-0496 | The ESP protocol is used for authentication and encryption of IPsec connections. |
| ISM-0498 | A security association lifetime of less than four hours (14400 seconds) is used for IPsec |
| ISM-0499 | Communications security doctrine and policy produced by ASD for the management and operati |
| ISM-0501 | Keyed cryptographic equipment is transported based on the sensitivity or classification of |
| ISM-0507 | Cryptographic key management processes, and supporting cryptographic key management proced |
| ISM-0994 | ECDH is used in preference to DH. |
| ISM-0998 | AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with |
| ISM-0999 | DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random E |
| ISM-1000 | PFS is used for IPsec connections. |
| ISM-1080 | An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm i |
| ISM-1091 | Keying material is changed when compromised or suspected of being compromised. |
| ISM-1139 | Only the latest version of TLS is used for TLS connections. |
| ISM-1233 | IKE version 2 is used for key exchange when establishing IPsec connections. |
| ISM-1369 | AES-GCM is used for encryption of TLS connections. |
| ISM-1370 | Only server-initiated secure renegotiation is used for TLS connections. |
| ISM-1372 | DH or ECDH is used for key establishment of TLS connections. |
| ISM-1373 | Anonymous DH is not used for TLS connections. |
| ISM-1374 | SHA-2-based certificates are used for TLS connections. |
| ISM-1375 | SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom funct |
| ISM-1446 | When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used. |
| ISM-1448 | When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is u |
| ISM-1449 | SSH private keys are protected with a password or a key encryption key. |
| ISM-1453 | Perfect Forward Secrecy (PFS) is used for TLS connections. |
| ISM-1506 | The use of SSH version 1 is disabled for SSH connections. |
| ISM-1553 | TLS compression is disabled for TLS connections. |
| ISM-1629 | When using DH for agreeing on encryption session keys, a modulus and associated parameters |
| ISM-1759 | When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is |
| ISM-1761 | When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves |
| ISM-1762 | When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are us |
| ISM-1763 | When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, prefe |
| ISM-1764 | When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably t |
| ISM-1765 | When using RSA for digital signatures, and transporting encryption session keys (and simil |
| ISM-1766 | When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA- |
| ISM-1767 | When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA- |
| ISM-1768 | When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA- |
| ISM-1769 | When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256. |
| ISM-1770 | When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256. |
| ISM-1771 | AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16. |
| ISM-1772 | PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, p |
| ISM-1802 | HACE are issued an Approval for Use by ASD and operated in accordance with the latest vers |
| ISM-1917 | The development and procurement of new cryptographic equipment, applications and libraries |
| ISM-1990 | When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre- |
| ISM-1991 | When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DS |
| ISM-1992 | When using ML-DSA for digital signatures, the hedged variant is used whenever possible. |
| ISM-1993 | Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of defau |
| ISM-1994 | When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA |
| ISM-1995 | When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 |
| ISM-1996 | When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptograph |
| ISM-2073 | A post-quantum cryptography transition plan is developed, implemented and maintained. |
Guidelines for cyber security documentation
| Code | Title |
|---|---|
| ISM-0039 | A cyber security strategy is developed, implemented and maintained. |
| ISM-0041 | Systems have a system security plan that includes an overview of the system (covering the |
| ISM-0043 | Systems have a cyber security incident response plan that covers the following: - guidelin |
| ISM-0047 | Organisational-level cyber security documentation is approved by the chief information sec |
| ISM-0888 | Cyber security documentation is reviewed at least annually and includes a 'current as at \ |
| ISM-0912 | Systems have a change and configuration management plan that includes: - the establishment |
| ISM-1163 | Systems have a continuous monitoring plan that includes: - conducting vulnerability scans |
| ISM-1563 | At the conclusion of a security assessment for a system, a security assessment report is p |
| ISM-1564 | At the conclusion of a security assessment for a system, a plan of action and milestones i |
| ISM-1602 | Cyber security documentation, including notification of subsequent changes, is communicate |
| ISM-1739 | A system's security architecture is approved prior to the development of the system. |
Guidelines for cyber security incidents
| Code | Title |
|---|---|
| ISM-0120 | Cyber security personnel have access to sufficient data sources and tools to ensure that s |
| ISM-0123 | Cyber security incidents are reported to the chief information security officer, or one of |
| ISM-0125 | A cyber security incident register is developed, implemented and maintained. |
| ISM-0133 | When a data spill occurs, data owners are advised and access to the data is restricted. |
| ISM-0137 | Legal advice is sought before allowing intrusion activity to continue on a system for the |
| ISM-0138 | The integrity of evidence gathered during an investigation is maintained by investigators: |
| ISM-0140 | Cyber security incidents are reported to ASD as soon as possible after they occur or are d |
| ISM-0576 | A cyber security incident management policy, and associated cyber security incident respon |
| ISM-0917 | When malicious code is detected, the following steps are taken to handle the infection: - |
| ISM-1213 | Following intrusion remediation activities, full network traffic is captured for at least |
| ISM-1609 | System owners are consulted before allowing intrusion activity to continue on a system for |
| ISM-1625 | An insider threat mitigation program is developed, implemented and maintained. |
| ISM-1626 | Legal advice is sought regarding the development and implementation of an insider threat m |
| ISM-1731 | Planning and coordination of intrusion remediation activities are conducted on a separate |
| ISM-1732 | To the extent possible, all intrusion remediation activities are conducted in a coordinate |
| ISM-1784 | The cyber security incident management policy, including the associated cyber security inc |
| ISM-1803 | A cyber security incident register contains the following for each cyber security incident |
| ISM-1819 | Following the identification of a cyber security incident, the cyber security incident res |
| ISM-1880 | Cyber security incidents that involve customer data are reported to customers and the publ |
| ISM-1881 | Cyber security incidents that do not involve customer data are reported to customers and t |
| ISM-1969 | Malicious code, when stored or communicated, is treated beforehand to prevent accidental e |
| ISM-1970 | Malicious code processed for cyber security incident response or research purposes is done |
Guidelines for cyber security roles
| Code | Title |
|---|---|
| ISM-0009 | System owners, in consultation with each system's authorising officer, identify any supple |
| ISM-0027 | System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensit |
| ISM-0714 | A CISO is appointed to provide cyber security leadership and guidance for their organisati |
| ISM-0717 | The CISO oversees the management of cyber security personnel within their organisation. |
| ISM-0718 | The CISO regularly reports directly to their organisation's board of directors or executiv |
| ISM-0720 | The CISO oversees the development, implementation and maintenance of a cyber security comm |
| ISM-0724 | The CISO implements cyber security measurement metrics and key performance indicators for |
| ISM-0725 | The CISO coordinates cyber security and business alignment through a cyber security steeri |
| ISM-0726 | The CISO coordinates security risk management activities between cyber security and busine |
| ISM-0731 | The CISO oversees cyber supply chain risk management activities for their organisation. |
| ISM-0732 | The CISO receives and manages a dedicated cyber security budget for their organisation. |
| ISM-0733 | The CISO is fully aware of all cyber security incidents within their organisation. |
| ISM-0734 | The CISO contributes to the development, implementation and maintenance of business contin |
| ISM-0735 | The CISO oversees the development, implementation and maintenance of their organisation's |
| ISM-1071 | Each system has a designated system owner. |
| ISM-1203 | System owners, in consultation with each system's authorising officer, conduct a threat an |
| ISM-1478 | The CISO oversees their organisation's cyber security program and ensures their organisati |
| ISM-1525 | System owners register each system with its authorising officer. |
| ISM-1526 | System owners continuously monitor the security of each system, and manage associated cybe |
| ISM-1587 | System owners report the security status of each system to its authorising officer at leas |
| ISM-1617 | The CISO regularly reviews and updates their organisation's cyber security program to ensu |
| ISM-1618 | The CISO oversees their organisation's response to cyber security incidents. |
| ISM-1633 | System owners, in consultation with each system's authorising officer, determine the syste |
| ISM-1634 | System owners, in consultation with each system's authorising officer, select controls for |
| ISM-1635 | System owners implement controls for each system and its operating environment. |
| ISM-1636 | System owners, in consultation with each system's authorising officer, ensure controls for |
| ISM-1918 | The CISO regularly reports directly to their organisation's audit, risk and compliance com |
| ISM-1966 | The CISO develops, implements, maintains and verifies on a regular basis a register of sys |
| ISM-1967 | System owners, in consultation with each system's authorising officer, ensure controls for |
| ISM-1968 | System owners obtain an authorisation to operate for each TOP SECRET system, including for |
| ISM-1997 | The board of directors or executive committee defines clear roles and responsibilities for |
| ISM-1998 | The board of directors or executive committee ensures that cyber security is integrated th |
| ISM-1999 | The board of directors or executive committee ensures the cyber security strategy for thei |
| ISM-2000 | The board of directors or executive committee seeks regular briefings or reporting on the |
| ISM-2001 | The board of directors or executive committee champions a positive cyber security culture |
| ISM-2002 | The board of directors or executive committee maintains a sufficient level of cyber securi |
| ISM-2003 | The board of directors or executive committee maintains awareness of key cyber security re |
| ISM-2004 | The board of directors or executive committee supports the development of cyber security s |
| ISM-2005 | The board of directors or executive committee understands the business criticality of thei |
| ISM-2006 | The board of directors or executive committee plans for major cyber security incidents, in |
| ISM-2020 | The CISO ensures sufficient cyber security personnel, with the right skills and experience |
| ISM-2021 | System owners implement and maintain data minimisation practices for each of their systems |
