Framework overlap

Does ACSC Essential Eight cover Australian Information Security Manual?

You hold ACSC Essential Eight and have been told to do Australian Information Security Manual. Here is how much overlaps, control by control.

5% of Australian Information Security Manual you already have

ACSC Essential Eight already covers about 5% of Australian Information Security Manual, leaving 1024 of 1081 controls as genuinely new work.

Already covered 57 Likely covered 0 New work 1024

What is genuinely new work

Nothing in ACSC Essential Eight reaches these. This is the list to scope.

ISM-0009
System owners, in consultation with each system's authorising officer, identify any supple
ISM-0027
System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensit
ISM-0039
A cyber security strategy is developed, implemented and maintained.
ISM-0041
Systems have a system security plan that includes an overview of the system (covering the
ISM-0042
System administration processes, and supporting system administration procedures, are deve
ISM-0043
Systems have a cyber security incident response plan that covers the following: - guidelin
ISM-0047
Organisational-level cyber security documentation is approved by the chief information sec
ISM-0072
Security requirements associated with the confidentiality, integrity and availability of d
ISM-0078
Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under
ISM-0100
Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessm
ISM-0109
Event logs from workstations are analysed in a timely manner to detect cyber security even
ISM-0120
Cyber security personnel have access to sufficient data sources and tools to ensure that s
ISM-0123
Cyber security incidents are reported to the chief information security officer, or one of
ISM-0125
A cyber security incident register is developed, implemented and maintained.
ISM-0133
When a data spill occurs, data owners are advised and access to the data is restricted.
ISM-0137
Legal advice is sought before allowing intrusion activity to continue on a system for the
ISM-0138
The integrity of evidence gathered during an investigation is maintained by investigators:
ISM-0140
Cyber security incidents are reported to ASD as soon as possible after they occur or are d
ISM-0141
The requirement for service providers to report cyber security incidents to a designated p
ISM-0142
The compromise or suspected compromise of cryptographic equipment or associated keying mat
ISM-0161
IT equipment and media are secured when not in use.
ISM-0164
Unauthorised people are prevented from observing systems, in particular workstation displa
ISM-0181
Cabling infrastructure is installed in accordance with relevant Australian Standards, as d
ISM-0187
SECRET cables, when bundled together or run in conduit, are run exclusively in their own i
ISM-0194
In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit
ISM-0195
In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to
ISM-0198
When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Orga
ISM-0201
Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre
ISM-0206
Cable labelling processes, and supporting cable labelling procedures, are developed, imple
ISM-0208
A cable register contains the following for each cable: - cable identifier - cable colour
ISM-0211
A cable register is developed, implemented, maintained and verified on a regular basis.
ISM-0213
SECRET and TOP SECRET cables are terminated on their own individual patch panels.
ISM-0216
TOP SECRET patch panels are installed in individual TOP SECRET cabinets.
ISM-0217
Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabi
ISM-0218
If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wa
ISM-0225
Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.
ISM-0229
Personnel are advised of the permitted sensitivity or classification of information that c
ISM-0230
Personnel are advised of security risks posed by non-secure telephone systems in areas whe
ISM-0231
When using cryptographic equipment to permit different levels of conversation for differen
ISM-0232
Telephone systems used for sensitive or classified conversations encrypt all traffic that
ISM-0233
Cordless telephone handsets and headsets are not used for sensitive or classified conversa
ISM-0235
Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone s
ISM-0236
Off-hook audio protection features are used on telephone systems in areas where background
ISM-0240
Paging, Multimedia Message Service, Short Message Service and messaging apps are not used
ISM-0245
MFDs are not connected to digital telephone systems.
ISM-0246
When an emanation security risk assessment is required, it is sought as early as possible
ISM-0249
System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployab
ISM-0250
IT equipment meets industry and government standards relating to electromagnetic interfere
ISM-0252
Cyber security awareness training is undertaken annually by all personnel and covers: - th
ISM-0258
A web usage policy is developed, implemented and maintained.
ISM-0260
All web access, including that by internal servers, is conducted through web proxies.
ISM-0261
The following details are centrally logged for websites accessed via web proxies: - web ad
ISM-0263
TLS traffic communicated through gateways is decrypted and inspected.
ISM-0264
An email usage policy is developed, implemented and maintained.
ISM-0267
Access to non-approved webmail services is blocked.
ISM-0269
Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To
ISM-0270
Protective markings are applied to emails and reflect the highest sensitivity or classific
ISM-0271
Protective marking tools do not automatically insert protective markings into emails.
ISM-0272
Protective marking tools do not allow users to select protective markings that a system ha
ISM-0280
If procuring an evaluated product, a product that has completed a PP-based evaluation, inc
ISM-0285
Evaluated products are delivered in a manner consistent with any delivery procedures defin
ISM-0286
When procuring high assurance information technology (IT) equipment, ASD is contacted for
ISM-0289
Evaluated products are installed, configured, administered and operated in an evaluated co
ISM-0290
High assurance IT equipment is installed, configured, administered and operated in an eval
ISM-0293
IT equipment is classified based on the highest sensitivity or classification of data that
ISM-0294
IT equipment, with the exception of high assurance IT equipment, is labelled with protecti
ISM-0296
ASD's approval is sought before applying labels to external surfaces of high assurance IT
ISM-0298
A centralised and managed approach that maintains the integrity of patches or updates, and
ISM-0300
Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equi
ISM-0304
Applications other than office productivity suites, web browsers and their extensions, ema
ISM-0305
Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared
ISM-0306
If an appropriately cleared technician is not used to undertake maintenance or repairs of
ISM-0307
If an appropriately cleared technician is not used to undertake maintenance or repairs of
ISM-0310
IT equipment maintained or repaired off site is done so at facilities approved for handlin
ISM-0311
IT equipment containing media is sanitised by removing the media from the IT equipment or
ISM-0312
IT equipment, including associated media, that is located overseas and has processed, stor
ISM-0313
IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures,
ISM-0315
High assurance IT equipment is destroyed prior to its disposal.
ISM-0316
Following sanitisation, destruction or declassification, a formal administrative decision
ISM-0317
At least three pages of random text with no blank areas are printed on each colour printer
ISM-0318
When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per e
ISM-0321
When disposing of IT equipment that has been designed or modified to meet emanation securi
ISM-0323
Media is classified to the highest sensitivity or classification of data it stores, unless
ISM-0325
Any media connected to a system with a higher sensitivity or classification than the media
ISM-0330
Before reclassifying media to a lower sensitivity or classification, the media is sanitise
ISM-0332
Media, with the exception of internally mounted fixed media within information technology
ISM-0336
A networked IT equipment register is developed, implemented, maintained and verified on a
ISM-0337
Media is only used with systems that are authorised to process, store or communicate its s
ISM-0341
Automatic execution features for removable media are disabled.
ISM-0343
If there is no business requirement for writing to removable media and devices, such funct
ISM-0345
External communication interfaces that allow DMA are disabled.
ISM-0347
When transferring data manually between two systems belonging to different security domain
ISM-0348
Media sanitisation processes, and supporting media sanitisation procedures, are developed,
ISM-0350
The following media types are destroyed prior to their disposal: - microfiche and microfil
ISM-0351
Volatile media is sanitised by removing its power for at least 10 minutes.
ISM-0352
SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its e
ISM-0354
Non-volatile magnetic media is sanitised by overwriting it at least once (or three times i
ISM-0356
Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its clas
ISM-0357
Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified
ISM-0358
Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains
ISM-0359
Non-volatile flash memory media is sanitised by overwriting it at least twice in its entir
ISM-0360
Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its
ISM-0361
Magnetic media is destroyed using a degausser with a suitable magnetic field strength and
ISM-0362
Product-specific directions provided by degausser manufacturers are followed.
ISM-0363
Media destruction processes, and supporting media destruction procedures, are developed, i
ISM-0368
Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results i
ISM-0370
The destruction of media is performed under the supervision of at least one cleared person
ISM-0371
Personnel supervising the destruction of media supervise its handling to the point of dest
ISM-0372
The destruction of media storing accountable material is performed under the supervision o
ISM-0373
Personnel supervising the destruction of media storing accountable material supervise its
ISM-0374
Media disposal processes, and supporting media disposal procedures, are developed, impleme
ISM-0375
Following sanitisation, destruction or declassification, a formal administrative decision
ISM-0378
Labels and markings indicating the owner, sensitivity, classification or any other marking
ISM-0380
Unneeded user accounts, components, services and functionality of operating systems are di
ISM-0382
Unprivileged users do not have the ability to uninstall or disable approved applications.
ISM-0383
Default user accounts or credentials for operating systems, including for any pre-configur
ISM-0385
Servers maintain effective functional separation with other servers allowing them to opera
ISM-0393
Databases and their contents are classified based on the sensitivity or classification of
ISM-0400
Development, testing, staging and production environments are segregated.
ISM-0401
Secure by Design principles and practices are followed throughout the software development
ISM-0402
Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to
ISM-0405
Requests for unprivileged access to systems and their resources are validated when first r
ISM-0407
A secure record is maintained for the life of systems and their resources that covers the
ISM-0408
Systems have a logon banner that reminds users of their security responsibilities when acc
ISM-0409
Foreign nationals, including seconded foreign nationals, do not have access to systems tha
ISM-0411
Foreign nationals, excluding seconded foreign nationals, do not have access to systems tha
ISM-0414
Personnel granted access to systems and their resources are uniquely identifiable.
