Skip to content

Releases: AustralianCyberSecurityCentre/ism-oscal

v2026.06.18

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 18 Jun 09:23

This version is based on the June 2026 Information security manual (ISM) and OSCAL version 1.1.2.

June 2026 ISM changes

Cyber security principles

Protect cyber security principles

The existing cyber security principle on ‘data protection’ was renamed to ‘cryptographic protection’ and amended to replace the reference to ‘ASD-approved algorithms and protocols’ with ‘ASD-approved cryptography’ as to not unintentionally exclude the use of high assurance cryptographic algorithms and protocols. [PRO-08]

Guidelines for cyber security documentation

Continuous monitoring plan

The existing control on developing and implementing continuous monitoring plans was split into two controls to separate documentation development from the performance of security assessments.
[ISM-1163, ISM-2118]

Guidelines for personnel security

Posting work-related information on online services

A new control was added recommending that personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted. [ISM-2104]

A new control was added recommending that personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such information is posted. [ISM-2105]

A new control was added recommending that personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases where such information is posted. [ISM-2106]

Posting personal information on online services

The existing control recommending that personnel are advised of security risks associated with posting personal information to online services and are encouraged to use any available privacy settings to restrict who can view such information was split into two controls to separate the posting of personal information to online services from the use of any available privacy settings. [ISM-0821, ISM-2107]

Guidelines for enterprise mobility

Encrypted communications

For the avoidance of doubt, a new control was added recommending that mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography. [ISM-2108]

Guidelines for media

Encrypting media

A new control was added recommending that pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes. [ISM-2109]

Guidelines for system hardening

User application releases

The existing control recommending that the latest release of office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are used was expanded to include extensions for all of the application types listed. [ISM-1467]

Hardening user application configurations

A new control was added recommending that user applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur. [ISM-2110]

The existing control recommending that unneeded components, services and functionality of office productivity suites, web browsers, email clients, PDF applications and security products are disabled or removed was expanded to all user applications and amended to include unneeded user accounts. [ISM-1470]

The existing control recommending that add-ons, extensions and plug-ins for office productivity suites, web browsers, email clients, PDF applications and security products are restricted to an organisation-approved set was expanded to all user applications. [ISM-1235]

A new control was added recommending that all temporary installation files created during user application installation processes are removed after user applications have been installed. [ISM-2111]

Artificial intelligence applications

A new control was added recommending that AI applications that process classified data have their ability to directly access external public data sources disabled. [ISM-2112]

A new control was added recommending that AI applications are configured to flag organisationally defined risky actions for human approval prior to their execution. [ISM-2113]

A new control was added recommending that baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations. [ISM-2114]

Hardening server application configurations

A new control was added recommending that extensions for server applications are restricted to an organisation-approved set. [ISM-2115]

The existing control recommending that all temporary installation files and logs created during server application installation processes are removed after server applications have been installed was amended to remove the requirement that logs be removed. [ISM-1245]

User account lockouts

The existing control recommending that user accounts, except for break glass accounts, are locked out after a maximum of five failed logon attempts was amended to capture the use of risk-based lockout mechanisms that implement automated lockout durations, such as Smart Lockout functionality used by Microsoft Entra ID. [ISM-1403]

Functional separation between operating environments

Existing controls relating to software-based isolation mechanisms were amended to replace references to ‘physical server hardware’ with ‘physical computing resources’. [ISM-1460, ISM-1461, ISM-1604, ISM-1605, ISM-1606, ISM-1607, ISM-1848]

Guidelines for security assurance

Security monitoring policy

The existing control recommending that an event logging policy is developed, implemented and maintained was amended to reference a security monitoring policy instead. [ISM-0580]

Event log monitoring

A new control was added recommending that cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents. [ISM-2116]

A new control was added recommending that suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents. [ISM-2117]

Vulnerability assessments and penetration tests

A new control was added recommending that suitable AI models are used to augment vulnerability assessments and penetration tests. [ISM-2119]

Guidelines for software development

Introduction to software development

The introduction to the ‘software development fundamentals’ section was amended to clarify that it applies to human, artificial intelligence (AI)-assisted, AI-powered and AI-driven software development activities. This includes noting that where a reference is made to software developers that it applies to both humans and AI agents.

Secure software development

A new control was added recommending that a secure software development policy is developed, implemented and maintained. [ISM-2120]

A new control was added recommending that software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used. [ISM-2121]

The existing control recommending that software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training on secure software development and programming practices was amended to including upskilling. [ISM-2037]

Software security testing

A new control was added recommending that suitable AI models are used to augment software security testing. [ISM-2122]

Data collection, retention and use

A new control was added recommending that all prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications. [ISM-2123]

Guidelines for cryptography

Using cryptographic algorithms

The existing control recommending that an ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm is used when encrypting media was amended to capture all scenarios where data is encrypted at rest. [ISM-1080]

Using cryptographic protocols

The existing control recommending that an ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is used to protect data when communicated over network infrastructure was amended to capture all scenarios where data is encrypted in transit. [ISM-0469]

Miscellaneous

For the avoidance of doubt, controls that referenced data being ‘encrypted’ were amended to clarify that ASD-approved cryptography must be used. [ISM-0233, ISM-0869, ISM-1059, ISM-1085, ISM-1277, ISM-1781, ISM-1928, ISM-1984, ISM-2017]