Guidelines for data transfers
| Code | Title |
|---|---|
| ISM-0657 | When manually importing data to systems, the data is scanned for malicious and active cont |
| ISM-0660 | Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly. |
| ISM-0661 | Users transferring data to and from systems are held accountable for data transfers they p |
| ISM-0663 | Data transfer processes, and supporting data transfer procedures, are developed, implement |
| ISM-0664 | Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustwort |
| ISM-0665 | Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services t |
| ISM-0669 | When manually exporting data from SECRET and TOP SECRET systems, digital signatures are va |
| ISM-0675 | Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a tru |
| ISM-1187 | When manually exporting data from systems, the data is checked for unsuitable protective m |
| ISM-1294 | Data transfer logs for systems are partially verified at least monthly. |
| ISM-1535 | Processes, and supporting procedures, are developed, implemented and maintained to prevent |
| ISM-1586 | Data transfer logs are used to record all data imports and exports from systems. |
| ISM-1778 | When manually importing data to systems, all data that fails security checks is quarantine |
| ISM-1779 | When manually exporting data from systems, all data that fails security checks is quaranti |
Guidelines for database systems
| Code | Title |
|---|---|
| ISM-0393 | Databases and their contents are classified based on the sensitivity or classification of |
| ISM-1243 | A database register is developed, implemented, maintained and verified on a regular basis. |
| ISM-1255 | Database users' ability to access, insert, modify and remove database contents is restrict |
| ISM-1256 | File-based access controls are applied to database files. |
| ISM-1268 | The need-to-know principle is enforced for database contents through the application of mi |
| ISM-1269 | Database servers and web servers are functionally separated. |
| ISM-1270 | Database servers are placed on a different network segment to user workstations. |
| ISM-1271 | Network access controls are implemented to restrict database server communications to stri |
| ISM-1272 | If only local access to a database is required, networking functionality of database manag |
| ISM-1273 | Database servers for development, testing, staging and production environments are segrega |
| ISM-1274 | Database contents from production environments are not used in non-production environments |
| ISM-1277 | Data communicated between database servers and web servers is encrypted. |
| ISM-1537 | Security-relevant events for databases are centrally logged, including: - access or modifi |
Guidelines for email
| Code | Title |
|---|---|
| ISM-0264 | An email usage policy is developed, implemented and maintained. |
| ISM-0267 | Access to non-approved webmail services is blocked. |
| ISM-0269 | Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To |
| ISM-0270 | Protective markings are applied to emails and reflect the highest sensitivity or classific |
| ISM-0271 | Protective marking tools do not automatically insert protective markings into emails. |
| ISM-0272 | Protective marking tools do not allow users to select protective markings that a system ha |
| ISM-0565 | Email servers are configured to block, log and report emails with inappropriate protective |
| ISM-0567 | Email servers only relay emails destined for or originating from their domains (including |
| ISM-0569 | Emails are routed via centralised email gateways. |
| ISM-0570 | Where backup or alternative email gateways are in place, they are maintained at the same s |
| ISM-0571 | When users send or receive emails, an authenticated and encrypted channel is used to route |
| ISM-0572 | Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing em |
| ISM-0574 | SPF is used to specify authorised email servers (or lack thereof) for an organisation's do |
| ISM-0861 | DKIM signing is enabled on emails originating from an organisation's domains (including su |
| ISM-1023 | The intended recipients of blocked inbound emails, and the senders of blocked outbound ema |
| ISM-1024 | Notifications of undeliverable emails are only sent to senders that can be verified via SP |
| ISM-1026 | DKIM signatures on incoming emails are verified. |
| ISM-1027 | Email distribution list applications used by external senders is configured such that it d |
| ISM-1089 | Protective marking tools do not allow users replying to or forwarding emails to select pro |
| ISM-1151 | SPF is used to verify the authenticity of incoming emails. |
| ISM-1183 | A hard fail SPF record is used when specifying authorised email servers (or lack thereof) |
| ISM-1234 | Email content filtering is implemented to filter potentially harmful content in email bodi |
| ISM-1502 | Emails arriving via an external connection where the email source address uses an internal |
| ISM-1540 | DMARC records are configured for an organisation's domains (including subdomains) such tha |
| ISM-1589 | MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers. |
| ISM-1799 | Incoming emails are rejected if they do not pass DMARC checks. |
Guidelines for enterprise mobility
| Code | Title |
|---|---|
| ISM-0240 | Paging, Multimedia Message Service, Short Message Service and messaging apps are not used |
| ISM-0682 | Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices. |
| ISM-0687 | Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that |
| ISM-0694 | Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET s |
| ISM-0701 | Mobile device emergency sanitisation processes, and supporting mobile device emergency san |
| ISM-0702 | If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SE |
| ISM-0705 | When accessing an organisation's network via a VPN connection, split tunnelling is disable |
| ISM-0863 | Mobile devices prevent personnel from installing non-approved applications once provisione |
| ISM-0864 | Mobile devices prevent personnel from disabling or modifying security functionality once p |
| ISM-0866 | Sensitive or classified data is not viewed on mobile devices in public locations unless ca |
| ISM-0869 | Mobile devices encrypt their internal storage and any removable media. |
| ISM-0870 | Mobile devices are carried or stored in a secured state when not being actively used. |
| ISM-0871 | Mobile devices are kept under continual direct supervision when being actively used. |
| ISM-0874 | Mobile devices and desktop computers access the internet via an organisation's internet ga |
| ISM-1082 | A mobile device usage policy is developed, implemented and maintained. |
| ISM-1083 | Personnel are advised of the sensitivity or classification permitted for voice and data co |
| ISM-1084 | If unable to carry or store mobile devices in a secured state, they are physically transfe |
| ISM-1085 | Mobile devices encrypt all sensitive or classified data communicated over public network i |
| ISM-1088 | Personnel report the potential compromise of mobile devices, removable media or credential |
| ISM-1145 | Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices. |
| ISM-1195 | Mobile Device Management solutions that have completed a Common Criteria evaluation agains |
| ISM-1196 | Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain |
| ISM-1198 | Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is |
| ISM-1199 | Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices ar |
| ISM-1200 | Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is |
| ISM-1297 | Legal advice is sought prior to allowing privately-owned mobile devices and desktop comput |
| ISM-1298 | Personnel are advised of privacy and security risks when travelling overseas with mobile d |
| ISM-1299 | Personnel are advised to take the following precautions when using mobile devices: - never |
| ISM-1300 | Upon returning from travelling overseas with mobile devices, personnel take the following |
| ISM-1366 | Security updates are applied to mobile devices as soon as they become available. |
| ISM-1400 | Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se |
| ISM-1482 | Personnel using organisation-owned mobile devices or desktop computers to access classifie |
| ISM-1533 | A mobile device management policy is developed, implemented and maintained. |
| ISM-1554 | If travelling overseas with mobile devices to high or extreme risk countries, personnel ar |
| ISM-1555 | Before travelling overseas with mobile devices, personnel take the following actions: - re |
| ISM-1556 | If returning from travelling overseas with mobile devices to high or extreme risk countrie |
| ISM-1644 | Sensitive or classified phone calls and conversations are not conducted in public location |
| ISM-1866 | Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se |
| ISM-1867 | Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile pla |
| ISM-1868 | SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand |
| ISM-1886 | Mobile devices are configured to operate in a supervised (or equivalent) mode. |
| ISM-1887 | Mobile devices are configured with remote locate and wipe functionality. |
| ISM-1888 | Mobile devices are configured with secure password-based lock screens. |
| ISM-2095 | Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se |
| ISM-2096 | Mobile devices are configured to enforce separation between organisational and personal mo |
| ISM-2097 | Mobile devices are configured with always on VPN functionality. |
| ISM-2098 | Mobile devices are configured to prevent data transfers over Universal Serial Bus connecti |
| ISM-2099 | Mobile devices are not connected to the infotainment systems of connected vehicles. |
| ISM-2100 | Sensitive or classified data is not viewed on mobile devices within or near connected vehi |
| ISM-2101 | Sensitive or classified phone calls and conversations are not conducted within or near con |
Guidelines for evaluated products
| Code | Title |
|---|---|
| ISM-0280 | If procuring an evaluated product, a product that has completed a PP-based evaluation, inc |
| ISM-0285 | Evaluated products are delivered in a manner consistent with any delivery procedures defin |
| ISM-0286 | When procuring high assurance information technology (IT) equipment, ASD is contacted for |
| ISM-0289 | Evaluated products are installed, configured, administered and operated in an evaluated co |
| ISM-0290 | High assurance IT equipment is installed, configured, administered and operated in an eval |
Guidelines for gateways
| Code | Title |
|---|---|
| ISM-0100 | Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessm |
| ISM-0260 | All web access, including that by internal servers, is conducted through web proxies. |
| ISM-0261 | The following details are centrally logged for websites accessed via web proxies: - web ad |
| ISM-0263 | TLS traffic communicated through gateways is decrypted and inspected. |
| ISM-0591 | Evaluated peripheral switches are used when sharing peripherals between systems. |
| ISM-0597 | When planning, designing, implementing or introducing additional connectivity to CDSs, ASD |
| ISM-0610 | Users are trained on the secure use of CDSs before access is granted. |
| ISM-0611 | System administrators for gateways are assigned the minimum privileges required to perform |
| ISM-0612 | System administrators for gateways are formally trained on the operation and management of |
| ISM-0613 | System administrators for gateways that connect to Australian Eyes Only or Releasable To n |
| ISM-0616 | Separation of duties is implemented in performing administrative activities for gateways. |
| ISM-0619 | Users authenticate to other networks accessed via gateways. |
| ISM-0622 | IT equipment authenticates to other networks accessed via gateways. |