ISM-0415
The use of shared user accounts is strictly controlled, and personnel using such accounts
ISM-0417
When systems cannot support multi-factor authentication, single-factor authentication usin
ISM-0418
Physical credentials are kept separate from systems they are used to authenticate to, exce
ISM-0420
Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are fo
ISM-0421
Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and
ISM-0422
Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20
ISM-0428
Services are configured with a session lock that: - activates after a maximum of 15 minute
ISM-0430
Access to systems and their resources are removed or suspended the same day personnel no l
ISM-0432
Access requirements for systems and their resources are documented in their system securit
ISM-0434
Personnel undergo appropriate employment screening and, where necessary, hold an appropria
ISM-0435
Personnel receive any necessary briefings before being granted access to systems and their
ISM-0441
When personnel are granted temporary access to systems and their resources, effective cont
ISM-0443
Temporary access is not granted to systems that process, store or communicate caveated or
ISM-0446
Foreign nationals, including seconded foreign nationals, do not have privileged access to
ISM-0447
Foreign nationals, excluding seconded foreign nationals, do not have privileged access to
ISM-0455
Where practical, cryptographic equipment, applications and libraries provide a means of da
ISM-0457
Cryptographic equipment, applications or libraries that have completed a Common Criteria e
ISM-0459
Full disk encryption, or partial encryption where access controls will only allow writing
ISM-0460
HACE is used when encrypting media that contains SECRET or TOP SECRET data.
ISM-0462
When a user authenticates to the encryption functionality of IT equipment or media, it is
ISM-0465
Cryptographic equipment, applications or libraries that have completed a Common Criteria e
ISM-0467
HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently s
ISM-0469
An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is
ISM-0471
Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment,
ISM-0472
When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is
ISM-0474
When using ECDH for agreeing on encryption session keys, a base point order and key size o
ISM-0475
When using ECDSA for digital signatures, a base point order and key size of at least 224 b
ISM-0476
When using RSA for digital signatures, and transporting encryption session keys (and simil
ISM-0477
When using RSA for digital signatures, and for transporting encryption session keys (and s
ISM-0479
Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.
ISM-0481
Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment,
ISM-0484
The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress x
ISM-0485
Public key-based authentication is used for SSH connections.
ISM-0487
When using logins without a password for SSH connections, the following are disabled: - ac
ISM-0488
If using remote access without the use of a password for SSH connections, the 'forced comm
ISM-0489
When SSH-agent or similar key caching applications are used, it is limited to workstations
ISM-0490
Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.
ISM-0494
Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel
ISM-0496
The ESP protocol is used for authentication and encryption of IPsec connections.
ISM-0498
A security association lifetime of less than four hours (14400 seconds) is used for IPsec
ISM-0499
Communications security doctrine and policy produced by ASD for the management and operati
ISM-0501
Keyed cryptographic equipment is transported based on the sensitivity or classification of
ISM-0507
Cryptographic key management processes, and supporting cryptographic key management proced
ISM-0516
Network documentation includes high-level network diagrams showing all connections into ne
ISM-0518
Network documentation is developed, implemented and maintained.
ISM-0520
Network access controls are implemented on networks to prevent the connection of unauthori
ISM-0521
IPv6 functionality is disabled in dual-stack network devices unless it is being used.
ISM-0529
VLANs are not used to separate network traffic between networks belonging to different sec
ISM-0530
Network devices managing VLANs are administered from the most trusted security domain.
ISM-0534
Unused physical ports on network devices are disabled.
ISM-0535
Network devices managing VLANs belonging to different security domains do not share VLAN t
ISM-0536
Public wireless networks provided for general public use are segregated from all other org
ISM-0546
When video conferencing or IP telephony traffic passes through a gateway containing a fire
ISM-0547
Video conferencing and IP telephony calls are conducted using a secure real-time transport
ISM-0548
Video conferencing and IP telephony calls are established using a secure session initiatio
ISM-0549
Video conferencing and IP telephony traffic is separated physically or logically from othe
ISM-0551
IP telephony is configured such that: - IP phones authenticate themselves to the call cont
ISM-0553
Authentication and authorisation is used for all actions on a video conferencing network,
ISM-0554
An encrypted and non-replayable two-way authentication scheme is used for call authenticat
ISM-0555
Authentication and authorisation is used for all actions on an IP telephony network, inclu
ISM-0556
Workstations are not connected to video conferencing units or IP phones unless the worksta
ISM-0558
IP phones used in public areas do not have the ability to access data networks, voicemail
ISM-0559
Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET
ISM-0565
Email servers are configured to block, log and report emails with inappropriate protective
ISM-0567
Email servers only relay emails destined for or originating from their domains (including
ISM-0569
Emails are routed via centralised email gateways.
ISM-0570
Where backup or alternative email gateways are in place, they are maintained at the same s
ISM-0571
When users send or receive emails, an authenticated and encrypted channel is used to route
ISM-0572
Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing em
ISM-0574
SPF is used to specify authorised email servers (or lack thereof) for an organisation's do
ISM-0576
A cyber security incident management policy, and associated cyber security incident respon
ISM-0580
An event logging policy is developed, implemented and maintained.
ISM-0582
Security-relevant events for Microsoft Windows operating systems are centrally logged.
ISM-0585
For each event logged, the date and time of the event, the relevant user or process, the r
ISM-0588
An MFD usage policy is developed, implemented and maintained.
ISM-0589
MFDs are not used to scan or copy documents above the sensitivity or classification of net
ISM-0590
Authentication measures for MFDs are the same strength as those used for workstations on n
ISM-0591
Evaluated peripheral switches are used when sharing peripherals between systems.
ISM-0597
When planning, designing, implementing or introducing additional connectivity to CDSs, ASD
ISM-0610
Users are trained on the secure use of CDSs before access is granted.
ISM-0611
System administrators for gateways are assigned the minimum privileges required to perform
ISM-0612
System administrators for gateways are formally trained on the operation and management of
ISM-0613
System administrators for gateways that connect to Australian Eyes Only or Releasable To n
ISM-0616
Separation of duties is implemented in performing administrative activities for gateways.
ISM-0619
Users authenticate to other networks accessed via gateways.
ISM-0622
IT equipment authenticates to other networks accessed via gateways.
ISM-0626
CDSs are implemented between SECRET or TOP SECRET networks and any other networks belongin
ISM-0628
Gateways are implemented between networks belonging to different security domains.
ISM-0629
For gateways between networks belonging to different security domains, any shared componen
ISM-0631
Gateways only allow explicitly authorised data flows.
ISM-0634
Security-relevant events for gateways are centrally logged, including: - data packets and
ISM-0635
CDSs implement isolated upward and downward network paths.
ISM-0637
Gateways implement a demilitarised zone if external parties require access to an organisat
ISM-0639
Evaluated firewalls are used between networks belonging to different security domains.
ISM-0643
Evaluated diodes are used for controlling the data flow of unidirectional gateways between
ISM-0645
Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC
ISM-0649
Files imported or exported via gateways or CDSs are filtered for allowed file types.
ISM-0651
Files identified by content filtering checks as malicious, or that cannot be inspected, ar
ISM-0652
Files identified by content filtering checks as suspicious are quarantined until reviewed
ISM-0657
When manually importing data to systems, the data is scanned for malicious and active cont
ISM-0659
Files imported or exported via gateways or CDSs undergo content filtering checks.
ISM-0660
Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly.
ISM-0661
Users transferring data to and from systems are held accountable for data transfers they p
ISM-0663
Data transfer processes, and supporting data transfer procedures, are developed, implement
ISM-0664
Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustwort
ISM-0665
Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services t
ISM-0669
When manually exporting data from SECRET and TOP SECRET systems, digital signatures are va
ISM-0670
Security-relevant events for CDSs are centrally logged.
ISM-0675
Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a tru
ISM-0677
Files imported or exported via gateways or CDSs that have a digital signature or cryptogra
ISM-0682
Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.
ISM-0687
Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that
ISM-0694
Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET s
ISM-0701
Mobile device emergency sanitisation processes, and supporting mobile device emergency san
ISM-0702
If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SE
ISM-0705
When accessing an organisation's network via a VPN connection, split tunnelling is disable
ISM-0714
A CISO is appointed to provide cyber security leadership and guidance for their organisati
ISM-0717
The CISO oversees the management of cyber security personnel within their organisation.
ISM-0718
The CISO regularly reports directly to their organisation's board of directors or executiv
ISM-0720
The CISO oversees the development, implementation and maintenance of a cyber security comm
ISM-0724
The CISO implements cyber security measurement metrics and key performance indicators for
ISM-0725
The CISO coordinates cyber security and business alignment through a cyber security steeri
ISM-0726
The CISO coordinates security risk management activities between cyber security and busine
ISM-0731
The CISO oversees cyber supply chain risk management activities for their organisation.
ISM-0732
The CISO receives and manages a dedicated cyber security budget for their organisation.
ISM-0733
The CISO is fully aware of all cyber security incidents within their organisation.
ISM-0734
The CISO contributes to the development, implementation and maintenance of business contin
ISM-0735
The CISO oversees the development, implementation and maintenance of their organisation's
ISM-0810
Classified systems are secured in facilities that meet the requirements for a security zon
ISM-0813
Server rooms, communications rooms and security containers are not left in unsecured state
ISM-0817
Personnel are advised of what suspicious contact via online services is and how to report
ISM-0820
Personnel are advised to not post work information to unauthorised online services and to
ISM-0821
Personnel are advised of security risks associated with posting personal information to on
ISM-0824
Personnel are advised not to send or receive files via unauthorised online services.
ISM-0829
Security measures are used to detect and respond to unauthorised RF devices in SECRET and
ISM-0831
Media is handled in a manner suitable for its sensitivity or classification.