Minor grammar corrections were made to principles and controls that did not affect their intent.
**[GOV-11, PRO-10, ISM-0043, ISM-0072, ISM-0120, ISM-0138, ISM-0211, ISM-0294, ISM-0305, ISM-0306, ISM-0307, ISM-0310, ISM-0332, ISM-0336, ISM-0385, ISM-0459, ISM-0484, ISM-0526, ISM-0549, ISM-0694, ISM-0725, ISM-0820, ISM-0835, ISM-0846, ISM-0853, ISM-1036, ISM-1037, ISM-1076, ISM-1146, ISM-1219, ISM-1243, ISM-1272, ISM-1289, ISM-1293, ISM-1297, ISM-1400, ISM-1417, ISM-1419, ISM-1429, ISM-1452, ISM-1483, ISM-1493, ISM-1543, ISM-1569, ISM-1574, ISM-1579, ISM-1582, ISM-1598, ISM-1637, ISM-1645, ISM-1676, ISM-1713, ISM-1736, ISM-1738, ISM-1740, `ISM-180...

Read more

v2026.03.24

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 24 Mar 08:35

This version is based on the March 2026 Information security manual (ISM) and OSCAL version 1.1.2.

March 2026 ISM changes

Cyber security principles

Implementing the cyber security principles

Important contextual information was included on how the Information security manual’s cyber security principles should be implemented by organisations.

Within each function, the cyber security principles are listed in a logical sequence that reflects how they should be considered for implementation. The numbers used for the cyber security principles are identifiers only and do not indicate an implementation order.

When implementing the cyber security principles, each cyber security principle should be supported by administrative and technical controls proportionate to an organisation’s size, complexity, operating environment and risk profile. These controls should be subject to ongoing risk-based monitoring and assurance activities. Where the term ‘systems’ is used, the elements listed in brackets define the scope of that cyber security principle.

Overall, the cyber security principles are interdependent and must be implemented collectively to achieve comprehensive cyber security outcomes.

Govern cyber security principles

References to ‘cyber supply chains’ as a system component within the Govern function were removed to support the creation of a Protect cyber security principle (PRO-16) on that topic. [GOV-03, GOV-05,
GOV-06, GOV-12]

A new cyber security principle on ‘executive artificial intelligence accountability’ was added recommending that the board of directors or executive committee is accountable for ensuring that artificial intelligence is secure, controllable, human-supervised and used in an ethical and accountable manner. [GOV-08]

The existing cyber security principle on ‘executive cyber security leadership’ was renamed to ‘cyber security leadership’. Furthermore, it was amended to recommend that the chief information security officer also deliver regular and timely risk-based reporting to the board of directors or executive committee on their organisation’s cyber security posture, the effectiveness of controls, current security risks and emerging cyber threats. [GOV-02]

The existing cyber security principle on ‘cyber security resourcing’ was amended to recommend that suitable and sufficient personnel and resources be maintained following their initial acquisition. [GOV-04]

A new cyber security principle on ‘security risk management responsibilities’ was added recommending that security risk management responsibilities for an organisation and their suppliers, partners and customers, including any shared responsibilities, are documented and communicated to all relevant parties with accountability arrangements in place to ensure their effective implementation. [GOV-09]

The existing cyber security principle on ‘security risk management’ was renamed to ‘security risk management assurance’. Furthermore, its scope was expanded from ‘systems’ to ‘an organisation and their systems’ with security risk management activities being subject to ongoing monitoring and assurance activities by the board of directors or executive committee. [GOV-03]

The existing cyber security principle on ‘security risk acceptance’ was amended to include inherited and shared security risks. [GOV-05]

The existing cyber security principle on ‘security risk communication’ was amended to include inherited and shared security risks. [GOV-06]

A new cyber security principle on ‘system exposure minimisation’ was added recommending that information about the design, configuration and operation of systems (infrastructure, operating systems, applications and data) is not publicly disclosed or shared externally unless necessary for commercial, legal, regulatory or security purposes, with any disclosure minimised, controlled and logged. [GOV-10]

The existing cyber security principle on ‘trustworthy suppliers’ was renamed to ‘supplier cyber security assurance’ and moved from the Protect function (PRO-03) to the Govern function (GOV-11). Furthermore, it was amended to recommend that supplier cyber security practices are independently verified, or otherwise risk-assessed, on a regular basis. [GOV-11]

The existing cyber security principle on ‘trustworthy personnel’ was renamed to ‘personnel suitability assurance’ and moved from the Protect function (PRO-11) to the Govern function (GOV-12). Furthermore, it was amended to replace the reference to ‘trustworthy personnel’ with ‘personnel whose suitability and trustworthiness have been established and are subject to ongoing assurance’. [GOV-12]

A new cyber security principle on ‘cyber security and safety’ was added recommending that controls for systems (infrastructure, operating systems, applications and data) do not compromise human, physical or environmental safety. [GOV-13]

A new cyber security principle on ‘legacy system management’ was added recommending that systems (infrastructure, operating systems, applications and data) that are not capable of meeting cyber security requirements are managed using compensating controls, along with enhanced monitoring and assurance activities, to maintain an acceptable level of residual risk until they can be decommissioned or replaced. [GOV-14]

The existing cyber security principle on ‘security risk insights’ was renamed to ‘continuous cyber security improvement’. Furthermore, it was rewritten to recommend that security risk management and associated cyber security activities are continually measured and reviewed using cyber threat intelligence and assurance activities, including exercises informed by real-world cyber threats, to identify, prioritise and incorporate improvements in governance arrangements, shared responsibilities and the effectiveness of controls. [GOV-07]