| ISM-0626 | CDSs are implemented between SECRET or TOP SECRET networks and any other networks belongin |
| ISM-0628 | Gateways are implemented between networks belonging to different security domains. |
| ISM-0629 | For gateways between networks belonging to different security domains, any shared componen |
| ISM-0631 | Gateways only allow explicitly authorised data flows. |
| ISM-0634 | Security-relevant events for gateways are centrally logged, including: - data packets and |
| ISM-0635 | CDSs implement isolated upward and downward network paths. |
| ISM-0637 | Gateways implement a demilitarised zone if external parties require access to an organisat |
| ISM-0639 | Evaluated firewalls are used between networks belonging to different security domains. |
| ISM-0643 | Evaluated diodes are used for controlling the data flow of unidirectional gateways between |
| ISM-0645 | Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC |
| ISM-0649 | Files imported or exported via gateways or CDSs are filtered for allowed file types. |
| ISM-0651 | Files identified by content filtering checks as malicious, or that cannot be inspected, ar |
| ISM-0652 | Files identified by content filtering checks as suspicious are quarantined until reviewed |
| ISM-0659 | Files imported or exported via gateways or CDSs undergo content filtering checks. |
| ISM-0670 | Security-relevant events for CDSs are centrally logged. |
| ISM-0677 | Files imported or exported via gateways or CDSs that have a digital signature or cryptogra |
| ISM-0958 | An organisation-approved list of domain names, or list of website categories, is implement |
| ISM-0961 | Client-side active content is restricted by web content filters to an organisation-approve |
| ISM-0963 | Web content filtering is implemented to filter potentially harmful web-based content. |
| ISM-1037 | Gateways undergo testing following configuration changes, and at regular intervals no more |
| ISM-1157 | Evaluated diodes are used for controlling the data flow of unidirectional gateways between |
| ISM-1158 | Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC |
| ISM-1171 | Attempts to access websites through their IP addresses instead of their domain names are b |
| ISM-1192 | Gateways inspect and filter data flows at the transport and above network layers. |
| ISM-1236 | Malicious domain names, dynamic domain names and domain names that can be registered anony |
| ISM-1237 | Web content filtering is applied to outbound web traffic where appropriate. |
| ISM-1284 | Files imported or exported via gateways or CDSs undergo content validation. |
| ISM-1286 | Files imported or exported via gateways or CDSs undergo content conversion. |
| ISM-1287 | Files imported or exported via gateways or CDSs undergo content sanitisation. |
| ISM-1288 | Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple |
| ISM-1289 | Archive files imported or exported via gateways or CDSs are unpacked in order to undergo c |
| ISM-1290 | Archive files are unpacked in a controlled manner to ensure content filter performance or |
| ISM-1293 | Encrypted files imported or exported via gateways or CDSs are decrypted in order to underg |
| ISM-1389 | Executable files imported via gateways or CDSs are automatically executed in a sandbox to |
| ISM-1427 | Gateways perform ingress traffic filtering to detect and prevent IP source address spoofin |
| ISM-1457 | Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET s |
| ISM-1480 | Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET sy |
| ISM-1520 | System administrators for gateways undergo appropriate employment screening, and where nec |
| ISM-1521 | CDSs implement protocol breaks at each network layer. |
| ISM-1522 | CDSs implement independent security-enforcing functions for upward and downward network pa |
| ISM-1523 | A sample of security-relevant events relating to data transfer policies are taken at least |
| ISM-1524 | Content filters used by CDSs undergo rigorous security testing to ensure they perform as e |
| ISM-1528 | Evaluated firewalls are used between an organisation's networks and public network infrast |
| ISM-1773 | System administrators for gateways that connect to Australian Government Access Only netwo |
| ISM-1774 | Gateways are managed via a secure path isolated from all connected networks. |
| ISM-1783 | Public IP addresses controlled by, or used by, an organisation are signed by valid ROA rec |
| ISM-1862 | If using a WAF, disclosing the IP addresses of web servers under an organisation's control |
| ISM-1965 | Files imported or exported via gateways or CDSs undergo content checking. |
| ISM-2018 | Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous System |
| ISM-2019 | TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), u |
Guidelines for information technology equipment
| Code | Title |
|---|---|
| ISM-0293 | IT equipment is classified based on the highest sensitivity or classification of data that |
| ISM-0294 | IT equipment, with the exception of high assurance IT equipment, is labelled with protecti |
| ISM-0296 | ASD's approval is sought before applying labels to external surfaces of high assurance IT |
| ISM-0305 | Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared |
| ISM-0306 | If an appropriately cleared technician is not used to undertake maintenance or repairs of |
| ISM-0307 | If an appropriately cleared technician is not used to undertake maintenance or repairs of |
| ISM-0310 | IT equipment maintained or repaired off site is done so at facilities approved for handlin |
| ISM-0311 | IT equipment containing media is sanitised by removing the media from the IT equipment or |
| ISM-0312 | IT equipment, including associated media, that is located overseas and has processed, stor |
| ISM-0313 | IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, |
| ISM-0315 | High assurance IT equipment is destroyed prior to its disposal. |
| ISM-0316 | Following sanitisation, destruction or declassification, a formal administrative decision |
| ISM-0317 | At least three pages of random text with no blank areas are printed on each colour printer |
| ISM-0318 | When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per e |
| ISM-0321 | When disposing of IT equipment that has been designed or modified to meet emanation securi |
| ISM-0336 | A networked IT equipment register is developed, implemented, maintained and verified on a |
| ISM-1076 | Televisions and computer monitors with minor burn-in or image persistence are sanitised by |
| ISM-1079 | ASD's approval is sought before undertaking any maintenance or repairs to high assurance I |
| ISM-1217 | Labels and markings indicating the owner, sensitivity, classification or any other marking |
| ISM-1218 | IT equipment, including associated media, that is located overseas and has processed, stor |
| ISM-1219 | MFD print drums and image transfer rollers are inspected and destroyed if there is remnant |
| ISM-1220 | Printer and MFD platens are inspected and destroyed if any text or images are retained on |
| ISM-1221 | Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a pa |
| ISM-1222 | Televisions and computer monitors that cannot be sanitised are destroyed. |
| ISM-1223 | Memory in network devices is sanitised using the following processes, in order of preferen |
| ISM-1534 | Printer ribbons in printers and MFDs are removed and destroyed. |
| ISM-1550 | IT equipment disposal processes, and supporting IT equipment disposal procedures, are deve |
| ISM-1551 | An IT equipment management policy is developed, implemented and maintained. |
| ISM-1598 | Following maintenance or repair activities for IT equipment, the IT equipment is inspected |
| ISM-1599 | IT equipment is handled in a manner suitable for its sensitivity or classification. |
| ISM-1741 | IT equipment destruction processes, and supporting IT equipment destruction procedures, ar |
| ISM-1742 | IT equipment that cannot be sanitised is destroyed. |
| ISM-1858 | IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictiv |
| ISM-1869 | A non-networked IT equipment register is developed, implemented, maintained and verified o |
| ISM-1913 | Approved configurations for IT equipment are developed, implemented and maintained. |
Guidelines for media
| Code | Title |
|---|---|
| ISM-0323 | Media is classified to the highest sensitivity or classification of data it stores, unless |
| ISM-0325 | Any media connected to a system with a higher sensitivity or classification than the media |
| ISM-0330 | Before reclassifying media to a lower sensitivity or classification, the media is sanitise |
| ISM-0332 | Media, with the exception of internally mounted fixed media within information technology |
| ISM-0337 | Media is only used with systems that are authorised to process, store or communicate its s |
| ISM-0347 | When transferring data manually between two systems belonging to different security domain |
| ISM-0348 | Media sanitisation processes, and supporting media sanitisation procedures, are developed, |
| ISM-0350 | The following media types are destroyed prior to their disposal: - microfiche and microfil |
| ISM-0351 | Volatile media is sanitised by removing its power for at least 10 minutes. |
| ISM-0352 | SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its e |
| ISM-0354 | Non-volatile magnetic media is sanitised by overwriting it at least once (or three times i |
| ISM-0356 | Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its clas |
| ISM-0357 | Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified |
| ISM-0358 | Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains |
| ISM-0359 | Non-volatile flash memory media is sanitised by overwriting it at least twice in its entir |
| ISM-0360 | Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its |
| ISM-0361 | Magnetic media is destroyed using a degausser with a suitable magnetic field strength and |
| ISM-0362 | Product-specific directions provided by degausser manufacturers are followed. |
| ISM-0363 | Media destruction processes, and supporting media destruction procedures, are developed, i |
| ISM-0368 | Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results i |
| ISM-0370 | The destruction of media is performed under the supervision of at least one cleared person |
| ISM-0371 | Personnel supervising the destruction of media supervise its handling to the point of dest |
| ISM-0372 | The destruction of media storing accountable material is performed under the supervision o |
| ISM-0373 | Personnel supervising the destruction of media storing accountable material supervise its |
| ISM-0374 | Media disposal processes, and supporting media disposal procedures, are developed, impleme |
| ISM-0375 | Following sanitisation, destruction or declassification, a formal administrative decision |
| ISM-0378 | Labels and markings indicating the owner, sensitivity, classification or any other marking |
| ISM-0831 | Media is handled in a manner suitable for its sensitivity or classification. |
| ISM-0835 | Following sanitisation, TOP SECRET volatile media retains its classification if it stored |
| ISM-0836 | Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety wit |
| ISM-0839 | The destruction of media storing accountable material is not outsourced. |
| ISM-0840 | When outsourcing the destruction of media storing non-accountable material, a National Ass |
| ISM-0947 | When transferring data manually between two systems belonging to different security domain |
| ISM-1059 | All data stored on media is encrypted. |
| ISM-1065 | The host-protected area and device configuration overlay table are reset prior to the sani |
| ISM-1067 | The ATA secure erase command is used, in addition to block overwriting software, to ensure |
| ISM-1160 | If using degaussers to destroy media, degaussers evaluated by the United States' National |
| ISM-1359 | A removable media usage policy is developed, implemented and maintained. |