ISM-0835
Following sanitisation, TOP SECRET volatile media retains its classification if it stored
ISM-0836
Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety wit
ISM-0839
The destruction of media storing accountable material is not outsourced.
ISM-0840
When outsourcing the destruction of media storing non-accountable material, a National Ass
ISM-0846
All users (with the exception of local administrator accounts and break glass accounts) ca
ISM-0853
On a daily basis, outside of business hours and after an appropriate period of inactivity,
ISM-0854
AUSTEO and AGAO data can only be accessed from systems under the sole control of the Austr
ISM-0861
DKIM signing is enabled on emails originating from an organisation's domains (including su
ISM-0863
Mobile devices prevent personnel from installing non-approved applications once provisione
ISM-0864
Mobile devices prevent personnel from disabling or modifying security functionality once p
ISM-0866
Sensitive or classified data is not viewed on mobile devices in public locations unless ca
ISM-0869
Mobile devices encrypt their internal storage and any removable media.
ISM-0870
Mobile devices are carried or stored in a secured state when not being actively used.
ISM-0871
Mobile devices are kept under continual direct supervision when being actively used.
ISM-0874
Mobile devices and desktop computers access the internet via an organisation's internet ga
ISM-0888
Cyber security documentation is reviewed at least annually and includes a 'current as at \
ISM-0912
Systems have a change and configuration management plan that includes: - the establishment
ISM-0917
When malicious code is detected, the following steps are taken to handle the infection: -
ISM-0926
Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink
ISM-0931
In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to
ISM-0938
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin
ISM-0947
When transferring data manually between two systems belonging to different security domain
ISM-0955
Application control is implemented using cryptographic hash rules, publisher certificate r
ISM-0958
An organisation-approved list of domain names, or list of website categories, is implement
ISM-0961
Client-side active content is restricted by web content filters to an organisation-approve
ISM-0963
Web content filtering is implemented to filter potentially harmful web-based content.
ISM-0971
The OWASP Application Security Verification Standard is used in the development of web app
ISM-0988
An accurate and consistent time source is used for event logging.
ISM-0994
ECDH is used in preference to DH.
ISM-0998
AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with
ISM-0999
DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random E
ISM-1000
PFS is used for IPsec connections.
ISM-1006
Security measures are implemented to prevent unauthorised access to network management tra
ISM-1013
The effective range of wireless communications outside an organisation's area of control i
ISM-1014
Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversation
ISM-1019
A denial of service response plan for video conferencing and IP telephony services is deve
ISM-1023
The intended recipients of blocked inbound emails, and the senders of blocked outbound ema
ISM-1024
Notifications of undeliverable emails are only sent to senders that can be verified via SP
ISM-1026
DKIM signatures on incoming emails are verified.
ISM-1027
Email distribution list applications used by external senders is configured such that it d
ISM-1028
A NIDS or NIPS is deployed in gateways between an organisation's networks and other networ
ISM-1030
A NIDS or NIPS is located immediately inside the outermost firewall for gateways and confi
ISM-1034
A HIPS or EDR solution is implemented on critical servers and high-value servers.
ISM-1036
MFDs are located in areas where their use can be observed.
ISM-1037
Gateways undergo testing following configuration changes, and at regular intervals no more
ISM-1053
Classified servers, network devices and cryptographic equipment are secured in server room
ISM-1055
LAN Manager and NT LAN Manager authentication methods are disabled.
ISM-1059
All data stored on media is encrypted.
ISM-1065
The host-protected area and device configuration overlay table are reset prior to the sani
ISM-1067
The ATA secure erase command is used, in addition to block overwriting software, to ensure
ISM-1071
Each system has a designated system owner.
ISM-1073
An organisation's systems are not accessed or administered by a service provider unless a
ISM-1074
Keys or equivalent access mechanisms to server rooms, communications rooms and security co
ISM-1076
Televisions and computer monitors with minor burn-in or image persistence are sanitised by
ISM-1078
A telephone system usage policy is developed, implemented and maintained.
ISM-1079
ASD's approval is sought before undertaking any maintenance or repairs to high assurance I
ISM-1080
An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm i
ISM-1082
A mobile device usage policy is developed, implemented and maintained.
ISM-1083
Personnel are advised of the sensitivity or classification permitted for voice and data co
ISM-1084
If unable to carry or store mobile devices in a secured state, they are physically transfe
ISM-1085
Mobile devices encrypt all sensitive or classified data communicated over public network i
ISM-1088
Personnel report the potential compromise of mobile devices, removable media or credential
ISM-1089
Protective marking tools do not allow users replying to or forwarding emails to select pro
ISM-1091
Keying material is changed when compromised or suspected of being compromised.
ISM-1095
Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.
ISM-1096
Cables are labelled at each end with sufficient source and destination details to enable t
ISM-1098
SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet wit
ISM-1100
TOP SECRET cables are terminated in an individual TOP SECRET cabinet.
ISM-1101
In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or c
ISM-1102
Cable reticulation systems leading into cabinets are terminated as close as possible to th
ISM-1103
In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms
ISM-1105
SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.
ISM-1107
Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither s
ISM-1109
Wall outlet box covers are clear plastic.
ISM-1111
Fibre-optic cables are used for cabling infrastructure instead of copper cables.
ISM-1112
Cables in non-TOP SECRET areas are inspectable every five metres or less.
ISM-1114
Cable bundles or conduits sharing a common cable reticulation system have a dividing parti
ISM-1115
Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.
ISM-1116
A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
ISM-1119
Cables in TOP SECRET areas are fully inspectable for their entire length.
ISM-1122
Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET ca
ISM-1123
A power distribution board with a feed from an Uninterruptible Power Supply is used to pow
ISM-1130
In shared facilities, cables are run in an enclosed cable reticulation system.
ISM-1133
In shared facilities, TOP SECRET cables are not run in party walls.
ISM-1137
System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD f
ISM-1139
Only the latest version of TLS is used for TLS connections.
ISM-1143
Patch management processes, and supporting patch management procedures, are developed, imp
ISM-1145
Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices.
ISM-1146
Personnel are advised to maintain separate work and personal user accounts for online serv
ISM-1151
SPF is used to verify the authenticity of incoming emails.
ISM-1157
Evaluated diodes are used for controlling the data flow of unidirectional gateways between
ISM-1158
Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC
ISM-1160
If using degaussers to destroy media, degaussers evaluated by the United States' National
ISM-1163
Systems have a continuous monitoring plan that includes: - conducting vulnerability scans
ISM-1164
In shared facilities, conduits or the front covers of ducts, cable trays in floors and cei
ISM-1171
Attempts to access websites through their IP addresses instead of their domain names are b
ISM-1178
Network documentation provided to a third party, or published in public tender documentati
ISM-1181
Networks are segregated into multiple network zones according to the criticality of server
ISM-1182
Network access controls are implemented to limit the flow of network traffic within and be
ISM-1183
A hard fail SPF record is used when specifying authorised email servers (or lack thereof)
ISM-1186
IPv6 capable network security appliances are used on IPv6 and dual-stack networks.
ISM-1187
When manually exporting data from systems, the data is checked for unsuitable protective m
ISM-1192
Gateways inspect and filter data flows at the transport and above network layers.
ISM-1195
Mobile Device Management solutions that have completed a Common Criteria evaluation agains
ISM-1196
Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain
ISM-1198
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is
ISM-1199
Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices ar
ISM-1200
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is
ISM-1203
System owners, in consultation with each system's authorising officer, conduct a threat an
ISM-1211
System administrators perform system administration activities in accordance with the syst
ISM-1213
Following intrusion remediation activities, full network traffic is captured for at least
ISM-1216
SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appro
ISM-1217
Labels and markings indicating the owner, sensitivity, classification or any other marking
ISM-1218
IT equipment, including associated media, that is located overseas and has processed, stor
ISM-1219
MFD print drums and image transfer rollers are inspected and destroyed if there is remnant
ISM-1220
Printer and MFD platens are inspected and destroyed if any text or images are retained on
ISM-1221
Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a pa
ISM-1222
Televisions and computer monitors that cannot be sanitised are destroyed.
ISM-1223
Memory in network devices is sanitised using the following processes, in order of preferen
ISM-1227
Credentials set for user accounts are randomly generated.
ISM-1228
Cyber security events are analysed in a timely manner to identify cyber security incidents
ISM-1233
IKE version 2 is used for key exchange when establishing IPsec connections.
ISM-1234
Email content filtering is implemented to filter potentially harmful content in email bodi
ISM-1235
Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clien
ISM-1236
Malicious domain names, dynamic domain names and domain names that can be registered anony
ISM-1237
Web content filtering is applied to outbound web traffic where appropriate.
ISM-1238
Threat modelling is used in support of the software development life cycle.
ISM-1239
Robust web application frameworks are used in the development of web applications.
ISM-1240
Validation and sanitisation are performed on all input received over the internet by softw
ISM-1241
Output encoding is performed on all output produced by web applications.
ISM-1243
A database register is developed, implemented, maintained and verified on a regular basis.
ISM-1245
All temporary installation files and logs created during server application installation p
ISM-1246
Server applications are hardened using ASD and vendor hardening guidance, with the most re
ISM-1247
Unneeded user accounts, components, services and functionality of server applications are
ISM-1249
Server applications are configured to run as a separate user account with the minimum priv
ISM-1250
The user accounts under which server applications run have limited access to their underly
ISM-1255
Database users' ability to access, insert, modify and remove database contents is restrict
ISM-1256
File-based access controls are applied to database files.
ISM-1260
Default user accounts or credentials for server applications, including for any pre-config
ISM-1263
Unique privileged user accounts are used for administering individual server applications.