Identity cyber security principles

References to ‘cyber supply chains’ as a system component within the Identify function were removed to support the creation of a Protect cyber security principle (PRO-16) on that topic. [IDE-01, IDE-02, IDE-03, IDE-04]

The existing cyber security principle on ‘asset identification’ was amended to include identities and credentials as system components. Furthermore, it was amended to recommend that assets be continually and centrally identified and documented. [IDE-01]

A new cyber security principle on ‘asset interdependencies’ was added recommending that interdependencies between systems (infrastructure, operating systems, applications and data) are continually and centrally identified and documented, including how the compromise of one system could affect the security or business operations of other dependent systems. [IDE-05]

The existing cyber security principle on ‘business criticality identification’ was renamed to ‘business criticality rating identification’. Furthermore, it was amended slightly for consistency with other cyber security principles without significantly changing its intent. [IDE-02]

The existing cyber security principle on ‘security requirement identification’ was amended slightly for consistency with other cyber security principles without significantly changing its intent. [IDE-03]

A new cyber security principle on ‘resilience requirement identification’ was added recommending that resilience requirements for systems (infrastructure, operating systems, applications and data) are identified and documented. [IDE-06]

The existing cyber security principle on ‘security risk identification’ was amended to expand its scope from ‘systems’ to ‘an organisation and their systems’. Furthermore, it was amended to recommend that security risk identification activities include the use of current strategic and sector-specific cyber threat intelligence and threat modelling. [IDE-04]

Protect cyber security principles

References to ‘cyber supply chains’ as a system component within the Identify function were removed to support the creation of a Protect cyber security principle (PRO-16) on that topic. [PRO-06, PRO-12, PRO-13]

The existing cyber security principle on ‘secure system lifecycle’ was amended to include resilience requirements as part of secure system lifecycle considerations. [PRO-01]

The existing cyber security principle on ‘secure by design’ was merged into the existing cyber security principle on ‘secure system lifecycle’. [PRO-02]

A new cyber security principle on ‘cyber supply chain security’ was added recommending that cyber supply chains supporting systems (infrastructure, operating systems, applications and data) are secure, resilient and support effective and coordinated cyber security incident response. [PRO-16]

The existing cyber security principle on ‘robust access control’ was renamed to ‘identity, credential and access management’. Furthermore, it was amended to reference supporting effective detection of identity and credential misuse. [PRO-13]

The existing cyber security principle on ‘secure administration’ was amended to recommend that administration activities be conducted in an auditable manner. [PRO-05]

The existing cyber security principle on ‘attack surface reduction’ was renamed to ‘secure configuration management’. Furthermore, it was rewritten to recommend that systems (infrastructure, operating systems and applications) are securely configured to approved and maintained baselines, including by reducing attack surfaces and attack paths, with configurations continually monitored and consistently enforced. [PRO-04]

The existing cyber security principle on ‘vulnerability management’ was amended to recommend that vulnerabilities be identified, documented, validated and prioritise...

Read more

v2025.12.9

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 09 Dec 05:32

This version is based on the December 2025 Information security manual (ISM) and OSCAL version 1.1.2.

December 2025 changes

Guidelines for personnel security

General-purpose artificial intelligence usage policy

A new control was added recommending that a general-purpose artificial intelligence usage policy is developed, implemented and maintained. [ISM-2074]

Guidelines for communications systems

Multifunction device usage policy

The existing control recommending that a fax machine and MFD usage policy is developed, implemented and maintained was amended to remove the reference to fax machines. [ISM-0588]

Connecting multifunction devices to digital telephone systems

The existing control recommending that a direct connection from an MFD to a digital telephone system is not enabled unless the digital telephone system is authorised to operate at the same sensitivity or classification as the network to which the MFD is connected was tightened to MFDs are not connected to digital telephone systems. [ISM-0245]

Observing multifunction device use

The existing control recommending that fax machines and MFDs are located in areas where their use can be observed was amended to remove the reference to fax machines. [ISM-1036]

Sending and receiving fax messages

Existing controls relating to sending and receiving fax messages were rescinded. [ISM-0241, ISM-1075, ISM-1092]

A new control was added recommending fax machines, and online fax services, are not used for sending or receiving fax messages. [ISM-2075]

Guidelines for information technology equipment

Sanitising fax machines

Existing controls relating to sanitising fax machines were rescinded. [ISM-1225, ISM-1226]

Guidelines for system hardening

Insecure authentication methods

A new control was added recommending that security questions are not used for authentication purposes. [ISM-2076]

A new control was added recommending that email is not used for out-of-band authentication purposes. [ISM-2077]

Password strength

The existing control recommending that passphrases used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are at least 4 random words with a total minimum length of 15 characters was amended to move the reference to 4 random words to ISM-1558. [ISM-0421]

The existing control recommending that passphrases used for single-factor authentication on SECRET systems are at least 5 random words with a total minimum length of 17 characters was amended to move the reference to 5 random words to ISM-1558. [ISM-1557]

The existing control recommending that passphrases used for single-factor authentication on TOP SECRET systems are at least 6 random words with a total minimum length of 20 characters was amended to move the reference to 6 random words to ISM-1558. [ISM-0422]

The existing control recommending that passphrases used for single-factor authentication are not a list of categorised words; do not form a real sentence in a natural language; and are not constructed from song lyrics, movies, literature or any other publicly available material was amended to include the recommended minimum number of words in passphrases. [ISM-1558]

A new control was added recommending that passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used. [ISM-2078]

A new control was added recommending that maximum length limits for passwords are not less than 64 characters. [ISM-2079]

A new control was added recommending that password complexity requirements are not imposed for passwords. [ISM-2080]

