Australian Information Security Manual
ACSC Information Security Manual. Australian Government cybersecurity controls baseline.
Australian Information Security Manual is a compliance framework from Australia with 22 domains and 1081 controls that map to 8 other frameworks. The largest domains are Guidelines for system hardening (215 controls), Guidelines for software development (104 controls), Guidelines for cryptography (73 controls). Every control below carries what it requires and what an assessor expects to see.
Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.
Visit cyber.gov.auFramework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (22)
Guidelines for communications infrastructure
| Code | Title |
|---|---|
| ISM-0181 | Cabling infrastructure standards |
| ISM-0187 | SECRET cable bundles and conduits |
| ISM-0194 | Sealing plastic and TOP SECRET conduit joints |
| ISM-0195 | Tamper-evident seals on TOP SECRET reticulation covers |
| ISM-0198 | Penetrating TOP SECRET audio secure rooms |
| ISM-0201 | Labelling TOP SECRET conduits |
| ISM-0206 | Cable labelling processes and procedures |
| ISM-0208 | Cable register contents |
| ISM-0211 | Cable register maintenance and verification |
| ISM-0213 | Terminating cables on patch panels |
| ISM-0216 | TOP SECRET patch panels in dedicated cabinets |
| ISM-0217 | Shared cabinets under spatial constraints |
| ISM-0218 | TOP SECRET fibre-optic fly leads over five metres |
| ISM-0246 | Timing of emanation security risk assessments |
| ISM-0249 | Emanation assessments for mobile and deployable systems |
| ISM-0250 | Electromagnetic interference and compatibility standards |
| ISM-0926 | Colours for lower-classified cables |
| ISM-1095 | Labelling wall outlet boxes |
| ISM-1096 | Labelling cables at each end |
| ISM-1098 | Terminating SECRET cables in cabinets |
| ISM-1100 | Terminating TOP SECRET cables in cabinets |
| ISM-1101 | TOP SECRET reticulation into server room cabinets |
| ISM-1102 | Terminating reticulation close to cabinets |
| ISM-1103 | TOP SECRET reticulation to cabinets outside server rooms |
| ISM-1105 | Contents of SECRET and TOP SECRET wall outlet boxes |
| ISM-1107 | Colours for lower-classified wall outlet boxes |
| ISM-1109 | Clear plastic wall outlet box covers |
| ISM-1111 | Use of fibre-optic cables |
| ISM-1112 | Inspectability of non-TOP SECRET cables |
| ISM-1114 | Separation within shared reticulation systems |
| ISM-1115 | Conduit for cables in walls |
| ISM-1116 | Visible gap between TOP SECRET cabinets |
| ISM-1119 | Full-length inspectability of TOP SECRET cables |
| ISM-1122 | TOP SECRET cables in wall penetrations |
| ISM-1123 | UPS-fed power for TOP SECRET equipment |
| ISM-1130 | Enclosed reticulation in shared facilities |
| ISM-1133 | TOP SECRET cables and party walls |
| ISM-1137 | Emanation assessments for fixed facilities |
| ISM-1164 | Clear covers for reticulation in shared facilities |
| ISM-1216 | Banding cables with non-conformant colours |
| ISM-1639 | Labelling building management cables |
| ISM-1640 | Labelling cables for foreign systems |
| ISM-1645 | Floor plan diagram maintenance |
| ISM-1646 | Floor plan diagram contents |
| ISM-1718 | SECRET cable colour |
| ISM-1719 | TOP SECRET cable colour |
| ISM-1720 | SECRET wall outlet box colour |
| ISM-1721 | TOP SECRET wall outlet box colour |
| ISM-1820 | Consistent cable colour per system |
| ISM-1821 | TOP SECRET cable bundles and conduits |
| ISM-1822 | Consistent wall outlet colour per system |
| ISM-1884 | Emanation security doctrine |
| ISM-1885 | Implementing emanation security mitigation advice |
Guidelines for communications systems
| Code | Title |
|---|---|
| ISM-0229 | Permitted classification for telephone conversations |
| ISM-0230 | Awareness of non-secure telephone risks |
| ISM-0231 | Visual indication of connection type |
| ISM-0232 | Encrypting telephone traffic over external systems |
| ISM-0233 | Cordless telephone handsets and headsets |
| ISM-0235 | Speakerphones in TOP SECRET areas |
| ISM-0236 | Off-hook audio protection features |
| ISM-0245 | Connecting MFDs to digital telephone systems |
| ISM-0546 | Video-aware and voice-aware firewalls and proxies |
| ISM-0547 | Secure real-time transport protocol for calls |
| ISM-0548 | Secure session initiation protocol for calls |
| ISM-0549 | Separating voice and video from data traffic |
| ISM-0551 | IP phone registration and device hardening |
| ISM-0553 | Authentication on video conferencing networks |
| ISM-0554 | Two-way call authentication scheme |
| ISM-0555 | Authentication on IP telephony networks |
| ISM-0556 | Workstations connected to phones and video units |
| ISM-0558 | IP phones in public areas |
| ISM-0559 | Microphones and webcams in SECRET areas |
| ISM-0588 | Multifunction device usage policy |
| ISM-0589 | Scanning and copying documents on MFDs |
| ISM-0590 | Authentication strength for MFDs |
| ISM-0931 | Push-to-talk handsets and headsets |
| ISM-1014 | Individual logins for classified IP phones |
| ISM-1019 | Denial of service response plan for communications |
| ISM-1036 | Observing multifunction device use |
| ISM-1078 | Telephone system usage policy |
| ISM-1450 | Microphones and webcams in TOP SECRET areas |
| ISM-1562 | Video conferencing and IP telephony hardening |
| ISM-1805 | Content of the denial of service response plan |
| ISM-1854 | Authenticating to multifunction devices |
| ISM-1855 | Logging multifunction device use |
| ISM-2075 | Sending and receiving fax messages |
Guidelines for cryptography
| Code | Title |
|---|---|
| ISM-0142 | Reporting cryptographic equipment compromise |
| ISM-0455 | Data recovery for encrypted data |
| ISM-0457 | Evaluated encryption for sensitive media |
| ISM-0459 | Full disk or partial encryption at rest |
| ISM-0460 | HACE for SECRET and TOP SECRET media |
| ISM-0462 | Handling authenticated encrypted equipment and media |
| ISM-0465 | Evaluated encryption for sensitive data in transit |
| ISM-0467 | HACE for SECRET and TOP SECRET data in transit |
| ISM-0469 | Encrypting data in transit |
| ISM-0471 | Using ASD-Approved Cryptographic Algorithms |
| ISM-0472 | Diffie-Hellman modulus of at least 2048 bits |
| ISM-0474 | ECDH key size and curve selection |
| ISM-0475 | ECDSA key size and curve selection |
| ISM-0476 | RSA modulus of at least 2048 bits |
| ISM-0477 | Separate RSA key pairs for signing and key transport |
| ISM-0479 | Avoiding Electronic Codebook Mode |
| ISM-0481 | Using ASD-Approved Cryptographic Protocols |
| ISM-0484 | Configuring the SSH daemon |
| ISM-0485 | Public key authentication for SSH |
| ISM-0487 | Restrictions on passwordless SSH logins |
| ISM-0488 | Forced commands for passwordless SSH access |
| ISM-0489 | Key caching limits for SSH-agent |
| ISM-0490 | Minimum S/MIME version |
| ISM-0494 | IPsec tunnel mode |
| ISM-0496 | Using ESP for IPsec |
| ISM-0498 | IPsec security association lifetimes |
| ISM-0499 | Complying with ASD COMSEC doctrine for HACE |
| ISM-0501 | Transporting keyed cryptographic equipment |
| ISM-0507 | Cryptographic key management processes |
| ISM-0994 | Preferring ECDH over DH |
| ISM-0998 | IPsec integrity algorithms |
| ISM-0999 | IPsec key establishment groups |
| ISM-1000 | Perfect Forward Secrecy for IPsec |
| ISM-1080 | Approved algorithms for media encryption |
| ISM-1091 | Changing compromised keying material |
| ISM-1139 | Using the latest TLS version |
| ISM-1233 | Using IKE version 2 |
| ISM-1369 | Using AES-GCM for TLS |
| ISM-1370 | Server-initiated secure renegotiation for TLS |
| ISM-1372 | DH or ECDH for TLS key establishment |
| ISM-1373 | Excluding anonymous DH for TLS |
| ISM-1374 | SHA-2-based certificates for TLS |
| ISM-1375 | SHA-2 for TLS HMAC and PRF |
| ISM-1446 | Curve selection for elliptic curve cryptography |
| ISM-1448 | Ephemeral DH and ECDH for TLS |
| ISM-1449 | Protecting SSH private keys |
| ISM-1453 | Perfect Forward Secrecy for TLS |
| ISM-1506 | Disabling SSH version 1 |
| ISM-1553 | Disabling TLS compression |