ISM-1268
The need-to-know principle is enforced for database contents through the application of mi
ISM-1269
Database servers and web servers are functionally separated.
ISM-1270
Database servers are placed on a different network segment to user workstations.
ISM-1271
Network access controls are implemented to restrict database server communications to stri
ISM-1272
If only local access to a database is required, networking functionality of database manag
ISM-1273
Database servers for development, testing, staging and production environments are segrega
ISM-1274
Database contents from production environments are not used in non-production environments
ISM-1275
All queries to databases from software are filtered for legitimate content and correct syn
ISM-1276
Parameterised queries or stored procedures, instead of dynamically generated queries, are
ISM-1277
Data communicated between database servers and web servers is encrypted.
ISM-1278
Software is designed or configured to provide as little error information as possible abou
ISM-1284
Files imported or exported via gateways or CDSs undergo content validation.
ISM-1286
Files imported or exported via gateways or CDSs undergo content conversion.
ISM-1287
Files imported or exported via gateways or CDSs undergo content sanitisation.
ISM-1288
Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple
ISM-1289
Archive files imported or exported via gateways or CDSs are unpacked in order to undergo c
ISM-1290
Archive files are unpacked in a controlled manner to ensure content filter performance or
ISM-1293
Encrypted files imported or exported via gateways or CDSs are decrypted in order to underg
ISM-1294
Data transfer logs for systems are partially verified at least monthly.
ISM-1296
Physical security is implemented to protect network devices in public areas from physical
ISM-1297
Legal advice is sought prior to allowing privately-owned mobile devices and desktop comput
ISM-1298
Personnel are advised of privacy and security risks when travelling overseas with mobile d
ISM-1299
Personnel are advised to take the following precautions when using mobile devices: - never
ISM-1300
Upon returning from travelling overseas with mobile devices, personnel take the following
ISM-1304
Default user accounts or credentials for network devices, including for any pre-configured
ISM-1311
SNMP version 1 and SNMP version 2 are not used on networks.
ISM-1312
All default SNMP community strings on network devices are changed and write access is disa
ISM-1314
All wireless devices are Wi-Fi Alliance certified.
ISM-1315
The administrative interface on wireless access points is disabled for wireless network co
ISM-1316
Default SSIDs of wireless access points are changed.
ISM-1317
SSIDs of non-public wireless networks are not readily associated with an organisation, the
ISM-1318
SSID broadcasting is not disabled on wireless access points.
ISM-1319
Static addressing is not used for assigning IP addresses on wireless networks.
ISM-1320
MAC address filtering is not used to restrict which devices can connect to wireless networ
ISM-1321
802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentic
ISM-1322
Evaluated supplicants, authenticators, wireless access points and authentication servers a
ISM-1323
Certificates are required for devices and users accessing wireless networks.
ISM-1324
Certificates are generated using an evaluated certificate authority or hardware security m
ISM-1327
Certificates are protected by logical and physical access controls, encryption, and user a
ISM-1330
The PMK caching period is not set to greater than 1440 minutes (24 hours).
ISM-1332
WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all w
ISM-1334
Wireless networks implement sufficient frequency separation from other wireless networks.
ISM-1335
Wireless access points enable the use of the 802.11w amendment to protect management frame
ISM-1338
Instead of deploying a small number of wireless access points that broadcast on high power
ISM-1341
A HIPS or EDR solution is implemented on workstations.
ISM-1359
A removable media usage policy is developed, implemented and maintained.
ISM-1361
Security Construction and Equipment Committee-approved equipment or ASIO-approved equipmen
ISM-1364
Network devices managing VLANs terminate VLANs belonging to different security domains on
ISM-1366
Security updates are applied to mobile devices as soon as they become available.
ISM-1369
AES-GCM is used for encryption of TLS connections.
ISM-1370
Only server-initiated secure renegotiation is used for TLS connections.
ISM-1372
DH or ECDH is used for key establishment of TLS connections.
ISM-1373
Anonymous DH is not used for TLS connections.
ISM-1374
SHA-2-based certificates are used for TLS connections.
ISM-1375
SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom funct
ISM-1380
Privileged users use separate privileged and unprivileged operating environments.
ISM-1385
Administrative infrastructure is segregated from the wider network and the internet.
ISM-1386
Network management traffic can only originate from administrative infrastructure.
ISM-1387
Administrative activities are conducted through jump servers.
ISM-1389
Executable files imported via gateways or CDSs are automatically executed in a sandbox to
ISM-1392
When implementing application control using path rules, only approved users can modify app
ISM-1395
Service providers, including any subcontractors, provide an appropriate level of protectio
ISM-1400
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se
ISM-1402
Credentials stored on systems are protected by a password manager; a hardware security mod
ISM-1403
User accounts, except for break glass accounts, are locked out after a maximum of five fai
ISM-1404
Unprivileged access to systems and their resources are disabled after 45 days of inactivit
ISM-1405
A centralised event logging facility is implemented.
ISM-1406
SOEs are used for workstations and servers.
ISM-1407
The latest release, or the previous release, of operating systems are used.
ISM-1408
Where supported, 64-bit versions of operating systems are used.
ISM-1409
Operating systems are hardened using ASD and vendor hardening guidance, with the most rest
ISM-1412
Web browsers are hardened using ASD and vendor hardening guidance, with the most restricti
ISM-1416
A software firewall is implemented on workstations and servers to restrict inbound and out
ISM-1417
An antivirus application is implemented on workstations and servers with: - signature-base
ISM-1418
If there is no business requirement for reading from removable media and devices, such fun
ISM-1419
Development and modification of software only takes place in development environments.
ISM-1420
Data from production environments is not used in non-production environments unless the no
ISM-1422
Unauthorised access to the authoritative source for software is prevented.
ISM-1424
Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame
ISM-1427
Gateways perform ingress traffic filtering to detect and prevent IP source address spoofin
ISM-1428
Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
ISM-1429
IPv6 tunnelling is blocked by network security appliances at externally-connected network
ISM-1430
Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protoco
ISM-1431
Denial-of-service attack mitigation strategies are discussed with cloud service providers,
ISM-1432
Domain names for online services are protected via registrar locking and confirming that d
ISM-1436
Critical online services are segregated from other online services that are more likely to
ISM-1437
Cloud service providers are used for hosting online services.
ISM-1438
Where a high availability requirement exists for website hosting, CDNs that cache websites
ISM-1439
If using CDNs, disclosing the IP addresses of web servers under an organisation's control
ISM-1446
When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.
ISM-1448
When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is u
ISM-1449
SSH private keys are protected with a password or a key encryption key.
ISM-1450
Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SE
ISM-1451
Types of data and its ownership is documented in contractual arrangements with service pro
ISM-1452
A supply chain risk assessment is performed for suppliers of operating systems, applicatio
ISM-1453
Perfect Forward Secrecy (PFS) is used for TLS connections.
ISM-1454
Communications between authenticators and a RADIUS server are encapsulated with an additio
ISM-1457
Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET s
ISM-1460
When using a software-based isolation mechanism to share a physical server's hardware, the
ISM-1461
When using a software-based isolation mechanism to share a physical server's hardware for
ISM-1467
The latest release of office productivity suites, web browsers and their extensions, email
ISM-1470
Unneeded components, services and functionality of office productivity suites, web browser
ISM-1471
When implementing application control using publisher certificate rules, publisher names a
ISM-1478
The CISO oversees their organisation's cyber security program and ensures their organisati
ISM-1479
Servers minimise communications with other servers at the network and file system level.
ISM-1480
Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET sy
ISM-1482
Personnel using organisation-owned mobile devices or desktop computers to access classifie
ISM-1483
The latest release of internet-facing server applications are used.
ISM-1485
Web browsers do not process web advertisements from the internet.
ISM-1486
Web browsers do not process Java from the internet.
ISM-1491
Unprivileged users are prevented from running script execution engines, including: - Windo
ISM-1492
Operating system exploit protection functionality is enabled.
ISM-1493
Software registers for workstations, servers, network devices and networked IT equipment a
ISM-1501
Operating systems that are no longer supported by vendors are replaced.
ISM-1502
Emails arriving via an external connection where the email source address uses an internal
ISM-1506
The use of SSH version 1 is disabled for SSH connections.
ISM-1510
A digital preservation policy is developed, implemented and maintained.
ISM-1517
Equipment that is capable of reducing microform to a fine powder, with resultant particles
ISM-1520
System administrators for gateways undergo appropriate employment screening, and where nec
ISM-1521
CDSs implement protocol breaks at each network layer.
ISM-1522
CDSs implement independent security-enforcing functions for upward and downward network pa
ISM-1523
A sample of security-relevant events relating to data transfer policies are taken at least
ISM-1524
Content filters used by CDSs undergo rigorous security testing to ensure they perform as e
ISM-1525
System owners register each system with its authorising officer.
ISM-1526
System owners continuously monitor the security of each system, and manage associated cybe
ISM-1528
Evaluated firewalls are used between an organisation's networks and public network infrast
ISM-1529
Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud servi
ISM-1530
Classified servers, network devices and cryptographic equipment are secured in security co
ISM-1532
VLANs are not used to separate network traffic between an organisation's networks and publ
ISM-1533
A mobile device management policy is developed, implemented and maintained.
ISM-1534
Printer ribbons in printers and MFDs are removed and destroyed.
ISM-1535
Processes, and supporting procedures, are developed, implemented and maintained to prevent
ISM-1536
All queries to databases from software that are initiated by users, and any resulting cras
ISM-1537
Security-relevant events for databases are centrally logged, including: - access or modifi
ISM-1540
DMARC records are configured for an organisation's domains (including subdomains) such tha
ISM-1542
Microsoft Office is configured to prevent activation of Object Linking and Embedding packa
ISM-1543
An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, impl
ISM-1546
Users are authenticated before they are granted access to a system and its resources.
