Back to Frameworks

Australian Information Security Manual

Australia
vISM March 2026 (OSCAL v2026.03.24)
22 domains
1081 controls

ACSC Information Security Manual. Australian Government cybersecurity controls baseline.

Verified

Australian Information Security Manual is a compliance framework from Australia with 22 domains and 1081 controls that map to 8 other frameworks. The largest domains are Guidelines for system hardening (215 controls), Guidelines for software development (104 controls), Guidelines for cryptography (73 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit cyber.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (22)

Guidelines for communications infrastructure

53 controls
Controls in the Guidelines for communications infrastructure domain of Australian Information Security Manual — 53 controls
CodeTitle
ISM-0181Cabling infrastructure standards
ISM-0187SECRET cable bundles and conduits
ISM-0194Sealing plastic and TOP SECRET conduit joints
ISM-0195Tamper-evident seals on TOP SECRET reticulation covers
ISM-0198Penetrating TOP SECRET audio secure rooms
ISM-0201Labelling TOP SECRET conduits
ISM-0206Cable labelling processes and procedures
ISM-0208Cable register contents
ISM-0211Cable register maintenance and verification
ISM-0213Terminating cables on patch panels
ISM-0216TOP SECRET patch panels in dedicated cabinets
ISM-0217Shared cabinets under spatial constraints
ISM-0218TOP SECRET fibre-optic fly leads over five metres
ISM-0246Timing of emanation security risk assessments
ISM-0249Emanation assessments for mobile and deployable systems
ISM-0250Electromagnetic interference and compatibility standards
ISM-0926Colours for lower-classified cables
ISM-1095Labelling wall outlet boxes
ISM-1096Labelling cables at each end
ISM-1098Terminating SECRET cables in cabinets
ISM-1100Terminating TOP SECRET cables in cabinets
ISM-1101TOP SECRET reticulation into server room cabinets
ISM-1102Terminating reticulation close to cabinets
ISM-1103TOP SECRET reticulation to cabinets outside server rooms
ISM-1105Contents of SECRET and TOP SECRET wall outlet boxes
ISM-1107Colours for lower-classified wall outlet boxes
ISM-1109Clear plastic wall outlet box covers
ISM-1111Use of fibre-optic cables
ISM-1112Inspectability of non-TOP SECRET cables
ISM-1114Separation within shared reticulation systems
ISM-1115Conduit for cables in walls
ISM-1116Visible gap between TOP SECRET cabinets
ISM-1119Full-length inspectability of TOP SECRET cables
ISM-1122TOP SECRET cables in wall penetrations
ISM-1123UPS-fed power for TOP SECRET equipment
ISM-1130Enclosed reticulation in shared facilities
ISM-1133TOP SECRET cables and party walls
ISM-1137Emanation assessments for fixed facilities
ISM-1164Clear covers for reticulation in shared facilities
ISM-1216Banding cables with non-conformant colours
ISM-1639Labelling building management cables
ISM-1640Labelling cables for foreign systems
ISM-1645Floor plan diagram maintenance
ISM-1646Floor plan diagram contents
ISM-1718SECRET cable colour
ISM-1719TOP SECRET cable colour
ISM-1720SECRET wall outlet box colour
ISM-1721TOP SECRET wall outlet box colour
ISM-1820Consistent cable colour per system
ISM-1821TOP SECRET cable bundles and conduits
ISM-1822Consistent wall outlet colour per system
ISM-1884Emanation security doctrine
ISM-1885Implementing emanation security mitigation advice

Guidelines for communications systems

33 controls
Controls in the Guidelines for communications systems domain of Australian Information Security Manual — 33 controls
CodeTitle
ISM-0229Permitted classification for telephone conversations
ISM-0230Awareness of non-secure telephone risks
ISM-0231Visual indication of connection type
ISM-0232Encrypting telephone traffic over external systems
ISM-0233Cordless telephone handsets and headsets
ISM-0235Speakerphones in TOP SECRET areas
ISM-0236Off-hook audio protection features
ISM-0245Connecting MFDs to digital telephone systems
ISM-0546Video-aware and voice-aware firewalls and proxies
ISM-0547Secure real-time transport protocol for calls
ISM-0548Secure session initiation protocol for calls
ISM-0549Separating voice and video from data traffic
ISM-0551IP phone registration and device hardening
ISM-0553Authentication on video conferencing networks
ISM-0554Two-way call authentication scheme
ISM-0555Authentication on IP telephony networks
ISM-0556Workstations connected to phones and video units
ISM-0558IP phones in public areas
ISM-0559Microphones and webcams in SECRET areas
ISM-0588Multifunction device usage policy
ISM-0589Scanning and copying documents on MFDs
ISM-0590Authentication strength for MFDs
ISM-0931Push-to-talk handsets and headsets
ISM-1014Individual logins for classified IP phones
ISM-1019Denial of service response plan for communications
ISM-1036Observing multifunction device use
ISM-1078Telephone system usage policy
ISM-1450Microphones and webcams in TOP SECRET areas
ISM-1562Video conferencing and IP telephony hardening
ISM-1805Content of the denial of service response plan
ISM-1854Authenticating to multifunction devices
ISM-1855Logging multifunction device use
ISM-2075Sending and receiving fax messages

Guidelines for cryptography

73 controls
Controls in the Guidelines for cryptography domain of Australian Information Security Manual — 73 controls
CodeTitle
ISM-0142Reporting cryptographic equipment compromise
ISM-0455Data recovery for encrypted data
ISM-0457Evaluated encryption for sensitive media
ISM-0459Full disk or partial encryption at rest
ISM-0460HACE for SECRET and TOP SECRET media
ISM-0462Handling authenticated encrypted equipment and media
ISM-0465Evaluated encryption for sensitive data in transit
ISM-0467HACE for SECRET and TOP SECRET data in transit
ISM-0469Encrypting data in transit
ISM-0471Using ASD-Approved Cryptographic Algorithms
ISM-0472Diffie-Hellman modulus of at least 2048 bits
ISM-0474ECDH key size and curve selection
ISM-0475ECDSA key size and curve selection
ISM-0476RSA modulus of at least 2048 bits
ISM-0477Separate RSA key pairs for signing and key transport
ISM-0479Avoiding Electronic Codebook Mode
ISM-0481Using ASD-Approved Cryptographic Protocols
ISM-0484Configuring the SSH daemon
ISM-0485Public key authentication for SSH
ISM-0487Restrictions on passwordless SSH logins
ISM-0488Forced commands for passwordless SSH access
ISM-0489Key caching limits for SSH-agent
ISM-0490Minimum S/MIME version
ISM-0494IPsec tunnel mode
ISM-0496Using ESP for IPsec
ISM-0498IPsec security association lifetimes
ISM-0499Complying with ASD COMSEC doctrine for HACE
ISM-0501Transporting keyed cryptographic equipment
ISM-0507Cryptographic key management processes
ISM-0994Preferring ECDH over DH
ISM-0998IPsec integrity algorithms
ISM-0999IPsec key establishment groups
ISM-1000Perfect Forward Secrecy for IPsec
ISM-1080Approved algorithms for media encryption
ISM-1091Changing compromised keying material
ISM-1139Using the latest TLS version
ISM-1233Using IKE version 2
ISM-1369Using AES-GCM for TLS
ISM-1370Server-initiated secure renegotiation for TLS
ISM-1372DH or ECDH for TLS key establishment
ISM-1373Excluding anonymous DH for TLS
ISM-1374SHA-2-based certificates for TLS
ISM-1375SHA-2 for TLS HMAC and PRF
ISM-1446Curve selection for elliptic curve cryptography
ISM-1448Ephemeral DH and ECDH for TLS
ISM-1449Protecting SSH private keys
ISM-1453Perfect Forward Secrecy for TLS
ISM-1506Disabling SSH version 1
ISM-1553Disabling TLS compression
ISM-1629Diffie-Hellman parameter selection
ISM-1759Diffie-Hellman modulus of at least 3072 bits
ISM-1761ECDH curves P-256, P-384 or P-521
ISM-1762ECDH curves P-384 or P-521
ISM-1763ECDSA curves P-256, P-384 or P-521
ISM-1764ECDSA curves P-384 or P-521
ISM-1765RSA modulus of at least 3072 bits
ISM-1766SHA-2 output size of at least 224 bits
ISM-1767SHA-2 output size of at least 256 bits
ISM-1768SHA-2 output size of at least 384 bits
ISM-1769AES key lengths
ISM-1770AES-192 or AES-256 key lengths
ISM-1771AES for IPsec encryption
ISM-1772IPsec pseudorandom function
ISM-1802Approved High Assurance Cryptographic Equipment
ISM-1917Procurement support for ML-DSA, ML-KEM and AES-256
ISM-1990FIPS 140-3 validation for ML-DSA and ML-KEM
ISM-1991ML-DSA parameter sets
ISM-1992Hedged ML-DSA signing
ISM-1993Restricting use of pre-hashed ML-DSA variants
ISM-1994Hash functions for pre-hashed ML-DSA
ISM-1995ML-KEM parameter sets for key encapsulation
ISM-1996Post-quantum traditional hybrid schemes
ISM-2073Post-quantum cryptography transition plan