A new control was added recommending that all ASCII printable characters are supported for passwords. [ISM-2081]

Changing credentials

The existing control recommending that credentials for user accounts be changed in response to specific events was amended to remove the recommendation for time-based password changes. [ISM-1590]

Guidelines for software development

Cryptographic bill of materials

A new control was added recommending that if a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of Australian Signals Directorate (ASD)-approved cryptographic algorithms. [ISM-2082]

A new control was added recommending that a cryptographic bill of materials is produced and made available to consumers of software. [ISM-2083]

Software event logging

The existing control recommending that security-relevant software crashes and error messages are centrally logged was reworded for clarity and amended to include security-relevant usage of software. [ISM-1911]

Secure artificial intelligence application development

The existing control recommending that the OWASP Top 10 for Large Language Model Applications are mitigated in the development of large language model applications was rescinded. [ISM-1923]

A new control was added recommending that artificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics, system architectures, use cases and security risks. [ISM-2084]

A new control was added recommending that the exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented. [ISM-2085]

Artificial intelligence model poisoning

A new control was added recommending that the source and integrity of artificial intelligence models, structures and weights are verified. [ISM-2086]

A new control was added recommending that the source and integrity of training data for artificial intelligence models is verified. [ISM-2087]

A new control was added recommending that data validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models. [ISM-2088]

Unbounded consumption

A new control was added recommending that artificial intelligence model performance metrics are monitored and anomalies are investigated. [ISM-2089]

A new control was added recommending that rate limiting is applied to inference queries for artificial intelligence models. [ISM-2090]

A new control was added recommending that resource limits are enforced for artificial intelligence models. [ISM-2091]

Excessive agency

A new control was added recommending that access control policies are implemented to enforce fine-grained permissions for artificial intelligence applications. [ISM-2092]

A new control was added recommending that role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data. [ISM-2093]

Sensitive data disclosure and improper output

A new control was added recommending that content filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output. [ISM-2094]

Miscellaneous

A number of existing controls referencing ‘memorised secrets’ or ‘passphrases’ were amended to replace such terms with ‘passwords’ to align with preferred language under the finalised NIST SP 800-63B-4 publication. [ISM-0417, ISM-0421, ISM-0422, ISM-0487, ISM-0488, ISM-1449, ISM-1557, ISM-1558, ISM-1559, ISM-1560, ISM-1561, ISM-1596]

A number of existing controls were amended to replace ‘cybersecurity’ with ‘cyber security’. [ISM-0047, ISM-0718, ISM-0888, ISM-1602, ISM-1997, ISM-1998, ISM-1999, ISM-2000, ISM-2001, ISM-2002, ISM-2003, ISM-2004, ISM-2006, ISM-2020, ISM-2022, ISM-2037, ISM-2038, ISM-2051]

A number of existing controls were reverted to prior versions to use ‘cyber security’ instead of ‘cybersecurity’. [ISM-0039, ISM-0043, ISM-0109, ISM-0120, ISM-0123, ISM-0125, ISM-0140, ISM-0141, ISM-0252, ISM-0576, ISM-0714, ISM-0717, ISM-0720, ISM-0724, ISM-0725, ISM-0726, ISM-0732, ISM-0733, ISM-0735, ISM-1228, ISM-1478, ISM-1617, ISM-1618, ISM-1784, ISM-1803, ISM-1819, ISM-1880, ISM-1881, ISM-1906, ISM-1907, ISM-1918, ISM-1960, ISM-1961, ISM-1970, ISM-1986, ISM-1987]

A number of existing controls were reverted to prior versions to use ‘cyber threat’ instead of ‘cyberthreat’. [ISM-1526, ISM-1617]

A number of existing controls were reworded without changing their intent. [ISM-0585, ISM-1847, ISM-1955, ISM-1956, ISM-2072]

Contact details

If you have any questions regarding this guidance you can write to us or call us on 1300 CYBER1 (1300 292 371).

v2025.10.8

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 08 Oct 09:27

This version is based on the September 2025 Information security manual (ISM) and OSCAL version 1.1.2. A patch release that supersedes v2025.09.15.

v2025.09.15

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 15 Sep 12:13

This version is based on the September 2025 Information security manual (ISM) and OSCAL version 1.1.2. A patch release that supersedes v2025.09.10.

v2025.09.10

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 10 Sep 13:23

This version is based on the September 2025 Information security manual (ISM) and OSCAL version 1.1.2.

September 2025 changes

Cybersecurity principles

All cybersecurity principles have been assigned a shorthand description for easier reference.

Identify principles

A new identify principle was introduced to capture the identification and documentation of assets for pre-existing systems within organisations. As this new identify principle underpins all other identify principles, it has been labelled as IDE-01. Subsequent identify principles were relabelled in sequential order.

  • IDE-01 – Asset identification: Systems (cyber supply chains, infrastructure, operating systems, applications and data) are identified and documented.

Protect principles

Protect principle PRO-03 was amended to replace ‘trusted suppliers’ with ‘trustworthy suppliers’.

Protect principle PRO-07 was amended to replace ‘trusted operating systems, applications and code’ with ‘trustworthy operating systems, applications and code’.

Protect principle PRO-11 was amended to replace ‘trusted and vetted personnel’ with ‘trustworthy personnel’.

Protect principle PRO-12 was amended to replace ‘personnel’ with ‘personnel and services’.

Detect principles

Detect principles DET-01 and DET-02 were amended to draw a distinction between the collection of both security-related event logs and all configuration changes with their subsequent analysis.