| ISM-1361 | Security Construction and Equipment Committee-approved equipment or ASIO-approved equipmen |
| ISM-1517 | Equipment that is capable of reducing microform to a fine powder, with resultant particles |
| ISM-1549 | A media management policy is developed, implemented and maintained. |
| ISM-1600 | Media is sanitised before it is used for the first time. |
| ISM-1641 | Following the use of a degausser, magnetic media is physically damaged by deforming any in |
| ISM-1642 | Media is sanitised before it is reused in a different security domain. |
| ISM-1713 | A removable media register is developed, implemented, maintained and verified on a regular |
| ISM-1722 | Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disin |
| ISM-1723 | Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrato |
| ISM-1724 | Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, |
| ISM-1725 | Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, dega |
| ISM-1726 | Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grind |
| ISM-1727 | Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrato |
| ISM-1728 | The resulting media waste particles from the destruction of SECRET media is stored and han |
| ISM-1729 | The resulting media waste particles from the destruction of TOP SECRET media is stored and |
| ISM-1735 | Media that cannot be successfully sanitised is destroyed prior to its disposal. |
Guidelines for networking
| Code | Title |
|---|---|
| ISM-0385 | Servers maintain effective functional separation with other servers allowing them to opera |
| ISM-0516 | Network documentation includes high-level network diagrams showing all connections into ne |
| ISM-0518 | Network documentation is developed, implemented and maintained. |
| ISM-0520 | Network access controls are implemented on networks to prevent the connection of unauthori |
| ISM-0521 | IPv6 functionality is disabled in dual-stack network devices unless it is being used. |
| ISM-0529 | VLANs are not used to separate network traffic between networks belonging to different sec |
| ISM-0530 | Network devices managing VLANs are administered from the most trusted security domain. |
| ISM-0534 | Unused physical ports on network devices are disabled. |
| ISM-0535 | Network devices managing VLANs belonging to different security domains do not share VLAN t |
| ISM-0536 | Public wireless networks provided for general public use are segregated from all other org |
| ISM-1006 | Security measures are implemented to prevent unauthorised access to network management tra |
| ISM-1013 | The effective range of wireless communications outside an organisation's area of control i |
| ISM-1028 | A NIDS or NIPS is deployed in gateways between an organisation's networks and other networ |
| ISM-1030 | A NIDS or NIPS is located immediately inside the outermost firewall for gateways and confi |
| ISM-1178 | Network documentation provided to a third party, or published in public tender documentati |
| ISM-1181 | Networks are segregated into multiple network zones according to the criticality of server |
| ISM-1182 | Network access controls are implemented to limit the flow of network traffic within and be |
| ISM-1186 | IPv6 capable network security appliances are used on IPv6 and dual-stack networks. |
| ISM-1304 | Default user accounts or credentials for network devices, including for any pre-configured |
| ISM-1311 | SNMP version 1 and SNMP version 2 are not used on networks. |
| ISM-1312 | All default SNMP community strings on network devices are changed and write access is disa |
| ISM-1314 | All wireless devices are Wi-Fi Alliance certified. |
| ISM-1315 | The administrative interface on wireless access points is disabled for wireless network co |
| ISM-1316 | Default SSIDs of wireless access points are changed. |
| ISM-1317 | SSIDs of non-public wireless networks are not readily associated with an organisation, the |
| ISM-1318 | SSID broadcasting is not disabled on wireless access points. |
| ISM-1319 | Static addressing is not used for assigning IP addresses on wireless networks. |
| ISM-1320 | MAC address filtering is not used to restrict which devices can connect to wireless networ |
| ISM-1321 | 802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentic |
| ISM-1322 | Evaluated supplicants, authenticators, wireless access points and authentication servers a |
| ISM-1323 | Certificates are required for devices and users accessing wireless networks. |
| ISM-1324 | Certificates are generated using an evaluated certificate authority or hardware security m |
| ISM-1327 | Certificates are protected by logical and physical access controls, encryption, and user a |
| ISM-1330 | The PMK caching period is not set to greater than 1440 minutes (24 hours). |
| ISM-1332 | WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all w |
| ISM-1334 | Wireless networks implement sufficient frequency separation from other wireless networks. |
| ISM-1335 | Wireless access points enable the use of the 802.11w amendment to protect management frame |
| ISM-1338 | Instead of deploying a small number of wireless access points that broadcast on high power |
| ISM-1364 | Network devices managing VLANs terminate VLANs belonging to different security domains on |
| ISM-1428 | Unless explicitly required, IPv6 tunnelling is disabled on all network devices. |
| ISM-1429 | IPv6 tunnelling is blocked by network security appliances at externally-connected network |
| ISM-1430 | Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protoco |
| ISM-1431 | Denial-of-service attack mitigation strategies are discussed with cloud service providers, |
| ISM-1432 | Domain names for online services are protected via registrar locking and confirming that d |
| ISM-1436 | Critical online services are segregated from other online services that are more likely to |
| ISM-1437 | Cloud service providers are used for hosting online services. |
| ISM-1438 | Where a high availability requirement exists for website hosting, CDNs that cache websites |
| ISM-1439 | If using CDNs, disclosing the IP addresses of web servers under an organisation's control |
| ISM-1454 | Communications between authenticators and a RADIUS server are encapsulated with an additio |
| ISM-1479 | Servers minimise communications with other servers at the network and file system level. |
| ISM-1532 | VLANs are not used to separate network traffic between an organisation's networks and publ |
| ISM-1577 | An organisation's networks are segregated from their service providers' networks. |
| ISM-1579 | Cloud service providers' ability to dynamically scale resources in response to a genuine s |
| ISM-1580 | Where a high availability requirement exists for online services, the services are archite |
| ISM-1581 | Continuous real-time monitoring of the capacity and availability of online services is per |
| ISM-1627 | Inbound network connections from anonymity networks are blocked. |
| ISM-1628 | Outbound network connections to anonymity networks are blocked. |
| ISM-1710 | Settings for wireless access points are hardened. |
| ISM-1711 | User identity confidentiality is used if available with EAP-TLS implementations. |
| ISM-1712 | The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications a |
| ISM-1781 | All data communicated over network infrastructure is encrypted. |
| ISM-1782 | A protective DNS service is used to block access to known malicious domain names. |
| ISM-1800 | Network devices are flashed with trusted firmware before they are used for the first time. |
| ISM-1801 | Network devices are restarted on at least a monthly basis. |
| ISM-1863 | Networked management interfaces for IT equipment are not directly exposed to the internet. |
| ISM-1912 | Network documentation includes device settings for all critical servers, high-value server |
| ISM-1962 | SMB version 1 is not used on networks. |
| ISM-1963 | Security-relevant events for internet-facing network devices are centrally logged. |
| ISM-1964 | Security-relevant events for non-internet-facing network devices are centrally logged. |
| ISM-2017 | DNS traffic is encrypted by clients and servers wherever supported. |
| ISM-2068 | Internet connectivity for networked devices is strictly limited to those that require acce |
Guidelines for personnel security
| Code | Title |
|---|---|
| ISM-0078 | Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under |
| ISM-0252 | Cyber security awareness training is undertaken annually by all personnel and covers: - th |
| ISM-0258 | A web usage policy is developed, implemented and maintained. |
| ISM-0405 | Requests for unprivileged access to systems and their resources are validated when first r |
| ISM-0407 | A secure record is maintained for the life of systems and their resources that covers the |
| ISM-0409 | Foreign nationals, including seconded foreign nationals, do not have access to systems tha |
| ISM-0411 | Foreign nationals, excluding seconded foreign nationals, do not have access to systems tha |
| ISM-0414 | Personnel granted access to systems and their resources are uniquely identifiable. |
| ISM-0415 | The use of shared user accounts is strictly controlled, and personnel using such accounts |
| ISM-0420 | Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are fo |
| ISM-0430 | Access to systems and their resources are removed or suspended the same day personnel no l |
| ISM-0432 | Access requirements for systems and their resources are documented in their system securit |
| ISM-0434 | Personnel undergo appropriate employment screening and, where necessary, hold an appropria |
| ISM-0435 | Personnel receive any necessary briefings before being granted access to systems and their |
| ISM-0441 | When personnel are granted temporary access to systems and their resources, effective cont |
| ISM-0443 | Temporary access is not granted to systems that process, store or communicate caveated or |
| ISM-0445 | Privileged users are assigned a dedicated privileged user account to be used solely for du |
| ISM-0446 | Foreign nationals, including seconded foreign nationals, do not have privileged access to |
| ISM-0447 | Foreign nationals, excluding seconded foreign nationals, do not have privileged access to |
| ISM-0817 | Personnel are advised of what suspicious contact via online services is and how to report |
| ISM-0820 | Personnel are advised to not post work information to unauthorised online services and to |
| ISM-0821 | Personnel are advised of security risks associated with posting personal information to on |
| ISM-0824 | Personnel are advised not to send or receive files via unauthorised online services. |
| ISM-0854 | AUSTEO and AGAO data can only be accessed from systems under the sole control of the Austr |
| ISM-1146 | Personnel are advised to maintain separate work and personal user accounts for online serv |
| ISM-1175 | Privileged user accounts (excluding those explicitly authorised to access online services) |
| ISM-1263 | Unique privileged user accounts are used for administering individual server applications. |
| ISM-1404 | Unprivileged access to systems and their resources are disabled after 45 days of inactivit |
| ISM-1507 | Requests for privileged access to systems and their resources are validated when first req |
| ISM-1508 | Privileged access to systems and their resources is limited to only what is required for u |
| ISM-1509 | Privileged access events are centrally logged. |
| ISM-1565 | Tailored privileged user training is undertaken annually by all privileged users. |
| ISM-1566 | Use of unprivileged access is centrally logged. |
| ISM-1583 | Personnel who are contractors are identified as such. |
| ISM-1591 | Access to systems and their resources are removed or suspended as soon as practicable when |