Guidelines for cyber security documentation

11 controls
Controls in the Guidelines for cyber security documentation domain of Australian Information Security Manual — 11 controls
CodeTitle
ISM-0039Cyber security strategy
ISM-0041System security plan contents
ISM-0043Cyber security incident response plan contents
ISM-0047CISO and authorising officer document approvals
ISM-0888Annual review and currency statements
ISM-0912Change and configuration management plan
ISM-1163Continuous monitoring plan
ISM-1563Security assessment report
ISM-1564Plan of action and milestones
ISM-1602Communication of cyber security documentation
ISM-1739Approval of security architecture before development

Guidelines for cyber security incidents

22 controls
Controls in the Guidelines for cyber security incidents domain of Australian Information Security Manual — 22 controls
CodeTitle
ISM-0120Access to data sources and tools
ISM-0123Reporting incidents to the CISO
ISM-0125Maintaining a cyber security incident register
ISM-0133Handling and containing data spills
ISM-0137Legal advice before allowing intrusions to continue
ISM-0138Maintaining the integrity of evidence
ISM-0140Reporting incidents to ASD
ISM-0576Incident management policy and response plan
ISM-0917Handling malicious code infections
ISM-1213Traffic capture after intrusion remediation
ISM-1609Consulting system owners before allowing intrusions to continue
ISM-1625Insider threat mitigation program
ISM-1626Legal advice on insider threat program
ISM-1731Separate system for remediation planning
ISM-1732Coordinated remediation during a planned outage
ISM-1784Annual exercising of incident response plan
ISM-1803Incident register entry contents
ISM-1819Enacting cyber security incident response plans
ISM-1880Reporting incidents involving customer data
ISM-1881Reporting incidents not involving customer data
ISM-1969Treating malicious code before storage or transfer
ISM-1970Dedicated malware analysis environment

Guidelines for cyber security roles

42 controls
Controls in the Guidelines for cyber security roles domain of Australian Information Security Manual — 42 controls
CodeTitle
ISM-0009Identifying supplementary controls
ISM-0027Authorisation to operate from authorising officer
ISM-0714Appointment of a CISO
ISM-0717CISO oversight of cyber security personnel
ISM-0718CISO reporting to the board
ISM-0720Cyber security communications strategy
ISM-0724Cyber security metrics and KPIs
ISM-0725Cyber security steering committee
ISM-0726Coordinating security risk management
ISM-0731Oversight of cyber supply chain risk management
ISM-0732Dedicated cyber security budget
ISM-0733CISO awareness of all incidents
ISM-0734CISO contribution to continuity and recovery planning
ISM-0735Oversight of awareness training program
ISM-1071Designated system owners
ISM-1203Threat and risk assessment for each system
ISM-1478Oversight of cyber security program and compliance
ISM-1525Registering systems with the authorising officer
ISM-1526Continuous security monitoring by system owners
ISM-1587Annual reporting of system security status
ISM-1617Review and update of cyber security program
ISM-1618CISO oversight of incident response
ISM-1633System boundary, criticality and objectives
ISM-1634Selecting and tailoring controls
ISM-1635Implementing controls for each system
ISM-1636Security assessment by organisational or IRAP assessors
ISM-1918CISO reporting to audit and risk committee
ISM-1966Register of systems
ISM-1967ASD assessment of TOP SECRET systems
ISM-1968Authorisation to operate for TOP SECRET systems
ISM-1997Defining cyber security roles and responsibilities
ISM-1998Integrating cyber security across business functions
ISM-1999Aligning cyber strategy with business strategy
ISM-2000Cyber security briefings to the board
ISM-2001Championing a positive cyber security culture
ISM-2002Board cyber security literacy
ISM-2003Awareness of cyber workforce and skills gaps
ISM-2004Supporting cyber skills development
ISM-2005Understanding critical business assets
ISM-2006Board planning for major cyber security incidents
ISM-2020CISO oversight of cyber security workforce
ISM-2021System owner data minimisation practices

Guidelines for data transfers

14 controls
Controls in the Guidelines for data transfers domain of Australian Information Security Manual — 14 controls
CodeTitle
ISM-0657Scanning manually imported data
ISM-0660Full monthly verification of SECRET and TOP SECRET transfer logs
ISM-0661User accountability for data transfers
ISM-0663Data transfer processes and procedures
ISM-0664Review and authorisation of classified data exports
ISM-0665Trustworthy sources for classified systems
ISM-0669Signature validation and keyword checks on manual exports
ISM-0675Digital signing of authorised classified exports
ISM-1187Checking manual exports for unsuitable markings
ISM-1294Partial monthly verification of transfer logs
ISM-1535Preventing export of AUSTEO, AGAO and REL data
ISM-1586Logging all data imports and exports
ISM-1778Quarantining failed manual imports
ISM-1779Quarantining failed manual exports

Guidelines for database systems

13 controls
Controls in the Guidelines for database systems domain of Australian Information Security Manual — 13 controls
CodeTitle
ISM-0393Classifying databases and their contents
ISM-1243Maintaining and verifying a database register
ISM-1255Restricting database user actions by duty
ISM-1256File-based access controls on database files
ISM-1268Need-to-know enforcement for database contents
ISM-1269Separating database servers from web servers
ISM-1270Network segmentation of database servers
ISM-1271Restricting database server network communications
ISM-1272Disabling unneeded database networking
ISM-1273Segregating database servers across environments
ISM-1274Production database contents in non-production environments
ISM-1277Encrypting web to database communications
ISM-1537Database event logging