| ISM-1629 | Diffie-Hellman parameter selection |
| ISM-1759 | Diffie-Hellman modulus of at least 3072 bits |
| ISM-1761 | ECDH curves P-256, P-384 or P-521 |
| ISM-1762 | ECDH curves P-384 or P-521 |
| ISM-1763 | ECDSA curves P-256, P-384 or P-521 |
| ISM-1764 | ECDSA curves P-384 or P-521 |
| ISM-1765 | RSA modulus of at least 3072 bits |
| ISM-1766 | SHA-2 output size of at least 224 bits |
| ISM-1767 | SHA-2 output size of at least 256 bits |
| ISM-1768 | SHA-2 output size of at least 384 bits |
| ISM-1769 | AES key lengths |
| ISM-1770 | AES-192 or AES-256 key lengths |
| ISM-1771 | AES for IPsec encryption |
| ISM-1772 | IPsec pseudorandom function |
| ISM-1802 | Approved High Assurance Cryptographic Equipment |
| ISM-1917 | Procurement support for ML-DSA, ML-KEM and AES-256 |
| ISM-1990 | FIPS 140-3 validation for ML-DSA and ML-KEM |
| ISM-1991 | ML-DSA parameter sets |
| ISM-1992 | Hedged ML-DSA signing |
| ISM-1993 | Restricting use of pre-hashed ML-DSA variants |
| ISM-1994 | Hash functions for pre-hashed ML-DSA |
| ISM-1995 | ML-KEM parameter sets for key encapsulation |
| ISM-1996 | Post-quantum traditional hybrid schemes |
| ISM-2073 | Post-quantum cryptography transition plan |
Guidelines for cyber security documentation
| Code | Title |
|---|---|
| ISM-0039 | Cyber security strategy |
| ISM-0041 | System security plan contents |
| ISM-0043 | Cyber security incident response plan contents |
| ISM-0047 | CISO and authorising officer document approvals |
| ISM-0888 | Annual review and currency statements |
| ISM-0912 | Change and configuration management plan |
| ISM-1163 | Continuous monitoring plan |
| ISM-1563 | Security assessment report |
| ISM-1564 | Plan of action and milestones |
| ISM-1602 | Communication of cyber security documentation |
| ISM-1739 | Approval of security architecture before development |
Guidelines for cyber security incidents
| Code | Title |
|---|---|
| ISM-0120 | Access to data sources and tools |
| ISM-0123 | Reporting incidents to the CISO |
| ISM-0125 | Maintaining a cyber security incident register |
| ISM-0133 | Handling and containing data spills |
| ISM-0137 | Legal advice before allowing intrusions to continue |
| ISM-0138 | Maintaining the integrity of evidence |
| ISM-0140 | Reporting incidents to ASD |
| ISM-0576 | Incident management policy and response plan |
| ISM-0917 | Handling malicious code infections |
| ISM-1213 | Traffic capture after intrusion remediation |
| ISM-1609 | Consulting system owners before allowing intrusions to continue |
| ISM-1625 | Insider threat mitigation program |
| ISM-1626 | Legal advice on insider threat program |
| ISM-1731 | Separate system for remediation planning |
| ISM-1732 | Coordinated remediation during a planned outage |
| ISM-1784 | Annual exercising of incident response plan |
| ISM-1803 | Incident register entry contents |
| ISM-1819 | Enacting cyber security incident response plans |
| ISM-1880 | Reporting incidents involving customer data |
| ISM-1881 | Reporting incidents not involving customer data |
| ISM-1969 | Treating malicious code before storage or transfer |
| ISM-1970 | Dedicated malware analysis environment |
Guidelines for cyber security roles
| Code | Title |
|---|---|
| ISM-0009 | Identifying supplementary controls |
| ISM-0027 | Authorisation to operate from authorising officer |
| ISM-0714 | Appointment of a CISO |
| ISM-0717 | CISO oversight of cyber security personnel |
| ISM-0718 | CISO reporting to the board |
| ISM-0720 | Cyber security communications strategy |
| ISM-0724 | Cyber security metrics and KPIs |
| ISM-0725 | Cyber security steering committee |
| ISM-0726 | Coordinating security risk management |
| ISM-0731 | Oversight of cyber supply chain risk management |
| ISM-0732 | Dedicated cyber security budget |
| ISM-0733 | CISO awareness of all incidents |
| ISM-0734 | CISO contribution to continuity and recovery planning |
| ISM-0735 | Oversight of awareness training program |
| ISM-1071 | Designated system owners |
| ISM-1203 | Threat and risk assessment for each system |
| ISM-1478 | Oversight of cyber security program and compliance |
| ISM-1525 | Registering systems with the authorising officer |
| ISM-1526 | Continuous security monitoring by system owners |
| ISM-1587 | Annual reporting of system security status |
| ISM-1617 | Review and update of cyber security program |
| ISM-1618 | CISO oversight of incident response |
| ISM-1633 | System boundary, criticality and objectives |
| ISM-1634 | Selecting and tailoring controls |
| ISM-1635 | Implementing controls for each system |
| ISM-1636 | Security assessment by organisational or IRAP assessors |
| ISM-1918 | CISO reporting to audit and risk committee |
| ISM-1966 | Register of systems |
| ISM-1967 | ASD assessment of TOP SECRET systems |
| ISM-1968 | Authorisation to operate for TOP SECRET systems |
| ISM-1997 | Defining cyber security roles and responsibilities |
| ISM-1998 | Integrating cyber security across business functions |
| ISM-1999 | Aligning cyber strategy with business strategy |
| ISM-2000 | Cyber security briefings to the board |
| ISM-2001 | Championing a positive cyber security culture |
| ISM-2002 | Board cyber security literacy |
| ISM-2003 | Awareness of cyber workforce and skills gaps |
| ISM-2004 | Supporting cyber skills development |
| ISM-2005 | Understanding critical business assets |
| ISM-2006 | Board planning for major cyber security incidents |
| ISM-2020 | CISO oversight of cyber security workforce |
| ISM-2021 | System owner data minimisation practices |
Guidelines for data transfers
| Code | Title |
|---|---|
| ISM-0657 | Scanning manually imported data |
| ISM-0660 | Full monthly verification of SECRET and TOP SECRET transfer logs |
| ISM-0661 | User accountability for data transfers |
| ISM-0663 | Data transfer processes and procedures |
| ISM-0664 | Review and authorisation of classified data exports |
| ISM-0665 | Trustworthy sources for classified systems |
| ISM-0669 | Signature validation and keyword checks on manual exports |
| ISM-0675 | Digital signing of authorised classified exports |
| ISM-1187 | Checking manual exports for unsuitable markings |
| ISM-1294 | Partial monthly verification of transfer logs |
| ISM-1535 | Preventing export of AUSTEO, AGAO and REL data |
| ISM-1586 | Logging all data imports and exports |
| ISM-1778 | Quarantining failed manual imports |
| ISM-1779 | Quarantining failed manual exports |
Guidelines for database systems
| Code | Title |
|---|---|
| ISM-0393 | Classifying databases and their contents |
| ISM-1243 | Maintaining and verifying a database register |
| ISM-1255 | Restricting database user actions by duty |
| ISM-1256 | File-based access controls on database files |
| ISM-1268 | Need-to-know enforcement for database contents |
| ISM-1269 | Separating database servers from web servers |
| ISM-1270 | Network segmentation of database servers |
| ISM-1271 | Restricting database server network communications |
| ISM-1272 | Disabling unneeded database networking |
| ISM-1273 | Segregating database servers across environments |
| ISM-1274 | Production database contents in non-production environments |
| ISM-1277 | Encrypting web to database communications |
| ISM-1537 | Database event logging |
Guidelines for email
| Code | Title |
|---|---|
| ISM-0264 | Email usage policy |
| ISM-0267 | Blocking non-approved webmail services |
| ISM-0269 | Caveated email and distribution lists |
| ISM-0270 | Protective markings on emails |
| ISM-0271 | No automatic insertion of protective markings |
| ISM-0272 | Restricting marking choices to authorised levels |
| ISM-0565 | Blocking emails with inappropriate markings |
| ISM-0567 | Preventing open relay email servers |
| ISM-0569 | Routing email through central gateways |
| ISM-0570 | Maintaining backup email gateways |
| ISM-0571 | Authenticated encrypted client email channels |
| ISM-0572 | Opportunistic TLS on email servers |
| ISM-0574 | SPF records for organisational domains |
| ISM-0861 | DKIM signing of outgoing email |