  • DET-01 – Centralised event logging: Security-relevant event logs and all configuration changes are centrally collected and stored securely.

  • DET-02 – Cybersecurity event detection: Security-relevant event logs and all configuration changes are analysed in a timely manner to detect cybersecurity events.

Recover principles

A new category of cybersecurity principles, recover (REC), was introduced to capture risk management activities associated with the resumption of normal business operations following cybersecurity incidents. In support of this, respond principle RES-05 was relabelled as recover principle REC-01.

  • REC-01 – Business operations resumption: Residual security risks for systems (cyber supply chains, infrastructure, operating systems, applications and data) are accepted prior to the resumption of normal business operations following cybersecurity incidents.

Guidelines for physical security

Bringing photographic and video recording devices into facilities

A new control was added recommending that an authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis. [ISM-2069]

A new control was added recommending that unauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas. [ISM-2070]

Guidelines for personnel security

Managing and reporting suspicious requests to disclose or change user account details

A new control was added recommending that personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them. [ISM-2071]

Guidelines for software development

Secure artificial intelligence application development

The existing control recommending that large language model applications evaluate the sentence perplexity of user prompts to detect and mitigate adversarial suffixes designed to assist in the generation of sensitive or harmful content was amended to refer to generative artificial intelligence applications (instead of large language model applications) and preventing the generation of unintended behaviour. [ISM-1924]

A new control was added recommending that artificial intelligence models are stored in a file format that does not allow arbitrary code execution. [ISM-2072]

Guidelines for cryptography

Cryptographic implementation assurance

The existing control recommending that cryptographic equipment or applications that have completed a Common Criteria evaluation against a Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data was amended to refer to ‘ASD-endorsed Protection Profiles’ instead. [ISM-0457]

The existing control recommending that cryptographic equipment or applications that have completed a Common Criteria evaluation against a Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure was amended to refer to ‘ASD-endorsed Protection Profiles’ instead. [ISM-0465]

Existing controls referencing ‘cryptographic equipment and applications’ were amended to refer to ‘cryptographic equipment, applications and libraries’ instead. [ISM-0455, ISM-0457, ISM-0465, ISM-0471, ISM-0481, ISM-1917]

Transitioning to post-quantum cryptography

A new control was added recommending that a post-quantum cryptography transition plan is developed, implemented and maintained. [ISM-2073]

Miscellaneous

A number of existing controls referencing ‘trusted suppliers’ and ‘trusted sources’ were amended to refer to ‘trustworthy suppliers’ and ‘trustworthy sources’ instead to emphasise that trust placed in suppliers and sources should be verifiable. [ISM-0664, ISM-0665, ISM-0675, ISM-2029]

An existing control was reworded for consistency of language without changing its intent. [ISM-1657]

Contact details

If you have any questions regarding this guidance you can write to us or call us on 1300 CYBER1 (1300 292 371).

v2025.07.16

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 16 Jul 11:07

This version is based on the June 2025 Information security manual (ISM) and OSCAL version 1.1.2.

June 2025 ISM changes

A summary of the content changes for the latest update of the Information security manual (ISM) are covered below.

Cybersecurity principles

Govern principles

The Govern (GOV) principles were rewritten in support of increased adoption of Secure by Design and Secure by Default principles and practices. Specifically:

  • GOV-01: The board of directors or executive committee is accountable for cybersecurity.

  • GOV-02: A chief information security officer provides leadership and oversight of cybersecurity activities.

  • GOV-03: Security risk management activities for systems (cyber supply chains, infrastructure, operating systems, applications and data) are embedded into organisational risk management frameworks.

  • GOV-04: Suitable and sufficient personnel and resources are identified and acquired in support of cybersecurity activities.

  • GOV-05: Security risks for systems (cyber supply chains, infrastructure, operating systems, applications and data) are accepted before they are authorised for use and continuously monitored and managed throughout their operational life.

  • GOV-06: Security risks for systems (cyber supply chains, infrastructure, operating systems, applications and data) are transparently and mutually communicated with stakeholders.

  • GOV-07: Security risk management, and associated cybersecurity activities, are regularly reviewed to identify potential improvements in processes and procedures.

Identify principles

The Identify (IDE) principles were rewritten in support of increased adoption of Secure by Design and Secure by Default principles and practices. Specifically:

  • IDE-01: The business criticality of systems (cyber supply chains, infrastructure, operating systems, applications and data) is determined and documented.

  • IDE-02: The confidentiality, integrity and availability requirements for systems (cyber supply chains, infrastructure, operating systems, applications and data) are determined and documented.

  • IDE-03: Security risks for systems (cyber supply chains, infrastructure, operating systems, applications and data) are identified and documented along with any associated risk management decisions.

Protect principles

The Protect (PRO) principles were rewritten in support of increased adoption of Secure by Design and Secure by Default principles and practices. Specifically:

  • PRO-01: Systems (infrastructure, operating systems and applications) are planned, designed, developed, tested, deployed, maintained and decommissioned according to their business criticality and their confidentiality, integrity and availability requirements.

  • PRO-02: Systems (infrastructure, operating systems and applications) are planned, designed, developed, tested, deployed, maintained and decommissioned using Secure by Design and Secure by Default principles and practices.

  • PRO-03: Systems (infrastructure, operating systems, applications and data) are delivered and supported by trusted suppliers.

  • PRO-04: Systems (infrastructure, operating systems and applications) are configured to reduce their attack surface.

  • PRO-05: Systems (infrastructure, operating systems, applications and data) are administered in a secure and accountable manner.