Guidelines for email

26 controls
Controls in the Guidelines for email domain of Australian Information Security Manual — 26 controls
CodeTitle
ISM-0264Email usage policy
ISM-0267Blocking non-approved webmail services
ISM-0269Caveated email and distribution lists
ISM-0270Protective markings on emails
ISM-0271No automatic insertion of protective markings
ISM-0272Restricting marking choices to authorised levels
ISM-0565Blocking emails with inappropriate markings
ISM-0567Preventing open relay email servers
ISM-0569Routing email through central gateways
ISM-0570Maintaining backup email gateways
ISM-0571Authenticated encrypted client email channels
ISM-0572Opportunistic TLS on email servers
ISM-0574SPF records for organisational domains
ISM-0861DKIM signing of outgoing email
ISM-1023Notifying senders and recipients of blocked email
ISM-1024Verified senders for undeliverable notifications
ISM-1026Verifying DKIM signatures on incoming email
ISM-1027Distribution list handling of external DKIM
ISM-1089Preventing marking downgrades on replies
ISM-1151SPF verification of incoming email
ISM-1183Hard fail SPF records
ISM-1234Filtering email bodies and attachments
ISM-1502Blocking external email using internal domains
ISM-1540DMARC reject policy for organisational domains
ISM-1589MTA-STS for email transport
ISM-1799Rejecting incoming email failing DMARC

Guidelines for enterprise mobility

50 controls
Controls in the Guidelines for enterprise mobility domain of Australian Information Security Manual — 50 controls
CodeTitle
ISM-0240Paging, SMS and messaging apps for sensitive data
ISM-0682Bluetooth on SECRET and TOP SECRET mobile devices
ISM-0687ASD-approved platforms for classified mobility
ISM-0694Private devices and classified systems
ISM-0701Mobile device emergency sanitisation procedures
ISM-0702Cryptographic zeroise in emergency sanitisation
ISM-0705Disabling VPN split tunnelling
ISM-0863Blocking unapproved application installation
ISM-0864Locking mobile device security settings
ISM-0866Viewing classified data in public
ISM-0869Encrypting mobile device storage
ISM-0870Securing mobile devices when not in use
ISM-0871Supervising mobile devices in use
ISM-0874Internet access via organisational gateways
ISM-1082Mobile device usage policy
ISM-1083Advising permitted classification for mobile communications
ISM-1084Transporting mobile devices in approved containers
ISM-1085Encrypting mobile data over public networks
ISM-1088Reporting potential mobile device compromise
ISM-1145Privacy filters on classified mobile devices
ISM-1195Common Criteria evaluated MDM solutions
ISM-1196Bluetooth discoverability on mobile devices
ISM-1198Pairing only with intended Bluetooth devices
ISM-1199Removing unneeded Bluetooth pairings
ISM-1200Bluetooth Secure Connections and Numeric Comparison
ISM-1297Legal advice before allowing privately-owned devices
ISM-1298Overseas travel privacy and security briefing
ISM-1299Mobile device security precautions for personnel
ISM-1300Actions after overseas travel
ISM-1366Applying security updates to mobile devices
ISM-1400Separating data on privately-owned devices
ISM-1482Separating data on organisation-owned devices
ISM-1533Mobile device management policy
ISM-1554Travel to high or extreme risk countries
ISM-1555Preparing mobile devices before overseas travel
ISM-1556Actions after travel to high risk countries
ISM-1644Sensitive conversations in public locations
ISM-1866Preventing storage of classified data on private devices
ISM-1867Evaluated mobile platforms and ASD configuration
ISM-1868Removable media on SECRET and TOP SECRET mobile devices
ISM-1886Supervised mode for mobile devices
ISM-1887Remote locate and wipe for mobile devices
ISM-1888Password-based lock screens on mobile devices
ISM-2095Unapproved AI agents on privately-owned devices
ISM-2096Separating organisational and personal apps
ISM-2097Always on VPN for mobile devices
ISM-2098Blocking USB data transfer on mobile devices
ISM-2099Connecting mobile devices to vehicle infotainment
ISM-2100Viewing sensitive data near connected vehicles
ISM-2101Conversations within or near connected vehicles

Guidelines for evaluated products

5 controls
Controls in the Guidelines for evaluated products domain of Australian Information Security Manual — 5 controls
CodeTitle
ISM-0280Preferring PP-based evaluated products
ISM-0285Delivery procedures for evaluated products
ISM-0286Delivery of high assurance IT equipment
ISM-0289Operating products in evaluated configuration
ISM-0290Operating high assurance IT equipment

Guidelines for gateways

63 controls
Controls in the Guidelines for gateways domain of Australian Information Security Manual — 63 controls
CodeTitle
ISM-0100IRAP assessment of gateways
ISM-0260Web access through web proxies
ISM-0261Web proxy event logging
ISM-0263Transport Layer Security filtering
ISM-0591Using evaluated peripheral switches
ISM-0597Consulting ASD on Cross Domain Solutions
ISM-0610Cross Domain Solution user training
ISM-0611Minimum privileges for gateway administrators
ISM-0612Formal training for gateway administrators
ISM-0613Australian nationals administering AUSTEO and REL gateways
ISM-0616Separation of duties for gateway administration
ISM-0619User authentication to networks via gateways
ISM-0622IT equipment authentication via gateways
ISM-0626Cross Domain Solutions for SECRET and TOP SECRET networks
ISM-0628Gateways between security domains
ISM-0629Administering shared gateway components
ISM-0631Explicitly authorised gateway data flows
ISM-0634Gateway event logging
ISM-0635Isolated upward and downward CDS paths
ISM-0637Demilitarised zones for external access
ISM-0639Evaluated firewalls between security domains
ISM-0643Evaluated diodes for public network connections
ISM-0645High assurance diodes for classified public connections
ISM-0649Filtering allowed file types
ISM-0651Blocking malicious and uninspectable files
ISM-0652Quarantining suspicious files
ISM-0659Content filtering checks on transferred files
ISM-0670Cross Domain Solution event logging
ISM-0677Validating file signatures and checksums
ISM-0958Approved domain or category lists for web traffic
ISM-0961Restricting client-side active content
ISM-0963Filtering harmful web content
ISM-1037Gateway testing after changes and six-monthly
ISM-1157Evaluated diodes for unidirectional gateways
ISM-1158High assurance diodes for SECRET and TOP SECRET networks
ISM-1171Blocking website access by IP address
ISM-1192Transport and application layer gateway inspection
ISM-1236Blocking malicious, dynamic and free domains
ISM-1237Outbound web content filtering
ISM-1284Content validation of transferred files
ISM-1286Content conversion of transferred files
ISM-1287Content sanitisation of transferred files
ISM-1288Multi-engine antivirus scanning of transferred files
ISM-1289Unpacking archive files for filtering
ISM-1290Controlled unpacking of archive files
ISM-1293Decrypting encrypted files for filtering
ISM-1389Sandboxing imported executable files
ISM-1427Ingress filtering against IP spoofing
ISM-1457High assurance switches between SECRET domains
ISM-1480High assurance switches to lower classified systems
ISM-1520Screening of gateway administrators
ISM-1521Protocol breaks in CDSs
ISM-1522Independent upward and downward paths
ISM-1523Quarterly CDS event sampling
ISM-1524Security testing of CDS content filters
ISM-1528Evaluated firewalls at public network boundaries
ISM-1773Nationality of AGAO gateway administrators
ISM-1774Isolated gateway management path
ISM-1783ROA signing of public IP addresses
ISM-1862Protecting WAF origin servers
ISM-1965Content checking of transferred files
ISM-2018RPKI route origin validation on BGP routers
ISM-2019ASD assessment of TOP SECRET gateways

Guidelines for information technology equipment

35 controls
Controls in the Guidelines for information technology equipment domain of Australian Information Security Manual — 35 controls
CodeTitle
ISM-0293Classifying IT equipment
ISM-0294Labelling IT equipment
ISM-0296Labelling high assurance IT equipment
ISM-0305Cleared technicians for on-site maintenance
ISM-0306Escorting uncleared technicians
ISM-0307Sanitisation before uncleared maintenance
ISM-0310Approved facilities for off-site repair
ISM-0311Sanitising media within IT equipment
ISM-0312Returning overseas AUSTEO and AGAO equipment
ISM-0313IT equipment sanitisation processes and procedures
ISM-0315Destroying high assurance IT equipment
ISM-0316Release of IT equipment to the public domain
ISM-0317Printing random text on cartridges and drums
ISM-0318Destroying unsanitisable cartridges and drums
ISM-0321Disposing of emanation security equipment
ISM-0336Networked IT equipment register
ISM-1076Sanitising monitors with minor burn-in
ISM-1079Approval for high assurance maintenance
ISM-1217Removing labels before disposal
ISM-1218Sanitising overseas AUSTEO and AGAO equipment
ISM-1219Inspecting MFD drums and transfer rollers
ISM-1220Inspecting printer and MFD platens
ISM-1221Checking paper paths for trapped pages
ISM-1222Destroying unsanitisable displays
ISM-1223Sanitising memory in network devices
ISM-1534Destroying printer ribbons
ISM-1550IT equipment disposal processes and procedures
ISM-1551IT equipment management policy
ISM-1598Inspection after maintenance and repair
ISM-1599Handling IT equipment
ISM-1741IT equipment destruction processes and procedures
ISM-1742Destroying unsanitisable IT equipment
ISM-1858Hardening IT equipment using ASD and vendor guidance
ISM-1869Non-networked IT equipment register
ISM-1913Approved configurations for IT equipment

Guidelines for media

54 controls
Controls in the Guidelines for media domain of Australian Information Security Manual — 54 controls
CodeTitle
ISM-0323Classifying media by data held
ISM-0325Reclassifying media to a higher classification
ISM-0330Reclassifying media to a lower classification
ISM-0332Labelling media with protective markings
ISM-0337Using media only with authorised systems
ISM-0347Write-once media for cross-domain transfers
ISM-0348Media sanitisation processes and procedures
ISM-0350Destroying media that cannot be sanitised
ISM-0351Removing power from volatile media
ISM-0352Overwriting SECRET and TOP SECRET volatile media
ISM-0354Overwriting non-volatile magnetic media
ISM-0356Classification of sanitised magnetic media
ISM-0357Sanitising EPROM media
ISM-0358Classification of sanitised EPROM and EEPROM
ISM-0359Overwriting flash memory media
ISM-0360Classification of sanitised flash media
ISM-0361Degausser field strength and orientation
ISM-0362Following degausser manufacturer directions
ISM-0363Media destruction processes and procedures
ISM-0368Particle size for destroyed media
ISM-0370Cleared supervision of media destruction
ISM-0371Supervising media to the point of destruction
ISM-0372Two-person supervision of accountable media destruction
ISM-0373Supervisor duties and destruction certificates
ISM-0374Media disposal process and procedures
ISM-0375Formal decision to release media
ISM-0378Removing labels and markings before disposal
ISM-0831Handling media by sensitivity or classification
ISM-0835TOP SECRET volatile media after sanitisation
ISM-0836EEPROM overwrite and verification
ISM-0839Keeping accountable media destruction in-house
ISM-0840NAID AAA certified destruction services
ISM-0947Sanitising media after cross-domain transfers
ISM-1059Encrypting data on media
ISM-1065Resetting HPA and DCO before drive sanitisation
ISM-1067ATA secure erase for growth defects table
ISM-1160Using NSA-evaluated degaussers
ISM-1359Removable media usage policy
ISM-1361SCEC or ASIO-approved destruction equipment
ISM-1517Destroying microfiche and microfilm
ISM-1549Media management policy
ISM-1600Sanitising new media before first use
ISM-1641Physical damage to media after degaussing
ISM-1642Sanitising media before reuse in another domain
ISM-1713Removable media register
ISM-1722Destroying electrostatic memory devices
ISM-1723Destroying magnetic floppy disks
ISM-1724Destroying magnetic hard disks
ISM-1725Destroying magnetic tapes
ISM-1726Destroying optical disks
ISM-1727Destroying semiconductor memory
ISM-1728Handling SECRET media waste particles
ISM-1729Handling TOP SECRET media waste particles
ISM-1735Destroying media that fails sanitisation

Guidelines for networking

71 controls
Controls in the Guidelines for networking domain of Australian Information Security Manual — 71 controls
CodeTitle
ISM-0385Functional separation between servers
ISM-0516Content of network diagrams
ISM-0518Maintaining network documentation
ISM-0520Blocking unauthorised network devices
ISM-0521Disabling unused IPv6 on dual-stack devices
ISM-0529VLANs not used between security domains
ISM-0530Administering VLAN devices from trusted domain
ISM-0534Disabling unused physical network ports
ISM-0535No shared trunks between security domains
ISM-0536Segregating public wireless networks
ISM-1006Protecting network management traffic
ISM-1013RF shielding for classified wireless
ISM-1028NIDS or NIPS at external gateways
ISM-1030NIDS placement and firewall rule alerts
ISM-1178Limiting network documentation to third parties
ISM-1181Network zones by criticality
ISM-1182Restricting traffic between network segments
ISM-1186IPv6-capable network security appliances
ISM-1304Default network device credentials
ISM-1311Disabling SNMP versions 1 and 2
ISM-1312Default SNMP community strings
ISM-1314Wi-Fi Alliance certified devices
ISM-1315Disabling wireless admin interface access
ISM-1316Changing default SSIDs
ISM-1317SSIDs that do not identify the organisation
ISM-1318Keeping SSID broadcasting enabled
ISM-1319No static addressing on wireless networks
ISM-1320Not relying on MAC address filtering
ISM-1321802.1X with EAP-TLS only
ISM-1322Evaluated 802.1X components
ISM-1323Certificates for wireless devices and users
ISM-1324Certificate generation using evaluated CA or HSM
ISM-1327Protecting wireless authentication certificates
ISM-1330PMK caching period limit
ISM-1332WPA3-Enterprise 192-bit mode
ISM-1334Frequency separation between wireless networks
ISM-1335Protecting wireless management frames
ISM-1338Low-power access point deployment
ISM-1364Separate interfaces for different domain VLANs
ISM-1428Disabling IPv6 tunnelling on devices
ISM-1429Blocking IPv6 tunnelling at boundaries
ISM-1430Stateful DHCPv6 with central lease logging
ISM-1431Discussing DoS mitigation with cloud providers
ISM-1432Registrar locking for domain names
ISM-1436Segregating critical online services
ISM-1437Cloud-based hosting of online services
ISM-1438CDNs for high availability website hosting
ISM-1439Protecting origin servers behind CDNs
ISM-1454Encapsulating RADIUS communications with IPsec or TLS
ISM-1479Minimising server-to-server communications
ISM-1532VLANs not used with public network infrastructure
ISM-1577Segregating networks from service provider networks
ISM-1579Verifying CSP dynamic scaling for demand spikes
ISM-1580Automatic failover between availability zones
ISM-1581Real-time capacity and availability monitoring
ISM-1627Blocking inbound anonymity network connections
ISM-1628Blocking outbound anonymity network connections
ISM-1710Hardening wireless access point settings
ISM-1711EAP-TLS user identity confidentiality
ISM-1712Fast BSS transition (802.11r) restrictions
ISM-1781Encrypting all data over network infrastructure
ISM-1782Protective DNS for malicious domains
ISM-1800Flashing network devices with trusted firmware
ISM-1801Monthly restarts of network devices
ISM-1863Management interfaces not exposed to the internet
ISM-1912Device settings in network documentation
ISM-1962Disabling SMB version 1
ISM-1963Logging events from internet-facing network devices
ISM-1964Logging events from internal network devices
ISM-2017Encrypting DNS traffic where supported
ISM-2068Limiting internet access for networked devices

Guidelines for personnel security

53 controls
Controls in the Guidelines for personnel security domain of Australian Information Security Manual — 53 controls
CodeTitle
ISM-0078Australian control of AUSTEO and AGAO systems
ISM-0252Annual cyber security awareness training content
ISM-0258Web usage policy
ISM-0405Validating unprivileged access requests
ISM-0407Secure record of user access authorisations
ISM-0409Foreign national access to AUSTEO and REL systems
ISM-0411Foreign national access to AGAO systems
ISM-0414Unique identification of system users
ISM-0415Controlling shared user accounts
ISM-0420Identifying foreign nationals by nationality
ISM-0430Same-day removal of access
ISM-0432Documenting access requirements in the SSP
ISM-0434Screening and clearances before access
ISM-0435Briefings before system access
ISM-0441Restricting temporary access to required data
ISM-0443No temporary access to caveated or SCI systems
ISM-0445Dedicated privileged user accounts
ISM-0446Foreign national privileged access to AUSTEO and REL systems
ISM-0447Foreign national privileged access to AGAO systems
ISM-0817Reporting suspicious contact via online services
ISM-0820Not posting work information online
ISM-0821Posting personal information to online services
ISM-0824Sending and receiving files via online services
ISM-0854Accessing AUSTEO and AGAO data from authorised facilities
ISM-1146Separate work and personal online accounts
ISM-1175Blocking internet, email and web for privileged accounts
ISM-1263Unique privileged accounts per server application
ISM-1404Disabling unprivileged access after 45 days inactivity
ISM-1507Validating privileged access requests
ISM-1508Least privilege for privileged access
ISM-1509Central logging of privileged access events
ISM-1565Annual tailored privileged user training
ISM-1566Central logging of unprivileged access
ISM-1583Identification of contractor personnel
ISM-1591Removing access for detected malicious activity
ISM-1610Documenting and testing emergency access
ISM-1611Break glass use only when normal authentication fails
ISM-1612Break glass use for authorised activities
ISM-1613Central logging of break glass use
ISM-1614Changing break glass credentials after use
ISM-1615Testing break glass accounts after credential changes
ISM-1647Disabling privileged access after 12 months
ISM-1648Disabling privileged access after 45 days inactivity
ISM-1649Just-in-time administration of systems
ISM-1650Logging privileged account and group management
ISM-1740Business email compromise awareness for payment staff
ISM-1852Least privilege for unprivileged access
ISM-1864System usage policy
ISM-1865Agreement to system usage policies before access
ISM-1883Limiting privileged accounts authorised for online services
ISM-2022Cyber security awareness training register
ISM-2071Social engineering advice for account support staff
ISM-2074General-purpose AI usage policy

Guidelines for physical security

19 controls
Controls in the Guidelines for physical security domain of Australian Information Security Manual — 19 controls
CodeTitle
ISM-0161Securing IT equipment and media
ISM-0164Preventing observation by unauthorised people
ISM-0225Prohibiting unauthorised RF and IR devices
ISM-0810Security zones for classified systems
ISM-0813Securing server rooms and containers
ISM-0829Detecting unauthorised RF devices
ISM-1053Zoned rooms for classified infrastructure
ISM-1074Controlling keys to secure areas
ISM-1296Protecting network devices in public areas
ISM-1530Security containers for classified infrastructure
ISM-1543Authorised RF and IR device register
ISM-1973Securing non-classified systems
ISM-1974Securing non-classified server rooms
ISM-1975Security containers for non-classified equipment
ISM-2007Authorised medical device register
ISM-2008Criteria for authorising medical devices
ISM-2009Prohibiting unauthorised medical devices
ISM-2069Authorised photographic and recording device register
ISM-2070Prohibiting unauthorised recording devices

Guidelines for procurement and outsourcing

38 controls
Controls in the Guidelines for procurement and outsourcing domain of Australian Information Security Manual — 38 controls
CodeTitle
ISM-0072Documenting data security requirements in contracts
ISM-0141Incident reporting obligations for providers
ISM-1073Contracts before provider system access
ISM-1395Provider and subcontractor data protection
ISM-1451Data types and ownership in contracts
ISM-1452Supply chain risk assessment
ISM-1529Cloud models for SECRET and TOP SECRET
ISM-1567Excluding high risk suppliers
ISM-1568Suppliers committed to product security
ISM-1569Shared responsibility model
ISM-1570IRAP assessment of cloud providers
ISM-1571Right to verify provider compliance
ISM-1572Data locations and change notification
ISM-1573Access to provider logs
ISM-1574Portable data storage in contracts
ISM-1575Notice of service cessation
ISM-1576Notification of unauthorised provider access
ISM-1631Identifying suppliers for systems
ISM-1632Suppliers with a strong security track record
ISM-1637Outsourced cloud service register
ISM-1638Cloud service register contents
ISM-1736Managed service register
ISM-1737Managed service register contents
ISM-1738Exercising the right to verify compliance
ISM-1785Supplier relationship management policy
ISM-1786Approved supplier list
ISM-1787Sourcing from approved suppliers
ISM-1788Alternative suppliers for critical products
ISM-1789Spares for critical equipment
ISM-1790Maintaining integrity during delivery
ISM-1791Integrity checks at acceptance
ISM-1792Authenticity checks at acceptance
ISM-1793IRAP assessment of managed service providers
ISM-1794Notice of provider arrangement changes
ISM-1804Break clauses for security failures
ISM-1882Suppliers committed to transparency
ISM-1971ASD assessment of TOP SECRET managed services
ISM-1972ASD assessment of TOP SECRET cloud services

Guidelines for software development

104 controls
Controls in the Guidelines for software development domain of Australian Information Security Manual — 104 controls
CodeTitle
ISM-0400Segregating software environments
ISM-0401Secure by Design in software development
ISM-0402SAST, DAST and SCA testing
ISM-0971Using the OWASP ASVS
ISM-1238Threat modelling in the development life cycle
ISM-1239Robust web application frameworks
ISM-1240Validating and sanitising internet input
ISM-1241Output encoding in web applications
ISM-1275Filtering database queries
ISM-1276Parameterised queries and stored procedures
ISM-1278Limiting database error information
ISM-1419Developing only in development environments
ISM-1420Production data in non-production environments
ISM-1422Protecting the authoritative software source
ISM-1424Web security policy response headers
ISM-1536Central logging of database queries and errors
ISM-1552HTTPS-only web application content
ISM-1616Vulnerability disclosure program
ISM-1717Hosting security.txt files for website domains
ISM-1730Producing a software bill of materials
ISM-1754Timely resolution of software vulnerabilities
ISM-1755Vulnerability disclosure policy
ISM-1756Vulnerability disclosure processes and procedures
ISM-1780SecDevOps practices for software development
ISM-1796Signing executable content
ISM-1797Signing installers, patches and updates
ISM-1798Secure configuration guidance for consumers
ISM-1816Protecting the authoritative source from modification
ISM-1817Authenticating internet-facing APIs that expose data
ISM-1818Authenticating internet-facing APIs that modify data
ISM-1849Using the OWASP Top 10 Proactive Controls
ISM-1850Mitigating the OWASP Top 10
ISM-1851Mitigating the OWASP API Security Top 10
ISM-1908Public disclosure of software vulnerabilities
ISM-1909Root cause analysis of vulnerabilities
ISM-1910Central logging of internet-facing API calls
ISM-1911Central logging of software events
ISM-1922Using the OWASP MASVS
ISM-1924Detecting and mitigating prompt injection
ISM-2013Authenticating internal APIs that modify data
ISM-2014Authenticating internal APIs that expose data
ISM-2015Central logging of internal API calls
ISM-2016Validating input received over local networks
ISM-2023Establishing an authoritative source for software
ISM-2024Using the authoritative source for all development
ISM-2025Issue tracking for development tasks
ISM-2026Scanning software artefacts for malicious content
ISM-2027Verifying software artefacts before import
ISM-2028Testing software artefacts for known weaknesses
ISM-2029Restricting third-party libraries to trustworthy sources
ISM-2030Scanning commits for secrets and keys
ISM-2031Using security features of build tools
ISM-2032Completing automated testing before builds
ISM-2033Documenting software security requirements
ISM-2034Documenting security design decisions
ISM-2035Security roles in the development life cycle
ISM-2036Security responsibilities of software developers
ISM-2037Secure development training for developers
ISM-2038Developer cyber security skills register
ISM-2039Reviewing the software threat model
ISM-2040Secure programming practices for chosen languages
ISM-2041Memory-safe programming languages and practices
ISM-2042Secure by Default principles
ISM-2043Readable and maintainable software architecture
ISM-2044No default credentials in software
ISM-2045Backwards compatibility without weakening security
ISM-2046Logging and permissions for user impersonation
ISM-2047Notifying users of authentication factor resets
ISM-2048Preventing users altering their own privileges
ISM-2049Re-authentication after permission or credential changes
ISM-2050Validating digital signatures and revocation
ISM-2051Software event log generation
ISM-2052Protecting sensitive data in event logs
ISM-2053Software end of life procedures
ISM-2054Using third-party software bills of materials
ISM-2055Using third-party build provenance
ISM-2056Producing software build provenance
ISM-2057Documenting and testing input validation rules
ISM-2058Validating data before deserialisation
ISM-2059Restricting and scanning file uploads
ISM-2060Code reviews for secure design and programming
ISM-2061Security peer reviews of critical components
ISM-2062Positive and negative unit and integration testing
ISM-2063Session cookie security flags
ISM-2064Signed opaque bearer tokens in session cookies
ISM-2065Entropy of unsigned session identifiers
ISM-2066Server-side session management
ISM-2067Single Logout for Single Sign On
ISM-2072Non-executable AI model file formats
ISM-2082Using third-party cryptographic bills of materials
ISM-2083Producing a cryptographic bill of materials
ISM-2084AI model and system cards
ISM-2085Hiding exact AI model confidence scores
ISM-2086Verifying AI model source and integrity
ISM-2087Verifying AI training data source and integrity
ISM-2088Validating AI training data
ISM-2089Monitoring AI model performance metrics
ISM-2090Rate limiting AI inference queries
ISM-2091Resource limits for AI models
ISM-2092Fine-grained permissions for AI applications
ISM-2093Role-based access for AI applications
ISM-2094Content filtering for AI output
ISM-2102Periodic weakness testing of software artefacts
ISM-2103Consent for training on organisational data

Guidelines for system hardening

215 controls
Controls in the Guidelines for system hardening domain of Australian Information Security Manual — 215 controls
CodeTitle
ISM-0341Disabling automatic execution for removable media
ISM-0343Blocking writes to removable media
ISM-0345Disabling DMA-capable interfaces
ISM-0380Removing unneeded operating system functionality
ISM-0382Preventing removal of approved applications
ISM-0383Default operating system accounts and credentials
ISM-0408Logon banner for security responsibilities
ISM-0417Single-factor authentication fallback
ISM-0418Keeping physical credentials apart from systems
ISM-0421Single-factor password length for PROTECTED systems
ISM-0422Single-factor password length for TOP SECRET systems
ISM-0428Session lock configuration
ISM-0582Centralised Microsoft Windows event logging
ISM-0843Application control on workstations
ISM-0846Preventing bypass of application control
ISM-0853Daily session termination and workstation restart
ISM-0938Selecting secure-by-design user application vendors
ISM-0955Application control rule types
ISM-0974Multi-factor authentication for unprivileged users
ISM-1034HIPS or EDR on critical servers
ISM-1055Disabling LAN Manager and NTLM
ISM-1173Multi-factor authentication for privileged users
ISM-1227Randomly generated credentials for user accounts
ISM-1235Restricting add-ons, extensions and plug-ins
ISM-1245Removing server application installation files
ISM-1246Hardening server applications
ISM-1247Removing unneeded server application functionality
ISM-1249Running server applications with minimum privileges
ISM-1250Limiting server application file system access
ISM-1260Default server application accounts and credentials
ISM-1341HIPS or EDR on workstations
ISM-1392Protecting folders used in path rules
ISM-1401Acceptable multi-factor authentication factors
ISM-1402Protecting stored credentials
ISM-1403Account lockout after failed logons
ISM-1406Standard Operating Environments
ISM-1407Operating system release currency
ISM-1408Using 64-bit operating systems
ISM-1409Hardening operating systems
ISM-1412Hardening web browsers
ISM-1416Host-based software firewall
ISM-1417Antivirus application configuration
ISM-1418Blocking reads from removable media
ISM-1460Secure-by-design vendors for isolation mechanisms
ISM-1461Shared hardware for SECRET and TOP SECRET environments
ISM-1467User application release currency
ISM-1470Removing unneeded user application functionality
ISM-1471Publisher and product names in certificate rules
ISM-1483Internet-facing server application release currency
ISM-1485Blocking web advertisements in browsers
ISM-1486Blocking Java in web browsers
ISM-1487Write access to Trusted Locations
ISM-1488Blocking macros from the internet
ISM-1489Locking Microsoft Office macro security settings
ISM-1490Application control on internet-facing servers
ISM-1491Blocking script execution engines for unprivileged users
ISM-1492Operating system exploit protection
ISM-1504Multi-factor authentication for online services
ISM-1505Multi-factor authentication for data repositories
ISM-1542Blocking Object Linking and Embedding packages
ISM-1544Microsoft recommended application blocklist
ISM-1546Authenticating users before access
ISM-1557Single-factor password length for SECRET systems
ISM-1558Constructing word-sequence passphrases
ISM-1559MFA password length for PROTECTED systems
ISM-1560MFA password length for SECRET systems
ISM-1561MFA password length for TOP SECRET systems
ISM-1582Annual validation of application control rulesets
ISM-1584Preventing users bypassing operating system security
ISM-1585Locking web browser security settings
ISM-1588Annual review of Standard Operating Environments
ISM-1590Changing compromised or exposed user credentials
ISM-1592Blocking user installation of unapproved applications
ISM-1593Identity verification before issuing credentials
ISM-1594Secure delivery of new credentials
ISM-1595Changing credentials on first use
ISM-1596No credential reuse across systems
ISM-1597Obscuring credentials during entry
ISM-1601Microsoft attack surface reduction rules
ISM-1603Disabling replay-susceptible authentication methods
ISM-1604Hardening software-based isolation mechanisms
ISM-1605Hardening the isolation host operating system
ISM-1606Patching isolation mechanisms and host operating systems
ISM-1607Monitoring and logging isolation mechanisms
ISM-1608Scanning third-party SOEs before use
ISM-1619Group Managed Service Accounts for service accounts
ISM-1620Protected Users group for privileged accounts
ISM-1621Disabling Windows PowerShell 2.0
ISM-1622PowerShell Constrained Language Mode
ISM-1623Central logging of PowerShell events
ISM-1624Protected Event Logging for script block logs
ISM-1654Disabling Internet Explorer 11
ISM-1655Disabling .NET Framework 3.5
ISM-1656Application control on internal servers
ISM-1657Application control scope of file types
ISM-1658Application control for drivers
ISM-1659Microsoft vulnerable driver blocklist
ISM-1660Central logging of application control events
ISM-1667Blocking Office child process creation
ISM-1668Blocking Office creating executable content
ISM-1669Blocking Office code injection
ISM-1670Blocking PDF application child processes
ISM-1671Disabling Microsoft Office macros by default
ISM-1672Antivirus scanning of Office macros
ISM-1673Blocking Win32 API calls from macros
ISM-1674Restricting which Office macros can run
ISM-1675Blocking user enablement of untrusted macros
ISM-1676Annual validation of trusted macro publishers
ISM-1679Multi-factor authentication for sensitive online services
ISM-1680Multi-factor authentication for other online services
ISM-1681Multi-factor authentication for customer services
ISM-1682Phishing-resistant multi-factor authentication
ISM-1683Central logging of multi-factor authentication events
ISM-1685Managing break glass and service account credentials
ISM-1686Enabling Credential Guard
ISM-1743Operating system vendor selection
ISM-1745Secure boot and measured boot functionality
ISM-1746Protecting paths used by application control rules
ISM-1748Locking email client security settings
ISM-1749Limiting cached logon credentials
ISM-1795Minimum length for privileged local credentials
ISM-1806Changing default user application accounts
ISM-1823Locking Office productivity suite security settings
ISM-1824Locking PDF application security settings
ISM-1825Locking security product settings
ISM-1826Server application vendor selection
ISM-1827Dedicated accounts for administering domain controllers
ISM-1828Disabling Print Spooler on domain controllers
ISM-1829No passwords in Group Policy Preferences
ISM-1830Central logging of Active Directory services events
ISM-1832Service Principal Names only on service accounts
ISM-1833Minimum privileges for user accounts
ISM-1834No duplicate Service Principal Names
ISM-1835Privileged accounts marked sensitive and not delegated
ISM-1836Requiring Kerberos pre-authentication
ISM-1838Not using the UserPassword attribute
ISM-1839No passwords in readable account properties
ISM-1840No reversible encryption for passwords
ISM-1841Restricting who can add machines to domains
ISM-1842Dedicated accounts for joining machines to domains
ISM-1843Reviewing accounts with unconstrained delegation
ISM-1844No delegation trust for non-DC computer accounts
ISM-1845Removing group memberships from disabled accounts
ISM-1846Pre-Windows 2000 Compatible Access group membership
ISM-1847Changing KRBTGT account credentials
ISM-1848Replacing unsupported isolation mechanisms
ISM-1859Office productivity suite hardening
ISM-1860PDF application hardening
ISM-1861Local Security Authority protection
ISM-1870Application control in user profiles and temporary folders
ISM-1871Application control in all other locations
ISM-1872Phishing-resistant MFA for online services
ISM-1873Phishing-resistant MFA option for customers
ISM-1874Enforcing phishing-resistant MFA for customers
ISM-1875Scanning networks for cleartext credentials
ISM-1889Logging command line process creation
ISM-1890Checking macros before signing or trusting
ISM-1891Blocking macros without V3 signatures
ISM-1892MFA for own sensitive customer services
ISM-1893MFA for third-party customer services
ISM-1894Phishing-resistant MFA for data repositories
ISM-1895Logging single-factor authentication events
ISM-1896Memory integrity functionality
ISM-1897Remote Credential Guard
ISM-1914Approved operating system configurations
ISM-1915Approved user application configurations
ISM-1916Approved server application configurations
ISM-1919Disabling authentication protocols without MFA
ISM-1920Preventing MFA self-enrolment from untrustworthy devices
ISM-1926Dedicated roles for identity servers
ISM-1927Limiting privileged access to identity servers
ISM-1928Securing identity server backups
ISM-1929LDAP signing on domain controllers
ISM-1930Passwords in Group Policy Preferences
ISM-1931SID filtering for domain and forest trusts
ISM-1932Minimising service accounts with SPNs
ISM-1933DCSync permissions for SPN service accounts
ISM-1934Annual review of DCSync permissions
ISM-1935Unconstrained delegation on computer accounts
ISM-1936Not using sIDHistory
ISM-1937Weekly checks for sIDHistory
ISM-1938Domain Computers write permissions
ISM-1939Minimising highly-privileged group membership
ISM-1940Service accounts in privileged groups
ISM-1941Computer accounts in privileged groups
ISM-1942Domain Computers in privileged groups
ISM-1943Strong certificate mapping
ISM-1944Removing the EDITF_ATTRIBUTESUBJECTALTNAME2 flag
ISM-1945Enrollee supplied subject in templates
ISM-1946Write access to certificate templates
ISM-1947Authentication EKUs in certificate templates
ISM-1948CA manager approval for SAN templates
ISM-1949Dedicated AD FS administration account
ISM-1950Disabling soft matching after initial sync
ISM-1951Hard match takeover
ISM-1952Not synchronising privileged accounts
ISM-1953Built-in Administrator account credentials
ISM-1954Randomly generated privileged account credentials
ISM-1955Changing computer account credentials
ISM-1956Changing AD FS certificates
ISM-1957HSM protection of CA private keys
ISM-1976Logging events for macOS
ISM-1977Logging events for Linux
ISM-1978Logging internet-facing server applications
ISM-1979Logging internal server applications
ISM-1980Credential hint functionality
ISM-2010AES for SPN service accounts
ISM-2011Disabling weaker MFA options
ISM-2012Screen lock configuration
ISM-2076Security questions for authentication
ISM-2077Email for out-of-band authentication
ISM-2078Blocking common and compromised passwords
ISM-2079Maximum password length
ISM-2080Password complexity requirements
ISM-2081Characters supported in passwords

Guidelines for system management

68 controls
Controls in the Guidelines for system management domain of Australian Information Security Manual — 68 controls
CodeTitle
ISM-0042System administration processes and procedures
ISM-0298Centralised and managed patching
ISM-0300Patching high assurance IT equipment
ISM-0304Removing unsupported applications
ISM-1143Patch management processes and procedures
ISM-1211Administration under change and configuration management
ISM-1380Separate privileged operating environments
ISM-1385Segregation of administrative infrastructure
ISM-1386Management traffic sourced from administrative infrastructure
ISM-1387Administration through jump servers
ISM-1493Maintaining software registers
ISM-1501Replacing unsupported operating systems
ISM-1510Digital preservation policy
ISM-1511Backups aligned to business criticality
ISM-1515Testing restoration to a common point
ISM-1547Data backup processes and procedures
ISM-1548Data restoration processes and procedures
ISM-1643Versions and patch histories in software registers
ISM-1687Privileged environments not virtualised within unprivileged ones
ISM-1688Unprivileged accounts denied privileged environment logon
ISM-1689Privileged accounts denied unprivileged environment logon
ISM-1690Non-critical patches for online services within two weeks
ISM-1691Patching user-facing applications within two weeks
ISM-1692Critical patches for user-facing applications within 48 hours
ISM-1693Patching other applications within one month
ISM-1694Non-critical OS patches for internet-facing systems within two weeks
ISM-1695OS patches for workstations and internal systems within one month
ISM-1696Critical OS patches for internal systems within 48 hours
ISM-1697Non-critical driver patches within one month
ISM-1698Daily vulnerability scanning of online services
ISM-1699Weekly scanning of office, browser, email, PDF and security products
ISM-1700Fortnightly scanning of other applications
ISM-1701Daily scanning of internet-facing OS
ISM-1702Fortnightly scanning of workstation and internal system OS
ISM-1703Fortnightly scanning for driver updates
ISM-1704Removing unsupported office, browser, email, PDF and security products
ISM-1705Privileged access to other users' backups
ISM-1706Privileged access to own backups
ISM-1707Privileged accounts prevented from altering backups
ISM-1708Backup administrators prevented from altering retained backups
ISM-1750Segregating administrative infrastructure by server tier
ISM-1751Non-critical OS patches for other IT equipment within one month
ISM-1752Fortnightly scanning of other IT equipment OS
ISM-1753Replacing unsupported internet-facing network devices
ISM-1807Fortnightly automated asset discovery
ISM-1808Up-to-date vulnerability database for scanning
ISM-1809Compensating controls for unsupported systems
ISM-1810Synchronised backups for a common restore point
ISM-1811Secure and resilient retention of backups
ISM-1812Unprivileged access to other users' backups
ISM-1813Unprivileged access to own backups
ISM-1814Unprivileged accounts prevented from altering backups
ISM-1876Critical patches for online services within 48 hours
ISM-1877Critical OS patches for internet-facing systems within 48 hours
ISM-1878Critical OS patches for other IT equipment within 48 hours
ISM-1879Critical driver patches within 48 hours
ISM-1898Use of Secure Admin Workstations
ISM-1899Blocking inbound connections to administrative infrastructure
ISM-1900Fortnightly scanning for firmware updates
ISM-1901Non-critical patches for user-facing applications within two weeks
ISM-1902Non-critical OS patches for internal systems within one month
ISM-1903Critical firmware patches within 48 hours
ISM-1904Non-critical firmware patches within one month
ISM-1905Removing unsupported online services
ISM-1921Assessing compromise likelihood for exploited vulnerabilities
ISM-1958DCSync-permissioned accounts denied unprivileged logon
ISM-1981Replacing unsupported internal network devices
ISM-1982Replacing unsupported networked IT equipment

Guidelines for system monitoring

19 controls
Controls in the Guidelines for system monitoring domain of Australian Information Security Manual — 19 controls
CodeTitle
ISM-0109Analysing workstation event logs
ISM-0580Event logging policy
ISM-0585Details captured for each logged event
ISM-0988Consistent time source for event logs
ISM-1228Analysing cyber security events for incidents
ISM-1405Implementing a centralised event logging facility
ISM-1815Protecting event logs from modification and deletion
ISM-1906Analysing internet-facing server event logs
ISM-1907Analysing internal server event logs
ISM-1959Consistent structured event log format
ISM-1960Analysing internet-facing network device event logs
ISM-1961Analysing internal network device event logs
ISM-1983Timely forwarding to the centralised facility
ISM-1984Encrypting event logs in transit
ISM-1985Protecting event logs from unauthorised access
ISM-1986Analysing critical server event logs
ISM-1987Analysing security product event logs
ISM-1988Searchable retention for 12 months
ISM-1989Retention under AFDA Express requirements

Your Compliance Coverage

If you comply with Australian Information Security Manual, you already cover:

Maps to 8 other frameworks

1081 total controls
ISO 27002:2022
327 source controls mapped|81 target controls covered
30%
New Zealand Information Security Manual (NZISM)
226 source controls mapped|275 target controls covered
21%
CIS Controls v8
222 source controls mapped|137 target controls covered
21%
NIST Cybersecurity Framework 2.0
202 source controls mapped|103 target controls covered
19%
ACSC Essential Eight
126 source controls mapped|167 target controls covered
12%
Protective Security Policy Framework (PSPF) Release 2026
38 source controls mapped|42 target controls covered
4%
ATO Digital Service Provider (DSP) Operational Security Framework
16 source controls mapped|9 target controls covered
1%
Australia IRAP - Information Security Registered Assessors Program
5 source controls mapped|5 target controls covered
0%

Coverage is not the same as your position

This page shows what Australian Information Security Manual overlaps with in general. Where your organisation actually stands, against the standard you are going for and the certifications you already hold, is a different question. Same graph and the same recorded refutations, scoped to you rather than to a pair.

The Compliance Position Diagnostic, $5,000 fixed, ten business days

What is Australian Information Security Manual and who does it apply to?

Australian Information Security Manual is a compliance framework from Australia with 22 domains and 1081 controls. ACSC Information Security Manual. Australian Government cybersecurity controls baseline. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Australian Information Security Manual actually require?

Australian Information Security Manual has 1081 controls organised across 22 domains. The largest domains are Guidelines for system hardening (215 controls), Guidelines for software development (104 controls), Guidelines for cryptography (73 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Australian Information Security Manual do I already cover?

Australian Information Security Manual maps to 8 other compliance frameworks. The top mapping partners are ISO 27002:2022 (30% coverage), New Zealand Information Security Manual (NZISM) (21% coverage), CIS Controls v8 (21% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Australian Information Security Manual?

Start your Australian Information Security Manual compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Australian Information Security Manual requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 1081 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 868 frameworks.

Get Started Free →

Free forever — no credit card required