| ISM-1023 | Notifying senders and recipients of blocked email |
| ISM-1024 | Verified senders for undeliverable notifications |
| ISM-1026 | Verifying DKIM signatures on incoming email |
| ISM-1027 | Distribution list handling of external DKIM |
| ISM-1089 | Preventing marking downgrades on replies |
| ISM-1151 | SPF verification of incoming email |
| ISM-1183 | Hard fail SPF records |
| ISM-1234 | Filtering email bodies and attachments |
| ISM-1502 | Blocking external email using internal domains |
| ISM-1540 | DMARC reject policy for organisational domains |
| ISM-1589 | MTA-STS for email transport |
| ISM-1799 | Rejecting incoming email failing DMARC |
Guidelines for enterprise mobility
| Code | Title |
|---|---|
| ISM-0240 | Paging, SMS and messaging apps for sensitive data |
| ISM-0682 | Bluetooth on SECRET and TOP SECRET mobile devices |
| ISM-0687 | ASD-approved platforms for classified mobility |
| ISM-0694 | Private devices and classified systems |
| ISM-0701 | Mobile device emergency sanitisation procedures |
| ISM-0702 | Cryptographic zeroise in emergency sanitisation |
| ISM-0705 | Disabling VPN split tunnelling |
| ISM-0863 | Blocking unapproved application installation |
| ISM-0864 | Locking mobile device security settings |
| ISM-0866 | Viewing classified data in public |
| ISM-0869 | Encrypting mobile device storage |
| ISM-0870 | Securing mobile devices when not in use |
| ISM-0871 | Supervising mobile devices in use |
| ISM-0874 | Internet access via organisational gateways |
| ISM-1082 | Mobile device usage policy |
| ISM-1083 | Advising permitted classification for mobile communications |
| ISM-1084 | Transporting mobile devices in approved containers |
| ISM-1085 | Encrypting mobile data over public networks |
| ISM-1088 | Reporting potential mobile device compromise |
| ISM-1145 | Privacy filters on classified mobile devices |
| ISM-1195 | Common Criteria evaluated MDM solutions |
| ISM-1196 | Bluetooth discoverability on mobile devices |
| ISM-1198 | Pairing only with intended Bluetooth devices |
| ISM-1199 | Removing unneeded Bluetooth pairings |
| ISM-1200 | Bluetooth Secure Connections and Numeric Comparison |
| ISM-1297 | Legal advice before allowing privately-owned devices |
| ISM-1298 | Overseas travel privacy and security briefing |
| ISM-1299 | Mobile device security precautions for personnel |
| ISM-1300 | Actions after overseas travel |
| ISM-1366 | Applying security updates to mobile devices |
| ISM-1400 | Separating data on privately-owned devices |
| ISM-1482 | Separating data on organisation-owned devices |
| ISM-1533 | Mobile device management policy |
| ISM-1554 | Travel to high or extreme risk countries |
| ISM-1555 | Preparing mobile devices before overseas travel |
| ISM-1556 | Actions after travel to high risk countries |
| ISM-1644 | Sensitive conversations in public locations |
| ISM-1866 | Preventing storage of classified data on private devices |
| ISM-1867 | Evaluated mobile platforms and ASD configuration |
| ISM-1868 | Removable media on SECRET and TOP SECRET mobile devices |
| ISM-1886 | Supervised mode for mobile devices |
| ISM-1887 | Remote locate and wipe for mobile devices |
| ISM-1888 | Password-based lock screens on mobile devices |
| ISM-2095 | Unapproved AI agents on privately-owned devices |
| ISM-2096 | Separating organisational and personal apps |
| ISM-2097 | Always on VPN for mobile devices |
| ISM-2098 | Blocking USB data transfer on mobile devices |
| ISM-2099 | Connecting mobile devices to vehicle infotainment |
| ISM-2100 | Viewing sensitive data near connected vehicles |
| ISM-2101 | Conversations within or near connected vehicles |
Guidelines for evaluated products
| Code | Title |
|---|---|
| ISM-0280 | Preferring PP-based evaluated products |
| ISM-0285 | Delivery procedures for evaluated products |
| ISM-0286 | Delivery of high assurance IT equipment |
| ISM-0289 | Operating products in evaluated configuration |
| ISM-0290 | Operating high assurance IT equipment |
Guidelines for gateways
| Code | Title |
|---|---|
| ISM-0100 | IRAP assessment of gateways |
| ISM-0260 | Web access through web proxies |
| ISM-0261 | Web proxy event logging |
| ISM-0263 | Transport Layer Security filtering |
| ISM-0591 | Using evaluated peripheral switches |
| ISM-0597 | Consulting ASD on Cross Domain Solutions |
| ISM-0610 | Cross Domain Solution user training |
| ISM-0611 | Minimum privileges for gateway administrators |
| ISM-0612 | Formal training for gateway administrators |
| ISM-0613 | Australian nationals administering AUSTEO and REL gateways |
| ISM-0616 | Separation of duties for gateway administration |
| ISM-0619 | User authentication to networks via gateways |
| ISM-0622 | IT equipment authentication via gateways |
| ISM-0626 | Cross Domain Solutions for SECRET and TOP SECRET networks |
| ISM-0628 | Gateways between security domains |
| ISM-0629 | Administering shared gateway components |
| ISM-0631 | Explicitly authorised gateway data flows |
| ISM-0634 | Gateway event logging |
| ISM-0635 | Isolated upward and downward CDS paths |
| ISM-0637 | Demilitarised zones for external access |
| ISM-0639 | Evaluated firewalls between security domains |
| ISM-0643 | Evaluated diodes for public network connections |
| ISM-0645 | High assurance diodes for classified public connections |
| ISM-0649 | Filtering allowed file types |
| ISM-0651 | Blocking malicious and uninspectable files |
| ISM-0652 | Quarantining suspicious files |
| ISM-0659 | Content filtering checks on transferred files |
| ISM-0670 | Cross Domain Solution event logging |
| ISM-0677 | Validating file signatures and checksums |
| ISM-0958 | Approved domain or category lists for web traffic |
| ISM-0961 | Restricting client-side active content |
| ISM-0963 | Filtering harmful web content |
| ISM-1037 | Gateway testing after changes and six-monthly |
| ISM-1157 | Evaluated diodes for unidirectional gateways |
| ISM-1158 | High assurance diodes for SECRET and TOP SECRET networks |
| ISM-1171 | Blocking website access by IP address |
| ISM-1192 | Transport and application layer gateway inspection |
| ISM-1236 | Blocking malicious, dynamic and free domains |
| ISM-1237 | Outbound web content filtering |
| ISM-1284 | Content validation of transferred files |
| ISM-1286 | Content conversion of transferred files |
| ISM-1287 | Content sanitisation of transferred files |
| ISM-1288 | Multi-engine antivirus scanning of transferred files |
| ISM-1289 | Unpacking archive files for filtering |
| ISM-1290 | Controlled unpacking of archive files |
| ISM-1293 | Decrypting encrypted files for filtering |
| ISM-1389 | Sandboxing imported executable files |
| ISM-1427 | Ingress filtering against IP spoofing |
| ISM-1457 | High assurance switches between SECRET domains |
| ISM-1480 | High assurance switches to lower classified systems |
| ISM-1520 | Screening of gateway administrators |
| ISM-1521 | Protocol breaks in CDSs |
| ISM-1522 | Independent upward and downward paths |
| ISM-1523 | Quarterly CDS event sampling |
| ISM-1524 | Security testing of CDS content filters |
| ISM-1528 | Evaluated firewalls at public network boundaries |
| ISM-1773 | Nationality of AGAO gateway administrators |
| ISM-1774 | Isolated gateway management path |
| ISM-1783 | ROA signing of public IP addresses |
| ISM-1862 | Protecting WAF origin servers |
| ISM-1965 | Content checking of transferred files |
| ISM-2018 | RPKI route origin validation on BGP routers |
| ISM-2019 | ASD assessment of TOP SECRET gateways |
Guidelines for information technology equipment
| Code | Title |
|---|---|
| ISM-0293 | Classifying IT equipment |
| ISM-0294 | Labelling IT equipment |
| ISM-0296 | Labelling high assurance IT equipment |
| ISM-0305 | Cleared technicians for on-site maintenance |
| ISM-0306 | Escorting uncleared technicians |
| ISM-0307 | Sanitisation before uncleared maintenance |
| ISM-0310 | Approved facilities for off-site repair |
| ISM-0311 | Sanitising media within IT equipment |
| ISM-0312 | Returning overseas AUSTEO and AGAO equipment |
| ISM-0313 | IT equipment sanitisation processes and procedures |
| ISM-0315 | Destroying high assurance IT equipment |
| ISM-0316 | Release of IT equipment to the public domain |
| ISM-0317 | Printing random text on cartridges and drums |
| ISM-0318 | Destroying unsanitisable cartridges and drums |
| ISM-0321 | Disposing of emanation security equipment |
| ISM-0336 | Networked IT equipment register |
| ISM-1076 | Sanitising monitors with minor burn-in |
| ISM-1079 | Approval for high assurance maintenance |
| ISM-1217 | Removing labels before disposal |
| ISM-1218 | Sanitising overseas AUSTEO and AGAO equipment |
| ISM-1219 | Inspecting MFD drums and transfer rollers |
| ISM-1220 | Inspecting printer and MFD platens |
| ISM-1221 | Checking paper paths for trapped pages |
| ISM-1222 | Destroying unsanitisable displays |
| ISM-1223 | Sanitising memory in network devices |
| ISM-1534 | Destroying printer ribbons |
| ISM-1550 | IT equipment disposal processes and procedures |
| ISM-1551 | IT equipment management policy |
| ISM-1598 | Inspection after maintenance and repair |
| ISM-1599 | Handling IT equipment |
| ISM-1741 | IT equipment destruction processes and procedures |
| ISM-1742 | Destroying unsanitisable IT equipment |
| ISM-1858 | Hardening IT equipment using ASD and vendor guidance |
| ISM-1869 | Non-networked IT equipment register |
| ISM-1913 | Approved configurations for IT equipment |
Guidelines for media
| Code | Title |
|---|---|
| ISM-0323 | Classifying media by data held |
| ISM-0325 | Reclassifying media to a higher classification |
| ISM-0330 | Reclassifying media to a lower classification |
| ISM-0332 | Labelling media with protective markings |
| ISM-0337 | Using media only with authorised systems |
| ISM-0347 | Write-once media for cross-domain transfers |
| ISM-0348 | Media sanitisation processes and procedures |
| ISM-0350 | Destroying media that cannot be sanitised |
| ISM-0351 | Removing power from volatile media |
| ISM-0352 | Overwriting SECRET and TOP SECRET volatile media |
| ISM-0354 | Overwriting non-volatile magnetic media |
| ISM-0356 | Classification of sanitised magnetic media |
| ISM-0357 | Sanitising EPROM media |
| ISM-0358 | Classification of sanitised EPROM and EEPROM |
| ISM-0359 | Overwriting flash memory media |
| ISM-0360 | Classification of sanitised flash media |
| ISM-0361 | Degausser field strength and orientation |
| ISM-0362 | Following degausser manufacturer directions |
| ISM-0363 | Media destruction processes and procedures |
| ISM-0368 | Particle size for destroyed media |
| ISM-0370 | Cleared supervision of media destruction |
| ISM-0371 | Supervising media to the point of destruction |
| ISM-0372 | Two-person supervision of accountable media destruction |
| ISM-0373 | Supervisor duties and destruction certificates |
| ISM-0374 | Media disposal process and procedures |
| ISM-0375 | Formal decision to release media |
| ISM-0378 | Removing labels and markings before disposal |
| ISM-0831 | Handling media by sensitivity or classification |
| ISM-0835 | TOP SECRET volatile media after sanitisation |
| ISM-0836 | EEPROM overwrite and verification |
| ISM-0839 | Keeping accountable media destruction in-house |
| ISM-0840 | NAID AAA certified destruction services |
| ISM-0947 | Sanitising media after cross-domain transfers |
| ISM-1059 | Encrypting data on media |
| ISM-1065 | Resetting HPA and DCO before drive sanitisation |
| ISM-1067 | ATA secure erase for growth defects table |
| ISM-1160 | Using NSA-evaluated degaussers |
| ISM-1359 | Removable media usage policy |
| ISM-1361 | SCEC or ASIO-approved destruction equipment |
| ISM-1517 | Destroying microfiche and microfilm |
| ISM-1549 | Media management policy |
| ISM-1600 | Sanitising new media before first use |
| ISM-1641 | Physical damage to media after degaussing |
| ISM-1642 | Sanitising media before reuse in another domain |
| ISM-1713 | Removable media register |
| ISM-1722 | Destroying electrostatic memory devices |
| ISM-1723 | Destroying magnetic floppy disks |
| ISM-1724 | Destroying magnetic hard disks |
| ISM-1725 | Destroying magnetic tapes |
| ISM-1726 | Destroying optical disks |
| ISM-1727 | Destroying semiconductor memory |
| ISM-1728 | Handling SECRET media waste particles |
| ISM-1729 | Handling TOP SECRET media waste particles |
| ISM-1735 | Destroying media that fails sanitisation |
Guidelines for networking
| Code | Title |
|---|---|
| ISM-0385 | Functional separation between servers |
| ISM-0516 | Content of network diagrams |
| ISM-0518 | Maintaining network documentation |
| ISM-0520 | Blocking unauthorised network devices |
| ISM-0521 | Disabling unused IPv6 on dual-stack devices |
| ISM-0529 | VLANs not used between security domains |
| ISM-0530 | Administering VLAN devices from trusted domain |
| ISM-0534 | Disabling unused physical network ports |
| ISM-0535 | No shared trunks between security domains |
| ISM-0536 | Segregating public wireless networks |
| ISM-1006 | Protecting network management traffic |
| ISM-1013 | RF shielding for classified wireless |
| ISM-1028 | NIDS or NIPS at external gateways |
| ISM-1030 | NIDS placement and firewall rule alerts |
| ISM-1178 | Limiting network documentation to third parties |
| ISM-1181 | Network zones by criticality |
| ISM-1182 | Restricting traffic between network segments |
| ISM-1186 | IPv6-capable network security appliances |
| ISM-1304 | Default network device credentials |
| ISM-1311 | Disabling SNMP versions 1 and 2 |
| ISM-1312 | Default SNMP community strings |
| ISM-1314 | Wi-Fi Alliance certified devices |
| ISM-1315 | Disabling wireless admin interface access |
| ISM-1316 | Changing default SSIDs |
| ISM-1317 | SSIDs that do not identify the organisation |
| ISM-1318 | Keeping SSID broadcasting enabled |
| ISM-1319 | No static addressing on wireless networks |
| ISM-1320 | Not relying on MAC address filtering |
| ISM-1321 | 802.1X with EAP-TLS only |
| ISM-1322 | Evaluated 802.1X components |
| ISM-1323 | Certificates for wireless devices and users |
| ISM-1324 | Certificate generation using evaluated CA or HSM |
| ISM-1327 | Protecting wireless authentication certificates |
| ISM-1330 | PMK caching period limit |
| ISM-1332 | WPA3-Enterprise 192-bit mode |
| ISM-1334 | Frequency separation between wireless networks |
| ISM-1335 | Protecting wireless management frames |
| ISM-1338 | Low-power access point deployment |
| ISM-1364 | Separate interfaces for different domain VLANs |
| ISM-1428 | Disabling IPv6 tunnelling on devices |
| ISM-1429 | Blocking IPv6 tunnelling at boundaries |
| ISM-1430 | Stateful DHCPv6 with central lease logging |
| ISM-1431 | Discussing DoS mitigation with cloud providers |
| ISM-1432 | Registrar locking for domain names |
| ISM-1436 | Segregating critical online services |
| ISM-1437 | Cloud-based hosting of online services |
| ISM-1438 | CDNs for high availability website hosting |
| ISM-1439 | Protecting origin servers behind CDNs |
| ISM-1454 | Encapsulating RADIUS communications with IPsec or TLS |
| ISM-1479 | Minimising server-to-server communications |
| ISM-1532 | VLANs not used with public network infrastructure |
| ISM-1577 | Segregating networks from service provider networks |
| ISM-1579 | Verifying CSP dynamic scaling for demand spikes |
| ISM-1580 | Automatic failover between availability zones |
| ISM-1581 | Real-time capacity and availability monitoring |
| ISM-1627 | Blocking inbound anonymity network connections |
| ISM-1628 | Blocking outbound anonymity network connections |
| ISM-1710 | Hardening wireless access point settings |
| ISM-1711 | EAP-TLS user identity confidentiality |
| ISM-1712 | Fast BSS transition (802.11r) restrictions |
| ISM-1781 | Encrypting all data over network infrastructure |
| ISM-1782 | Protective DNS for malicious domains |
| ISM-1800 | Flashing network devices with trusted firmware |
| ISM-1801 | Monthly restarts of network devices |
| ISM-1863 | Management interfaces not exposed to the internet |
| ISM-1912 | Device settings in network documentation |
| ISM-1962 | Disabling SMB version 1 |
| ISM-1963 | Logging events from internet-facing network devices |
| ISM-1964 | Logging events from internal network devices |
| ISM-2017 | Encrypting DNS traffic where supported |
| ISM-2068 | Limiting internet access for networked devices |
Guidelines for personnel security
| Code | Title |
|---|---|
| ISM-0078 | Australian control of AUSTEO and AGAO systems |
| ISM-0252 | Annual cyber security awareness training content |
| ISM-0258 | Web usage policy |
| ISM-0405 | Validating unprivileged access requests |
| ISM-0407 | Secure record of user access authorisations |
| ISM-0409 | Foreign national access to AUSTEO and REL systems |
| ISM-0411 | Foreign national access to AGAO systems |
| ISM-0414 | Unique identification of system users |
| ISM-0415 | Controlling shared user accounts |
| ISM-0420 | Identifying foreign nationals by nationality |
| ISM-0430 | Same-day removal of access |
| ISM-0432 | Documenting access requirements in the SSP |
| ISM-0434 | Screening and clearances before access |
| ISM-0435 | Briefings before system access |
| ISM-0441 | Restricting temporary access to required data |
| ISM-0443 | No temporary access to caveated or SCI systems |
| ISM-0445 | Dedicated privileged user accounts |
| ISM-0446 | Foreign national privileged access to AUSTEO and REL systems |
| ISM-0447 | Foreign national privileged access to AGAO systems |
| ISM-0817 | Reporting suspicious contact via online services |
| ISM-0820 | Not posting work information online |
| ISM-0821 | Posting personal information to online services |
| ISM-0824 | Sending and receiving files via online services |
| ISM-0854 | Accessing AUSTEO and AGAO data from authorised facilities |
| ISM-1146 | Separate work and personal online accounts |
| ISM-1175 | Blocking internet, email and web for privileged accounts |
| ISM-1263 | Unique privileged accounts per server application |
| ISM-1404 | Disabling unprivileged access after 45 days inactivity |
| ISM-1507 | Validating privileged access requests |
| ISM-1508 | Least privilege for privileged access |
| ISM-1509 | Central logging of privileged access events |
| ISM-1565 | Annual tailored privileged user training |
| ISM-1566 | Central logging of unprivileged access |
| ISM-1583 | Identification of contractor personnel |
| ISM-1591 | Removing access for detected malicious activity |
| ISM-1610 | Documenting and testing emergency access |
| ISM-1611 | Break glass use only when normal authentication fails |
| ISM-1612 | Break glass use for authorised activities |
| ISM-1613 | Central logging of break glass use |
| ISM-1614 | Changing break glass credentials after use |
| ISM-1615 | Testing break glass accounts after credential changes |
| ISM-1647 | Disabling privileged access after 12 months |
| ISM-1648 | Disabling privileged access after 45 days inactivity |
| ISM-1649 | Just-in-time administration of systems |
| ISM-1650 | Logging privileged account and group management |
| ISM-1740 | Business email compromise awareness for payment staff |
| ISM-1852 | Least privilege for unprivileged access |
| ISM-1864 | System usage policy |
| ISM-1865 | Agreement to system usage policies before access |
| ISM-1883 | Limiting privileged accounts authorised for online services |
| ISM-2022 | Cyber security awareness training register |
| ISM-2071 | Social engineering advice for account support staff |
| ISM-2074 | General-purpose AI usage policy |
Guidelines for physical security
| Code | Title |
|---|---|
| ISM-0161 | Securing IT equipment and media |
| ISM-0164 | Preventing observation by unauthorised people |
| ISM-0225 | Prohibiting unauthorised RF and IR devices |
| ISM-0810 | Security zones for classified systems |
| ISM-0813 | Securing server rooms and containers |
| ISM-0829 | Detecting unauthorised RF devices |
| ISM-1053 | Zoned rooms for classified infrastructure |
| ISM-1074 | Controlling keys to secure areas |
| ISM-1296 | Protecting network devices in public areas |
| ISM-1530 | Security containers for classified infrastructure |
| ISM-1543 | Authorised RF and IR device register |
| ISM-1973 | Securing non-classified systems |
| ISM-1974 | Securing non-classified server rooms |
| ISM-1975 | Security containers for non-classified equipment |
| ISM-2007 | Authorised medical device register |
| ISM-2008 | Criteria for authorising medical devices |
| ISM-2009 | Prohibiting unauthorised medical devices |
| ISM-2069 | Authorised photographic and recording device register |
| ISM-2070 | Prohibiting unauthorised recording devices |
Guidelines for procurement and outsourcing
| Code | Title |
|---|---|
| ISM-0072 | Documenting data security requirements in contracts |
| ISM-0141 | Incident reporting obligations for providers |
| ISM-1073 | Contracts before provider system access |
| ISM-1395 | Provider and subcontractor data protection |
| ISM-1451 | Data types and ownership in contracts |
| ISM-1452 | Supply chain risk assessment |
| ISM-1529 | Cloud models for SECRET and TOP SECRET |
| ISM-1567 | Excluding high risk suppliers |
| ISM-1568 | Suppliers committed to product security |
| ISM-1569 | Shared responsibility model |
| ISM-1570 | IRAP assessment of cloud providers |
| ISM-1571 | Right to verify provider compliance |
| ISM-1572 | Data locations and change notification |
| ISM-1573 | Access to provider logs |
| ISM-1574 | Portable data storage in contracts |
| ISM-1575 | Notice of service cessation |
| ISM-1576 | Notification of unauthorised provider access |
| ISM-1631 | Identifying suppliers for systems |
| ISM-1632 | Suppliers with a strong security track record |
| ISM-1637 | Outsourced cloud service register |
| ISM-1638 | Cloud service register contents |
| ISM-1736 | Managed service register |
| ISM-1737 | Managed service register contents |
| ISM-1738 | Exercising the right to verify compliance |
| ISM-1785 | Supplier relationship management policy |
| ISM-1786 | Approved supplier list |
| ISM-1787 | Sourcing from approved suppliers |
| ISM-1788 | Alternative suppliers for critical products |
| ISM-1789 | Spares for critical equipment |
| ISM-1790 | Maintaining integrity during delivery |
| ISM-1791 | Integrity checks at acceptance |
| ISM-1792 | Authenticity checks at acceptance |
| ISM-1793 | IRAP assessment of managed service providers |
| ISM-1794 | Notice of provider arrangement changes |
| ISM-1804 | Break clauses for security failures |
| ISM-1882 | Suppliers committed to transparency |
| ISM-1971 | ASD assessment of TOP SECRET managed services |
| ISM-1972 | ASD assessment of TOP SECRET cloud services |
Guidelines for software development
| Code | Title |
|---|---|
| ISM-0400 | Segregating software environments |
| ISM-0401 | Secure by Design in software development |
| ISM-0402 | SAST, DAST and SCA testing |
| ISM-0971 | Using the OWASP ASVS |
| ISM-1238 | Threat modelling in the development life cycle |
| ISM-1239 | Robust web application frameworks |
| ISM-1240 | Validating and sanitising internet input |
| ISM-1241 | Output encoding in web applications |
| ISM-1275 | Filtering database queries |
| ISM-1276 | Parameterised queries and stored procedures |
| ISM-1278 | Limiting database error information |
| ISM-1419 | Developing only in development environments |
| ISM-1420 | Production data in non-production environments |
| ISM-1422 | Protecting the authoritative software source |
| ISM-1424 | Web security policy response headers |
| ISM-1536 | Central logging of database queries and errors |
| ISM-1552 | HTTPS-only web application content |
| ISM-1616 | Vulnerability disclosure program |
| ISM-1717 | Hosting security.txt files for website domains |
| ISM-1730 | Producing a software bill of materials |
| ISM-1754 | Timely resolution of software vulnerabilities |
| ISM-1755 | Vulnerability disclosure policy |
| ISM-1756 | Vulnerability disclosure processes and procedures |
| ISM-1780 | SecDevOps practices for software development |
| ISM-1796 | Signing executable content |
| ISM-1797 | Signing installers, patches and updates |
| ISM-1798 | Secure configuration guidance for consumers |
| ISM-1816 | Protecting the authoritative source from modification |
| ISM-1817 | Authenticating internet-facing APIs that expose data |
| ISM-1818 | Authenticating internet-facing APIs that modify data |
| ISM-1849 | Using the OWASP Top 10 Proactive Controls |
| ISM-1850 | Mitigating the OWASP Top 10 |
| ISM-1851 | Mitigating the OWASP API Security Top 10 |
| ISM-1908 | Public disclosure of software vulnerabilities |
| ISM-1909 | Root cause analysis of vulnerabilities |
| ISM-1910 | Central logging of internet-facing API calls |
| ISM-1911 | Central logging of software events |
| ISM-1922 | Using the OWASP MASVS |
| ISM-1924 | Detecting and mitigating prompt injection |
| ISM-2013 | Authenticating internal APIs that modify data |
| ISM-2014 | Authenticating internal APIs that expose data |
| ISM-2015 | Central logging of internal API calls |
| ISM-2016 | Validating input received over local networks |
| ISM-2023 | Establishing an authoritative source for software |
| ISM-2024 | Using the authoritative source for all development |
| ISM-2025 | Issue tracking for development tasks |
| ISM-2026 | Scanning software artefacts for malicious content |
| ISM-2027 | Verifying software artefacts before import |
| ISM-2028 | Testing software artefacts for known weaknesses |
| ISM-2029 | Restricting third-party libraries to trustworthy sources |
| ISM-2030 | Scanning commits for secrets and keys |
| ISM-2031 | Using security features of build tools |
| ISM-2032 | Completing automated testing before builds |
| ISM-2033 | Documenting software security requirements |
| ISM-2034 | Documenting security design decisions |
| ISM-2035 | Security roles in the development life cycle |
| ISM-2036 | Security responsibilities of software developers |
| ISM-2037 | Secure development training for developers |
| ISM-2038 | Developer cyber security skills register |
| ISM-2039 | Reviewing the software threat model |
| ISM-2040 | Secure programming practices for chosen languages |
| ISM-2041 | Memory-safe programming languages and practices |
| ISM-2042 | Secure by Default principles |
| ISM-2043 | Readable and maintainable software architecture |
| ISM-2044 | No default credentials in software |
| ISM-2045 | Backwards compatibility without weakening security |
| ISM-2046 | Logging and permissions for user impersonation |
| ISM-2047 | Notifying users of authentication factor resets |
| ISM-2048 | Preventing users altering their own privileges |
| ISM-2049 | Re-authentication after permission or credential changes |
| ISM-2050 | Validating digital signatures and revocation |
| ISM-2051 | Software event log generation |
| ISM-2052 | Protecting sensitive data in event logs |
| ISM-2053 | Software end of life procedures |
| ISM-2054 | Using third-party software bills of materials |
| ISM-2055 | Using third-party build provenance |
| ISM-2056 | Producing software build provenance |
| ISM-2057 | Documenting and testing input validation rules |
| ISM-2058 | Validating data before deserialisation |
| ISM-2059 | Restricting and scanning file uploads |
| ISM-2060 | Code reviews for secure design and programming |
| ISM-2061 | Security peer reviews of critical components |
| ISM-2062 | Positive and negative unit and integration testing |
| ISM-2063 | Session cookie security flags |
| ISM-2064 | Signed opaque bearer tokens in session cookies |
| ISM-2065 | Entropy of unsigned session identifiers |
| ISM-2066 | Server-side session management |
| ISM-2067 | Single Logout for Single Sign On |
| ISM-2072 | Non-executable AI model file formats |
| ISM-2082 | Using third-party cryptographic bills of materials |
| ISM-2083 | Producing a cryptographic bill of materials |
| ISM-2084 | AI model and system cards |
| ISM-2085 | Hiding exact AI model confidence scores |
| ISM-2086 | Verifying AI model source and integrity |
| ISM-2087 | Verifying AI training data source and integrity |
| ISM-2088 | Validating AI training data |
| ISM-2089 | Monitoring AI model performance metrics |
| ISM-2090 | Rate limiting AI inference queries |
| ISM-2091 | Resource limits for AI models |
| ISM-2092 | Fine-grained permissions for AI applications |
| ISM-2093 | Role-based access for AI applications |
| ISM-2094 | Content filtering for AI output |
| ISM-2102 | Periodic weakness testing of software artefacts |
| ISM-2103 | Consent for training on organisational data |
Guidelines for system hardening
| Code | Title |
|---|---|
| ISM-0341 | Disabling automatic execution for removable media |
| ISM-0343 | Blocking writes to removable media |
| ISM-0345 | Disabling DMA-capable interfaces |
| ISM-0380 | Removing unneeded operating system functionality |
| ISM-0382 | Preventing removal of approved applications |
| ISM-0383 | Default operating system accounts and credentials |
| ISM-0408 | Logon banner for security responsibilities |
| ISM-0417 | Single-factor authentication fallback |
| ISM-0418 | Keeping physical credentials apart from systems |
| ISM-0421 | Single-factor password length for PROTECTED systems |
| ISM-0422 | Single-factor password length for TOP SECRET systems |
| ISM-0428 | Session lock configuration |
| ISM-0582 | Centralised Microsoft Windows event logging |
| ISM-0843 | Application control on workstations |
| ISM-0846 | Preventing bypass of application control |
| ISM-0853 | Daily session termination and workstation restart |
| ISM-0938 | Selecting secure-by-design user application vendors |
| ISM-0955 | Application control rule types |
| ISM-0974 | Multi-factor authentication for unprivileged users |
| ISM-1034 | HIPS or EDR on critical servers |
| ISM-1055 | Disabling LAN Manager and NTLM |
| ISM-1173 | Multi-factor authentication for privileged users |
| ISM-1227 | Randomly generated credentials for user accounts |
| ISM-1235 | Restricting add-ons, extensions and plug-ins |
| ISM-1245 | Removing server application installation files |
| ISM-1246 | Hardening server applications |
| ISM-1247 | Removing unneeded server application functionality |
| ISM-1249 | Running server applications with minimum privileges |
| ISM-1250 | Limiting server application file system access |
| ISM-1260 | Default server application accounts and credentials |
| ISM-1341 | HIPS or EDR on workstations |
| ISM-1392 | Protecting folders used in path rules |
| ISM-1401 | Acceptable multi-factor authentication factors |
| ISM-1402 | Protecting stored credentials |
| ISM-1403 | Account lockout after failed logons |
| ISM-1406 | Standard Operating Environments |
| ISM-1407 | Operating system release currency |
| ISM-1408 | Using 64-bit operating systems |
| ISM-1409 | Hardening operating systems |
| ISM-1412 | Hardening web browsers |
| ISM-1416 | Host-based software firewall |
| ISM-1417 | Antivirus application configuration |
| ISM-1418 | Blocking reads from removable media |
| ISM-1460 | Secure-by-design vendors for isolation mechanisms |
| ISM-1461 | Shared hardware for SECRET and TOP SECRET environments |
| ISM-1467 | User application release currency |
| ISM-1470 | Removing unneeded user application functionality |
| ISM-1471 | Publisher and product names in certificate rules |
| ISM-1483 | Internet-facing server application release currency |
| ISM-1485 | Blocking web advertisements in browsers |
| ISM-1486 | Blocking Java in web browsers |
| ISM-1487 | Write access to Trusted Locations |
| ISM-1488 | Blocking macros from the internet |
| ISM-1489 | Locking Microsoft Office macro security settings |
| ISM-1490 | Application control on internet-facing servers |
| ISM-1491 | Blocking script execution engines for unprivileged users |
| ISM-1492 | Operating system exploit protection |
| ISM-1504 | Multi-factor authentication for online services |
| ISM-1505 | Multi-factor authentication for data repositories |
| ISM-1542 | Blocking Object Linking and Embedding packages |
| ISM-1544 | Microsoft recommended application blocklist |
| ISM-1546 | Authenticating users before access |
| ISM-1557 | Single-factor password length for SECRET systems |
| ISM-1558 | Constructing word-sequence passphrases |
| ISM-1559 | MFA password length for PROTECTED systems |
| ISM-1560 | MFA password length for SECRET systems |
| ISM-1561 | MFA password length for TOP SECRET systems |
| ISM-1582 | Annual validation of application control rulesets |
| ISM-1584 | Preventing users bypassing operating system security |
| ISM-1585 | Locking web browser security settings |
| ISM-1588 | Annual review of Standard Operating Environments |
| ISM-1590 | Changing compromised or exposed user credentials |
| ISM-1592 | Blocking user installation of unapproved applications |
| ISM-1593 | Identity verification before issuing credentials |
| ISM-1594 | Secure delivery of new credentials |
| ISM-1595 | Changing credentials on first use |
| ISM-1596 | No credential reuse across systems |
| ISM-1597 | Obscuring credentials during entry |
| ISM-1601 | Microsoft attack surface reduction rules |
| ISM-1603 | Disabling replay-susceptible authentication methods |
| ISM-1604 | Hardening software-based isolation mechanisms |
| ISM-1605 | Hardening the isolation host operating system |
| ISM-1606 | Patching isolation mechanisms and host operating systems |
| ISM-1607 | Monitoring and logging isolation mechanisms |
| ISM-1608 | Scanning third-party SOEs before use |
| ISM-1619 | Group Managed Service Accounts for service accounts |
| ISM-1620 | Protected Users group for privileged accounts |
| ISM-1621 | Disabling Windows PowerShell 2.0 |
| ISM-1622 | PowerShell Constrained Language Mode |
| ISM-1623 | Central logging of PowerShell events |
| ISM-1624 | Protected Event Logging for script block logs |
| ISM-1654 | Disabling Internet Explorer 11 |
| ISM-1655 | Disabling .NET Framework 3.5 |
| ISM-1656 | Application control on internal servers |
| ISM-1657 | Application control scope of file types |
| ISM-1658 | Application control for drivers |
| ISM-1659 | Microsoft vulnerable driver blocklist |
| ISM-1660 | Central logging of application control events |
| ISM-1667 | Blocking Office child process creation |
| ISM-1668 | Blocking Office creating executable content |
| ISM-1669 | Blocking Office code injection |
| ISM-1670 | Blocking PDF application child processes |
| ISM-1671 | Disabling Microsoft Office macros by default |
| ISM-1672 | Antivirus scanning of Office macros |
| ISM-1673 | Blocking Win32 API calls from macros |
| ISM-1674 | Restricting which Office macros can run |
| ISM-1675 | Blocking user enablement of untrusted macros |
| ISM-1676 | Annual validation of trusted macro publishers |
| ISM-1679 | Multi-factor authentication for sensitive online services |
| ISM-1680 | Multi-factor authentication for other online services |
| ISM-1681 | Multi-factor authentication for customer services |
| ISM-1682 | Phishing-resistant multi-factor authentication |
| ISM-1683 | Central logging of multi-factor authentication events |
| ISM-1685 | Managing break glass and service account credentials |
| ISM-1686 | Enabling Credential Guard |
| ISM-1743 | Operating system vendor selection |
| ISM-1745 | Secure boot and measured boot functionality |
| ISM-1746 | Protecting paths used by application control rules |
| ISM-1748 | Locking email client security settings |
| ISM-1749 | Limiting cached logon credentials |
| ISM-1795 | Minimum length for privileged local credentials |
| ISM-1806 | Changing default user application accounts |
| ISM-1823 | Locking Office productivity suite security settings |
| ISM-1824 | Locking PDF application security settings |
| ISM-1825 | Locking security product settings |
| ISM-1826 | Server application vendor selection |
| ISM-1827 | Dedicated accounts for administering domain controllers |
| ISM-1828 | Disabling Print Spooler on domain controllers |
| ISM-1829 | No passwords in Group Policy Preferences |
| ISM-1830 | Central logging of Active Directory services events |
| ISM-1832 | Service Principal Names only on service accounts |
| ISM-1833 | Minimum privileges for user accounts |
| ISM-1834 | No duplicate Service Principal Names |
| ISM-1835 | Privileged accounts marked sensitive and not delegated |
| ISM-1836 | Requiring Kerberos pre-authentication |
| ISM-1838 | Not using the UserPassword attribute |
| ISM-1839 | No passwords in readable account properties |
| ISM-1840 | No reversible encryption for passwords |
| ISM-1841 | Restricting who can add machines to domains |
| ISM-1842 | Dedicated accounts for joining machines to domains |
| ISM-1843 | Reviewing accounts with unconstrained delegation |
| ISM-1844 | No delegation trust for non-DC computer accounts |
| ISM-1845 | Removing group memberships from disabled accounts |
| ISM-1846 | Pre-Windows 2000 Compatible Access group membership |
| ISM-1847 | Changing KRBTGT account credentials |
| ISM-1848 | Replacing unsupported isolation mechanisms |
| ISM-1859 | Office productivity suite hardening |
| ISM-1860 | PDF application hardening |
| ISM-1861 | Local Security Authority protection |
| ISM-1870 | Application control in user profiles and temporary folders |
| ISM-1871 | Application control in all other locations |
| ISM-1872 | Phishing-resistant MFA for online services |
| ISM-1873 | Phishing-resistant MFA option for customers |
| ISM-1874 | Enforcing phishing-resistant MFA for customers |
| ISM-1875 | Scanning networks for cleartext credentials |
| ISM-1889 | Logging command line process creation |
| ISM-1890 | Checking macros before signing or trusting |
| ISM-1891 | Blocking macros without V3 signatures |
| ISM-1892 | MFA for own sensitive customer services |
| ISM-1893 | MFA for third-party customer services |
| ISM-1894 | Phishing-resistant MFA for data repositories |
| ISM-1895 | Logging single-factor authentication events |
| ISM-1896 | Memory integrity functionality |
| ISM-1897 | Remote Credential Guard |
| ISM-1914 | Approved operating system configurations |
| ISM-1915 | Approved user application configurations |
| ISM-1916 | Approved server application configurations |
| ISM-1919 | Disabling authentication protocols without MFA |
| ISM-1920 | Preventing MFA self-enrolment from untrustworthy devices |
| ISM-1926 | Dedicated roles for identity servers |
| ISM-1927 | Limiting privileged access to identity servers |
| ISM-1928 | Securing identity server backups |
| ISM-1929 | LDAP signing on domain controllers |
| ISM-1930 | Passwords in Group Policy Preferences |
| ISM-1931 | SID filtering for domain and forest trusts |
| ISM-1932 | Minimising service accounts with SPNs |
| ISM-1933 | DCSync permissions for SPN service accounts |
| ISM-1934 | Annual review of DCSync permissions |
| ISM-1935 | Unconstrained delegation on computer accounts |
| ISM-1936 | Not using sIDHistory |
| ISM-1937 | Weekly checks for sIDHistory |
| ISM-1938 | Domain Computers write permissions |
| ISM-1939 | Minimising highly-privileged group membership |
| ISM-1940 | Service accounts in privileged groups |
| ISM-1941 | Computer accounts in privileged groups |
| ISM-1942 | Domain Computers in privileged groups |
| ISM-1943 | Strong certificate mapping |
| ISM-1944 | Removing the EDITF_ATTRIBUTESUBJECTALTNAME2 flag |
| ISM-1945 | Enrollee supplied subject in templates |
| ISM-1946 | Write access to certificate templates |
| ISM-1947 | Authentication EKUs in certificate templates |
| ISM-1948 | CA manager approval for SAN templates |
| ISM-1949 | Dedicated AD FS administration account |
| ISM-1950 | Disabling soft matching after initial sync |
| ISM-1951 | Hard match takeover |
| ISM-1952 | Not synchronising privileged accounts |
| ISM-1953 | Built-in Administrator account credentials |
| ISM-1954 | Randomly generated privileged account credentials |
| ISM-1955 | Changing computer account credentials |
| ISM-1956 | Changing AD FS certificates |
| ISM-1957 | HSM protection of CA private keys |
| ISM-1976 | Logging events for macOS |
| ISM-1977 | Logging events for Linux |
| ISM-1978 | Logging internet-facing server applications |
| ISM-1979 | Logging internal server applications |
| ISM-1980 | Credential hint functionality |
| ISM-2010 | AES for SPN service accounts |
| ISM-2011 | Disabling weaker MFA options |
| ISM-2012 | Screen lock configuration |
| ISM-2076 | Security questions for authentication |
| ISM-2077 | Email for out-of-band authentication |
| ISM-2078 | Blocking common and compromised passwords |
| ISM-2079 | Maximum password length |
| ISM-2080 | Password complexity requirements |
| ISM-2081 | Characters supported in passwords |
Guidelines for system management
| Code | Title |
|---|---|
| ISM-0042 | System administration processes and procedures |
| ISM-0298 | Centralised and managed patching |
| ISM-0300 | Patching high assurance IT equipment |
| ISM-0304 | Removing unsupported applications |
| ISM-1143 | Patch management processes and procedures |
| ISM-1211 | Administration under change and configuration management |
| ISM-1380 | Separate privileged operating environments |
| ISM-1385 | Segregation of administrative infrastructure |
| ISM-1386 | Management traffic sourced from administrative infrastructure |
| ISM-1387 | Administration through jump servers |
| ISM-1493 | Maintaining software registers |
| ISM-1501 | Replacing unsupported operating systems |
| ISM-1510 | Digital preservation policy |
| ISM-1511 | Backups aligned to business criticality |
| ISM-1515 | Testing restoration to a common point |
| ISM-1547 | Data backup processes and procedures |
| ISM-1548 | Data restoration processes and procedures |
| ISM-1643 | Versions and patch histories in software registers |
| ISM-1687 | Privileged environments not virtualised within unprivileged ones |
| ISM-1688 | Unprivileged accounts denied privileged environment logon |
| ISM-1689 | Privileged accounts denied unprivileged environment logon |
| ISM-1690 | Non-critical patches for online services within two weeks |
| ISM-1691 | Patching user-facing applications within two weeks |
| ISM-1692 | Critical patches for user-facing applications within 48 hours |
| ISM-1693 | Patching other applications within one month |
| ISM-1694 | Non-critical OS patches for internet-facing systems within two weeks |
| ISM-1695 | OS patches for workstations and internal systems within one month |
| ISM-1696 | Critical OS patches for internal systems within 48 hours |
| ISM-1697 | Non-critical driver patches within one month |
| ISM-1698 | Daily vulnerability scanning of online services |
| ISM-1699 | Weekly scanning of office, browser, email, PDF and security products |
| ISM-1700 | Fortnightly scanning of other applications |
| ISM-1701 | Daily scanning of internet-facing OS |
| ISM-1702 | Fortnightly scanning of workstation and internal system OS |
| ISM-1703 | Fortnightly scanning for driver updates |
| ISM-1704 | Removing unsupported office, browser, email, PDF and security products |
| ISM-1705 | Privileged access to other users' backups |
| ISM-1706 | Privileged access to own backups |
| ISM-1707 | Privileged accounts prevented from altering backups |
| ISM-1708 | Backup administrators prevented from altering retained backups |
| ISM-1750 | Segregating administrative infrastructure by server tier |
| ISM-1751 | Non-critical OS patches for other IT equipment within one month |
| ISM-1752 | Fortnightly scanning of other IT equipment OS |
| ISM-1753 | Replacing unsupported internet-facing network devices |
| ISM-1807 | Fortnightly automated asset discovery |
| ISM-1808 | Up-to-date vulnerability database for scanning |
| ISM-1809 | Compensating controls for unsupported systems |
| ISM-1810 | Synchronised backups for a common restore point |
| ISM-1811 | Secure and resilient retention of backups |
| ISM-1812 | Unprivileged access to other users' backups |
| ISM-1813 | Unprivileged access to own backups |
| ISM-1814 | Unprivileged accounts prevented from altering backups |
| ISM-1876 | Critical patches for online services within 48 hours |
| ISM-1877 | Critical OS patches for internet-facing systems within 48 hours |
| ISM-1878 | Critical OS patches for other IT equipment within 48 hours |
| ISM-1879 | Critical driver patches within 48 hours |
| ISM-1898 | Use of Secure Admin Workstations |
| ISM-1899 | Blocking inbound connections to administrative infrastructure |
| ISM-1900 | Fortnightly scanning for firmware updates |
| ISM-1901 | Non-critical patches for user-facing applications within two weeks |
| ISM-1902 | Non-critical OS patches for internal systems within one month |
| ISM-1903 | Critical firmware patches within 48 hours |
| ISM-1904 | Non-critical firmware patches within one month |
| ISM-1905 | Removing unsupported online services |
| ISM-1921 | Assessing compromise likelihood for exploited vulnerabilities |
| ISM-1958 | DCSync-permissioned accounts denied unprivileged logon |
| ISM-1981 | Replacing unsupported internal network devices |
| ISM-1982 | Replacing unsupported networked IT equipment |
Guidelines for system monitoring
| Code | Title |
|---|---|
| ISM-0109 | Analysing workstation event logs |
| ISM-0580 | Event logging policy |
| ISM-0585 | Details captured for each logged event |
| ISM-0988 | Consistent time source for event logs |
| ISM-1228 | Analysing cyber security events for incidents |
| ISM-1405 | Implementing a centralised event logging facility |
| ISM-1815 | Protecting event logs from modification and deletion |
| ISM-1906 | Analysing internet-facing server event logs |
| ISM-1907 | Analysing internal server event logs |
| ISM-1959 | Consistent structured event log format |
| ISM-1960 | Analysing internet-facing network device event logs |
| ISM-1961 | Analysing internal network device event logs |
| ISM-1983 | Timely forwarding to the centralised facility |
| ISM-1984 | Encrypting event logs in transit |
| ISM-1985 | Protecting event logs from unauthorised access |
| ISM-1986 | Analysing critical server event logs |
| ISM-1987 | Analysing security product event logs |
| ISM-1988 | Searchable retention for 12 months |
| ISM-1989 | Retention under AFDA Express requirements |
Your Compliance Coverage
If you comply with Australian Information Security Manual, you already cover:
ISO 27002:2022
30%
327 controls mapped
Compare →New Zealand Information Security Manual (NZISM)
21%
226 controls mapped
Compare →CIS Controls v8
21%
222 controls mapped
Compare →+ 5 more: NIST Cybersecurity Framework 2.0 (19%), ACSC Essential Eight (12%)
See all 8 mapped frameworks ↓Maps to 8 other frameworks
Coverage is not the same as your position
This page shows what Australian Information Security Manual overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.
The Compliance Position Diagnostic, $5,000 fixed, ten business daysWhat is Australian Information Security Manual and who does it apply to?
Australian Information Security Manual is a compliance framework from Australia with 22 domains and 1081 controls. ACSC Information Security Manual. Australian Government cybersecurity controls baseline. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Australian Information Security Manual actually require?
Australian Information Security Manual has 1081 controls organised across 22 domains. The largest domains are Guidelines for system hardening (215 controls), Guidelines for software development (104 controls), Guidelines for cryptography (73 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Australian Information Security Manual do I already cover?
Australian Information Security Manual maps to 8 other compliance frameworks. The top mapping partners are ISO 27002:2022 (30% coverage), New Zealand Information Security Manual (NZISM) (21% coverage), CIS Controls v8 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Australian Information Security Manual?
Start your Australian Information Security Manual compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Information Security Manual requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 1081 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.
Get Started Free →Free forever — no credit card required