  • PRO-06: Vulnerabilities in systems (cyber supply chains, infrastructure, operating systems, applications and data) are identified and mitigated in a timely manner.

  • PRO-07: Only trusted and supported operating systems, applications and code can execute on systems.

  • PRO-08: Data is encrypted at rest and in transit.

  • PRO-09: Data communicated between different security domains is controlled and inspectable.

  • PRO-10: Operating systems, applications, settings and data are backed up in a secure and proven manner on a regular basis.

  • PRO-11: Only trusted and vetted personnel are granted access to systems (cyber supply chains, infrastructure, operating systems, applications and data).

  • PRO-12: Personnel are granted the minimum access to systems (cyber supply chains, infrastructure, operating systems, applications and data) required to undertake their duties.

  • PRO-13: Robust and secure identity, credential and access management is used to control access to systems (cyber supply chains, infrastructure, operating systems, applications and data).

  • PRO-14: Personnel are provided with ongoing cybersecurity awareness training tailored to their duties.

  • PRO-15: Physical access to systems (infrastructure) is restricted to authorised personnel and monitored for unusual activities.

Detect principles

The Detect (DET) principles were rewritten in support of increased adoption of Secure by Design and Secure by Default principles and practices. Specifically:

  • DET-01: Security-relevant event logs are centrally collected and stored securely, then analysed in a timely manner to detect cybersecurity events.

  • DET-02: Security-relevant configuration changes are centrally collected and stored securely, then analysed in a timely manner to detect cybersecurity events.

  • DET-03: Cybersecurity events are analysed in a timely manner to identify cybersecurity incidents.

Respond principles

The Respond (RES) principles were rewritten in support of increased adoption of Secure by Design and Secure by Default principles and practices. Specifically:

  • RES-01: Cybersecurity incident response, business continuity and disaster recovery plans support continued business operations during cybersecurity incidents, and the resumption of normal business operations following cybersecurity incidents.

  • RES-02: Cybersecurity incidents, including associated response activities, are reported internally and externally to relevant bodies and stakeholders in a timely manner.

  • RES-03: Cybersecurity incidents are contained, eradicated and recovered from in a timely manner.

  • RES-04: Lessons learnt from cybersecurity incidents are captured, and areas for improvement are identified and actioned in a timely manner.

  • RES-05: Security risks for systems (cyber supply chains, infrastructure, operating systems, applications and data) are accepted prior to the resumption of normal business operations following cybersecurity incidents.

Maturity modelling

The maturity model provided for the assessment of the implementation of the cybersecurity principles was rescinded.

Guidelines for cybersecurity roles

Identifying critical business assets

The existing control the board of directors or executive committee understands the business criticality of their organisation’s systems, applications and data, including at least a basic understanding of what exists, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified was amended to simply refer to ‘systems’ to ensure consistency of language while noting that applications and data are integral components of systems. [ISM-2005]

Overseeing cybersecurity personnel

A new control was added recommending that the CISO ensures sufficient cybersecurity personnel, with the right skills and experience, are acquired to support cybersecurity activities within their organisation. [ISM-2020]

Protecting systems and their resources

The existing control recommending that agencies must identify and analyse security risks to their information and systems was reintroduced and amended to system owners, in consultation with each system’s authorising officer, conduct a threat and risk assessment for each system. [ISM-1203]

The existing control recommending that agencies must determine system-specific security risks that could warrant additional controls to those specified in this manual was reintroduced and amended to system owners, in consultation with each system’s authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation’s risk tolerances. [ISM-0009]

A new control was added recommending that system owners implement and maintain data minimisation practices for each of their systems. [ISM-2021]

Guidelines for procurement and outsourcing

Cyber supply chain risk management activities

Existing controls referring to the procurement of applications were expanded to capture the procurement of operating systems. [ISM-1452, ISM-1568, ISM-1631, ISM-1632, ISM-1882]

The existing control recommending applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems and cyber supply chains was amended to simply refer to ‘systems’ to ensure consistency of language while noting that cyber supply chains are integral components of systems. [ISM-1632]

Sourcing operating systems, applications, IT equipment, OT equipment and services

Existing controls referring to the sourcing of applications were amended to capture the sourcing of operating systems. [ISM-1787, ISM-1788]

Delivery of operating systems, applications, IT equipment, OT equipment and services

Existing controls referring to the delivery of applications were amended to capture the delivery of operating systems. [ISM-1790, ISM-1791, ISM-1792]

Access to systems by service providers

The existing control recommending _an organisation’s systems, applications and data are not accessed or administered by a service provider unless a contractual arrangement exists betwe...

Read more

v2025.03.31

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 31 Mar 12:23

This version is based on the March 2025 Information security manual (ISM) and OSCAL version 1.1.2.

March 2025 ISM changes

A summary of the content changes for the latest update of the Information security manual (ISM) are covered below.