ISM-1547
Data backup processes, and supporting data backup procedures, are developed, implemented a
ISM-1548
Data restoration processes, and supporting data restoration procedures, are developed, imp
ISM-1549
A media management policy is developed, implemented and maintained.
ISM-1550
IT equipment disposal processes, and supporting IT equipment disposal procedures, are deve
ISM-1551
An IT equipment management policy is developed, implemented and maintained.
ISM-1552
All web application content is offered exclusively using HTTPS.
ISM-1553
TLS compression is disabled for TLS connections.
ISM-1554
If travelling overseas with mobile devices to high or extreme risk countries, personnel ar
ISM-1555
Before travelling overseas with mobile devices, personnel take the following actions: - re
ISM-1556
If returning from travelling overseas with mobile devices to high or extreme risk countrie
ISM-1557
Passwords used for single-factor authentication on SECRET systems are a minimum of 17 char
ISM-1558
Passwords using a sequence of words for single-factor authentication are not constructed u
ISM-1559
Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and
ISM-1560
Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 charac
ISM-1561
Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 c
ISM-1562
Video conferencing and IP telephony infrastructure is hardened.
ISM-1563
At the conclusion of a security assessment for a system, a security assessment report is p
ISM-1564
At the conclusion of a security assessment for a system, a plan of action and milestones i
ISM-1565
Tailored privileged user training is undertaken annually by all privileged users.
ISM-1566
Use of unprivileged access is centrally logged.
ISM-1567
Suppliers identified as high risk by a cyber supply chain risk assessment are not used.
ISM-1568
Operating systems, applications, IT equipment, OT equipment and services are procured from
ISM-1569
A shared responsibility model is created, documented and shared between suppliers and thei
ISM-1570
Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTE
ISM-1571
The right to verify compliance with security requirements is documented in contractual arr
ISM-1572
The regions or availability zones where data will be processed, stored and communicated, a
ISM-1573
Access to all logs relating to an organisation's data and services is documented in contra
ISM-1574
The storage of data in a portable manner that allows for backups, service migration and se
ISM-1575
A minimum notification period of one month for the cessation of any services by a service
ISM-1576
If an organisation's systems are accessed or administered by a service provider in an unau
ISM-1577
An organisation's networks are segregated from their service providers' networks.
ISM-1579
Cloud service providers' ability to dynamically scale resources in response to a genuine s
ISM-1580
Where a high availability requirement exists for online services, the services are archite
ISM-1581
Continuous real-time monitoring of the capacity and availability of online services is per
ISM-1583
Personnel who are contractors are identified as such.
ISM-1584
Unprivileged users are prevented from bypassing, disabling or modifying security functiona
ISM-1585
Web browser security settings cannot be changed by users.
ISM-1586
Data transfer logs are used to record all data imports and exports from systems.
ISM-1587
System owners report the security status of each system to its authorising officer at leas
ISM-1588
SOEs are reviewed and updated at least annually.
ISM-1589
MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.
ISM-1590
Credentials for user accounts are changed if: - they are compromised - they are suspected
ISM-1591
Access to systems and their resources are removed or suspended as soon as practicable when
ISM-1592
Unprivileged users do not have the ability to install unapproved applications.
ISM-1593
Users provide sufficient evidence to verify their identity when requesting new credentials
ISM-1594
Credentials are provided to users via a secure communications channel or, if not possible,
ISM-1595
Credentials provided to users are changed on first use.
ISM-1596
Credentials are not reused by users across different systems.
ISM-1597
Credentials are obscured as they are entered into systems.
ISM-1598
Following maintenance or repair activities for IT equipment, the IT equipment is inspected
ISM-1599
IT equipment is handled in a manner suitable for its sensitivity or classification.
ISM-1600
Media is sanitised before it is used for the first time.
ISM-1601
Microsoft's attack surface reduction rules are implemented.
ISM-1602
Cyber security documentation, including notification of subsequent changes, is communicate
ISM-1603
Authentication methods susceptible to replay attacks are disabled.
ISM-1604
When using a software-based isolation mechanism to share a physical server's hardware, the
ISM-1605
When using a software-based isolation mechanism to share a physical server's hardware, the
ISM-1606
When using a software-based isolation mechanism to share a physical server's hardware, pat
ISM-1607
When using a software-based isolation mechanism to share a physical server's hardware, int
ISM-1608
SOEs provided by third parties are scanned for malicious code and configurations.
ISM-1609
System owners are consulted before allowing intrusion activity to continue on a system for
ISM-1610
A method of emergency access to systems and their resources is documented and tested at le
ISM-1611
Break glass accounts are only used when normal authentication processes cannot be used.
ISM-1612
Break glass accounts are only used for specific authorised activities.
ISM-1613
Use of break glass accounts is centrally logged.
ISM-1614
Break glass account credentials are changed by the account custodian after they are access
ISM-1615
Break glass accounts are tested after credentials are changed.
ISM-1616
A vulnerability disclosure program is implemented to assist with the secure development an
ISM-1617
The CISO regularly reviews and updates their organisation's cyber security program to ensu
ISM-1618
The CISO oversees their organisation's response to cyber security incidents.
ISM-1619
Service accounts are created as group Managed Service Accounts.
ISM-1620
Privileged user accounts are members of the Protected Users security group.
ISM-1621
Windows PowerShell 2.0 is disabled or removed.
ISM-1622
PowerShell is configured to use Constrained Language Mode.
ISM-1623
PowerShell module logging, script block logging and transcription events are centrally log
ISM-1624
PowerShell script block logs are protected by Protected Event Logging functionality.
ISM-1625
An insider threat mitigation program is developed, implemented and maintained.
ISM-1626
Legal advice is sought regarding the development and implementation of an insider threat m
ISM-1627
Inbound network connections from anonymity networks are blocked.
ISM-1628
Outbound network connections to anonymity networks are blocked.
ISM-1629
When using DH for agreeing on encryption session keys, a modulus and associated parameters
ISM-1631
Suppliers of operating systems, applications, IT equipment, OT equipment and services asso
ISM-1632
Operating systems, applications, IT equipment, OT equipment and services are procured from
ISM-1633
System owners, in consultation with each system's authorising officer, determine the syste
ISM-1634
System owners, in consultation with each system's authorising officer, select controls for
ISM-1635
System owners implement controls for each system and its operating environment.
ISM-1636
System owners, in consultation with each system's authorising officer, ensure controls for
ISM-1637
An outsourced cloud service register is developed, implemented, maintained and verified on
ISM-1638
An outsourced cloud service register contains the following for each outsourced cloud serv
ISM-1639
Building management cables are labelled with their purpose in black writing on a yellow ba
ISM-1640
Cables for foreign systems installed in Australian facilities are labelled at inspection p
ISM-1641
Following the use of a degausser, magnetic media is physically damaged by deforming any in
ISM-1642
Media is sanitised before it is reused in a different security domain.
ISM-1643
Software registers contain versions and patch histories of applications, drivers, operatin
ISM-1644
Sensitive or classified phone calls and conversations are not conducted in public location
ISM-1645
Floor plan diagrams are developed, implemented, maintained and verified on a regular basis
ISM-1646
Floor plan diagrams contain the following: - cable paths (including ingress and egress poi
ISM-1647
Privileged access to systems and their resources are disabled after 12 months unless reval
ISM-1648
Privileged access to systems and their resources are disabled after 45 days of inactivity.
ISM-1654
Internet Explorer 11 is disabled or removed.
ISM-1655
.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
ISM-1667
Microsoft Office is blocked from creating child processes.
ISM-1668
Microsoft Office is blocked from creating executable content.
ISM-1669
Microsoft Office is blocked from injecting code into other processes.
ISM-1670
PDF applications are blocked from creating child processes.
ISM-1685
Credentials for break glass accounts, local administrator accounts and service accounts ar
ISM-1686
Credential Guard functionality is enabled.
ISM-1687
Privileged operating environments are not virtualised within unprivileged operating enviro
ISM-1688
Unprivileged user accounts cannot logon to privileged operating environments.
ISM-1689
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivil
ISM-1690
Patches, updates or other vendor mitigations for vulnerabilities in online services are ap
ISM-1691
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su
ISM-1692
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su
ISM-1693
Patches, updates or other vendor mitigations for vulnerabilities in applications other tha
ISM-1694
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i
ISM-1695
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w
ISM-1696
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w
ISM-1697
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi
ISM-1698
A vulnerability scanner is used at least daily to identify missing patches or updates for
ISM-1699
A vulnerability scanner is used at least weekly to identify missing patches or updates for
ISM-1700
A vulnerability scanner is used at least fortnightly to identify missing patches or update
ISM-1701
A vulnerability scanner is used at least daily to identify missing patches or updates for
ISM-1702
A vulnerability scanner is used at least fortnightly to identify missing patches or update
ISM-1703
A vulnerability scanner is used at least fortnightly to identify missing patches or update
ISM-1704
Office productivity suites, web browsers and their extensions, email clients, PDF applicat
ISM-1710
Settings for wireless access points are hardened.
ISM-1711
User identity confidentiality is used if available with EAP-TLS implementations.
ISM-1712
The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications a
ISM-1713
A removable media register is developed, implemented, maintained and verified on a regular
ISM-1717
A 'security.txt' file is hosted for each of an organisation's internet-facing website doma
ISM-1718
SECRET cables are coloured salmon pink.