| ISM-1610 | A method of emergency access to systems and their resources is documented and tested at le |
| ISM-1611 | Break glass accounts are only used when normal authentication processes cannot be used. |
| ISM-1612 | Break glass accounts are only used for specific authorised activities. |
| ISM-1613 | Use of break glass accounts is centrally logged. |
| ISM-1614 | Break glass account credentials are changed by the account custodian after they are access |
| ISM-1615 | Break glass accounts are tested after credentials are changed. |
| ISM-1647 | Privileged access to systems and their resources are disabled after 12 months unless reval |
| ISM-1648 | Privileged access to systems and their resources are disabled after 45 days of inactivity. |
| ISM-1649 | Just-in-time administration is used for the administration of systems and their resources. |
| ISM-1650 | Privileged user account and security group management events are centrally logged. |
| ISM-1740 | Personnel dealing with banking details and payment requests are advised of what business e |
| ISM-1852 | Unprivileged access to systems and their resources is limited to only what is required for |
| ISM-1864 | A system usage policy is developed, implemented and maintained. |
| ISM-1865 | Personnel agree to abide by system usage policies before being granted access to systems a |
| ISM-1883 | Privileged user accounts explicitly authorised to access online services are strictly limi |
| ISM-2022 | A cyber security awareness training register is developed, implemented and maintained. |
| ISM-2071 | Personnel dealing with user account details are advised of what social engineering attacks |
| ISM-2074 | A general-purpose artificial intelligence usage policy is developed, implemented and maint |
Guidelines for physical security
| Code | Title |
|---|---|
| ISM-0161 | IT equipment and media are secured when not in use. |
| ISM-0164 | Unauthorised people are prevented from observing systems, in particular workstation displa |
| ISM-0225 | Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas. |
| ISM-0810 | Classified systems are secured in facilities that meet the requirements for a security zon |
| ISM-0813 | Server rooms, communications rooms and security containers are not left in unsecured state |
| ISM-0829 | Security measures are used to detect and respond to unauthorised RF devices in SECRET and |
| ISM-1053 | Classified servers, network devices and cryptographic equipment are secured in server room |
| ISM-1074 | Keys or equivalent access mechanisms to server rooms, communications rooms and security co |
| ISM-1296 | Physical security is implemented to protect network devices in public areas from physical |
| ISM-1530 | Classified servers, network devices and cryptographic equipment are secured in security co |
| ISM-1543 | An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, impl |
| ISM-1973 | Non-classified systems are secured in suitably secure facilities. |
| ISM-1974 | Non-classified servers, network devices and cryptographic equipment are secured in suitabl |
| ISM-1975 | Non-classified servers, network devices and cryptographic equipment are secured in suitabl |
| ISM-2007 | An authorised medical device register for SECRET and TOP SECRET areas is developed, implem |
| ISM-2008 | Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, a |
| ISM-2009 | Unauthorised medical devices are not brought into SECRET and TOP SECRET areas. |
| ISM-2069 | An authorised photographic and video recording device register for SECRET and TOP SECRET a |
| ISM-2070 | Unauthorised photographic and video recording devices are not brought into SECRET and TOP |
Guidelines for procurement and outsourcing
| Code | Title |
|---|---|
| ISM-0072 | Security requirements associated with the confidentiality, integrity and availability of d |
| ISM-0141 | The requirement for service providers to report cyber security incidents to a designated p |
| ISM-1073 | An organisation's systems are not accessed or administered by a service provider unless a |
| ISM-1395 | Service providers, including any subcontractors, provide an appropriate level of protectio |
| ISM-1451 | Types of data and its ownership is documented in contractual arrangements with service pro |
| ISM-1452 | A supply chain risk assessment is performed for suppliers of operating systems, applicatio |
| ISM-1529 | Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud servi |
| ISM-1567 | Suppliers identified as high risk by a cyber supply chain risk assessment are not used. |
| ISM-1568 | Operating systems, applications, IT equipment, OT equipment and services are procured from |
| ISM-1569 | A shared responsibility model is created, documented and shared between suppliers and thei |
| ISM-1570 | Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTE |
| ISM-1571 | The right to verify compliance with security requirements is documented in contractual arr |
| ISM-1572 | The regions or availability zones where data will be processed, stored and communicated, a |
| ISM-1573 | Access to all logs relating to an organisation's data and services is documented in contra |
| ISM-1574 | The storage of data in a portable manner that allows for backups, service migration and se |
| ISM-1575 | A minimum notification period of one month for the cessation of any services by a service |
| ISM-1576 | If an organisation's systems are accessed or administered by a service provider in an unau |
| ISM-1631 | Suppliers of operating systems, applications, IT equipment, OT equipment and services asso |
| ISM-1632 | Operating systems, applications, IT equipment, OT equipment and services are procured from |
| ISM-1637 | An outsourced cloud service register is developed, implemented, maintained and verified on |
| ISM-1638 | An outsourced cloud service register contains the following for each outsourced cloud serv |
| ISM-1736 | A managed service register is developed, implemented, maintained and verified on a regular |
| ISM-1737 | A managed service register contains the following for each managed service: - managed serv |
| ISM-1738 | The right to verify compliance with security requirements documented in contractual arrang |
| ISM-1785 | A supplier relationship management policy is developed, implemented and maintained. |
| ISM-1786 | An approved supplier list is developed, implemented and maintained. |
| ISM-1787 | Operating systems, applications, IT equipment, OT equipment and services are sourced from |
| ISM-1788 | Multiple potential suppliers are identified for sourcing critical operating systems, appli |
| ISM-1789 | Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserv |
| ISM-1790 | Operating systems, applications, IT equipment, OT equipment and services are delivered in |
| ISM-1791 | The integrity of operating systems, applications, IT equipment, OT equipment and services |
| ISM-1792 | The authenticity of operating systems, applications, IT equipment, OT equipment and servic |
| ISM-1793 | Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SEC |
| ISM-1794 | A minimum notification period of one month by service providers for significant changes to |
| ISM-1804 | Break clauses associated with failure to meet security requirements are documented in cont |
| ISM-1882 | Operating systems, applications, IT equipment, OT equipment and services are procured from |
| ISM-1971 | Managed service providers and their TOP SECRET managed services, including sensitive compa |
| ISM-1972 | Outsourced cloud service providers and their TOP SECRET cloud services, including sensitiv |
Guidelines for software development
| Code | Title |
|---|---|
| ISM-0400 | Development, testing, staging and production environments are segregated. |
| ISM-0401 | Secure by Design principles and practices are followed throughout the software development |
| ISM-0402 | Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to |
| ISM-0971 | The OWASP Application Security Verification Standard is used in the development of web app |
| ISM-1238 | Threat modelling is used in support of the software development life cycle. |
| ISM-1239 | Robust web application frameworks are used in the development of web applications. |
| ISM-1240 | Validation and sanitisation are performed on all input received over the internet by softw |
| ISM-1241 | Output encoding is performed on all output produced by web applications. |
| ISM-1275 | All queries to databases from software are filtered for legitimate content and correct syn |
| ISM-1276 | Parameterised queries or stored procedures, instead of dynamically generated queries, are |
| ISM-1278 | Software is designed or configured to provide as little error information as possible abou |
| ISM-1419 | Development and modification of software only takes place in development environments. |
| ISM-1420 | Data from production environments is not used in non-production environments unless the no |
| ISM-1422 | Unauthorised access to the authoritative source for software is prevented. |
| ISM-1424 | Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame |
| ISM-1536 | All queries to databases from software that are initiated by users, and any resulting cras |
| ISM-1552 | All web application content is offered exclusively using HTTPS. |
| ISM-1616 | A vulnerability disclosure program is implemented to assist with the secure development an |
| ISM-1717 | A 'security.txt' file is hosted for each of an organisation's internet-facing website doma |
| ISM-1730 | A software bill of materials is produced and made available to consumers of software. |
| ISM-1754 | Vulnerabilities identified in software are resolved in a timely manner. |
| ISM-1755 | A vulnerability disclosure policy is developed, implemented and maintained. |
| ISM-1756 | Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, ar |
| ISM-1780 | SecDevOps practices are used for software development. |
| ISM-1796 | Files containing executable content are digitally signed by a certificate with a verifiabl |
| ISM-1797 | Installers, patches and updates are digitally signed or provided with cryptographic checks |
| ISM-1798 | Secure configuration guidance, in the form of a hardening guide or loosening guide, is pro |
| ISM-1816 | Unauthorised modification of the authoritative source for software is prevented. |
| ISM-1817 | Authentication and authorisation of clients is performed when clients call network APIs th |
| ISM-1818 | Authentication and authorisation of clients is performed when clients call network APIs th |
| ISM-1849 | The OWASP Top 10 Proactive Controls are used in the development of web applications. |
| ISM-1850 | The OWASP Top 10 are mitigated in the development of web applications. |
| ISM-1851 | The OWASP API Security Top 10 are mitigated in the development of web APIs. |
| ISM-1908 | Vulnerabilities identified in software are publicly disclosed in a responsible and timely |
| ISM-1909 | In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent |
| ISM-1910 | Network API calls that facilitate modification of data, or access to data not authorised f |
| ISM-1911 | Security-relevant usage, error messages and crashes for software are centrally logged. |
| ISM-1922 | The OWASP Mobile Application Security Verification Standard is used in the development of |
| ISM-1924 | Generative artificial intelligence applications evaluate user prompts to detect and mitiga |
| ISM-2013 | Authentication and authorisation of clients is performed when clients call network APIs th |
| ISM-2014 | Authentication and authorisation of clients is performed when clients call network APIs th |
| ISM-2015 | Network API calls that facilitate modification of data, or access to data not authorised f |
| ISM-2016 | Validation and sanitisation are performed on all input received over a local network by so |
| ISM-2023 | An authoritative source for software is established and maintained. |