Guidelines for cybersecurity roles

Embedding cybersecurity

A new control was added recommending that the board of directors or executive committee defines clear roles and responsibilities for cybersecurity both within the board of directors or executive committee and broadly within their organisation. [ISM-1997]

A new control was added recommending that the board of directors or executive committee ensures that cybersecurity is integrated throughout all business functions within their organisation. [ISM-1998]

A new control was added recommending that the board of directors or executive committee ensures the cybersecurity strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation. [ISM-1999]

A new control was added recommending that the board of directors or executive committee seeks regular briefings or reporting on the cybersecurity posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts. [ISM-2000]

Championing a positive cybersecurity culture

A new control was added recommending that the board of directors or executive committee champions a positive cybersecurity culture within their organisation, including through leading by example. [ISM-2001]

Building cybersecurity expertise

A new control was added recommending that the board of directors or executive committee maintains a sufficient level of cybersecurity literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations. [ISM-2002]

A new control was added recommending that the board of directors or executive committee maintains awareness of key cybersecurity recruitment activities, retention rates for cybersecurity personnel, and cybersecurity skills and experience gaps within their organisation. [ISM-2003]

A new control was added recommending that the board of directors or executive committee supports the development of cybersecurity skills and experience for all personnel via internal and external cybersecurity awareness raising and training opportunities. [ISM-2004]

Identifying critical business assets

A new control was added recommending that the board of directors or executive committee understands the business criticality of their organisation’s systems, applications and data, including at least a basic understanding of what exists, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified. [ISM-2005]

Planning for major cybersecurity incidents

A new control was added recommending that the board of directors or executive committee plans for major cybersecurity incidents, including by participating in exercises, and understand their duties in relation to such cybersecurity incidents. [ISM-2006]

Protecting systems and their resources

The existing control recommending that system owners determine the type, value and security objectives for each system based on an assessment of the impact if it were to be compromised was amended to recommend that system owners determine the system boundary, business criticality and security objectives for each system in consultation with the system’s authorising officer. [ISM-1633]

The existing control recommending that system owners select controls for each system and tailor them to achieve desired security objectives was amended to recommend that this activity be conducted in consultation with the system’s authorising officer. [ISM-1634]

The existing control recommending that system owners ensure controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation’s own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended was amended to recommend that this activity be conducted in consultation with the system’s authorising officer. [ISM-1636]

The existing control recommending that system owners ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and its operating environment, undergo a security assessment by ASD assessors (or their delegates) to determine if they have been implemented correctly and are operating as intended was amended to recommend that this activity be conducted in consultation with the system’s authorising officer. [ISM-1967]

Guidelines for physical security

Bringing medical devices into facilities

A new control was added recommending that an authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis. [ISM-2007]

A new control was added recommending that medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria:

  • are listed on the Australian Register of Therapeutic Goods
  • have been prescribed by a legally qualified medical practitioner
  • have been commercially purchased within Australia
  • do not have inbuilt cellular connectivity
  • are capable of operating independently of mobile devices
  • where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas. [ISM-2008]

A new control was added recommending that unauthorised medical devices are not brought into SECRET and TOP SECRET areas. [ISM-2009]

Guidelines for cybersecurity documentation

Change and configuration management plan

The previously rescinded control on change management processes was reinstated and amended to cover the development of change and configuration management plans for systems, specifically: Systems have a change and configuration management plan that includes:

  • what constitutes routine and urgent changes to the configuration of systems
  • how changes to the configuration of systems will be requested, tracked and documented
  • who needs to be consulted prior to routine and urgent changes to the configuration of systems
  • who needs to approve routine and urgent changes to the configuration of systems
  • who needs to be notified of routine and urgent changes to the configuration of systems
  • what additional change management and configuration management processes and procedures need be to followed before, during and after routine and urgent changes to the configuration of systems. [ISM-0912]

Guidelines for information technology equipment

IT equipment selection

The existing control on the selection of IT equipment was rescinded due to duplication of an existing procurement control within the Guidelines for procurement and outsourcing. [ISM-1857]

Guidelines for system hardening

Host-based intrusion detection and response

The existing control recommending that a HIPS is implemented on workstations was amended to specify that either a HIPS or Endpoint Detection and Response (EDR) solution can be used. [ISM-1341]

The existing control recommending that a HIPS is implemented on critical servers and high-value servers was amended to specify that either a HIPS or EDR solution can be used. [ISM-1034]

Microsoft Active Directory Domain Services account hardening

A new control was added recommending that service accounts configured with an SPN use the Advanced Encryption Standard for encryption. [ISM-2010]

Multi-factor authentication

A new control was added recommending that when phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.
[ISM-2011]

Session locking

The existing control recommending that systems are configured with a session or screen lock that […] was amended to focus exclusively on session locking. This includes new recommendations that a maximum of 12 hours overall be adopted before session locking occurs (i.e. before forced re-authentication) and that users use all authentication factors when re-authenticating a session. [ISM-0428]

Screen locking

A new control was added recommending that systems are configured with a screen lock that […]. This control was split from ISM-0428 with the addition of a new recommendation that users use all authentication factors when re-authenticating to unlock a system. [ISM-2012]

Guidelines for system management

System administration processes and procedures

The existing control recommending that system administrators document requirements for administrative activities, consider potential security impacts, obtain any necessary approvals, notify users of any disruptions or outages, and maintain system and security documentation was amended to system administrators perform system administration activities in accordance with the system’s change and configuration management plan. [ISM-1211]

Guidelines for software development

Development, testing, staging and production environments

The existing control recommending that development, testing and production environments are segregated was amended to include staging environments. [ISM-0400]

The existing control recommending that _data from production environments is not used in a deve...

Read more

v2024.12.19

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 18 Dec 13:26
a62b6ae

This version is based on the December 2024 Information Security Manual (ISM) and OSCAL version 1.1.2.

Additionally, the ISM OSCAL prop custom namespace version has been increased reflecting the changes required for the ISM December 2024 release, including the ALL-baseline profile being replaced by the NON_CLASSIFIED-baseline profile. Please refer to the ISM release notes below for more information.