ISM-1719
TOP SECRET cables are coloured red.
ISM-1720
SECRET wall outlet boxes are coloured salmon pink.
ISM-1721
TOP SECRET wall outlet boxes are coloured red.
ISM-1722
Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disin
ISM-1723
Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrato
ISM-1724
Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator,
ISM-1725
Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, dega
ISM-1726
Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grind
ISM-1727
Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrato
ISM-1728
The resulting media waste particles from the destruction of SECRET media is stored and han
ISM-1729
The resulting media waste particles from the destruction of TOP SECRET media is stored and
ISM-1730
A software bill of materials is produced and made available to consumers of software.
ISM-1731
Planning and coordination of intrusion remediation activities are conducted on a separate
ISM-1732
To the extent possible, all intrusion remediation activities are conducted in a coordinate
ISM-1735
Media that cannot be successfully sanitised is destroyed prior to its disposal.
ISM-1736
A managed service register is developed, implemented, maintained and verified on a regular
ISM-1737
A managed service register contains the following for each managed service: - managed serv
ISM-1738
The right to verify compliance with security requirements documented in contractual arrang
ISM-1739
A system's security architecture is approved prior to the development of the system.
ISM-1740
Personnel dealing with banking details and payment requests are advised of what business e
ISM-1741
IT equipment destruction processes, and supporting IT equipment destruction procedures, ar
ISM-1742
IT equipment that cannot be sanitised is destroyed.
ISM-1743
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin
ISM-1745
Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is ena
ISM-1746
When implementing application control using path rules, only approved users can change fil
ISM-1748
Email client security settings cannot be changed by users.
ISM-1749
Cached credentials are limited to one previous logon.
ISM-1750
Administrative infrastructure for critical servers, high-value servers and regular servers
ISM-1751
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I
ISM-1752
A vulnerability scanner is used at least fortnightly to identify missing patches or update
ISM-1753
Internet-facing network devices that are no longer supported by vendors are replaced.
ISM-1754
Vulnerabilities identified in software are resolved in a timely manner.
ISM-1755
A vulnerability disclosure policy is developed, implemented and maintained.
ISM-1756
Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, ar
ISM-1759
When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is
ISM-1761
When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves
ISM-1762
When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are us
ISM-1763
When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, prefe
ISM-1764
When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably t
ISM-1765
When using RSA for digital signatures, and transporting encryption session keys (and simil
ISM-1766
When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-
ISM-1767
When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA-
ISM-1768
When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA-
ISM-1769
When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.
ISM-1770
When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.
ISM-1771
AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.
ISM-1772
PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, p
ISM-1773
System administrators for gateways that connect to Australian Government Access Only netwo
ISM-1774
Gateways are managed via a secure path isolated from all connected networks.
ISM-1778
When manually importing data to systems, all data that fails security checks is quarantine
ISM-1779
When manually exporting data from systems, all data that fails security checks is quaranti
ISM-1780
SecDevOps practices are used for software development.
ISM-1781
All data communicated over network infrastructure is encrypted.
ISM-1782
A protective DNS service is used to block access to known malicious domain names.
ISM-1783
Public IP addresses controlled by, or used by, an organisation are signed by valid ROA rec
ISM-1784
The cyber security incident management policy, including the associated cyber security inc
ISM-1785
A supplier relationship management policy is developed, implemented and maintained.
ISM-1786
An approved supplier list is developed, implemented and maintained.
ISM-1787
Operating systems, applications, IT equipment, OT equipment and services are sourced from
ISM-1788
Multiple potential suppliers are identified for sourcing critical operating systems, appli
ISM-1789
Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserv
ISM-1790
Operating systems, applications, IT equipment, OT equipment and services are delivered in
ISM-1791
The integrity of operating systems, applications, IT equipment, OT equipment and services
ISM-1792
The authenticity of operating systems, applications, IT equipment, OT equipment and servic
ISM-1793
Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SEC
ISM-1794
A minimum notification period of one month by service providers for significant changes to
ISM-1795
Credentials for built-in Administrator accounts, break glass accounts, local administrator
ISM-1796
Files containing executable content are digitally signed by a certificate with a verifiabl
ISM-1797
Installers, patches and updates are digitally signed or provided with cryptographic checks
ISM-1798
Secure configuration guidance, in the form of a hardening guide or loosening guide, is pro
ISM-1799
Incoming emails are rejected if they do not pass DMARC checks.
ISM-1800
Network devices are flashed with trusted firmware before they are used for the first time.
ISM-1801
Network devices are restarted on at least a monthly basis.
ISM-1802
HACE are issued an Approval for Use by ASD and operated in accordance with the latest vers
ISM-1803
A cyber security incident register contains the following for each cyber security incident
ISM-1804
Break clauses associated with failure to meet security requirements are documented in cont
ISM-1805
A denial of service response plan for video conferencing and IP telephony services contain
ISM-1806
Default user accounts or credentials for user applications, including for any pre-configur
ISM-1807
An automated method of asset discovery is used at least fortnightly to support the detecti
ISM-1808
A vulnerability scanner with an up-to-date vulnerability database is used for vulnerabilit
ISM-1809
When applications, operating systems, network devices or networked IT equipment that are n
ISM-1815
Event logs are protected from unauthorised modification and deletion.
ISM-1816
Unauthorised modification of the authoritative source for software is prevented.
ISM-1817
Authentication and authorisation of clients is performed when clients call network APIs th
ISM-1818
Authentication and authorisation of clients is performed when clients call network APIs th
ISM-1819
Following the identification of a cyber security incident, the cyber security incident res
ISM-1820
Cables for individual systems use a consistent colour.
ISM-1821
TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their o
ISM-1822
Wall outlet boxes for individual systems use a consistent colour.
ISM-1823
Office productivity suite security settings cannot be changed by users.
ISM-1824
PDF application security settings cannot be changed by users.
ISM-1825
Security product security settings cannot be changed by users.
ISM-1826
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin
ISM-1827
Microsoft AD DS domain controllers are administered using dedicated domain administrator u
ISM-1828
The Print Spooler service is disabled on Microsoft AD DS domain controllers.
ISM-1829
Passwords are not stored in Group Policy Preferences.
ISM-1830
Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA server
ISM-1832
Only service accounts and computer accounts are configured with Service Principal Names (S
ISM-1833
User accounts are provisioned with the minimum privileges required.
ISM-1834
Duplicate SPNs do not exist within the domain.
ISM-1835
Privileged user accounts are configured as sensitive and cannot be delegated.
ISM-1836
User accounts require Kerberos pre-authentication.
ISM-1838
The UserPassword attribute for user accounts is not used.
ISM-1839
Account properties accessible by unprivileged users are not used to store passwords.
ISM-1840
User account passwords do not use reversible encryption.
ISM-1841
Unprivileged user accounts cannot add machines to the domain.
ISM-1842
Dedicated privileged service accounts are used to add machines to the domain.
ISM-1843
User accounts with unconstrained delegation are reviewed at least annually, and those with
ISM-1844
Computer accounts that are not Microsoft AD DS domain controllers are not trusted for dele
ISM-1845
When a user account is disabled, it is removed from all security group memberships.
ISM-1846
The Pre-Windows 2000 Compatible Access security group does not contain user accounts.
ISM-1847
Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are change
ISM-1848
When using a software-based isolation mechanism to share a physical server's hardware, the
ISM-1849
The OWASP Top 10 Proactive Controls are used in the development of web applications.
ISM-1850
The OWASP Top 10 are mitigated in the development of web applications.
ISM-1851
The OWASP API Security Top 10 are mitigated in the development of web APIs.
ISM-1852
Unprivileged access to systems and their resources is limited to only what is required for
ISM-1854
Users authenticate to MFDs before they can print, scan or copy documents.
ISM-1855
Use of MFDs for printing, scanning and copying purposes, including the capture of shadow c
ISM-1858
IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictiv
ISM-1859
Office productivity suites are hardened using ASD and vendor hardening guidance, with the
ISM-1860
PDF applications are hardened using ASD and vendor hardening guidance, with the most restr
ISM-1861
Local Security Authority protection functionality is enabled.
ISM-1862
If using a WAF, disclosing the IP addresses of web servers under an organisation's control
ISM-1863
Networked management interfaces for IT equipment are not directly exposed to the internet.
ISM-1864
A system usage policy is developed, implemented and maintained.
ISM-1865
Personnel agree to abide by system usage policies before being granted access to systems a
ISM-1866
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se
ISM-1867
Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile pla
ISM-1868
SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand
ISM-1869
A non-networked IT equipment register is developed, implemented, maintained and verified o
ISM-1875
Networks are scanned at least monthly to identify any credentials that are being stored in
ISM-1876
Patches, updates or other vendor mitigations for vulnerabilities in online services are ap
ISM-1877
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i
ISM-1878
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I
ISM-1879
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi
ISM-1880
Cyber security incidents that involve customer data are reported to customers and the publ
ISM-1881
Cyber security incidents that do not involve customer data are reported to customers and t
ISM-1882
Operating systems, applications, IT equipment, OT equipment and services are procured from
ISM-1884
Emanation security doctrine produced by ASD for the management of emanation security matte
ISM-1885
Recommended actions contained within emanation security mitigation advice issued for syste
ISM-1886
Mobile devices are configured to operate in a supervised (or equivalent) mode.
ISM-1887
Mobile devices are configured with remote locate and wipe functionality.
ISM-1888
Mobile devices are configured with secure password-based lock screens.
ISM-1889
Command line process creation events are centrally logged.
ISM-1895
Successful and unsuccessful single-factor authentication events are centrally logged.
ISM-1896
Memory integrity functionality is enabled.