| ISM-2024 | The authoritative source for software is used for all software development activities. |
| ISM-2025 | An issue tracking solution is used to link software development tasks to security issues a |
| ISM-2026 | All software artefacts are scanned for malicious content before being imported into the au |
| ISM-2027 | All software artefacts are verified by a digital signature, or a secure hash provided over |
| ISM-2028 | All software artefacts are tested to detect known weaknesses using static application secu |
| ISM-2029 | The authoritative source for software restricts the use and import of third-party librarie |
| ISM-2030 | Scanning is used during commits to identify plain text or encoded secrets and keys, which |
| ISM-2031 | Compilers, interpreters and build tools (including pipelines) that provide security featur |
| ISM-2032 | The build solution ensures that all automated testing is completed without warnings, alert |
| ISM-2033 | All software security requirements are documented, stored securely and maintained througho |
| ISM-2034 | Security design decisions are documented and reviewed throughout the software development |
| ISM-2035 | Security roles, responsibilities and knowledge requirements required to support the softwa |
| ISM-2036 | Security responsibilities for software developers are identified and documented. |
| ISM-2037 | Software developers that lack sufficient cyber security knowledge and skills required for |
| ISM-2038 | A software developer cyber security knowledge and skills register is implemented and maint |
| ISM-2039 | The software threat model is reviewed throughout the software development life cycle to en |
| ISM-2040 | Secure programming practices for the chosen programming language are used for software dev |
| ISM-2041 | Memory-safe programming languages, or less preferably memory-safe programming practices, a |
| ISM-2042 | Secure by Default principles and practices are followed throughout the software developmen |
| ISM-2043 | Software is architected and structured to support readability and maintainability. |
| ISM-2044 | Software has no default credentials; however, if credentials are required, they are create |
| ISM-2045 | Application backwards compatibility does not compromise any security measures or features. |
| ISM-2046 | Where software allows user impersonation, sensitive data is not logged and appropriate per |
| ISM-2047 | Where software allows an authentication factor to be reset, the user is notified of the re |
| ISM-2048 | Where software supports multiple user roles, non-administrative users are prevented from a |
| ISM-2049 | When user permissions or credentials are changed, software forces all impacted users to re |
| ISM-2050 | When digital signatures are processed by software, they are validated against a certificat |
| ISM-2051 | Software generates sufficient event logs to support the detection of cyber security events |
| ISM-2052 | Event logs produced by software ensure that any sensitive data is protected. |
| ISM-2053 | End of life procedures for software, covering how to remove the software and how to archiv |
| ISM-2054 | If a software bill of materials is available for imported third-party software components, |
| ISM-2055 | If a software build provenance is available for imported third-party software components, |
| ISM-2056 | A software build provenance is produced and made available to consumers of software. |
| ISM-2057 | All input validation rules are documented, matched in code and tested with both positive a |
| ISM-2058 | Data sources and serialised data inputs are validated before being deserialised. |
| ISM-2059 | File uploads or input are restricted to specific file types, with malicious content scanni |
| ISM-2060 | Code reviews are utilised to ensure software meets Secure by Design principles and practic |
| ISM-2061 | Software developer-supported security-focused peer reviews are conducted on all critical a |
| ISM-2062 | Unit testing and integration testing, covering both positive and negative use cases, are u |
| ISM-2063 | If supported, web application session cookies set the HttpOnly flag, Secure flag and the S |
| ISM-2064 | Web application session cookies contain only digitally signed opaque bearer tokens. |
| ISM-2065 | Web application session cookies using opaque bearer tokens that are not digitally signed u |
| ISM-2066 | Web application sessions are centrally managed server side. |
| ISM-2067 | Web applications that support Single Sign On equally support Single Logout. |
| ISM-2072 | Artificial intelligence models are stored in a non-executable file format that does not al |
| ISM-2082 | If a cryptographic bill of materials is available for imported third-party software compon |
| ISM-2083 | A cryptographic bill of materials is produced and made available to consumers of software. |
| ISM-2084 | Artificial intelligence-specific documentation, including model and system cards (or equiv |
| ISM-2085 | The exposure of exact artificial intelligence model confidence scores in API responses or |
| ISM-2086 | The source and integrity of artificial intelligence models, structures and weights are ver |
| ISM-2087 | The source and integrity of training data for artificial intelligence models is verified. |
| ISM-2088 | Data validation and verification techniques are used to ensure the reliability and accurac |
| ISM-2089 | Artificial intelligence model performance metrics are monitored and anomalies are investig |
| ISM-2090 | Rate limiting is applied to inference queries for artificial intelligence models. |
| ISM-2091 | Resource limits are enforced for artificial intelligence models. |
| ISM-2092 | Access control policies are implemented to enforce fine-grained permissions for artificial |
| ISM-2093 | Role-based access controls are implemented for artificial intelligence applications to res |
| ISM-2094 | Content filtering is implemented by artificial intelligence applications to detect and blo |
| ISM-2102 | Existing software artefacts in the authoritative source for software are periodically test |
| ISM-2103 | Organisational data generated, collected or processed by artificial intelligence applicati |
Guidelines for system hardening
| Code | Title |
|---|---|
| ISM-0341 | Automatic execution features for removable media are disabled. |
| ISM-0343 | If there is no business requirement for writing to removable media and devices, such funct |
| ISM-0345 | External communication interfaces that allow DMA are disabled. |
| ISM-0380 | Unneeded user accounts, components, services and functionality of operating systems are di |
| ISM-0382 | Unprivileged users do not have the ability to uninstall or disable approved applications. |
| ISM-0383 | Default user accounts or credentials for operating systems, including for any pre-configur |
| ISM-0408 | Systems have a logon banner that reminds users of their security responsibilities when acc |
| ISM-0417 | When systems cannot support multi-factor authentication, single-factor authentication usin |
| ISM-0418 | Physical credentials are kept separate from systems they are used to authenticate to, exce |
| ISM-0421 | Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and |
| ISM-0422 | Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 |
| ISM-0428 | Services are configured with a session lock that: - activates after a maximum of 15 minute |
| ISM-0582 | Security-relevant events for Microsoft Windows operating systems are centrally logged. |
| ISM-0843 | Application control is implemented on workstations. |
| ISM-0846 | All users (with the exception of local administrator accounts and break glass accounts) ca |
| ISM-0853 | On a daily basis, outside of business hours and after an appropriate period of inactivity, |
| ISM-0938 | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin |
| ISM-0955 | Application control is implemented using cryptographic hash rules, publisher certificate r |
| ISM-0974 | Multi-factor authentication is used to authenticate unprivileged users of systems. |
| ISM-1034 | A HIPS or EDR solution is implemented on critical servers and high-value servers. |
| ISM-1055 | LAN Manager and NT LAN Manager authentication methods are disabled. |
| ISM-1173 | Multi-factor authentication is used to authenticate privileged users of systems. |
| ISM-1227 | Credentials set for user accounts are randomly generated. |
| ISM-1235 | Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clien |
| ISM-1245 | All temporary installation files and logs created during server application installation p |
| ISM-1246 | Server applications are hardened using ASD and vendor hardening guidance, with the most re |
| ISM-1247 | Unneeded user accounts, components, services and functionality of server applications are |
| ISM-1249 | Server applications are configured to run as a separate user account with the minimum priv |
| ISM-1250 | The user accounts under which server applications run have limited access to their underly |
| ISM-1260 | Default user accounts or credentials for server applications, including for any pre-config |
| ISM-1341 | A HIPS or EDR solution is implemented on workstations. |
| ISM-1392 | When implementing application control using path rules, only approved users can modify app |
| ISM-1401 | Multi-factor authentication uses either: something users have and something users know, or |
| ISM-1402 | Credentials stored on systems are protected by a password manager; a hardware security mod |
| ISM-1403 | User accounts, except for break glass accounts, are locked out after a maximum of five fai |
| ISM-1406 | SOEs are used for workstations and servers. |
| ISM-1407 | The latest release, or the previous release, of operating systems are used. |
| ISM-1408 | Where supported, 64-bit versions of operating systems are used. |
| ISM-1409 | Operating systems are hardened using ASD and vendor hardening guidance, with the most rest |
| ISM-1412 | Web browsers are hardened using ASD and vendor hardening guidance, with the most restricti |
| ISM-1416 | A software firewall is implemented on workstations and servers to restrict inbound and out |
| ISM-1417 | An antivirus application is implemented on workstations and servers with: - signature-base |
| ISM-1418 | If there is no business requirement for reading from removable media and devices, such fun |
| ISM-1460 | When using a software-based isolation mechanism to share a physical server's hardware, the |
| ISM-1461 | When using a software-based isolation mechanism to share a physical server's hardware for |
| ISM-1467 | The latest release of office productivity suites, web browsers and their extensions, email |
| ISM-1470 | Unneeded components, services and functionality of office productivity suites, web browser |
| ISM-1471 | When implementing application control using publisher certificate rules, publisher names a |
| ISM-1483 | The latest release of internet-facing server applications are used. |
| ISM-1485 | Web browsers do not process web advertisements from the internet. |
| ISM-1486 | Web browsers do not process Java from the internet. |
| ISM-1487 | Only privileged users responsible for checking that Microsoft Office macros are free of ma |
| ISM-1488 | Microsoft Office macros in files originating from the internet are blocked. |
| ISM-1489 | Microsoft Office macro security settings cannot be changed by users. |
| ISM-1490 | Application control is implemented on internet-facing servers. |
| ISM-1491 | Unprivileged users are prevented from running script execution engines, including: - Windo |
| ISM-1492 | Operating system exploit protection functionality is enabled. |
| ISM-1504 | Multi-factor authentication is used to authenticate users to their organisation's online s |
| ISM-1505 | Multi-factor authentication is used to authenticate users of data repositories. |
| ISM-1542 | Microsoft Office is configured to prevent activation of Object Linking and Embedding packa |
| ISM-1544 | Microsoft's recommended application blocklist is implemented. |
| ISM-1546 | Users are authenticated before they are granted access to a system and its resources. |
| ISM-1557 | Passwords used for single-factor authentication on SECRET systems are a minimum of 17 char |
| ISM-1558 | Passwords using a sequence of words for single-factor authentication are not constructed u |
| ISM-1559 | Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and |
| ISM-1560 | Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 charac |
| ISM-1561 | Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 c |
| ISM-1582 | Application control rulesets are validated on an annual or more frequent basis. |
| ISM-1584 | Unprivileged users are prevented from bypassing, disabling or modifying security functiona |
| ISM-1585 | Web browser security settings cannot be changed by users. |
| ISM-1588 | SOEs are reviewed and updated at least annually. |
| ISM-1590 | Credentials for user accounts are changed if: - they are compromised - they are suspected |
| ISM-1592 | Unprivileged users do not have the ability to install unapproved applications. |
| ISM-1593 | Users provide sufficient evidence to verify their identity when requesting new credentials |
| ISM-1594 | Credentials are provided to users via a secure communications channel or, if not possible, |
| ISM-1595 | Credentials provided to users are changed on first use. |
| ISM-1596 | Credentials are not reused by users across different systems. |
| ISM-1597 | Credentials are obscured as they are entered into systems. |
| ISM-1601 | Microsoft's attack surface reduction rules are implemented. |
| ISM-1603 | Authentication methods susceptible to replay attacks are disabled. |
| ISM-1604 | When using a software-based isolation mechanism to share a physical server's hardware, the |
| ISM-1605 | When using a software-based isolation mechanism to share a physical server's hardware, the |
| ISM-1606 | When using a software-based isolation mechanism to share a physical server's hardware, pat |
| ISM-1607 | When using a software-based isolation mechanism to share a physical server's hardware, int |
| ISM-1608 | SOEs provided by third parties are scanned for malicious code and configurations. |
| ISM-1619 | Service accounts are created as group Managed Service Accounts. |
| ISM-1620 | Privileged user accounts are members of the Protected Users security group. |
| ISM-1621 | Windows PowerShell 2.0 is disabled or removed. |
| ISM-1622 | PowerShell is configured to use Constrained Language Mode. |
| ISM-1623 | PowerShell module logging, script block logging and transcription events are centrally log |
| ISM-1624 | PowerShell script block logs are protected by Protected Event Logging functionality. |
| ISM-1654 | Internet Explorer 11 is disabled or removed. |
| ISM-1655 | .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed. |
| ISM-1656 | Application control is implemented on non-internet-facing servers. |
| ISM-1657 | Application control restricts the execution of executables, libraries, scripts, installers |
| ISM-1658 | Application control restricts the execution of drivers to an organisation-approved set. |
| ISM-1659 | Microsoft's vulnerable driver blocklist is implemented. |
| ISM-1660 | Allowed and blocked application control events are centrally logged. |
| ISM-1667 | Microsoft Office is blocked from creating child processes. |
| ISM-1668 | Microsoft Office is blocked from creating executable content. |
| ISM-1669 | Microsoft Office is blocked from injecting code into other processes. |
| ISM-1670 | PDF applications are blocked from creating child processes. |
| ISM-1671 | Microsoft Office macros are disabled for users that do not have a demonstrated business re |
| ISM-1672 | Microsoft Office macro antivirus scanning is enabled. |
| ISM-1673 | Microsoft Office macros are blocked from making Win32 API calls. |
| ISM-1674 | Only Microsoft Office macros running from within a sandboxed environment, a Trusted Locati |
| ISM-1675 | Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via t |
| ISM-1676 | Microsoft Office's list of trusted publishers is validated on an annual or more frequent b |
| ISM-1679 | Multi-factor authentication is used to authenticate users to third-party online services t |
| ISM-1680 | Multi-factor authentication (where available) is used to authenticate users to third-party |
| ISM-1681 | Multi-factor authentication is used to authenticate customers to online customer services |
| ISM-1682 | Multi-factor authentication used for authenticating users of systems is phishing-resistant |
| ISM-1683 | Successful and unsuccessful multi-factor authentication events are centrally logged. |
| ISM-1685 | Credentials for break glass accounts, local administrator accounts and service accounts ar |
| ISM-1686 | Credential Guard functionality is enabled. |
| ISM-1743 | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin |
| ISM-1745 | Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is ena |
| ISM-1746 | When implementing application control using path rules, only approved users can change fil |
| ISM-1748 | Email client security settings cannot be changed by users. |
| ISM-1749 | Cached credentials are limited to one previous logon. |
| ISM-1795 | Credentials for built-in Administrator accounts, break glass accounts, local administrator |
| ISM-1806 | Default user accounts or credentials for user applications, including for any pre-configur |
| ISM-1823 | Office productivity suite security settings cannot be changed by users. |
| ISM-1824 | PDF application security settings cannot be changed by users. |
| ISM-1825 | Security product security settings cannot be changed by users. |
| ISM-1826 | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin |
| ISM-1827 | Microsoft AD DS domain controllers are administered using dedicated domain administrator u |
| ISM-1828 | The Print Spooler service is disabled on Microsoft AD DS domain controllers. |
| ISM-1829 | Passwords are not stored in Group Policy Preferences. |
| ISM-1830 | Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA server |
| ISM-1832 | Only service accounts and computer accounts are configured with Service Principal Names (S |
| ISM-1833 | User accounts are provisioned with the minimum privileges required. |
| ISM-1834 | Duplicate SPNs do not exist within the domain. |
| ISM-1835 | Privileged user accounts are configured as sensitive and cannot be delegated. |
| ISM-1836 | User accounts require Kerberos pre-authentication. |
| ISM-1838 | The UserPassword attribute for user accounts is not used. |
| ISM-1839 | Account properties accessible by unprivileged users are not used to store passwords. |
| ISM-1840 | User account passwords do not use reversible encryption. |
| ISM-1841 | Unprivileged user accounts cannot add machines to the domain. |
| ISM-1842 | Dedicated privileged service accounts are used to add machines to the domain. |
| ISM-1843 | User accounts with unconstrained delegation are reviewed at least annually, and those with |
| ISM-1844 | Computer accounts that are not Microsoft AD DS domain controllers are not trusted for dele |
| ISM-1845 | When a user account is disabled, it is removed from all security group memberships. |
| ISM-1846 | The Pre-Windows 2000 Compatible Access security group does not contain user accounts. |
| ISM-1847 | Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are change |
| ISM-1848 | When using a software-based isolation mechanism to share a physical server's hardware, the |
| ISM-1859 | Office productivity suites are hardened using ASD and vendor hardening guidance, with the |
| ISM-1860 | PDF applications are hardened using ASD and vendor hardening guidance, with the most restr |
| ISM-1861 | Local Security Authority protection functionality is enabled. |
| ISM-1870 | Application control is applied to user profiles and temporary folders used by operating sy |
| ISM-1871 | Application control is applied to all locations other than user profiles and temporary fol |
| ISM-1872 | Multi-factor authentication used for authenticating users of online services is phishing-r |
| ISM-1873 | Multi-factor authentication used for authenticating customers of online customer services |
| ISM-1874 | Multi-factor authentication used for authenticating customers of online customer services |
| ISM-1875 | Networks are scanned at least monthly to identify any credentials that are being stored in |
| ISM-1889 | Command line process creation events are centrally logged. |
| ISM-1890 | Microsoft Office macros are checked to ensure they are free of malicious code before being |
| ISM-1891 | Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be |
| ISM-1892 | Multi-factor authentication is used to authenticate users to their organisation's online c |
| ISM-1893 | Multi-factor authentication is used to authenticate users to third-party online customer s |
| ISM-1894 | Multi-factor authentication used for authenticating users of data repositories is phishing |
| ISM-1895 | Successful and unsuccessful single-factor authentication events are centrally logged. |
| ISM-1896 | Memory integrity functionality is enabled. |
| ISM-1897 | Remote Credential Guard functionality is enabled. |
| ISM-1914 | Approved configurations for operating systems are developed, implemented and maintained. |
| ISM-1915 | Approved configurations for user applications are developed, implemented and maintained. |
| ISM-1916 | Approved configurations for server applications are developed, implemented and maintained. |
| ISM-1919 | When multi-factor authentication is used to authenticate users or customers to online serv |
| ISM-1920 | When multi-factor authentication is used to authenticate users to online services, online |
| ISM-1926 | Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers an |
| ISM-1927 | Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS |
| ISM-1928 | Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS |
| ISM-1929 | Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain control |
| ISM-1930 | Passwords are prevented from being stored in Group Policy Preferences. |
| ISM-1931 | SID Filtering is enabled for domain and forest trusts. |
| ISM-1932 | The number of service accounts configured with an SPN is minimised. |
| ISM-1933 | Service accounts configured with an SPN do not have DCSync permissions. |
| ISM-1934 | User accounts with DCSync permissions are reviewed at least annually, and those without an |
| ISM-1935 | Computer accounts are not configured for unconstrained delegation. |
| ISM-1936 | The sIDHistory attribute for user accounts is not used. |
| ISM-1937 | User accounts are checked at least weekly for the presence of the sIDHistory attribute. |
| ISM-1938 | The Domain Computers security group does not have write or modify permissions to any Micro |
| ISM-1939 | The number of user accounts that are members of the Domain Admins, Enterprise Admins or ot |
| ISM-1940 | Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-p |
| ISM-1941 | Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly- |
| ISM-1942 | The Domain Computers security group is not a member of any privileged or highly-privileged |
| ISM-1943 | Strong mapping between certificates and users is enforced. |
| ISM-1944 | The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations. |
| ISM-1945 | The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates. |
| ISM-1946 | Unprivileged user accounts do not have write access to certificate templates. |
| ISM-1947 | Extended Key Usages that enable user authentication are removed. |
| ISM-1948 | CA Certificate Manager approval is required for certificate templates that allow a Subject |
| ISM-1949 | Microsoft AD FS servers are administered using a dedicated service account that is not use |
| ISM-1950 | Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial |
| ISM-1951 | Hard match takeover is disabled for Microsoft Entra Connect servers. |
| ISM-1952 | Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra |
| ISM-1953 | Credentials for the built-in Administrator account in each domain are long, unique, unpred |
| ISM-1954 | Credentials for built-in Administrator accounts, break glass accounts, local administrator |
| ISM-1955 | Credentials for computer accounts are changed if they are compromised, they are suspected |
| ISM-1956 | Microsoft AD FS token-signing and encryption certificates are changed twice in quick succe |
| ISM-1957 | Private keys for Microsoft AD CS CA servers are protected by a hardware security module. |
| ISM-1976 | Security-relevant events for Apple macOS operating systems are centrally logged. |
| ISM-1977 | Security-relevant events for Linux operating systems are centrally logged. |
| ISM-1978 | Security-relevant events for server applications on internet-facing servers are centrally |
| ISM-1979 | Security-relevant events for server applications on non-internet-facing servers are centra |
| ISM-1980 | Credential hint functionality is not used for systems. |
| ISM-2010 | Service accounts configured with an SPN use the Advanced Encryption Standard for encryptio |
| ISM-2011 | When phishing-resistant multi-factor authentication is used by user accounts, other non-ph |
| ISM-2012 | Systems are configured with a screen lock that: - activates after a maximum of 15 minutes |
| ISM-2076 | Security questions are not used for authentication purposes. |
| ISM-2077 | Email is not used for out-of-band authentication purposes. |
| ISM-2078 | Passwords appearing in lists of commonly used passwords or lists of compromised passwords |
| ISM-2079 | Maximum length limits for passwords are not less than 64 characters. |
| ISM-2080 | Password complexity requirements are not imposed for passwords. |
| ISM-2081 | All ASCII printable characters are supported for passwords. |
Guidelines for system management
| Code | Title |
|---|---|
| ISM-0042 | System administration processes, and supporting system administration procedures, are deve |
| ISM-0298 | A centralised and managed approach that maintains the integrity of patches or updates, and |
| ISM-0300 | Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equi |
| ISM-0304 | Applications other than office productivity suites, web browsers and their extensions, ema |
| ISM-1143 | Patch management processes, and supporting patch management procedures, are developed, imp |
| ISM-1211 | System administrators perform system administration activities in accordance with the syst |
| ISM-1380 | Privileged users use separate privileged and unprivileged operating environments. |
| ISM-1385 | Administrative infrastructure is segregated from the wider network and the internet. |
| ISM-1386 | Network management traffic can only originate from administrative infrastructure. |
| ISM-1387 | Administrative activities are conducted through jump servers. |
| ISM-1493 | Software registers for workstations, servers, network devices and networked IT equipment a |
| ISM-1501 | Operating systems that are no longer supported by vendors are replaced. |
| ISM-1510 | A digital preservation policy is developed, implemented and maintained. |
| ISM-1511 | Backups of data, applications and settings are performed and retained in accordance with b |
| ISM-1515 | Restoration of data, applications and settings from backups to a common point in time is t |
| ISM-1547 | Data backup processes, and supporting data backup procedures, are developed, implemented a |
| ISM-1548 | Data restoration processes, and supporting data restoration procedures, are developed, imp |
| ISM-1643 | Software registers contain versions and patch histories of applications, drivers, operatin |
| ISM-1687 | Privileged operating environments are not virtualised within unprivileged operating enviro |
| ISM-1688 | Unprivileged user accounts cannot logon to privileged operating environments. |
| ISM-1689 | Privileged user accounts (excluding local administrator accounts) cannot logon to unprivil |
| ISM-1690 | Patches, updates or other vendor mitigations for vulnerabilities in online services are ap |
| ISM-1691 | Patches, updates or other vendor mitigations for vulnerabilities in office productivity su |
| ISM-1692 | Patches, updates or other vendor mitigations for vulnerabilities in office productivity su |
| ISM-1693 | Patches, updates or other vendor mitigations for vulnerabilities in applications other tha |
| ISM-1694 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i |
| ISM-1695 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w |
| ISM-1696 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w |
| ISM-1697 | Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi |
| ISM-1698 | A vulnerability scanner is used at least daily to identify missing patches or updates for |
| ISM-1699 | A vulnerability scanner is used at least weekly to identify missing patches or updates for |
| ISM-1700 | A vulnerability scanner is used at least fortnightly to identify missing patches or update |
| ISM-1701 | A vulnerability scanner is used at least daily to identify missing patches or updates for |
| ISM-1702 | A vulnerability scanner is used at least fortnightly to identify missing patches or update |
| ISM-1703 | A vulnerability scanner is used at least fortnightly to identify missing patches or update |
| ISM-1704 | Office productivity suites, web browsers and their extensions, email clients, PDF applicat |
| ISM-1705 | Privileged user accounts (excluding backup administrator accounts) cannot access backups b |
| ISM-1706 | Privileged user accounts (excluding backup administrator accounts) cannot access their own |
| ISM-1707 | Privileged user accounts (excluding backup administrator accounts) are prevented from modi |
| ISM-1708 | Backup administrator accounts are prevented from modifying and deleting backups during the |
| ISM-1750 | Administrative infrastructure for critical servers, high-value servers and regular servers |
| ISM-1751 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I |
| ISM-1752 | A vulnerability scanner is used at least fortnightly to identify missing patches or update |
| ISM-1753 | Internet-facing network devices that are no longer supported by vendors are replaced. |
| ISM-1807 | An automated method of asset discovery is used at least fortnightly to support the detecti |
| ISM-1808 | A vulnerability scanner with an up-to-date vulnerability database is used for vulnerabilit |
| ISM-1809 | When applications, operating systems, network devices or networked IT equipment that are n |
| ISM-1810 | Backups of data, applications and settings are synchronised to enable restoration to a com |
| ISM-1811 | Backups of data, applications and settings are retained in a secure and resilient manner. |
| ISM-1812 | Unprivileged user accounts cannot access backups belonging to other user accounts. |
| ISM-1813 | Unprivileged user accounts cannot access their own backups. |
| ISM-1814 | Unprivileged user accounts are prevented from modifying and deleting backups. |
| ISM-1876 | Patches, updates or other vendor mitigations for vulnerabilities in online services are ap |
| ISM-1877 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i |
| ISM-1878 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I |
| ISM-1879 | Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi |
| ISM-1898 | Secure Admin Workstations are used in the performance of administrative activities. |
| ISM-1899 | Network devices that do not belong to administrative infrastructure cannot initiate connec |
| ISM-1900 | A vulnerability scanner is used at least fortnightly to identify missing patches or update |
| ISM-1901 | Patches, updates or other vendor mitigations for vulnerabilities in office productivity su |
| ISM-1902 | Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w |
| ISM-1903 | Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w |
| ISM-1904 | Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w |
| ISM-1905 | Online services that are no longer supported by vendors are removed. |
| ISM-1921 | The likelihood of system compromise is frequently assessed when working exploits exist for |
| ISM-1958 | User accounts with DCSync permissions cannot logon to unprivileged operating environments. |
| ISM-1981 | Non-internet-facing network devices that are no longer supported by vendors are replaced. |
| ISM-1982 | Networked IT equipment that is no longer supported by vendors is replaced. |
Guidelines for system monitoring
| Code | Title |
|---|---|
| ISM-0109 | Event logs from workstations are analysed in a timely manner to detect cyber security even |
| ISM-0580 | An event logging policy is developed, implemented and maintained. |
| ISM-0585 | For each event logged, the date and time of the event, the relevant user or process, the r |
| ISM-0988 | An accurate and consistent time source is used for event logging. |
| ISM-1228 | Cyber security events are analysed in a timely manner to identify cyber security incidents |
| ISM-1405 | A centralised event logging facility is implemented. |
| ISM-1815 | Event logs are protected from unauthorised modification and deletion. |
| ISM-1906 | Event logs from internet-facing servers are analysed in a timely manner to detect cyber se |
| ISM-1907 | Event logs from non-internet-facing servers are analysed in a timely manner to detect cybe |
| ISM-1959 | To the extent possible, event logs are captured and stored in a consistent and structured |
| ISM-1960 | Event logs from internet-facing network devices are analysed in a timely manner to detect |
| ISM-1961 | Event logs from non-internet-facing network devices are analysed in a timely manner to det |
| ISM-1983 | Event logs sent to a centralised event logging facility are done so as soon as possible af |
| ISM-1984 | Event logs sent to a centralised event logging facility are encrypted in transit. |
| ISM-1985 | Event logs are protected from unauthorised access. |
| ISM-1986 | Event logs from critical servers are analysed in a timely manner to detect cyber security |
| ISM-1987 | Event logs from security products are analysed in a timely manner to detect cyber security |
| ISM-1988 | Event logs are retained in a searchable manner for at least 12 months. |
| ISM-1989 | Event logs are retained as per minimum retention requirements for various classes of recor |
Maps to 2 other frameworks
Frequently Asked Questions
What is Australian Information Security Manual?
Australian Information Security Manual is a compliance framework from Australia with 22 domains and 1081 controls. ACSC Information Security Manual. Australian Government cybersecurity controls baseline. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Australian Information Security Manual have?
Australian Information Security Manual has 1081 controls organised across 22 domains. The largest domains are Guidelines for system hardening (215 controls), Guidelines for software development (104 controls), Guidelines for cryptography (73 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Australian Information Security Manual map to?
Australian Information Security Manual maps to 2 other compliance frameworks. The top mapping partners are ACSC Essential Eight (5% coverage), Australia IRAP - Information Security Registered Assessors Program (0% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Australian Information Security Manual compliance?
Start your Australian Information Security Manual compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Information Security Manual requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 1081 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required