December 2024 ISM Changes

A summary of the content changes for the latest update of the Information Security Manual (ISM) are covered below.

Using the Information Security Manual

Select controls

The NC applicability marking has been introduced for controls applicable to non-classified systems used by either government or non-government entities. In doing so, the All applicability that previously captured such systems has been replaced by the NC, OS, P, S, TS applicability marking. Note, government entities operating non-classified systems can continue to refer to them as OFFICIAL systems.

Guidelines for Cyber Security Roles

Overseeing the cyber security program

A new control was added recommending that the CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation. [ISM-1966]

Protecting systems and their resources

The existing control recommending that system owners ensure controls for each system and its operating environment are assessed to determine if they have been implemented correctly and are operating as intended was split into two controls to clearly articulate that non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET systems can be assessed by an organisation’s own assessors or an IRAP assessor while TOP SECRET systems, including sensitive compartmented information systems, need to be assessed by ASD assessors (or their delegates). [ISM-1636, ISM-1967]

The existing control recommending that system owners obtain authorisation to operate each system from its authorising officer based on the acceptance of the security risks associated with its operation was split into two controls to clearly articulate that only Director-General ASD (or their delegate) can accept security risks associated with the operation of TOP SECRET systems, including sensitive compartmented information systems.
[ISM-0027, ISM-1968]

Guidelines for Cyber Security Incidents

Handling and containing malicious code infections

A new control was added recommending that malicious code, when stored or communicated, is treated beforehand to prevent accidental execution. [ISM-1969]

A new control was added recommending that malicious code processed for cyber security incident response or research purposes is done so in a dedicated analysis environment that is segregated from other systems. [ISM-1970]

Guidelines for Procurement and Outsourcing

Assessment of managed service providers

The existing control recommending that managed service providers and their managed services undergo a security assessment by an IRAP assessor at least every 24 months was amended to specify that this recommendation relates to non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services. In addition, the recommendation was amended to specify that the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release) needs to be used. [ISM-1793]

A new control was added recommending that managed service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months. [ISM-1971]

Assessment of outsourced cloud service providers

The existing control recommending that outsourced cloud service providers and their cloud services undergo a security assessment by an IRAP assessor at least every 24 months was amended to specify that this recommendation relates to non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services. In addition, the recommendation was amended to specify that the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release) needs to be used. [ISM-1570]

A new control was added recommending that outsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months. [ISM-1972]

Guidelines for Physical Security

Physical access to systems

A new control was added recommending that non-classified systems are secured in suitably secure facilities.
[ISM-1973]

The existing control recommending that systems are secured in facilities that meet the requirements for a security zone suitable for their classification was amended to specify that this recommendation relates to classified systems.
[ISM-0810]

Physical access to servers, network devices and cryptographic equipment

A new control was added recommending that non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms. [ISM-1974]

The existing control recommending that servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification was amended to specify that this recommendation relates to classified servers, network devices and cryptographic equipment. [ISM-1053]

A new control was added recommending that non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers. [ISM-1975]

The existing control recommending that servers, network devices and cryptographic equipment are secured in security containers or secure rooms suitable for their classification taking into account the combination of security zones they reside in was amended to specify that this recommendation relates to classified servers, network devices and cryptographic equipment. In addition, the control was amended to remove the reference to secure rooms. [ISM-1530]

The existing control recommending that server rooms, communications rooms, security containers and secure rooms are not left in unsecured states was amended to remove the reference to secure rooms. [ISM-0813]

The existing control recommending that keys or equivalent access mechanisms to server rooms, communications rooms, security containers and secure rooms are appropriately controlled was amended to remove the reference to secure rooms. [ISM-1074]

Guidelines for Communications Infrastructure

Cable colours

The existing control recommending that OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red was expanded to include non-classified cables. [ISM-0926]

Cable inspectability

The existing control recommending that cables are inspectable at a minimum of five-metre intervals was amended to clarify that cables should be inspectable every five-metres or less. [ISM-1112]

Wall outlet box colours

The existing control recommending that OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red was expanded to include non-classified wall outlet boxes. [ISM-1107]

Emanation security threat assessments

The existing control recommending that system owners deploying OFFICIAL: Sensitive or PROTECTED systems with radio frequency transmitters (including any wireless capabilities) that will be located within 20 meters of SECRET or TOP SECRET systems contact ASD for an emanation security threat assessment has been rescinded. [ISM-0248]

Existing controls relating to emanation security threat assessments, that included OFFICIAL: Sensitive and PROTECTED systems within their scope, have been re-scoped to apply exclusively to SECRET and TOP SECRET systems.
[ISM-0246, ISM-1885]

Guidelines for Communications Systems

Speakerphones

The existing control recommending that speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room was expanded to include non-classified telephone systems. [ISM-0235]

Off-hook audio protection

The existing control recommending that in SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements was expanded to include non-classified telephone systems. [ISM-0931]

Microphones and webcams

The existing control recommending that microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas was expanded to include non-classified workstations. [ISM-0559]

The existing control recommending that microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas was expanded to include non-classified workstations.
[ISM-1450]

Guidelines for Enterprise Mobility

Using Bluetooth functionality

Existing controls relating to the use of Bluetooth functionality with OFFICIAL: Sensitive and PROTECTED mobile devices were expanded to include non-clas...

Read more

v2024.10.4

Choose a tag to compare

@ACSCUser4 ACSCUser4 released this 04 Oct 05:10

This version is based on October patch release of the September 2024 Information Security Manual (ISM) and OSCAL version 1.1.2. A patch release that supersedes v2024.09.26.