ISM-1897
Remote Credential Guard functionality is enabled.
ISM-1898
Secure Admin Workstations are used in the performance of administrative activities.
ISM-1899
Network devices that do not belong to administrative infrastructure cannot initiate connec
ISM-1900
A vulnerability scanner is used at least fortnightly to identify missing patches or update
ISM-1901
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su
ISM-1902
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w
ISM-1903
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w
ISM-1904
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w
ISM-1905
Online services that are no longer supported by vendors are removed.
ISM-1906
Event logs from internet-facing servers are analysed in a timely manner to detect cyber se
ISM-1907
Event logs from non-internet-facing servers are analysed in a timely manner to detect cybe
ISM-1908
Vulnerabilities identified in software are publicly disclosed in a responsible and timely
ISM-1909
In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent
ISM-1910
Network API calls that facilitate modification of data, or access to data not authorised f
ISM-1911
Security-relevant usage, error messages and crashes for software are centrally logged.
ISM-1912
Network documentation includes device settings for all critical servers, high-value server
ISM-1913
Approved configurations for IT equipment are developed, implemented and maintained.
ISM-1914
Approved configurations for operating systems are developed, implemented and maintained.
ISM-1915
Approved configurations for user applications are developed, implemented and maintained.
ISM-1916
Approved configurations for server applications are developed, implemented and maintained.
ISM-1917
The development and procurement of new cryptographic equipment, applications and libraries
ISM-1918
The CISO regularly reports directly to their organisation's audit, risk and compliance com
ISM-1919
When multi-factor authentication is used to authenticate users or customers to online serv
ISM-1920
When multi-factor authentication is used to authenticate users to online services, online
ISM-1921
The likelihood of system compromise is frequently assessed when working exploits exist for
ISM-1922
The OWASP Mobile Application Security Verification Standard is used in the development of
ISM-1924
Generative artificial intelligence applications evaluate user prompts to detect and mitiga
ISM-1926
Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers an
ISM-1927
Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS
ISM-1928
Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS
ISM-1929
Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain control
ISM-1930
Passwords are prevented from being stored in Group Policy Preferences.
ISM-1931
SID Filtering is enabled for domain and forest trusts.
ISM-1932
The number of service accounts configured with an SPN is minimised.
ISM-1933
Service accounts configured with an SPN do not have DCSync permissions.
ISM-1934
User accounts with DCSync permissions are reviewed at least annually, and those without an
ISM-1935
Computer accounts are not configured for unconstrained delegation.
ISM-1936
The sIDHistory attribute for user accounts is not used.
ISM-1937
User accounts are checked at least weekly for the presence of the sIDHistory attribute.
ISM-1938
The Domain Computers security group does not have write or modify permissions to any Micro
ISM-1939
The number of user accounts that are members of the Domain Admins, Enterprise Admins or ot
ISM-1940
Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-p
ISM-1941
Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly-
ISM-1942
The Domain Computers security group is not a member of any privileged or highly-privileged
ISM-1943
Strong mapping between certificates and users is enforced.
ISM-1944
The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
ISM-1945
The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
ISM-1946
Unprivileged user accounts do not have write access to certificate templates.
ISM-1947
Extended Key Usages that enable user authentication are removed.
ISM-1948
CA Certificate Manager approval is required for certificate templates that allow a Subject
ISM-1949
Microsoft AD FS servers are administered using a dedicated service account that is not use
ISM-1950
Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial
ISM-1951
Hard match takeover is disabled for Microsoft Entra Connect servers.
ISM-1952
Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra
ISM-1953
Credentials for the built-in Administrator account in each domain are long, unique, unpred
ISM-1954
Credentials for built-in Administrator accounts, break glass accounts, local administrator
ISM-1955
Credentials for computer accounts are changed if they are compromised, they are suspected
ISM-1956
Microsoft AD FS token-signing and encryption certificates are changed twice in quick succe
ISM-1957
Private keys for Microsoft AD CS CA servers are protected by a hardware security module.
ISM-1958
User accounts with DCSync permissions cannot logon to unprivileged operating environments.
ISM-1959
To the extent possible, event logs are captured and stored in a consistent and structured
ISM-1960
Event logs from internet-facing network devices are analysed in a timely manner to detect
ISM-1961
Event logs from non-internet-facing network devices are analysed in a timely manner to det
ISM-1962
SMB version 1 is not used on networks.
ISM-1963
Security-relevant events for internet-facing network devices are centrally logged.
ISM-1964
Security-relevant events for non-internet-facing network devices are centrally logged.
ISM-1965
Files imported or exported via gateways or CDSs undergo content checking.
ISM-1966
The CISO develops, implements, maintains and verifies on a regular basis a register of sys
ISM-1967
System owners, in consultation with each system's authorising officer, ensure controls for
ISM-1968
System owners obtain an authorisation to operate for each TOP SECRET system, including for
ISM-1969
Malicious code, when stored or communicated, is treated beforehand to prevent accidental e
ISM-1970
Malicious code processed for cyber security incident response or research purposes is done
ISM-1971
Managed service providers and their TOP SECRET managed services, including sensitive compa
ISM-1972
Outsourced cloud service providers and their TOP SECRET cloud services, including sensitiv
ISM-1973
Non-classified systems are secured in suitably secure facilities.
ISM-1974
Non-classified servers, network devices and cryptographic equipment are secured in suitabl
ISM-1975
Non-classified servers, network devices and cryptographic equipment are secured in suitabl
ISM-1976
Security-relevant events for Apple macOS operating systems are centrally logged.
ISM-1977
Security-relevant events for Linux operating systems are centrally logged.
ISM-1978
Security-relevant events for server applications on internet-facing servers are centrally
ISM-1979
Security-relevant events for server applications on non-internet-facing servers are centra
ISM-1980
Credential hint functionality is not used for systems.
ISM-1981
Non-internet-facing network devices that are no longer supported by vendors are replaced.
ISM-1982
Networked IT equipment that is no longer supported by vendors is replaced.
ISM-1983
Event logs sent to a centralised event logging facility are done so as soon as possible af
ISM-1984
Event logs sent to a centralised event logging facility are encrypted in transit.
ISM-1985
Event logs are protected from unauthorised access.
ISM-1986
Event logs from critical servers are analysed in a timely manner to detect cyber security
ISM-1987
Event logs from security products are analysed in a timely manner to detect cyber security
ISM-1988
Event logs are retained in a searchable manner for at least 12 months.
ISM-1989
Event logs are retained as per minimum retention requirements for various classes of recor
ISM-1990
When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-
ISM-1991
When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DS
ISM-1992
When using ML-DSA for digital signatures, the hedged variant is used whenever possible.
ISM-1993
Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of defau
ISM-1994
When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA
ISM-1995
When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768
ISM-1996
When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptograph
ISM-1997
The board of directors or executive committee defines clear roles and responsibilities for
ISM-1998
The board of directors or executive committee ensures that cyber security is integrated th
ISM-1999
The board of directors or executive committee ensures the cyber security strategy for thei
ISM-2000
The board of directors or executive committee seeks regular briefings or reporting on the
ISM-2001
The board of directors or executive committee champions a positive cyber security culture
ISM-2002
The board of directors or executive committee maintains a sufficient level of cyber securi
ISM-2003
The board of directors or executive committee maintains awareness of key cyber security re
ISM-2004
The board of directors or executive committee supports the development of cyber security s
ISM-2005
The board of directors or executive committee understands the business criticality of thei
ISM-2006
The board of directors or executive committee plans for major cyber security incidents, in
ISM-2007
An authorised medical device register for SECRET and TOP SECRET areas is developed, implem
ISM-2008
Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, a
ISM-2009
Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
ISM-2010
Service accounts configured with an SPN use the Advanced Encryption Standard for encryptio
ISM-2011
When phishing-resistant multi-factor authentication is used by user accounts, other non-ph
ISM-2012
Systems are configured with a screen lock that: - activates after a maximum of 15 minutes
ISM-2013
Authentication and authorisation of clients is performed when clients call network APIs th
ISM-2014
Authentication and authorisation of clients is performed when clients call network APIs th
ISM-2015
Network API calls that facilitate modification of data, or access to data not authorised f
ISM-2016
Validation and sanitisation are performed on all input received over a local network by so
ISM-2017
DNS traffic is encrypted by clients and servers wherever supported.
ISM-2018
Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous System
ISM-2019
TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), u
ISM-2020
The CISO ensures sufficient cyber security personnel, with the right skills and experience
ISM-2021
System owners implement and maintain data minimisation practices for each of their systems
ISM-2022
A cyber security awareness training register is developed, implemented and maintained.
ISM-2023
An authoritative source for software is established and maintained.
ISM-2024
The authoritative source for software is used for all software development activities.
ISM-2025
An issue tracking solution is used to link software development tasks to security issues a
ISM-2026
All software artefacts are scanned for malicious content before being imported into the au
ISM-2027
All software artefacts are verified by a digital signature, or a secure hash provided over
ISM-2028
All software artefacts are tested to detect known weaknesses using static application secu
ISM-2029
The authoritative source for software restricts the use and import of third-party librarie
ISM-2030
Scanning is used during commits to identify plain text or encoded secrets and keys, which
ISM-2031
Compilers, interpreters and build tools (including pipelines) that provide security featur
ISM-2032
The build solution ensures that all automated testing is completed without warnings, alert
ISM-2033
All software security requirements are documented, stored securely and maintained througho
ISM-2034
Security design decisions are documented and reviewed throughout the software development
ISM-2035
Security roles, responsibilities and knowledge requirements required to support the softwa
ISM-2036
Security responsibilities for software developers are identified and documented.
