ASD Information Security Manual (ISM)
The Australian Signals Directorate Information Security Manual is the Australian Government's primary cyber security framework. It provides a comprehensive set of cyber security principles and guidelines for protecting systems and data at all classification levels. The ISM contains over 870 controls organized across system hardening, management, monitoring, development, networking, cryptography, gateways, and data transfer guidelines.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (33)
Access
| Code | Title |
|---|---|
| ISM-AC-1 | Access Control |
Backup and Recovery
Chapter 12: Data backup, restoration, and digital preservation
| Code | Title |
|---|---|
| ISM-1511 | Backups performed |
| ISM-1515 | Restoration Testing |
| ISM-1705 | Backup Access Restriction |
| ISM-1810 | Backup immutability |
| ISM-1811 | Resilient Backup Storage |
Cryptography
| Code | Title |
|---|---|
| ISM-0459 | Data at Rest Encryption |
| ISM-0476 | RSA Key Length |
| ISM-0484 | SSH Hardening |
| ISM-1139 | TLS minimum version |
| ISM-1369 | TLS Encryption Algorithm |
| ISM-1453 | Perfect Forward Secrecy |
| ISM-1506 | SSH v1 Disabled |
| ISM-1553 | TLS Compression Disabled |
| ISM-1917 | Post-Quantum Readiness |
| ISM-CR-1 | Cryptographic Fundamentals |
| ISM-CR-2 | Key Management |
| ISM-CR-TLS | Transport Layer Security |
Cryptography
Chapter 18: Cryptographic controls, TLS, SSH, and post-quantum readiness
| Code | Title |
|---|---|
| ISM-0459 | Data at Rest Encryption |
| ISM-0476 | RSA Key Length |
| ISM-0484 | SSH Hardening |
| ISM-1139 | TLS minimum version |
| ISM-1369 | TLS Encryption Algorithm |
| ISM-1453 | Perfect Forward Secrecy |
| ISM-1506 | SSH v1 Disabled |
| ISM-1553 | TLS Compression Disabled |
| ISM-1917 | Post-Quantum Readiness |
| ISM-CR-1 | Cryptographic Fundamentals |
| ISM-CR-2 | Key Management |
| ISM-CR-TLS | Transport Layer Security |
Cyber Security Principles and Governance
Chapters 2-4: Cyber security principles, roles, responsibilities, and security documentation
| Code | Title |
|---|---|
| ISM-0027 | System security plan |
| ISM-0047 | System Security Plan |
| ISM-0714 | Chief Information Security Officer appointment |
| ISM-0888 | Incident response plan documented |
| ISM-1211 | Incident Response Plan |
| ISM-1526 | System owner responsibilities |
| ISM-1563 | Security Assessment Report |
| ISM-1567 | Change management |
| ISM-1568 | Shared Responsibility Model |
Data
| Code | Title |
|---|---|
| ISM-DA-1 | Database Security |
| Code | Title |
|---|---|
| ISM-EM-1 | Email Security |
Gateways and Content Filtering
Chapter 19: Firewalls, cross-domain solutions, web proxies, and content inspection
| Code | Title |
|---|---|
| ISM-0260 | Web Proxy Requirement |
| ISM-0263 | Network segmentation |
| ISM-0631 | Gateway between networks |
| ISM-0637 | DMZ Implementation |
| ISM-0963 | Content Filter Blocking |
| ISM-1288 | Multi-Engine Antivirus |
| ISM-1389 | Sandbox Analysis |
| ISM-1528 | Evaluated Firewalls |
Governance
| Code | Title |
|---|---|
| ISM-G-CISO | Chief Information Security Officer |
Identification
| Code | Title |
|---|---|
| ISM-ID-MFA | Multi-Factor Authentication |
| ISM-ID-PAM | Privileged Access Management |
Incident Management
| Code | Title |
|---|---|
| ISM-IRP | Incident Response Plan |
| ISM-IRR | Cyber Security Incident Reporting |
Information
| Code | Title |
|---|---|
| ISM-IC-1 | Information Classification and Handling |
| ISM-IC-2 | Information Aggregation and Caveats |
Media
| Code | Title |
|---|---|
| ISM-MEDIA-1 | Media Management and Sanitisation |
Media and Facilities Security
Chapters 7-10: Guidelines for media, equipment, and physical facility security
| Code | Title |
|---|---|
| ISM-0159 | Media Sanitisation |
| ISM-0164 | Equipment Maintenance |
| ISM-0336 | ICT Equipment Classification |
| ISM-0363 | Media Destruction |
| ISM-1053 | Cabling infrastructure standards |
| ISM-1076 | ICT Equipment Disposal |
Mobility
| Code | Title |
|---|---|
| ISM-MO-1 | Mobile Device Management |
| ISM-MO-2 | Working Outside the Office |
Monitoring
| Code | Title |
|---|---|
| ISM-LOG-1 | Event Logging and Monitoring |
Network Security
| Code | Title |
|---|---|
| ISM-0520 | Unauthorised Device Prevention |
| ISM-1028 | NIDS/NIPS Deployment |
| ISM-1181 | Network Segmentation |
| ISM-1182 | Wireless network security |
| ISM-1311 | SNMP v1/v2 Prohibition |
| ISM-1627 | Anonymity Network Inbound Blocking |
| ISM-1628 | Anonymity Network Outbound Blocking |
| ISM-1781 | Data Encryption in Transit |
| ISM-1782 | Protective DNS |
| ISM-1800 | Trusted Firmware |
| ISM-NET-GW | Gateways and Internet Connections |
| ISM-NET-SEG | Network Segmentation and Segregation |
| UK-TSA-NET-01 | Security Architecture |
| UK-TSA-NET-02 | Access Control and Authentication |
| UK-TSA-NET-03 | Supply Chain Security |
Network Security
Security requirements for telecoms networks and services
| Code | Title |
|---|---|
| ISM-0520 | Unauthorised Device Prevention |
| ISM-1028 | NIDS/NIPS Deployment |
| ISM-1181 | Network Segmentation |
| ISM-1182 | Wireless network security |
| ISM-1311 | SNMP v1/v2 Prohibition |
| ISM-1627 | Anonymity Network Inbound Blocking |
| ISM-1628 | Anonymity Network Outbound Blocking |
| ISM-1781 | Data Encryption in Transit |
| ISM-1782 | Protective DNS |
| ISM-1800 | Trusted Firmware |
| ISM-NET-GW | Gateways and Internet Connections |
| ISM-NET-SEG | Network Segmentation and Segregation |
| UK-TSA-NET-01 | Security Architecture |
| UK-TSA-NET-02 | Access Control and Authentication |
| UK-TSA-NET-03 | Supply Chain Security |
Outsourcing
| Code | Title |
|---|---|
| ISM-OUT-1 | Outsourcing and Service Providers |
Patch Management
Chapter 12: Patching operating systems, applications, and firmware
| Code | Title |
|---|---|
| ISM-1143 | Patch Management Processes |
| ISM-1691 | Application Patching - Regular |
| ISM-1692 | Application Patching - Critical |
| ISM-1694 | Server OS Patching - Regular |
| ISM-1696 | Workstation OS Patching - Critical |
| ISM-1698 | Vulnerability Scanning - Online Services |
| ISM-1699 | Vulnerability Scanning - Applications |
| ISM-1876 | API security |
| ISM-1877 | Container security |
Personnel
| Code | Title |
|---|---|
| ISM-PER-1 | Personnel Security |
Personnel Security
Requirements for ensuring personnel suitability and managing insider threats
| Code | Title |
|---|---|
| AEO-PS-1 | Employee Vetting |
| AEO-PS-2 | Security Awareness Training |
| AEO-PS-3 | Access Management |
| CTPAT-PE-1 | Pre-Employment Verification |
| CTPAT-PE-2 | Employee Screening |
| CTPAT-PE-3 | Education and Training |
| DSPF-PERS-1 | Personnel Suitability |
| DSPF-PERS-2 | Security Clearances |
| DSPF-PERS-3 | Ongoing Personnel Assessment |
| DSPF-PERS-4 | Insider Threat Management |
| DSPF-PERS-5 | Security Awareness and Training |
| ISM-0252 | Cyber Security Awareness Training |
| ISM-0414 | Database hardening |
| ISM-0434 | Need to know enforced |
| ISM-1146 | Targeted Cyber Security Training |
| ISM-1175 | Privileged workstations |
| ISM-1503 | Separate Privileged Operating Environments |
| ISM-1507 | Privileged Access Limitation |
| ISM-1508 | Privileged Access Review |
| PSPF-PERS-1 | Eligibility and Suitability |
| PSPF-PERS-2 | Security Clearances |
| PSPF-PERS-3 | Ongoing Suitability |
| PSPF-PERS-4 | Separation and Transfer |
Physical
| Code | Title |
|---|---|
| ISM-PHY-1 | Facilities and Systems Physical Security |
Principles
| Code | Title |
|---|---|
| ISM-CSP-1 | Cyber Security Principles - Govern |
| ISM-CSP-2 | Cyber Security Principles - Protect |
| ISM-CSP-3 | Cyber Security Principles - Detect |
| ISM-CSP-4 | Cyber Security Principles - Respond |
Software
| Code | Title |
|---|---|
| ISM-SD-1 | Software Development |
Software Development Security
Chapter 14: Secure development practices, web application security, and vulnerability management
| Code | Title |
|---|---|
| ISM-0400 | Secure development standards |
| ISM-0401 | Secure Design Principles |
| ISM-0402 | Security Testing |
| ISM-0971 | Web Application Security Standard |
| ISM-1240 | Input Validation |
| ISM-1241 | Output Encoding |
| ISM-1275 | Database Query Filtering |
| ISM-1424 | Security Headers |
| ISM-1616 | Vulnerability Disclosure Program |
| ISM-1730 | Software Bill of Materials |
| ISM-1780 | SecDevOps |
| ISM-1850 | OWASP Top 10 Mitigation |
System Hardening
| Code | Title |
|---|---|
| ISM-SYS-APP | System Hardening - Application Selection |
| ISM-SYS-HARD | System Hardening - Operating Systems |
System Hardening - Application Control
Chapter 11: Application control (Essential Eight mitigation strategy)
| Code | Title |
|---|---|
| ISM-0843 | Patch operating systems |
| ISM-0955 | Application Control Rules |
| ISM-1490 | Multi-factor authentication |
| ISM-1544 | Microsoft Blocklist |
| ISM-1582 | Application Control Validation |
| ISM-1656 | Application Control on Non-Internet Servers |
| ISM-1657 | Hardened user application config |
| ISM-1658 | Driver Execution Control |
| ISM-1870 | Application Control - User Folders |
System Hardening - Application and Browser Hardening
Chapter 11: Hardening of office suites, web browsers, email clients, and PDF applications
| Code | Title |
|---|---|
| ISM-1412 | Web Browser Hardening |
| ISM-1467 | Latest Application Versions |
| ISM-1485 | Block Web Advertisements |
| ISM-1486 | Block Java in Browsers |
| ISM-1667 | PDF reader hardening |
| ISM-1668 | Office Executable Content Blocking |
| ISM-1671 | Macros restriction |
| ISM-1674 | Trusted Macro Sources |
| ISM-1859 | Cloud identity federation |
System Hardening - Authentication
Chapter 11: Multi-factor authentication and credential management
| Code | Title |
|---|---|
| ISM-0421 | Password storage |
| ISM-0974 | Privileged access just-in-time |
| ISM-1173 | MFA for Privileged Users |
| ISM-1401 | MFA Factor Types |
| ISM-1403 | Account Lockout |
| ISM-1504 | MFA for Sensitive Services |
| ISM-1590 | Credential Rotation |
| ISM-1682 | Phishing-Resistant MFA |
| ISM-1686 | Credential Guard |
System Hardening - Operating Systems
Chapter 11: Operating system hardening and configuration management
| Code | Title |
|---|---|
| ISM-1407 | Server hardening baseline |
| ISM-1408 | 64-bit Operating Systems |
| ISM-1409 | OS Hardening |
| ISM-1410 | Default credentials changed |
| ISM-1584 | Security Function Protection |
| ISM-1588 | SOE Annual Review |
| ISM-1745 | Secure Boot |
System Monitoring and Event Logging
Chapter 13: Event logging, analysis, and centralised monitoring
| Code | Title |
|---|---|
| ISM-0580 | Event Logging Policy |
| ISM-0584 | Authentication Event Logging |
| ISM-0585 | Event Log Content |
| ISM-0586 | Event log content |
| ISM-0859 | Centralised logging |
| ISM-0988 | Accurate Time Source |
| ISM-1228 | Log retention |
| ISM-1405 | Configuration management |
Web
| Code | Title |
|---|---|
| ISM-WEB-1 | Web Content Filtering |
Your Compliance Coverage
If you comply with ASD Information Security Manual (ISM), you already cover:
Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1
30%
50 controls mapped
Compare →South Korea ISMS-P
28%
46 controls mapped
Compare →AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association)
25%
42 controls mapped
Compare →+ 643 more: NIS2 Directive Implementing Acts (25%), TISAX - Trusted Information Security Assessment Exchange (25%)
See all 646 mapped frameworks ↓Maps to 646 other frameworks
Frequently Asked Questions
What is ASD Information Security Manual (ISM)?
ASD Information Security Manual (ISM) is a compliance framework from Australia with 33 domains and 166 controls. The Australian Signals Directorate Information Security Manual is the Australian Government's primary cyber security framework. It provides a comprehensive set of cyber security principles and guidelines for protecting systems and data at all classification levels. The ISM contains over 870 controls organized across system hardening, management, monitoring, development, networking, cryptography, gateways, and data transfer guidelines. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does ASD Information Security Manual (ISM) have?
ASD Information Security Manual (ISM) has 166 controls organised across 33 domains. The largest domains are Personnel Security (23 controls), Network Security (13 controls), Software Development Security (12 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does ASD Information Security Manual (ISM) map to?
ASD Information Security Manual (ISM) maps to 646 other compliance frameworks. The top mapping partners are Cloud Security Alliance Cloud Controls Matrix (CCM) v4.0.1 (30% coverage), South Korea ISMS-P (28% coverage), AWWA Cybersecurity Guidance for the Water Sector (American Water Works Association) (25% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with ASD Information Security Manual (ISM) compliance?
Start your ASD Information Security Manual (ISM) compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASD Information Security Manual (ISM) requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 166 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required