ISM-2037
Software developers that lack sufficient cyber security knowledge and skills required for
ISM-2038
A software developer cyber security knowledge and skills register is implemented and maint
ISM-2039
The software threat model is reviewed throughout the software development life cycle to en
ISM-2040
Secure programming practices for the chosen programming language are used for software dev
ISM-2041
Memory-safe programming languages, or less preferably memory-safe programming practices, a
ISM-2042
Secure by Default principles and practices are followed throughout the software developmen
ISM-2043
Software is architected and structured to support readability and maintainability.
ISM-2044
Software has no default credentials; however, if credentials are required, they are create
ISM-2045
Application backwards compatibility does not compromise any security measures or features.
ISM-2046
Where software allows user impersonation, sensitive data is not logged and appropriate per
ISM-2047
Where software allows an authentication factor to be reset, the user is notified of the re
ISM-2048
Where software supports multiple user roles, non-administrative users are prevented from a
ISM-2049
When user permissions or credentials are changed, software forces all impacted users to re
ISM-2050
When digital signatures are processed by software, they are validated against a certificat
ISM-2051
Software generates sufficient event logs to support the detection of cyber security events
ISM-2052
Event logs produced by software ensure that any sensitive data is protected.
ISM-2053
End of life procedures for software, covering how to remove the software and how to archiv
ISM-2054
If a software bill of materials is available for imported third-party software components,
ISM-2055
If a software build provenance is available for imported third-party software components,
ISM-2056
A software build provenance is produced and made available to consumers of software.
ISM-2057
All input validation rules are documented, matched in code and tested with both positive a
ISM-2058
Data sources and serialised data inputs are validated before being deserialised.
ISM-2059
File uploads or input are restricted to specific file types, with malicious content scanni
ISM-2060
Code reviews are utilised to ensure software meets Secure by Design principles and practic
ISM-2061
Software developer-supported security-focused peer reviews are conducted on all critical a
ISM-2062
Unit testing and integration testing, covering both positive and negative use cases, are u
ISM-2063
If supported, web application session cookies set the HttpOnly flag, Secure flag and the S
ISM-2064
Web application session cookies contain only digitally signed opaque bearer tokens.
ISM-2065
Web application session cookies using opaque bearer tokens that are not digitally signed u
ISM-2066
Web application sessions are centrally managed server side.
ISM-2067
Web applications that support Single Sign On equally support Single Logout.
ISM-2068
Internet connectivity for networked devices is strictly limited to those that require acce
ISM-2069
An authorised photographic and video recording device register for SECRET and TOP SECRET a
ISM-2070
Unauthorised photographic and video recording devices are not brought into SECRET and TOP
ISM-2071
Personnel dealing with user account details are advised of what social engineering attacks
ISM-2072
Artificial intelligence models are stored in a non-executable file format that does not al
ISM-2073
A post-quantum cryptography transition plan is developed, implemented and maintained.
ISM-2074
A general-purpose artificial intelligence usage policy is developed, implemented and maint
ISM-2075
Fax machines, and online fax services, are not used for sending or receiving fax messages.
ISM-2076
Security questions are not used for authentication purposes.
ISM-2077
Email is not used for out-of-band authentication purposes.
ISM-2078
Passwords appearing in lists of commonly used passwords or lists of compromised passwords
ISM-2079
Maximum length limits for passwords are not less than 64 characters.
ISM-2080
Password complexity requirements are not imposed for passwords.
ISM-2081
All ASCII printable characters are supported for passwords.
ISM-2082
If a cryptographic bill of materials is available for imported third-party software compon
ISM-2083
A cryptographic bill of materials is produced and made available to consumers of software.
ISM-2084
Artificial intelligence-specific documentation, including model and system cards (or equiv
ISM-2085
The exposure of exact artificial intelligence model confidence scores in API responses or
ISM-2086
The source and integrity of artificial intelligence models, structures and weights are ver
ISM-2087
The source and integrity of training data for artificial intelligence models is verified.
ISM-2088
Data validation and verification techniques are used to ensure the reliability and accurac
ISM-2089
Artificial intelligence model performance metrics are monitored and anomalies are investig
ISM-2090
Rate limiting is applied to inference queries for artificial intelligence models.
ISM-2091
Resource limits are enforced for artificial intelligence models.
ISM-2092
Access control policies are implemented to enforce fine-grained permissions for artificial
ISM-2093
Role-based access controls are implemented for artificial intelligence applications to res
ISM-2094
Content filtering is implemented by artificial intelligence applications to detect and blo
ISM-2095
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se
ISM-2096
Mobile devices are configured to enforce separation between organisational and personal mo
ISM-2097
Mobile devices are configured with always on VPN functionality.
ISM-2098
Mobile devices are configured to prevent data transfers over Universal Serial Bus connecti
ISM-2099
Mobile devices are not connected to the infotainment systems of connected vehicles.
ISM-2100
Sensitive or classified data is not viewed on mobile devices within or near connected vehi
ISM-2101
Sensitive or classified phone calls and conversations are not conducted within or near con
ISM-2102
Existing software artefacts in the authoritative source for software are periodically test
ISM-2103
Organisational data generated, collected or processed by artificial intelligence applicati
Show the 57 you already have
ISM-0445
Privileged users are assigned a dedicated privileged user account to be used solely for du
ISM-0843
Application control is implemented on workstations.
ISM-0974
Multi-factor authentication is used to authenticate unprivileged users of systems.
ISM-1173
Multi-factor authentication is used to authenticate privileged users of systems.
ISM-1175
Privileged user accounts (excluding those explicitly authorised to access online services)
ISM-1401
Multi-factor authentication uses either: something users have and something users know, or
ISM-1487
Only privileged users responsible for checking that Microsoft Office macros are free of ma
ISM-1488
Microsoft Office macros in files originating from the internet are blocked.
ISM-1489
Microsoft Office macro security settings cannot be changed by users.
ISM-1490
Application control is implemented on internet-facing servers.
ISM-1504
Multi-factor authentication is used to authenticate users to their organisation's online s
ISM-1505
Multi-factor authentication is used to authenticate users of data repositories.
ISM-1507
Requests for privileged access to systems and their resources are validated when first req
ISM-1508
Privileged access to systems and their resources is limited to only what is required for u
ISM-1509
Privileged access events are centrally logged.
ISM-1511
Backups of data, applications and settings are performed and retained in accordance with b
ISM-1515
Restoration of data, applications and settings from backups to a common point in time is t
ISM-1544
Microsoft's recommended application blocklist is implemented.
ISM-1582
Application control rulesets are validated on an annual or more frequent basis.
ISM-1649
Just-in-time administration is used for the administration of systems and their resources.
ISM-1650
Privileged user account and security group management events are centrally logged.
ISM-1656
Application control is implemented on non-internet-facing servers.
ISM-1657
Application control restricts the execution of executables, libraries, scripts, installers
ISM-1658
Application control restricts the execution of drivers to an organisation-approved set.
ISM-1659
Microsoft's vulnerable driver blocklist is implemented.
ISM-1660
Allowed and blocked application control events are centrally logged.
ISM-1671
Microsoft Office macros are disabled for users that do not have a demonstrated business re
ISM-1672
Microsoft Office macro antivirus scanning is enabled.
ISM-1673
Microsoft Office macros are blocked from making Win32 API calls.
ISM-1674
Only Microsoft Office macros running from within a sandboxed environment, a Trusted Locati
ISM-1675
Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via t
ISM-1676
Microsoft Office's list of trusted publishers is validated on an annual or more frequent b
ISM-1679
Multi-factor authentication is used to authenticate users to third-party online services t
ISM-1680
Multi-factor authentication (where available) is used to authenticate users to third-party
ISM-1681
Multi-factor authentication is used to authenticate customers to online customer services
ISM-1682
Multi-factor authentication used for authenticating users of systems is phishing-resistant
ISM-1683
Successful and unsuccessful multi-factor authentication events are centrally logged.
ISM-1705
Privileged user accounts (excluding backup administrator accounts) cannot access backups b
ISM-1706
Privileged user accounts (excluding backup administrator accounts) cannot access their own
ISM-1707
Privileged user accounts (excluding backup administrator accounts) are prevented from modi
ISM-1708
Backup administrator accounts are prevented from modifying and deleting backups during the
ISM-1810
Backups of data, applications and settings are synchronised to enable restoration to a com
ISM-1811
Backups of data, applications and settings are retained in a secure and resilient manner.
ISM-1812
Unprivileged user accounts cannot access backups belonging to other user accounts.
ISM-1813
Unprivileged user accounts cannot access their own backups.
ISM-1814
Unprivileged user accounts are prevented from modifying and deleting backups.
ISM-1870
Application control is applied to user profiles and temporary folders used by operating sy
ISM-1871
Application control is applied to all locations other than user profiles and temporary fol
ISM-1872
Multi-factor authentication used for authenticating users of online services is phishing-r
ISM-1873
Multi-factor authentication used for authenticating customers of online customer services
ISM-1874
Multi-factor authentication used for authenticating customers of online customer services
ISM-1883
Privileged user accounts explicitly authorised to access online services are strictly limi
ISM-1890
Microsoft Office macros are checked to ensure they are free of malicious code before being
ISM-1891
Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be
ISM-1892
Multi-factor authentication is used to authenticate users to their organisation's online c
ISM-1893
Multi-factor authentication is used to authenticate users to third-party online customer s
ISM-1894
Multi-factor authentication used for authenticating users of data repositories is phishing

How this is calculated

Already covered means a mapping runs from a control in ACSC Essential Eight to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition