Skip to content
arrow_back
search

Controls library.

1,382 controls across 4 frameworks

Comparing to global GRC platforms? See Control Stack vs Drata, Vanta and Scytale.

search

Annex A 10.2 · ISO 42001
Allocating Responsibilities
Annex A 10.3 · ISO 42001
Manage Suppliers to Support Responsible AI Use
Annex A 10.4 · ISO 42001
Consider Customer Expectations and Needs When Using AI
Annex A 2.2 · ISO 42001
AI Policy
Annex A 2.3 · ISO 42001
Alignment with Other Organisational Policies
Annex A 2.4 · ISO 42001
Review the AI Policy at Planned Intervals to Keep It Effective
Annex A 3.2 · ISO 42001
Define and Allocate AI Roles and Responsibilities
Annex A 3.3 · ISO 42001
Process for Reporting Concerns About AI Systems
Annex A 4.2 · ISO 42001
Resource Documentation
Annex A 4.3 · ISO 42001
Document the Data Resources Used by Your AI System
Annex A 4.4 · ISO 42001
Document the Tooling Resources Used for AI Systems
Annex A 4.5 · ISO 42001
Document System and Computing Resources Used by AI Systems
Annex A 4.6 · ISO 42001
Document the People and Skills Running Your AI System
Annex A 5.1 · ISO 27001
Policies for information security
Annex A 5.10 · ISO 27001
Acceptable Use Policies for Information and Assets
Annex A 5.11 · ISO 27001
Return of Organisation's Assets upon Departure
Annex A 5.12 · ISO 27001
Information Classification Policy and Practices
Annex A 5.13 · ISO 27001
Labelling of Information
Annex A 5.14 · ISO 27001
Information Transfer Policies and Procedures
Annex A 5.15 · ISO 27001
Access Control Policies and Procedures
Annex A 5.16 · ISO 27001
Identity life cycle management
Annex A 5.17 · ISO 27001
Management of Authentication Information
Annex A 5.18 · ISO 27001
Managing Access Rights to Information Assets
Annex A 5.19 · ISO 27001
Managing Information Security in Supplier Relationships
Annex A 5.2 · ISO 27001
Defining Information Security Roles and Responsibilities
Annex A 5.2 · ISO 42001
AI System Impact Assessment Process
Annex A 5.20 · ISO 27001
Integrating security clauses in supplier agreements
Annex A 5.21 · ISO 27001
Managing Information Security in the ICT Supply Chain
Annex A 5.22 · ISO 27001
Monitoring and Managing Supplier Services
Annex A 5.23 · ISO 27001
Cloud Service Security Management
Annex A 5.24 · ISO 27001
Information security incident management planning and preparation
Annex A 5.25 · ISO 27001
Assessment and decision on information security events
Annex A 5.26 · ISO 27001
Response to Information Security Incidents
Annex A 5.27 · ISO 27001
Learning from information security incidents
Annex A 5.28 · ISO 27001
Procedures for Collecting and Preserving Evidence
Annex A 5.29 · ISO 27001
Maintain information security during disruptions
Annex A 5.3 · ISO 42001
Document and Retain AI Impact Assessment Results
Annex A 5.3 · ISO 27001
Segregation of Duties
Annex A 5.30 · ISO 27001
ICT Readiness for Business Continuity
Annex A 5.31 · ISO 27001
Compliance with Information Security Legal Requirements
Annex A 5.32 · ISO 27001
Intellectual Property Rights Protection
Annex A 5.33 · ISO 27001
Protection of Records
Annex A 5.34 · ISO 27001
Privacy and Protection of Personally Identifiable Information
Annex A 5.35 · ISO 27001
Independent review of information security
Annex A 5.36 · ISO 27001
Review compliance with information security policies
Annex A 5.37 · ISO 27001
Documented Operating Procedures for Information Processing
Annex A 5.4 · ISO 42001
Assess and Document AI Impacts on Individuals and Groups
Annex A 5.4 · ISO 27001
Management responsibilities for information security
Annex A 5.5 · ISO 27001
Establish and Maintain Contact with Authorities
Annex A 5.5 · ISO 42001
Assess and Document AI Societal Impacts Across the Life Cycle
Annex A 5.6 · ISO 27001
Contact with special interest groups
Annex A 5.7 · ISO 27001
Threat Intelligence Collection and Analysis
Annex A 5.8 · ISO 27001
Information security in project management
Annex A 5.9 · ISO 27001
Inventory management of information and associated assets
Annex A 6.1 · ISO 27001
Personnel Background Verification
Annex A 6.1.2 · ISO 42001
Objectives for Responsible Development of AI Systems
Annex A 6.1.3 · ISO 42001
Processes for Responsible AI System Design and Development
Annex A 6.2 · ISO 27001
Terms and conditions of employment for security
Annex A 6.2.2 · ISO 42001
AI System Requirements and Specification
Annex A 6.2.3 · ISO 42001
Documentation of AI System Design and Development
Annex A 6.2.4 · ISO 42001
AI System Verification and Validation
Annex A 6.2.5 · ISO 42001
AI System Deployment
Annex A 6.2.6 · ISO 42001
Defining and Documenting Ongoing AI System Operation Requirements
Annex A 6.2.7 · ISO 42001
Provide AI System Technical Documentation to Interested Parties
Annex A 6.2.8 · ISO 42001
AI System Recording of Event Logs
Annex A 6.3 · ISO 27001
Information security awareness, education and training program
Annex A 6.4 · ISO 27001
Disciplinary Process for Information Security Violations
Annex A 6.5 · ISO 27001
Responsibilities after employment termination or role change
Annex A 6.6 · ISO 27001
Confidentiality and Non-disclosure Agreements
Annex A 6.7 · ISO 27001
Remote Working Security Measures
Annex A 6.8 · ISO 27001
Mechanisms for Reporting Security Events
Annex A 7.1 · ISO 27001
Physical Security Perimeters
Annex A 7.10 · ISO 27001
Secure Management of Storage Media
Annex A 7.11 · ISO 27001
Protection from Utility Failures
Annex A 7.12 · ISO 27001
Secure Cabling for Power and Data
Annex A 7.13 · ISO 27001
Proper Maintenance of Equipment
Annex A 7.14 · ISO 27001
Secure disposal or re-use of equipment
Annex A 7.2 · ISO 27001
Physical access controls for secure areas
Annex A 7.2 · ISO 42001
Data for Development and Enhancement of AI System
Annex A 7.3 · ISO 42001
Acquisition and Selection of Data
Annex A 7.3 · ISO 27001
Physical Security for Offices and Facilities
Annex A 7.4 · ISO 42001
Quality of Data for AI Systems
Annex A 7.4 · ISO 27001
Continuous monitoring of physical access to premises
Annex A 7.5 · ISO 27001
Protecting against physical and environmental threats
Annex A 7.5 · ISO 42001
Data Provenance
Annex A 7.6 · ISO 42001
Data Preparation
Annex A 7.6 · ISO 27001
Security Measures for Working in Secure Areas
Annex A 7.7 · ISO 27001
Clear desk and clear screen policies
Annex A 7.8 · ISO 27001
Equipment Siting and Protection
Annex A 7.9 · ISO 27001
Security of Off-Site Assets
Annex A 8.1 · ISO 27001
Protection of User Endpoint Devices
Annex A 8.10 · ISO 27001
Secure deletion of information when no longer needed
Annex A 8.11 · ISO 27001
Data Masking for Sensitive Information
Annex A 8.12 · ISO 27001
Data Leakage Prevention Measures
Annex A 8.13 · ISO 27001
Backup and Recovery Procedures for Data
Annex A 8.14 · ISO 27001
Redundancy of Information Processing Facilities
Annex A 8.15 · ISO 27001
Logging of Activities and Events
Annex A 8.16 · ISO 27001
Monitoring Networks and Systems for Anomalous Behaviour
Annex A 8.17 · ISO 27001
Clock synchronisation for information systems
Annex A 8.18 · ISO 27001
Use of Privileged Utility Programs
Annex A 8.19 · ISO 27001
Secure Software Installation Procedures
Annex A 8.2 · ISO 42001
Provide Users the Information They Need to Use the AI System
Annex A 8.2 · ISO 27001
Management of Privileged Access Rights
Annex A 8.20 · ISO 27001
Network and Network Devices Security
Annex A 8.21 · ISO 27001
Security of Network Services
Annex A 8.22 · ISO 27001
Network Segregation for Security
Annex A 8.23 · ISO 27001
Web Filtering to Reduce Malicious Website Exposure
Annex A 8.24 · ISO 27001
Effective Use of Cryptography and Key Management
Annex A 8.25 · ISO 27001
Secure Development Lifecycle
Annex A 8.26 · ISO 27001
Defining Security Requirements for Applications
Annex A 8.27 · ISO 27001
Secure system architecture and engineering principles
Annex A 8.28 · ISO 27001
Secure Coding Practices in Software Development
Annex A 8.29 · ISO 27001
Security testing in development and acceptance
Annex A 8.3 · ISO 42001
External Reporting
Annex A 8.3 · ISO 27001
Restrict access to information and assets
Annex A 8.30 · ISO 27001
Management of Outsourced System Development
Annex A 8.31 · ISO 27001
Separation of Development, Test, and Production Environments
Annex A 8.32 · ISO 27001
Change management procedures for information systems
Annex A 8.33 · ISO 27001
Test Information Selection and Protection
Annex A 8.34 · ISO 27001
Protection of information systems during audits
Annex A 8.4 · ISO 42001
Document a Plan for Communicating Incidents to AI System Users
Annex A 8.4 · ISO 27001
Access management for source code and tools
Annex A 8.5 · ISO 27001
Secure authentication technologies and procedures
Annex A 8.5 · ISO 42001
Determine and Document AI Reporting Obligations to Interested Parties
Annex A 8.6 · ISO 27001
Capacity Management for Resource Use
Annex A 8.7 · ISO 27001
Protection against malware
Annex A 8.8 · ISO 27001
Management of Technical Vulnerabilities
Annex A 8.9 · ISO 27001
Configuration Management for Secure IT Systems
Annex A 9.2 · ISO 42001
Define and Document Processes for Responsible Use of AI Systems
Annex A 9.3 · ISO 42001
Objectives for Responsible Use of AI System
Annex A 9.4 · ISO 42001
Intended Use of the AI System
E8-AC-ML1.1 · Essential 8
Application control is implemented on workstations.
E8-AC-ML1.2 · Essential 8
Application control is applied to user profiles and temporary folders
E8-AC-ML1.3 · Essential 8
Ensure only approved applications and scripts can run
E8-AC-ML2.1 · Essential 8
Application control is implemented on internet-facing servers
E8-AC-ML2.10 · Essential 8
Report cyber security incidents to ASD quickly
E8-AC-ML2.11 · Essential 8
Cybersecurity incident response plan is enacted after incident identification
E8-AC-ML2.2 · Essential 8
Application control excludes user profiles and temporary folders
E8-AC-ML2.3 · Essential 8
Microsoft's recommended application blocklist is implemented
E8-AC-ML2.4 · Essential 8
Annual validation of application control rulesets
E8-AC-ML2.5 · Essential 8
Allowed and blocked application control events are centrally logged
E8-AC-ML2.6 · Essential 8
Event logs are protected from unauthorised modification and deletion
E8-AC-ML2.7 · Essential 8
Event logs from internet-facing servers are analysed to detect cybersecurity events
E8-AC-ML2.8 · Essential 8
Cybersecurity events are analysed in a timely manner
E8-AC-ML2.9 · Essential 8
Cyber security incidents are reported promptly to CISO
E8-AC-ML3.1 · Essential 8
Application control is implemented on non-internet-facing servers
E8-AC-ML3.2 · Essential 8
Application control restricts driver execution to an approved set
E8-AC-ML3.3 · Essential 8
Microsoft's vulnerable driver blocklist is implemented
E8-AC-ML3.4 · Essential 8
Event logs from non-internet-facing servers are analysed
E8-AC-ML3.5 · Essential 8
Workstation event logs are promptly analysed for security events
E8-AH-ML1.1 · Essential 8
Disable or remove Internet Explorer 11
E8-AH-ML1.2 · Essential 8
Web browsers must not execute Java content from the internet
E8-AH-ML1.3 · Essential 8
Web browsers block web ads from the internet
E8-AH-ML1.4 · Essential 8
Web browser security settings locked down to users
E8-AH-ML2.1 · Essential 8
Web browsers are hardened with the most restrictive guidance
E8-AH-ML2.10 · Essential 8
PDF software security settings cannot be changed by users
E8-AH-ML2.11 · Essential 8
Centrally log PowerShell module, script block, and transcription events
E8-AH-ML2.12 · Essential 8
Command line process creation logging is centralised
E8-AH-ML2.13 · Essential 8
Protect event logs from unauthorised changes or deletion
E8-AH-ML2.14 · Essential 8
Timely Analysis of Event Logs from Internet-Facing Servers
E8-AH-ML2.15 · Essential 8
Timely Analysis of Cyber Security Events to Identify Incidents
E8-AH-ML2.16 · Essential 8
Cybersecurity incidents must be reported immediately to the CISO
E8-AH-ML2.17 · Essential 8
Report cyber security incidents to ASD promptly
E8-AH-ML2.18 · Essential 8
Cyber incident response plan is enacted after identification
E8-AH-ML2.2 · Essential 8
Block Microsoft Office from creating child processes
E8-AH-ML2.3 · Essential 8
Block Microsoft Office from creating executable content
E8-AH-ML2.4 · Essential 8
Block Microsoft Office from injecting code into other processes
E8-AH-ML2.5 · Essential 8
Configure Microsoft Office to prevent activation of OLE packages
E8-AH-ML2.6 · Essential 8
Office productivity suites are hardened using ASD and vendor guidance
E8-AH-ML2.7 · Essential 8
Office productivity suite settings are immutable by users
E8-AH-ML2.8 · Essential 8
Block PDF software from creating child processes
E8-AH-ML2.9 · Essential 8
Ensure PDF software is securely configured using guidance.
E8-AH-ML3.1 · Essential 8
.NET Framework 3.5, 3.0, 2.0 is disabled or removed
E8-AH-ML3.2 · Essential 8
Ensure Windows PowerShell 2.0 is disabled or removed
E8-AH-ML3.3 · Essential 8
PowerShell is configured to use Constrained Language Mode
E8-AH-ML3.4 · Essential 8
Analyse event logs from non-internet-facing servers for cyber threats
E8-AH-ML3.5 · Essential 8
Timely Analysis of Workstation Event Logs for Cybersecurity
E8-MF-ML1.1 · Essential 8
Require multi-factor authentication for sensitive online services
E8-MF-ML1.2 · Essential 8
Multi-factor authentication for third-party services handling sensitive data
E8-MF-ML1.3 · Essential 8
Use multi-factor authentication for non-sensitive third-party services
E8-MF-ML1.4 · Essential 8
Use multi-factor authentication for online services handling customer data
E8-MF-ML1.5 · Essential 8
Multi-factor authentication for third-party services with sensitive customer data
E8-MF-ML1.6 · Essential 8
Multi-factor authentication for customer access to online services handling sensitive data
E8-MF-ML1.7 · Essential 8
Multi-factor authentication combines two factors like a device and a PIN
E8-MF-ML2.1 · Essential 8
Multi-factor authentication for privileged users of systems
E8-MF-ML2.10 · Essential 8
Report cyber security incidents to the Chief Information Security Officer promptly
E8-MF-ML2.11 · Essential 8
Report cybersecurity incidents to ASD immediately
E8-MF-ML2.12 · Essential 8
Cybersecurity incident response plan enacted after incident identification
E8-MF-ML2.2 · Essential 8
Use multi-factor authentication for unprivileged user access
E8-MF-ML2.3 · Essential 8
Multi-factor authentication online services must be phishing-resistant
E8-MF-ML2.5 · Essential 8
Multi-factor authentication used for system access is phishing-resistant
E8-MF-ML2.6 · Essential 8
MFA success and failure events are centrally logged
E8-MF-ML2.7 · Essential 8
Protect event logs from unauthorised changes
E8-MF-ML2.8 · Essential 8
Timely analysis of event logs from internet-facing servers
E8-MF-ML2.9 · Essential 8
Cybersecurity events are analysed to identify incidents timely
E8-MF-ML3.1 · Essential 8
Multi-factor authentication is used to authenticate users of data repositories
E8-MF-ML3.2 · Essential 8
Phishing-resistant multi-factor authentication for online customer services
E8-MF-ML3.3 · Essential 8
Phishing-resistant multi-factor authentication for data repositories
E8-MF-ML3.4 · Essential 8
Analyse event logs from non-internet-facing servers timely to detect security events
E8-MF-ML3.5 · Essential 8
Timely analysis of workstation event logs for cybersecurity events
E8-PA-ML1.1 · Essential 8
Automated asset discovery at least fortnightly
E8-PA-ML1.2 · Essential 8
Up-to-date vulnerability scanner used for scanning activities
E8-PA-ML1.3 · Essential 8
Daily vulnerability scanning for missing patches in online services
E8-PA-ML1.4 · Essential 8
Weekly scanning for missing patches or updates in key software
E8-PA-ML1.5 · Essential 8
Apply critical application patches within 48 hours
E8-PA-ML1.6 · Essential 8
Apply non-critical patches for online services within two weeks
E8-PA-ML1.8 · Essential 8
Unsupported online services are removed by the organisation
E8-PA-ML1.9 · Essential 8
Removal of unsupported software and applications
E8-PA-ML2.1 · Essential 8
Fortnightly vulnerability scanning for non-core applications
E8-PA-ML2.2 · Essential 8
Timely Patching of Non-Critical Application Vulnerabilities
E8-PA-ML3.1 · Essential 8
Patch critical vulnerabilities in applications within 48 hours
E8-PA-ML3.2 · Essential 8
Apply patches for non-critical vulnerabilities within two weeks
E8-PA-ML3.3 · Essential 8
Remove unsupported applications excluding certain categories
E8-PO-ML1.1 · Essential 8
Automated bi-weekly asset discovery for vulnerability scanning
E8-PO-ML1.2 · Essential 8
Use a vulnerability scanner with an updated database
E8-PO-ML1.3 · Essential 8
Use a daily vulnerability scanner for internet-facing systems
E8-PO-ML1.4 · Essential 8
Use a vulnerability scanner fortnightly to find missing OS patches
E8-PO-ML1.5 · Essential 8
Apply critical patches to internet-facing OS within 48 hours
E8-PO-ML1.6 · Essential 8
Timely application of non-critical patches for internet-facing OS vulnerabilities
E8-PO-ML1.8 · Essential 8
Replace unsupported operating systems
E8-PO-ML3.1 · Essential 8
Vulnerability scanner used fortnightly to identify missing driver patches
E8-PO-ML3.2 · Essential 8
At least fortnightly use of a vulnerability scanner for firmware
E8-PO-ML3.3 · Essential 8
Apply critical patches to non-internet-facing OS within 48 hours
E8-PO-ML3.4 · Essential 8
Non-critical OS patches applied within one month if no exploits exist
E8-PO-ML3.5 · Essential 8
Apply critical driver patches within 48 hours
E8-PO-ML3.6 · Essential 8
Apply non-critical driver patches within one month
E8-PO-ML3.7 · Essential 8
Apply critical firmware patches within 48 hours
E8-PO-ML3.8 · Essential 8
Firmware vulnerabilities patched within one month if non-critical and no exploits
E8-PO-ML3.9 · Essential 8
The latest or previous OS release is used
E8-RA-ML1.1 · Essential 8
Validating privileged access requests upon initial request
E8-RA-ML1.2 · Essential 8
Dedicated privileged accounts for admin tasks
E8-RA-ML1.3 · Essential 8
Prevent privileged accounts from accessing internet, email, and web services
E8-RA-ML1.4 · Essential 8
Limit privileged accounts to essential online service access
E8-RA-ML1.5 · Essential 8
Privileged users use separate privileged and unprivileged environments
E8-RA-ML1.6 · Essential 8
Unprivileged accounts restricted from logging into privileged environments
E8-RA-ML1.7 · Essential 8
Prevent privileged accounts from accessing unprivileged environments
E8-RA-ML2.1 · Essential 8
Disable privileged access after 12 months without revalidation
E8-RA-ML2.10 · Essential 8
Timely analysis of cyber security events to identify incidents
E8-RA-ML2.11 · Essential 8
Report cyber incidents to the CISO promptly
E8-RA-ML2.12 · Essential 8
Report cyber security incidents to ASD promptly
E8-RA-ML2.13 · Essential 8
Enact cyber incident response plan after an incident is identified
E8-RA-ML2.2 · Essential 8
Privileged access is disabled after 45 days of inactivity
E8-RA-ML2.3 · Essential 8
Privileged environments are not virtualised within unprivileged environments
E8-RA-ML2.4 · Essential 8
Conduct administrative activities through jump servers
E8-RA-ML2.5 · Essential 8
Long, unique, and managed credentials for admin accounts
E8-RA-ML2.6 · Essential 8
Privileged access events are centrally logged.
E8-RA-ML2.7 · Essential 8
Centrally log privileged account and group management events
E8-RA-ML2.8 · Essential 8
Event logs are protected from unauthorised changes and losses
E8-RA-ML2.9 · Essential 8
Event logs are analysed promptly for security events
E8-RA-ML3.1 · Essential 8
Limit privileged access to what is necessary for duties
E8-RA-ML3.2 · Essential 8
Use Secure Admin Workstations for Administrative Tasks
E8-RA-ML3.3 · Essential 8
Just-in-time administration is used for administering systems and applications.
E8-RA-ML3.4 · Essential 8
Memory integrity functionality is enabled
E8-RA-ML3.5 · Essential 8
Local Security Authority protection functionality is enabled
E8-RA-ML3.6 · Essential 8
Enable Credential Guard for secure credential storage
E8-RA-ML3.7 · Essential 8
Enable Remote Credential Guard functionality
E8-RA-ML3.8 · Essential 8
Timely analysis of event logs from non-internet-facing servers
E8-RA-ML3.9 · Essential 8
Timely analysis of workstation event logs for security events
E8-RB-ML1.1 · Essential 8
Backups aligned with business continuity needs
E8-RB-ML1.2 · Essential 8
Ensure backups are synchronised for restoration to a common point in time
E8-RB-ML1.3 · Essential 8
Backups retained securely and resiliently
E8-RB-ML1.4 · Essential 8
Test backup restoration to a common point during disaster recovery
E8-RB-ML1.5 · Essential 8
Unprivileged accounts cannot access others' backups
E8-RB-ML1.6 · Essential 8
Prevent unprivileged accounts from modifying and deleting backups
E8-RB-ML2.1 · Essential 8
Prevent privileged accounts from accessing others' backups
E8-RB-ML2.2 · Essential 8
Privileged accounts cannot modify or delete backups.
E8-RB-ML3.1 · Essential 8
Unprivileged accounts cannot access their own backups
E8-RB-ML3.2 · Essential 8
Privileged accounts cannot access their own backups
E8-RB-ML3.3 · Essential 8
Backup administrators cannot modify or delete backups during retention
E8-RM-ML1.1 · Essential 8
Disable Microsoft Office macros for users without a business need
E8-RM-ML1.2 · Essential 8
Block Microsoft Office macros from the internet
E8-RM-ML1.3 · Essential 8
Enable antivirus scanning for Microsoft Office macros
E8-RM-ML1.4 · Essential 8
Prevent users from changing Microsoft Office macro security settings
E8-RM-ML2.1 · Essential 8
Microsoft Office macros are blocked from making Win32 API calls
E8-RM-ML3.1 · Essential 8
Restrict Microsoft Office macros to only trusted or sandboxed environments
E8-RM-ML3.2 · Essential 8
Check Microsoft Office macros for malicious code before signing or trusting
E8-RM-ML3.3 · Essential 8
Only privileged users can modify content in Trusted Locations
E8-RM-ML3.4 · Essential 8
Untrusted Publisher Macros Cannot Be Enabled via Message Bar or Backstage View
E8-RM-ML3.5 · Essential 8
Block enabling of non-V3 signed Microsoft Office macros via Message Bar
E8-RM-ML3.6 · Essential 8
Validate list of trusted publishers in Microsoft Office annually
ISM-0009 · ASD ISM
Identify Supplementary Controls for System Security
ISM-0027 · ASD ISM
Mandatory Authorisation for System Operation
ISM-0039 · ASD ISM
Develop and Maintain a Cyber Security Strategy
ISM-0041 · ASD ISM
Develop a Detailed System Security Plan
ISM-0042 · ASD ISM
Maintain Effective System Administration Practices
ISM-0043 · ASD ISM
Cyber Security Incident Response Plan Requirements
ISM-0047 · ASD ISM
Approval Process for Cyber Security Documentation
ISM-0072 · ASD ISM
Document Security Requirements in Contractual Arrangements
ISM-0078 · ASD ISM
Australian Supervision of AUSTEO/AGAO Data Systems
ISM-0100 · ASD ISM
Regular IRAP Assessment of Sensitive Gateways
ISM-0109 · ASD ISM
Timely Analysis of Workstation Event Logs
ISM-0120 · ASD ISM
Access to Tools for Detecting Security Events
ISM-0123 · ASD ISM
Report Cyber Security Incidents Promptly
ISM-0125 · ASD ISM
Maintaining a Cyber Security Incident Register
ISM-0133 · ASD ISM
Responding to Data Spills by Restricting Access
ISM-0137 · ASD ISM
Seek Legal Advice for Intrusion Evidence Collection
ISM-0138 · ASD ISM
Maintaining Integrity of Evidence in Investigations
ISM-0140 · ASD ISM
Prompt Reporting of Cyber Incidents to ASD
ISM-0141 · ASD ISM
Report Cyber Incidents Promptly to Designated Contacts
ISM-0142 · ASD ISM
Report Cryptographic Equipment Compromises Promptly
ISM-0161 · ASD ISM
Ensure Security of Unused IT Equipment and Media
ISM-0164 · ASD ISM
Prevent Unauthorised Viewing of System Displays
ISM-0181 · ASD ISM
Ensure Cabling Meets Australian Standards
ISM-0187 · ASD ISM
Exclusive Secret Cable Bundling in Infrastructure
ISM-0194 · ASD ISM
Sealing Conduit Joints in Shared Facilities
ISM-0195 · ASD ISM
Seal Removable Covers on TOP SECRET Cables
ISM-0198 · ASD ISM
Consultation for Penetrating Audio Secure Rooms
ISM-0201 · ASD ISM
Labelling Requirements for TOP SECRET Conduits
ISM-0206 · ASD ISM
Develop and Maintain Cable Labelling Processes
ISM-0208 · ASD ISM
Maintain a Comprehensive Cable Register
ISM-0211 · ASD ISM
Develop and Verify a Cable Register
ISM-0213 · ASD ISM
Segregate Patch Panels for Secret-Level Cables
ISM-0216 · ASD ISM
Ensure Separate Cabinets for TOP SECRET Patch Panels
ISM-0217 · ASD ISM
Secure Separation of Non-TOP SECRET and TOP SECRET Panels
ISM-0218 · ASD ISM
Label and Protect Long TS Fibre-Optic Leads
ISM-0225 · ASD ISM
Prevent Unauthorised RF and IR Device Entry
ISM-0229 · ASD ISM
Guidelines for Discussing Sensitive Information Over Phones
ISM-0230 · ASD ISM
Advising on Risks of Non-Secure Telephone Systems
ISM-0231 · ASD ISM
Visual Indication for Secure Telephone Connections
ISM-0232 · ASD ISM
Encrypt External Traffic for Sensitive Calls
ISM-0233 · ASD ISM
Use Encrypted Cordless Systems for Sensitive Conversations
ISM-0235 · ASD ISM
Use of Speakerphones in TOP SECRET Areas
ISM-0236 · ASD ISM
Implement Off-hook Audio Protection on Telephones
ISM-0240 · ASD ISM
Prevent Sensitive Data in Messaging Services
ISM-0245 · ASD ISM
Prevent MFD Connections to Digital Phone Systems
ISM-0246 · ASD ISM
Contact ASD for Emanation Security Assessment
ISM-0249 · ASD ISM
Separate Classified and Personal Data on Personal Devices
ISM-0250 · ASD ISM
Ensure IT Equipment Meets EMI/EMC Standards
ISM-0252 · ASD ISM
Annual Cyber Security Awareness for Personnel
ISM-0258 · ASD ISM
Establish and Maintain a Web Usage Policy
ISM-0260 · ASD ISM
Ensure All Web Access Uses Proxies
ISM-0261 · ASD ISM
Log Web Proxy Activity for Security Analysis
ISM-0263 · ASD ISM
Inspect and Decrypt TLS Traffic through Gateways
ISM-0264 · ASD ISM
Develop and Maintain an Email Usage Policy
ISM-0267 · ASD ISM
Blocking Access to Unapproved Webmail Services
ISM-0269 · ASD ISM
Restrict Sensitive Emails to Verified Recipients
ISM-0270 · ASD ISM
Apply Protective Markings to Emails Based on Sensitivity
ISM-0271 · ASD ISM
Prevent Automatic Email Marking by Protective Tools
ISM-0272 · ASD ISM
Prevent Unauthorised Protective Marking Selection
ISM-0280 · ASD ISM
Choose PP-evaluated Products Over EAL-based Ones
ISM-0285 · ASD ISM
Ensuring Evaluated Products Follow Delivery Procedures
ISM-0286 · ASD ISM
Consult ASD for High Assurance IT Delivery Procedures
ISM-0289 · ASD ISM
Implement and Manage Evaluated Products Correctly
ISM-0290 · ASD ISM
Secure Configuration of High Assurance IT Equipment
ISM-0293 · ASD ISM
Classify IT Equipment by Data Sensitivity
ISM-0294 · ASD ISM
Label IT Equipment with Sensitivity Markings
ISM-0296 · ASD ISM
Approval Required for High Assurance IT Equipment Labelling
ISM-0298 · ASD ISM
Centralised System Patch and Update Management
ISM-0300 · ASD ISM
Apply System Security Patches with Approval
ISM-0304 · ASD ISM
Remove Unsupported Applications for System Security
ISM-0305 · ASD ISM
On-Site IT Equipment Maintenance by Cleared Technicians
ISM-0306 · ASD ISM
Escort Uncleared Technicians During IT Equipment Maintenance or Repairs
ISM-0307 · ASD ISM
Sanitise Equipment When Not Using Cleared Technician
ISM-0310 · ASD ISM
Off-Site IT Equipment Handling Approvals
ISM-0311 · ASD ISM
Ensuring Sanitisation of IT Equipment Media
ISM-0312 · ASD ISM
Return Overseas Equipment for Destruction
ISM-0313 · ASD ISM
Develop and Maintain IT Equipment Sanitisation Procedures
ISM-0315 · ASD ISM
Ensure Destruction of High Assurance IT Equipment
ISM-0316 · ASD ISM
Formal Decision on IT Equipment Disposal
ISM-0317 · ASD ISM
Ensuring Data Erasure on Printer Cartridges and Drums
ISM-0318 · ASD ISM
Safely Disposing of Unsanitised Printer Components
ISM-0321 · ASD ISM
Contact ASD for Guidance on Secure IT Disposal
ISM-0323 · ASD ISM
Classifying Media by Data Sensitivity
ISM-0325 · ASD ISM
Reclassify Media to Higher Sensitivity
ISM-0330 · ASD ISM
Proper Sanitisation and Reclassification of Media
ISM-0332 · ASD ISM
Label Media With Protective Markings Reflecting Sensitivity Or Classification
ISM-0336 · ASD ISM
Develop and Maintain Networked IT Equipment Register
ISM-0337 · ASD ISM
Ensure Media is Used with Authorised Systems
ISM-0341 · ASD ISM
Disable Automatic Execution for Removable Media
ISM-0343 · ASD ISM
Disabling Unnecessary Access to Removable Media
ISM-0345 · ASD ISM
Disable External Interfaces for Direct Memory Access
ISM-0347 · ASD ISM
Use Write-Once Media for Secure Data Transfers
ISM-0348 · ASD ISM
Develop and Maintain Media Sanitisation Procedures
ISM-0350 · ASD ISM
Destroy Unsanitizable Media Before Disposal
ISM-0351 · ASD ISM
Proper Method for Volatile Media Sanitisation
ISM-0352 · ASD ISM
Secure Volatile Media by Overwriting with Random Data
ISM-0354 · ASD ISM
Ensuring Proper Sanitisation of Magnetic Media
ISM-0356 · ASD ISM
Classify Magnetic Media After Sanitisation
ISM-0357 · ASD ISM
Sanitising Non-volatile EPROM Media
ISM-0358 · ASD ISM
Classification Retention for Sanitised EPROM and EEPROM
ISM-0359 · ASD ISM
Proper Sanitisation of Non-Volatile Flash Memory
ISM-0360 · ASD ISM
Classification Retention After Flash Memory Sanitisation
ISM-0361 · ASD ISM
Using Degaussers for Magnetic Media Destruction
ISM-0362 · ASD ISM
Follow Manufacturer's Directions for Degaussing
ISM-0363 · ASD ISM
Develop and Maintain Media Destruction Processes
ISM-0368 · ASD ISM
Ensuring Media Particles Are No Larger Than 9 mm
ISM-0370 · ASD ISM
Supervise Media Destruction with Cleared Personnel
ISM-0371 · ASD ISM
Ensure Proper Supervision of Media Destruction
ISM-0372 · ASD ISM
Supervision of Media Destruction Procedures
ISM-0373 · ASD ISM
Supervise and Certify Accountable Material Destruction
ISM-0374 · ASD ISM
Develop and Maintain Media Disposal Procedures
ISM-0375 · ASD ISM
Decide on Public Release of Data Storage Media
ISM-0378 · ASD ISM
Remove Labels from Media Before Disposal
ISM-0380 · ASD ISM
Disable Unneeded OS Accounts and Services
ISM-0382 · ASD ISM
Restrict Unprivileged User Actions on Applications
ISM-0383 · ASD ISM
Change Default OS User Accounts During Setup
ISM-0385 · ASD ISM
Maintain Effective Functional Separation Between Servers
ISM-0393 · ASD ISM
Classify Databases Based on Data Sensitivity
ISM-0400 · ASD ISM
Segregation of Environments in Software Development
ISM-0401 · ASD ISM
Implement Secure by Design in Software Development
ISM-0402 · ASD ISM
Software Vulnerability Testing Using SAST, DAST and SCA
ISM-0405 · ASD ISM
Validation for Unprivileged System Access Requests
ISM-0407 · ASD ISM
Maintain Secure User Access Records
ISM-0408 · ASD ISM
System Login Security Reminder Banner
ISM-0409 · ASD ISM
Restrict Foreign Nationals' Access to Sensitive Data
ISM-0411 · ASD ISM
Restrict System Access for Foreign Nationals
ISM-0414 · ASD ISM
Ensure Unique Identification for System Access
ISM-0415 · ASD ISM
Strict Control of Shared User Accounts
ISM-0417 · ASD ISM
Use Passwords When Multi-Factor Authentication Isn't Supported
ISM-0418 · ASD ISM
Keep Physical Credentials Separate from Systems
ISM-0420 · ASD ISM
Identify Nationality of Foreign Personnel in System
ISM-0421 · ASD ISM
Require Minimum 15-Character Passwords for Security
ISM-0422 · ASD ISM
Ensuring Strong Passwords for TOP SECRET Systems
ISM-0428 · ASD ISM
Enforcement of Secure Session Locking Measures
ISM-0430 · ASD ISM
Immediate Suspension of Unneeded System Access
ISM-0432 · ASD ISM
Document System Access Requirements in Security Plans
ISM-0434 · ASD ISM
Ensure Personnel Employment Screening and Security Clearance
ISM-0435 · ASD ISM
Pre-Access Briefings for System Resources
ISM-0441 · ASD ISM
Ensuring Limited Access for Temporary System Use
ISM-0443 · ASD ISM
Restrict Temporary Access to Secure Systems
ISM-0445 · ASD ISM
Dedicated Accounts for Privileged User Activities
ISM-0446 · ASD ISM
Restrict Privileged Access for Foreign Nationals
ISM-0447 · ASD ISM
Restrict Privileged Access for Foreign Nationals
ISM-0455 · ASD ISM
Enable Data Recovery for Encrypted Data
ISM-0457 · ASD ISM
Use Evaluated Crypto for Sensitive Data Encryption
ISM-0459 · ASD ISM
Implement Full or Partial Disk Encryption
ISM-0460 · ASD ISM
Use HACE for Encrypting Sensitive Media
ISM-0462 · ASD ISM
Managing Encryption Access for IT Equipment and Media
ISM-0465 · ASD ISM
Use Evaluated Cryptographic Tools for Sensitive Data
ISM-0467 · ASD ISM
Using HACE for Secure Communication of Data
ISM-0469 · ASD ISM
Use Approved Cryptographic Protocols When Encrypting Data In Transit
ISM-0471 · ASD ISM
Use Only High Assurance Cryptographic Algorithms
ISM-0472 · ASD ISM
Using Proper Modulus Size for Diffie-Hellman Keys
ISM-0474 · ASD ISM
Using Secure Elliptic Curve Diffie-Hellman Encryption
ISM-0475 · ASD ISM
Use P-384 Curve for Secure Digital Signatures
ISM-0476 · ASD ISM
Ensuring Strong RSA Modulus for Digital Security
ISM-0477 · ASD ISM
Separate RSA Key Pairs for Different Functions
ISM-0479 · ASD ISM
Avoid Using ECB Mode for Symmetric Encryption
ISM-0481 · ASD ISM
Ensure Use of High Assurance Cryptographic Protocols
ISM-0484 · ASD ISM
Configure SSH for Secure Server Access
ISM-0485 · ASD ISM
Use Public Key Authentication for SSH Access
ISM-0487 · ASD ISM
Disable Certain Features for Passwordless SSH Logins
ISM-0488 · ASD ISM
Use Forced Commands for SSH Without Passwords
ISM-0489 · ASD ISM
SSH-Agent Key Expiry and Screen Lock Requirements
ISM-0490 · ASD ISM
Ensure S/MIME 3.0 or Later is Used
ISM-0494 · ASD ISM
Use of IPsec Tunnel and Transport Modes
ISM-0496 · ASD ISM
Use ESP Protocol for Secure IPsec Connections
ISM-0498 · ASD ISM
Ensure Short Lifetimes for IPsec Associations
ISM-0499 · ASD ISM
Ensure Compliance with ASD Communication Security Policies
ISM-0501 · ASD ISM
Transport of Keyed Cryptographic Equipment
ISM-0507 · ASD ISM
Develop and Maintain Cryptographic Key Management Processes
ISM-0516 · ASD ISM
Comprehensive Network Diagrams for Critical Components
ISM-0518 · ASD ISM
Maintain Comprehensive Network Documentation
ISM-0520 · ASD ISM
Prevent Unauthorised Network Device Connections
ISM-0521 · ASD ISM
Disable Unused IPv6 on Dual-Stack Devices
ISM-0529 · ASD ISM
Avoid Using VLANs for Different Security Domains
ISM-0530 · ASD ISM
Administer VLANs from Trusted Security Domains
ISM-0534 · ASD ISM
Disable Unused Network Device Ports
ISM-0535 · ASD ISM
Prevent VLAN Trunk Sharing Across Security Domains
ISM-0536 · ASD ISM
Segregate Public Wireless Networks from Organisation Networks
ISM-0546 · ASD ISM
Use Video and Voice-Aware Firewalls at Gateways
ISM-0547 · ASD ISM
Secure Protocols for Video and IP Telephony
ISM-0548 · ASD ISM
Ensure Secure Protocols for Video and IP Calls
ISM-0549 · ASD ISM
Separate Video Conferencing and IP Telephony Traffic From Other Data
ISM-0551 · ASD ISM
Ensure Secure IP Telephony Device Authentication
ISM-0553 · ASD ISM
Authenticate Video Calls and Manage Settings
ISM-0554 · ASD ISM
Secure Two-Way Authentication for Video Calls
ISM-0555 · ASD ISM
Ensure Authentication for IP Telephony Actions
ISM-0556 · ASD ISM
Ensure Traffic Separation for Video Conferencing and Telephony
ISM-0558 · ASD ISM
Restrict IP Phone Network Access in Public Areas
ISM-0559 · ASD ISM
Restrict Microphone and Webcam Use in SECRET Areas
ISM-0565 · ASD ISM
Email Security for Protective Markings
ISM-0567 · ASD ISM
Restrict Email Relay to Specific Domains
ISM-0569 · ASD ISM
Centralise Email Routing via Gateways
ISM-0570 · ASD ISM
Maintain Backup Email Gateways to Primary Standards
ISM-0571 · ASD ISM
Ensure Secure Email Transmission via Gateways
ISM-0572 · ASD ISM
Enable Opportunistic TLS for Email Server Encryption
ISM-0574 · ASD ISM
Use SPF to Authorise Email Servers
ISM-0576 · ASD ISM
Develop and Maintain Cyber Security Incident Plans
ISM-0580 · ASD ISM
Develop, Implement and Maintain a Security Monitoring Policy
ISM-0582 · ASD ISM
Central Logging of Windows Security Events
ISM-0585 · ASD ISM
Capture Detailed Information in Event Logs
ISM-0588 · ASD ISM
Develop and Maintain MFD Usage Policy
ISM-0589 · ASD ISM
Limit Document Sensitivity on MFDs Based on Network Classification
ISM-0590 · ASD ISM
Ensure Strong Authentication for Multi-Function Devices
ISM-0591 · ASD ISM
Use Evaluated Peripheral Switches Securely
ISM-0597 · ASD ISM
Consult ASD Before Changing CDS Connectivity
ISM-0610 · ASD ISM
Train Users on Secure Use of CDSs
ISM-0611 · ASD ISM
Restrict Privileges for Gateway Administrators
ISM-0612 · ASD ISM
Training for Gateway System Administrators
ISM-0613 · ASD ISM
Requirement for Gateway System Administrators Nationality
ISM-0616 · ASD ISM
Ensure Separation of Duties for Gateway Admins
ISM-0619 · ASD ISM
User Authentication for Network Gateway Access
ISM-0622 · ASD ISM
Ensuring Network Authentication via Gateways
ISM-0626 · ASD ISM
Implementing CDS for Secure Network Segmentation
ISM-0628 · ASD ISM
Implementing Secure Network Gateways
ISM-0629 · ASD ISM
Manage Gateways Between Different Security Domains
ISM-0631 · ASD ISM
Restrict Data Flows with Authorised Gateways
ISM-0634 · ASD ISM
Central Logging for Gateway Security Events
ISM-0635 · ASD ISM
Ensure Network Paths are Isolated in CDSs
ISM-0637 · ASD ISM
Implementing Demilitarised Zones in Gateways
ISM-0639 · ASD ISM
High Assurance Evaluation for Diode Gateways
ISM-0643 · ASD ISM
Use of Diodes for Unidirectional Gateway Security
ISM-0645 · ASD ISM
High Assurance Evaluation of Unidirectional Gateways
ISM-0649 · ASD ISM
Filter Gateway Files for Allowed Types
ISM-0651 · ASD ISM
Block Malicious or Uninspectable Files
ISM-0652 · ASD ISM
Quarantine Suspicious Files for Review
ISM-0657 · ASD ISM
Scanning Data for Threats Before Manual Import
ISM-0659 · ASD ISM
Filtering Content of Gateway and CDS Files
ISM-0660 · ASD ISM
Monthly Verification of Data Transfer Logs for SECRET Systems
ISM-0661 · ASD ISM
User Accountability for Data Transfers
ISM-0663 · ASD ISM
Develop and Maintain Data Transfer Procedures
ISM-0664 · ASD ISM
Authorisation of Secret Data Exports
ISM-0665 · ASD ISM
Verification Required for Exporting Secret Data
ISM-0669 · ASD ISM
Security Measures for Manual Data Export
ISM-0670 · ASD ISM
Central Logging of CDS Security Events
ISM-0675 · ASD ISM
Ensure Data Exports are Digitally Signed
ISM-0677 · ASD ISM
Ensure File Integrity Through Signature Validation
ISM-0682 · ASD ISM
Disable Bluetooth on SECRET/TS Mobile Devices
ISM-0687 · ASD ISM
Use Approved Platforms for Secure Mobile Access
ISM-0694 · ASD ISM
Block Privately Owned Devices From SECRET and TOP SECRET Systems
ISM-0701 · ASD ISM
CISO Management of Cyber Security Personnel
ISM-0702 · ASD ISM
Using Cryptographic Sanitisation on Mobile Devices
ISM-0705 · ASD ISM
Disable Split Tunnelling for VPN Connections
ISM-0714 · ASD ISM
Appoint a CISO to Lead Cyber Security Across IT and OT
ISM-0717 · ASD ISM
CISO Oversight of Cyber Security Personnel
ISM-0718 · ASD ISM
CISO Reporting to Board on Cyber Security
ISM-0720 · ASD ISM
Develop and Maintain a Cyber Security Communication Strategy
ISM-0724 · ASD ISM
Implement Cyber Security Metrics and KPIs
ISM-0725 · ASD ISM
Cyber Security Steering Committee Coordination
ISM-0726 · ASD ISM
Coordinate Security Risk Management Activities
ISM-0731 · ASD ISM
CISO Oversight of Cyber Supply Chain Risks
ISM-0732 · ASD ISM
Manage and Allocate Cyber Security Budget
ISM-0733 · ASD ISM
Ensure CISO Awareness of Cyber Incidents
ISM-0734 · ASD ISM
CISO Role in Disaster Recovery Planning
ISM-0735 · ASD ISM
Secure Facilities for Classified Systems
ISM-0810 · ASD ISM
Secure Facilities Based on System Classification
ISM-0813 · ASD ISM
Ensure Secure Access to Critical Infrastructure
ISM-0817 · ASD ISM
Reporting Suspicious Online Contact Awareness
ISM-0820 · ASD ISM
Avoid Posting Work Data on Unauthorised Online Services
ISM-0821 · ASD ISM
Advise on Risks of Posting Personal Information Online
ISM-0824 · ASD ISM
Avoid Using Unauthorised Online File Services
ISM-0829 · ASD ISM
Detect Unauthorised RF Devices in Secure Areas
ISM-0831 · ASD ISM
Ensure Proper Handling of Sensitive Media
ISM-0835 · ASD ISM
TOP SECRET Volatile Media Retains Classification After Sanitisation
ISM-0836 · ASD ISM
Overwriting EEPROM for Complete Data Sanitisation
ISM-0839 · ASD ISM
Prohibit Outsourcing of Media Destruction
ISM-0840 · ASD ISM
Certified Services for Outsourced Media Destruction
ISM-0843 · ASD ISM
Ensure Workstation Security with Application Control
ISM-0846 · ASD ISM
Prevent Users Disabling, Bypassing or Exempting Application Control
ISM-0853 · ASD ISM
Terminate User Sessions and Restart Workstations Daily
ISM-0854 · ASD ISM
Access Restrictions for AUSTEO and AGAO Data
ISM-0861 · ASD ISM
Enable DKIM Signing for Organisational Emails
ISM-0863 · ASD ISM
Prevent Installation of Unapproved Mobile Apps
ISM-0864 · ASD ISM
Prevent Modifications to Security Settings on Mobile Devices
ISM-0866 · ASD ISM
Ensure Privacy While Viewing Data in Public
ISM-0869 · ASD ISM
Encrypt Storage on Mobile Devices
ISM-0870 · ASD ISM
Secure Storage and Handling of Mobile Devices
ISM-0871 · ASD ISM
Supervise Mobile Devices During Active Use
ISM-0874 · ASD ISM
Ensure Internet Access via Organisation's Gateway
ISM-0888 · ASD ISM
Annual Review of Cyber Security Documentation
ISM-0912 · ASD ISM
Establish and Manage System Configuration Changes
ISM-0917 · ASD ISM
Procedures for Handling Malicious Code Infections
ISM-0926 · ASD ISM
Ensure Cables Are Not Salmon Pink or Red
ISM-0931 · ASD ISM
Off-hook Audio Protection Using Push-to-Talk Devices
ISM-0938 · ASD ISM
Select Secure-by-Design Committed Vendors
ISM-0947 · ASD ISM
Sanitise Media After Data Transfers Between Domains
ISM-0955 · ASD ISM
Implementing Application Control Measures
ISM-0958 · ASD ISM
Implement Domain Name Allow and Block Lists
ISM-0961 · ASD ISM
Restrict Active Content with Web Filters
ISM-0963 · ASD ISM
Implementing Web Content Filters for Safety
ISM-0971 · ASD ISM
Use OWASP Standards in Web Application Development
ISM-0974 · ASD ISM
Implement Multi-factor Authentication for User Access
ISM-0988 · ASD ISM
Ensure Accurate Time Source for Event Logs
ISM-0994 · ASD ISM
Use ECDH for Secure Key Exchanges
ISM-0998 · ASD ISM
Using Integrity Algorithms for IPsec Connections
ISM-0999 · ASD ISM
Use DH or ECDH for Secure Key Establishment
ISM-1000 · ASD ISM
Utilising Perfect Forward Secrecy for IPsec
ISM-1006 · ASD ISM
Prevent Unauthorised Access to Network Traffic
ISM-1013 · ASD ISM
Limit Wireless Range with RF Shielding
ISM-1014 · ASD ISM
Implement Individual Logins for Secure IP Phone Use
ISM-1019 · ASD ISM
Develop a Denial of Service Response Plan
ISM-1023 · ASD ISM
Notify Parties of Blocked Emails
ISM-1024 · ASD ISM
Verify Senders for Email Failure Notifications
ISM-1026 · ASD ISM
Verification of DKIM Signatures on Incoming Emails
ISM-1027 · ASD ISM
Configure Email Distribution Lists to Preserve DKIM Signatures
ISM-1028 · ASD ISM
Use NIDS/NIPS for Gateway Network Security
ISM-1030 · ASD ISM
Deploy NIDS/NIPS for Gateway Traffic Monitoring
ISM-1034 · ASD ISM
Disable Legacy Authentication Methods in Networks
ISM-1036 · ASD ISM
Place Multifunction Devices Where Their Use Can Be Observed
ISM-1037 · ASD ISM
Regular Testing of Gateway Security Configurations
ISM-1053 · ASD ISM
Secure Physical Access for Classified Equipment
ISM-1055 · ASD ISM
Disable Insecure LAN Manager Authentication
ISM-1059 · ASD ISM
Encrypt All Data Stored on Media Using ASD-Approved Cryptography
ISM-1065 · ASD ISM
Reset Device Settings Before Media Sanitisation
ISM-1067 · ASD ISM
Secure Erase for Non-Volatile Magnetic Media
ISM-1071 · ASD ISM
Assign System Ownership for Better Oversight
ISM-1073 · ASD ISM
Ensure Provider Contracts for System Access
ISM-1074 · ASD ISM
Controlling Access to Critical IT Infrastructure
ISM-1076 · ASD ISM
Sanitise Screen Burn-In With a Solid White Image
ISM-1078 · ASD ISM
Develop and Maintain Telephone System Usage Policy
ISM-1079 · ASD ISM
Seek Approval for High Assurance IT Repairs
ISM-1080 · ASD ISM
Use AACA or High Assurance Algorithms for Data Encryption
ISM-1082 · ASD ISM
Develop and Maintain Mobile Device Usage Policy
ISM-1083 · ASD ISM
Advise Personnel on Mobile Communication Sensitivity
ISM-1084 · ASD ISM
Transporting Mobile Devices Securely
ISM-1085 · ASD ISM
Encrypt Sensitive Data Over Public Networks
ISM-1088 · ASD ISM
Report Potential Compromises of Mobile Devices Overseas
ISM-1089 · ASD ISM
Prevent Lower Email Protective Marking Selection
ISM-1091 · ASD ISM
Change Keying Material When Compromised
ISM-1095 · ASD ISM
Proper Labelling of Wall Outlet Boxes
ISM-1096 · ASD ISM
Ensure Proper Labelling of Cables for Identification
ISM-1098 · ASD ISM
Terminate Cable Systems at Cabinet Boundaries
ISM-1100 · ASD ISM
Terminating TOP SECRET Cables in Cabinets
ISM-1101 · ASD ISM
Terminate Cabling Closely in Top Secret Areas
ISM-1102 · ASD ISM
Terminate Cable Reticulation Close to Cabinet
ISM-1103 · ASD ISM
Terminate Cables Outside Cabinets in Secure Areas
ISM-1105 · ASD ISM
Ensure Wall Outlets Have Appropriate Cable Security
ISM-1107 · ASD ISM
Colour Restrictions for Wall Outlet Boxes
ISM-1109 · ASD ISM
Ensure Clear Plastic Covers for Wall Outlets
ISM-1111 · ASD ISM
Ensure Fibre-Optic Cables Replace Copper Cables
ISM-1112 · ASD ISM
Ensure Cables Are Inspectable Every Five Metres
ISM-1114 · ASD ISM
Ensure Separation in Cable Reticulation Systems
ISM-1115 · ASD ISM
Ensure Cables Use Conduits in Walls
ISM-1116 · ASD ISM
Ensure Separation Between Top Secret and Other Cabinets
ISM-1119 · ASD ISM
Ensure Cables in TOP SECRET Areas are Inspectable
ISM-1122 · ASD ISM
Secure TOP SECRET Cable Wall Exits
ISM-1123 · ASD ISM
Ensure UPS Powers All Top Secret IT Equipment
ISM-1130 · ASD ISM
Use Enclosed Systems for Shared Facility Cables
ISM-1133 · ASD ISM
Prevent Installation of TOP SECRET Cables in Shared Walls
ISM-1137 · ASD ISM
Request Risk Assessment for Emanation Security
ISM-1139 · ASD ISM
Require Latest Version of TLS for Security
ISM-1143 · ASD ISM
Develop and Maintain Patch Management Procedures
ISM-1145 · ASD ISM
Apply Privacy Filters to Protect Device Screens
ISM-1146 · ASD ISM
Separate Personal and Work Accounts for Online Services
ISM-1151 · ASD ISM
Verify Email Authenticity Using SPF
ISM-1157 · ASD ISM
Use NSA-evaluated Degaussers for Media Destruction
ISM-1158 · ASD ISM
High Assurance Evaluation for Network Diodes
ISM-1160 · ASD ISM
Use NSA-evaluated Degaussers for Media Destruction
ISM-1163 · ASD ISM
Continuous Monitoring Plan to Find and Fix Vulnerabilities
ISM-1164 · ASD ISM
Use Clear Plastic for Shared Facility Cabling Covers
ISM-1171 · ASD ISM
Block Direct IP Access to Websites
ISM-1173 · ASD ISM
Use Multi-Factor Authentication for Privileged Users
ISM-1175 · ASD ISM
Restrict Privileged Users from Internet Access
ISM-1178 · ASD ISM
Limit Network Documentation for Third Parties
ISM-1181 · ASD ISM
Segregate Networks by Server Criticality
ISM-1182 · ASD ISM
Implement Network Traffic Control Measures
ISM-1183 · ASD ISM
Implement Hard Fail SPF Records for Email Security
ISM-1186 · ASD ISM
Ensure IPv6 Network Security Appliances Are Used
ISM-1187 · ASD ISM
Check Data for Improper Markings Before Export
ISM-1192 · ASD ISM
Inspecting and Filtering Data with Gateways
ISM-1195 · ASD ISM
Enforce Policy with Evaluated Mobile Device Management
ISM-1196 · ASD ISM
Keep Mobile Devices Undiscoverable via Bluetooth
ISM-1198 · ASD ISM
Secure Bluetooth Pairing for Mobile Devices
ISM-1199 · ASD ISM
Remove Unnecessary Bluetooth Pairings on Devices
ISM-1200 · ASD ISM
Secure Bluetooth Pairing for Mobile Devices
ISM-1203 · ASD ISM
Risk Assessment for System Security
ISM-1211 · ASD ISM
System Admin Activities Follow Change Management Plan
ISM-1213 · ASD ISM
Analyse Network Traffic Post-Intrusion Remediation
ISM-1216 · ASD ISM
Ensure Correct Labelling of Non-conformant Cables
ISM-1217 · ASD ISM
Remove Identifying Labels from IT Equipment Before Disposal
ISM-1218 · ASD ISM
Sanitise Overseas IT Equipment Handling Sensitive Data
ISM-1219 · ASD ISM
Inspect and Destroy MFD Print Drums and Image Transfer Rollers
ISM-1220 · ASD ISM
Inspect and Destroy Retained Images on Printer Platens
ISM-1221 · ASD ISM
Processes for Sanitising Memory in Network Devices
ISM-1222 · ASD ISM
Destroy Unsanitised Televisions and Monitors
ISM-1223 · ASD ISM
Methods for Sanitising Network Device Memory
ISM-1227 · ASD ISM
Randomly Generate User Account Credentials
ISM-1228 · ASD ISM
Analyse Cyber Security Events Promptly
ISM-1233 · ASD ISM
Use IKE Version 2 for IPsec Key Exchange
ISM-1234 · ASD ISM
Protect Email Systems with Content Filtering
ISM-1235 · ASD ISM
Restrict User Application Extensions
ISM-1236 · ASD ISM
Blocking Malicious and Anonymous Domain Names
ISM-1237 · ASD ISM
Implement Web Content Filters for Outbound Traffic
ISM-1238 · ASD ISM
Incorporate Threat Modelling in Software Development
ISM-1239 · ASD ISM
Ensure Use of Robust Web Application Frameworks
ISM-1240 · ASD ISM
Ensure Input Validation and Sanitisation for Internet Data
ISM-1241 · ASD ISM
Ensuring Secure Web Application Output Encoding
ISM-1243 · ASD ISM
Develop and Verify Database Register
ISM-1245 · ASD ISM
Remove Temporary Files After Server Installation
ISM-1246 · ASD ISM
Apply Strict Server Application Hardening Guidelines
ISM-1247 · ASD ISM
Disable or Remove Unneeded Server Features
ISM-1249 · ASD ISM
Limit Server Application User Privileges
ISM-1250 · ASD ISM
Limit Server Application User Account Privileges
ISM-1255 · ASD ISM
Restrict Database User Access Based on Duties
ISM-1256 · ASD ISM
Implement File-Based Access Controls for Databases
ISM-1260 · ASD ISM
Secure Server Applications by Changing Default Credentials
ISM-1263 · ASD ISM
Enforce Unique Accounts for Server Administration
ISM-1268 · ASD ISM
Enforce Need-to-Know Access in Databases
ISM-1269 · ASD ISM
Ensure Databases and Web Servers are Separated
ISM-1270 · ASD ISM
Separate Network Segments for Database Servers
ISM-1271 · ASD ISM
Restrict Network Access to Database Servers
ISM-1272 · ASD ISM
Disable Database Networking for Local Access
ISM-1273 · ASD ISM
Segregate Environments for Database Servers
ISM-1274 · ASD ISM
Ensure Non-Production Databases Match Production Security
ISM-1275 · ASD ISM
Ensure Secure Database Queries in Software
ISM-1276 · ASD ISM
Use Safe Database Query Methods
ISM-1277 · ASD ISM
Encrypt Database and Web Server Communications
ISM-1278 · ASD ISM
Minimise Database Error Information in Software
ISM-1284 · ASD ISM
Ensure Content Validation for Gateway Files
ISM-1286 · ASD ISM
Ensure Content Conversion at Gateways
ISM-1287 · ASD ISM
Ensure Gateway and CDS File Content Sanitisation
ISM-1288 · ASD ISM
Antivirus Scanning of Gateway Files
ISM-1289 · ASD ISM
Unpack Archive Files for Content Filtering at Gateways
ISM-1290 · ASD ISM
Controlled Unpacking of Archive Files for Filtering
ISM-1293 · ASD ISM
Decrypt Encrypted Files for Content Filtering
ISM-1294 · ASD ISM
Partial Monthly Verification of Data Transfer Logs
ISM-1296 · ASD ISM
Protect Network Devices in Public Areas
ISM-1297 · ASD ISM
Seek Legal Advice for Personal Device Access
ISM-1298 · ASD ISM
Advise Personnel on Overseas Mobile Device Security
ISM-1299 · ASD ISM
Personnel Awareness for Secure Mobile Device Usage
ISM-1300 · ASD ISM
Mobile Device Security After Overseas Travel
ISM-1304 · ASD ISM
Secure Network Devices by Changing Default Credentials
ISM-1311 · ASD ISM
Prevent Use of Insecure SNMP Versions on Networks
ISM-1312 · ASD ISM
Changing Default SNMP Community Strings on Devices
ISM-1314 · ASD ISM
Ensure Wireless Devices are Wi-Fi Alliance Certified
ISM-1315 · ASD ISM
Disable Wireless Network Administrative Interfaces
ISM-1316 · ASD ISM
Ensure Default Wireless SSIDs Are Changed
ISM-1317 · ASD ISM
Secure Naming of Non-Public Wireless Networks
ISM-1318 · ASD ISM
Prevent SSID Broadcasting on Access Points
ISM-1319 · ASD ISM
Avoid Static IP Addressing on Wireless Networks
ISM-1320 · ASD ISM
Avoid Using MAC Filtering for Wireless Access Control
ISM-1321 · ASD ISM
Implement EAP-TLS for Secure Wireless Authentication
ISM-1322 · ASD ISM
Assessing 802.1X Components in Wireless Networks
ISM-1323 · ASD ISM
Requiring Certificates for Wireless Network Access
ISM-1324 · ASD ISM
Certificate Generation for Secure Authentication
ISM-1327 · ASD ISM
Secure Certificates for Network Authentication
ISM-1330 · ASD ISM
Limit PMK Caching Duration on Wireless Networks
ISM-1332 · ASD ISM
Ensure Wireless Traffic is Secure with WPA3-Enterprise
ISM-1334 · ASD ISM
Ensure Frequency Separation in Wireless Networks
ISM-1335 · ASD ISM
Enabling 802.11w to Protect Wireless Management Frames
ISM-1338 · ASD ISM
Use Lower-Powered Wireless Access Points for Coverage
ISM-1341 · ASD ISM
Implement HIPS or EDR on Workstations
ISM-1359 · ASD ISM
Establish and Maintain Removable Media Policy
ISM-1361 · ASD ISM
Use Approved Equipment for Media Destruction
ISM-1364 · ASD ISM
Separate VLANs by Security Domains
ISM-1366 · ASD ISM
Ensure Timely Security Updates for Mobile Devices
ISM-1369 · ASD ISM
Ensure TLS Connections Use AES-GCM Encryption
ISM-1370 · ASD ISM
Ensure Only Server-Initiated TLS Renegotiation
ISM-1372 · ASD ISM
Secure Key Establishment Using DH or ECDH in TLS
ISM-1373 · ASD ISM
Ensure TLS Connections do not use Anonymous DH
ISM-1374 · ASD ISM
Use SHA-2 Certificates for Secure TLS Connections
ISM-1375 · ASD ISM
Use SHA-2 for Secure TLS Connections
ISM-1380 · ASD ISM
Use Separate Privileged and Unprivileged Environments
ISM-1385 · ASD ISM
Segregation of Administrative Infrastructure from Networks
ISM-1386 · ASD ISM
Restrict Network Management Traffic Origin
ISM-1387 · ASD ISM
Use Jump Servers for Administrative Activities
ISM-1389 · ASD ISM
Analyse Executable Files in Sandboxes
ISM-1392 · ASD ISM
Restrict File Modifications via Path Rules
ISM-1395 · ASD ISM
Ensuring Data Protection by Service Providers
ISM-1400 · ASD ISM
Enforce Data Separation on Personal Devices
ISM-1401 · ASD ISM
Implement Multi-Factor Authentication for Security
ISM-1402 · ASD ISM
Protecting Stored Credentials with Security Measures
ISM-1403 · ASD ISM
Lock Accounts After Five Failed Logon Attempts
ISM-1404 · ASD ISM
Disabling Inactive User Access After 45 Days
ISM-1405 · ASD ISM
Implement a Centralised Event Logging Facility
ISM-1406 · ASD ISM
Use SOEs for Workstations and Servers
ISM-1407 · ASD ISM
Ensure Use of Current OS Versions
ISM-1408 · ASD ISM
Use 64-bit Operating Systems Where Supported
ISM-1409 · ASD ISM
Implement Restrictive OS Hardening Guidelines
ISM-1412 · ASD ISM
Web Browser Hardening with Strict Guidelines
ISM-1416 · ASD ISM
Implement Firewalls to Control Network Connections
ISM-1417 · ASD ISM
Ensure Antivirus Protection on Workstations and Servers
ISM-1418 · ASD ISM
Disable Unnecessary Removable Media Access
ISM-1419 · ASD ISM
Software Development in Development Environments
ISM-1420 · ASD ISM
Ensure Non-Production Security Matches Production
ISM-1422 · ASD ISM
Prevent Unauthorised Access to Software Source
ISM-1424 · ASD ISM
Ensure Web Security Through Response Headers
ISM-1427 · ASD ISM
Prevent IP Source Address Spoofing in Gateways
ISM-1428 · ASD ISM
Disable IPv6 Tunnelling Unless Necessary
ISM-1429 · ASD ISM
Block IPv6 Tunnelling at Externally Connected Network Boundaries
ISM-1430 · ASD ISM
Configure IPv6 Addresses with DHCPv6 in Stateful Mode
ISM-1431 · ASD ISM
Strategies for Mitigating Denial-of-Service Attacks
ISM-1432 · ASD ISM
Protect Online Services from Domain Hijacking
ISM-1436 · ASD ISM
Segregate Critical Services to Prevent DoS Attacks
ISM-1437 · ASD ISM
Utilising Cloud Providers for Hosting Online Services
ISM-1438 · ASD ISM
Ensure High Availability by Using CDNs
ISM-1439 · ASD ISM
Restrict IP Disclosure in CDNs
ISM-1446 · ASD ISM
Use Approved Elliptic Curves for Encryption
ISM-1448 · ASD ISM
Use Ephemeral DH or ECDH for TLS Key Establishment
ISM-1449 · ASD ISM
Protect SSH Private Keys with Passwords or Encryption
ISM-1450 · ASD ISM
Restricting Devices in Top Secret Areas
ISM-1451 · ASD ISM
Document Data Ownership in Service Contracts
ISM-1452 · ASD ISM
Perform Supply Chain Risk Assessments for System Suppliers
ISM-1453 · ASD ISM
Ensure PFS is Enabled for TLS Connections
ISM-1454 · ASD ISM
Enhancing Security with Encrypted RADIUS Communications
ISM-1457 · ASD ISM
Evaluate Peripheral Switches for Security Domains
ISM-1460 · ASD ISM
Secure By Design Vendor Isolation Mechanisms
ISM-1461 · ASD ISM
Same Classification and Security Domain for Shared Isolation Hosts
ISM-1467 · ASD ISM
Use Latest Releases of User Applications
ISM-1470 · ASD ISM
Disable Unneeded Accounts, Components, Services and Application Functionality
ISM-1471 · ASD ISM
Utilise Publisher and Product Names in App Control
ISM-1478 · ASD ISM
CISO Management of Cyber Security Compliance
ISM-1479 · ASD ISM
Minimise Server-to-Server Communication
ISM-1480 · ASD ISM
Ensure High Assurance for Peripheral Switches
ISM-1482 · ASD ISM
Ensure Separation of Classified and Personal Data on Devices
ISM-1483 · ASD ISM
Use Latest Release of Internet-Facing Server Applications
ISM-1485 · ASD ISM
Prevent Web Browsers from Processing Ads
ISM-1486 · ASD ISM
Restrict Java Processing in Web Browsers
ISM-1487 · ASD ISM
Restrict Macro Editing to Privileged Users
ISM-1488 · ASD ISM
Blocking Internet-Originating Macros in Office Files
ISM-1489 · ASD ISM
Prevent Users from Changing Office Macro Security Settings
ISM-1490 · ASD ISM
Implement Application Control on Internet-Facing Servers
ISM-1491 · ASD ISM
Prevent Script Execution by Unprivileged Users
ISM-1492 · ASD ISM
Enable Exploit Protection in Operating Systems
ISM-1493 · ASD ISM
Maintain and Verify Software Registers
ISM-1501 · ASD ISM
Replace Unsupported Operating Systems
ISM-1502 · ASD ISM
Ensure Multi-factor Authentication for Online Services
ISM-1504 · ASD ISM
Implement Multi-factor Authentication
ISM-1505 · ASD ISM
Implement Multi-factor Authentication for Data Repositories
ISM-1506 · ASD ISM
Disable SSH Version 1 for Security
ISM-1507 · ASD ISM
Ensure Requests for Privileged Access are Verified
ISM-1508 · ASD ISM
Limit Privileged Access to Essential Duties Only
ISM-1509 · ASD ISM
Log Privileged Access Events Centrally for Monitoring
ISM-1510 · ASD ISM
Develop and Maintain a Digital Preservation Policy
ISM-1511 · ASD ISM
Conduct and Maintain Regular Data Backups
ISM-1515 · ASD ISM
Test Backup Restoration During Disaster Recovery
ISM-1517 · ASD ISM
Microform Destruction Using Fine Powder Method
ISM-1520 · ASD ISM
Employment Screening for Gateway Administrators
ISM-1521 · ASD ISM
Use Protocol Breaks to Separate Network Layers
ISM-1522 · ASD ISM
Ensure CDSs Separate Upward and Downward Data Paths
ISM-1523 · ASD ISM
Regular Assessment of Security Events in CDS
ISM-1524 · ASD ISM
Ensure Rigorous Testing of Content Filters
ISM-1525 · ASD ISM
Register Systems with Authorising Officers
ISM-1526 · ASD ISM
Determine System Boundaries and Objectives
ISM-1528 · ASD ISM
Utilising Evaluated Firewalls for Network Security
ISM-1529 · ASD ISM
Limit Cloud Services to Community or Private for SECRETS
ISM-1530 · ASD ISM
Secure Classified Equipment in Suitable Security Containers
ISM-1532 · ASD ISM
Avoid Using VLANs for Network Separation
ISM-1533 · ASD ISM
Establish Mobile Device Management Policies
ISM-1534 · ASD ISM
Prevent Inappropriate Export of Sensitive Data
ISM-1535 · ASD ISM
Prevent Unsuitable Foreign Data Exports
ISM-1536 · ASD ISM
Prevent OLE Package Activation in Microsoft Office
ISM-1537 · ASD ISM
Log Security-Relevant Database Events Centrally
ISM-1540 · ASD ISM
Configuring DMARC for Email Security
ISM-1542 · ASD ISM
Disable OLE in Microsoft Office for Security
ISM-1543 · ASD ISM
Register for RF and IR Devices in Secret Areas
ISM-1544 · ASD ISM
Implement Microsoft's Application Blocklist
ISM-1546 · ASD ISM
Ensure User Authentication Before System Access
ISM-1547 · ASD ISM
Develop and Maintain Data Backup Procedures
ISM-1548 · ASD ISM
Develop and Maintain Data Restoration Processes
ISM-1549 · ASD ISM
Develop and Maintain Media Management Policy
ISM-1550 · ASD ISM
Develop and Maintain IT Equipment Disposal Procedures
ISM-1551 · ASD ISM
Develop and Maintain IT Equipment Management Policy
ISM-1552 · ASD ISM
Secure Web Content with HTTPS Only
ISM-1553 · ASD ISM
Disable TLS Compression for Security
ISM-1554 · ASD ISM
Guidelines for Using Mobile Devices Abroad
ISM-1555 · ASD ISM
Prepare Mobile Devices Before Overseas Travel
ISM-1556 · ASD ISM
Security Measures After Overseas Travel with Mobile Devices
ISM-1557 · ASD ISM
Ensure Strong Passwords for SECRET Systems
ISM-1558 · ASD ISM
Ensure Secure Construction of Passwords
ISM-1559 · ASD ISM
Minimum Password Length for Secure Systems
ISM-1560 · ASD ISM
Ensure Strong Passwords for SECRET System Authentication
ISM-1561 · ASD ISM
Ensure Strong Passwords for TOP SECRET Systems
ISM-1562 · ASD ISM
Secure Video Conferencing and Telephony Systems
ISM-1563 · ASD ISM
Generate Comprehensive Security Assessment Reports
ISM-1564 · ASD ISM
Develop Plan of Action Post Security Assessment
ISM-1565 · ASD ISM
Annual Training for Privileged Users
ISM-1566 · ASD ISM
Central Logging of Unprivileged System Access
ISM-1567 · ASD ISM
Avoid High-Risk Suppliers in Cyber Supply Chain
ISM-1568 · ASD ISM
Ensure Security Commitment from Suppliers
ISM-1569 · ASD ISM
Document and Share a Supplier Customer Shared Responsibility Model
ISM-1570 · ASD ISM
Regular IRAP Assessment of Cloud Service Providers
ISM-1571 · ASD ISM
Verify Security Compliance in Service Contracts
ISM-1572 · ASD ISM
Document Service Provider Data Handling and Change Notifications
ISM-1573 · ASD ISM
Log Access Documentation with Service Providers
ISM-1574 · ASD ISM
Data Portability in Service Contracts
ISM-1575 · ASD ISM
One-Month Notice for Service Termination
ISM-1576 · ASD ISM
Notify Organisation of Unauthorised System Access
ISM-1577 · ASD ISM
Ensure Network Segregation from Service Providers
ISM-1579 · ASD ISM
Dynamic Resource Scaling for Demand Spikes
ISM-1580 · ASD ISM
Ensure High Availability for Online Services
ISM-1581 · ASD ISM
Monitor Capacity and Availability of Online Services
ISM-1582 · ASD ISM
Annual Validation of Application Control Rulesets
ISM-1583 · ASD ISM
Ensure Contractors are Identified as Users
ISM-1584 · ASD ISM
Prevent Unauthorised Changes to Security Settings
ISM-1585 · ASD ISM
Prevent User Changes to Browser Security Settings
ISM-1586 · ASD ISM
Record All Data Imports and Exports
ISM-1587 · ASD ISM
Annual Security Status Reporting for Systems
ISM-1588 · ASD ISM
Annual Review of Standard Operating Environments
ISM-1589 · ASD ISM
Enable MTA-STS for Secure Email Transport
ISM-1590 · ASD ISM
Mandate Credential Changes Upon Compromise
ISM-1591 · ASD ISM
Suspend User Access for Malicious Activity
ISM-1592 · ASD ISM
Prevent Unauthorised Application Installations by Users
ISM-1593 · ASD ISM
Verifying User Identity for New Credentials
ISM-1594 · ASD ISM
Secure Delivery of User Account Credentials
ISM-1595 · ASD ISM
Ensure Initial User Credentials Are Changed
ISM-1596 · ASD ISM
Avoid Reusing Credentials Across Systems
ISM-1597 · ASD ISM
Ensuring Credential Input Obscurity
ISM-1598 · ASD ISM
Inspect IT Equipment Post-Maintenance for Unauthorised Changes
ISM-1599 · ASD ISM
Proper Handling of Sensitive IT Equipment
ISM-1600 · ASD ISM
Ensure Media is Sanitised Before Initial Use
ISM-1601 · ASD ISM
Implement Microsoft Attack Surface Reduction Rules
ISM-1602 · ASD ISM
Ensure Cyber Security Docs Are Communicated
ISM-1603 · ASD ISM
Disabling Vulnerable Authentication Methods
ISM-1604 · ASD ISM
Harden Software Isolation Mechanisms Sharing Physical Computing Resources
ISM-1605 · ASD ISM
Harden the Operating System Beneath Software Isolation Mechanisms
ISM-1606 · ASD ISM
Patch Isolation Mechanisms and Underlying Operating Systems Promptly
ISM-1607 · ASD ISM
Integrity Monitoring and Logging for Isolation Mechanism
ISM-1608 · ASD ISM
Scan Third-Party SOEs for Malicious Code
ISM-1609 · ASD ISM
Consult System Owners Before Continuing Intrusions
ISM-1610 · ASD ISM
Document and Test Emergency System Access Procedures
ISM-1611 · ASD ISM
Use Break Glass Accounts Only in Emergencies
ISM-1612 · ASD ISM
Restricted Use of Break Glass Accounts for Emergencies
ISM-1613 · ASD ISM
Central Logging of Break Glass Account Usage
ISM-1614 · ASD ISM
Manage Emergency Account Access Changes
ISM-1615 · ASD ISM
Testing Break Glass Accounts Post Credential Change
ISM-1616 · ASD ISM
Implementing a Vulnerability Disclosure Program
ISM-1617 · ASD ISM
Regular Review of Cyber Security Program
ISM-1618 · ASD ISM
CISO's Role in Cyber Security Incident Response
ISM-1619 · ASD ISM
Configure Service Accounts as Managed Service Accounts
ISM-1620 · ASD ISM
Ensure Privileged Accounts are Secured in AD
ISM-1621 · ASD ISM
Disable or Remove Windows PowerShell 2.0
ISM-1622 · ASD ISM
Ensure PowerShell Uses Constrained Language Mode
ISM-1623 · ASD ISM
Centralised Logging of PowerShell Activities
ISM-1624 · ASD ISM
Protect PowerShell Script Block Logs
ISM-1625 · ASD ISM
Develop Insider Threat Mitigation Programs
ISM-1626 · ASD ISM
Seek Legal Advice for Insider Threat Plans
ISM-1627 · ASD ISM
Block Inbound Traffic from Anonymity Networks
ISM-1628 · ASD ISM
Prevent Anonymity Network Traffic in Outbound Connections
ISM-1629 · ASD ISM
Select Correct Modulus for Diffie-Hellman Encryption
ISM-1631 · ASD ISM
Identify Suppliers in Cyber Supply Chain
ISM-1632 · ASD ISM
Ensure Secure Procurement from Reliable Suppliers
ISM-1633 · ASD ISM
Implement Emanation Security Mitigation Recommendations
ISM-1634 · ASD ISM
Tailoring System Controls for Security and Resilience
ISM-1635 · ASD ISM
Ensure Security Controls for System Environments
ISM-1636 · ASD ISM
Security Assessment for System Controls
ISM-1637 · ASD ISM
Maintain an Outsourced Cloud Service Register
ISM-1638 · ASD ISM
Maintain a Comprehensive Outsourced Cloud Service Register
ISM-1639 · ASD ISM
Label Building Management Cables Clearly
ISM-1640 · ASD ISM
Label Cables for Foreign Systems in Australia
ISM-1641 · ASD ISM
Ensure Degaussed Media is Physically Damaged
ISM-1642 · ASD ISM
Ensure Media is Sanitised Before Reuse
ISM-1643 · ASD ISM
Maintain Detailed Software Version and Patch Records
ISM-1644 · ASD ISM
Secure Communication Practices in Public Areas
ISM-1645 · ASD ISM
Maintain and Verify Floor Plan Diagrams
ISM-1646 · ASD ISM
Detail Cabling Paths and Points on Floor Plans
ISM-1647 · ASD ISM
Disable Privileged Access After 12 Months
ISM-1648 · ASD ISM
Disabling Inactive Privileged Access to Systems
ISM-1649 · ASD ISM
Implement Just-in-Time Administration for System Access
ISM-1650 · ASD ISM
Log Management of Privileged User Activities
ISM-1654 · ASD ISM
Disable or Remove Internet Explorer 11
ISM-1655 · ASD ISM
Ensure .NET Framework 3.5 is Disabled or Removed
ISM-1656 · ASD ISM
Implement Application Control on Secure Servers
ISM-1657 · ASD ISM
Restrict Application Execution to Approved Set
ISM-1658 · ASD ISM
Restrict Execution of Drivers via Application Control
ISM-1659 · ASD ISM
Implement Microsoft's Vulnerable Driver Blocklist
ISM-1660 · ASD ISM
Central Logging of Application Events
ISM-1667 · ASD ISM
Prevent Child Processes in Microsoft Office
ISM-1668 · ASD ISM
Prevent Microsoft Office from Creating Executable Files
ISM-1669 · ASD ISM
Prevent Microsoft Office from Injecting Code
ISM-1670 · ASD ISM
Prevent PDF Applications from Creating Child Processes
ISM-1671 · ASD ISM
Disabling Microsoft Office Macros for Unauthorised Users
ISM-1672 · ASD ISM
Enable Antivirus Scanning for Office Macros
ISM-1673 · ASD ISM
Prevent Win32 API Calls by Office Macros
ISM-1674 · ASD ISM
Ensuring Secure Execution of Microsoft Office Macros
ISM-1675 · ASD ISM
Prevent Enabling Untrusted Microsoft Office Macros
ISM-1676 · ASD ISM
Validate Microsoft Office Trusted Publishers List At Least Annually
ISM-1679 · ASD ISM
Use Multi-factor Authentication for Third-party Services
ISM-1680 · ASD ISM
Use Multi-Factor Authentication for Online Services
ISM-1681 · ASD ISM
Mandating Multi-Factor Authentication for Customer Services
ISM-1682 · ASD ISM
Enhance User Security with Phishing-resistant MFA
ISM-1683 · ASD ISM
Central Logging of Multi-factor Authentication Events
ISM-1685 · ASD ISM
Strengthening Passwords for Critical Accounts
ISM-1686 · ASD ISM
Enable Credential Guard for Credential Protection
ISM-1687 · ASD ISM
Prevent Virtualisation of Privileged Environments
ISM-1688 · ASD ISM
Restrict Privileged Environment Access
ISM-1689 · ASD ISM
Restrict Privileged Accounts Access to Non-Privileged Environments
ISM-1690 · ASD ISM
Timely Application of Non-Critical Vulnerability Patches
ISM-1691 · ASD ISM
Timely Vulnerability Patching in Software Tools
ISM-1692 · ASD ISM
Quick Apply Critical Patches for Vulnerabilities
ISM-1693 · ASD ISM
Timely Application of Patches to Mitigate Vulnerabilities
ISM-1694 · ASD ISM
Timely Application of Non-Critical Security Patches
ISM-1695 · ASD ISM
Timely Application of System Security Patches
ISM-1696 · ASD ISM
Apply Critical Patches Within 48 Hours
ISM-1697 · ASD ISM
Apply Non-Critical Patches Within One Month
ISM-1698 · ASD ISM
Daily Vulnerability Scanning for Missing Updates
ISM-1699 · ASD ISM
Weekly Vulnerability Scanning for Software Updates
ISM-1700 · ASD ISM
Regular Vulnerability Scanning for Applications
ISM-1701 · ASD ISM
Daily Vulnerability Scanning for Internet-Facing Systems
ISM-1702 · ASD ISM
Regularly Scan for Missing Security Patches
ISM-1703 · ASD ISM
Regular Vulnerability Scanning for Missing Patches
ISM-1704 · ASD ISM
Remove Unsupported Software to Ensure Security
ISM-1705 · ASD ISM
Restrict Access to User Account Backups
ISM-1706 · ASD ISM
Prevent Backup Access by Privileged Users
ISM-1707 · ASD ISM
Restrict Backup Modifications by Privileged Users
ISM-1708 · ASD ISM
Prevent Backup Modifications During Retention
ISM-1710 · ASD ISM
Secure Default Settings for Wireless Access Points
ISM-1711 · ASD ISM
Ensure User Identity Confidentiality in EAP-TLS
ISM-1712 · ASD ISM
Ensure Secure Authenticator Communication for Wireless FT
ISM-1713 · ASD ISM
Develop and Maintain a Removable Media Register
ISM-1717 · ASD ISM
Implement Security.txt for Vulnerability Disclosure
ISM-1718 · ASD ISM
Colour Code for SECRET Cables
ISM-1719 · ASD ISM
Colour Code for TOP SECRET Cables
ISM-1720 · ASD ISM
Colour Coding for Secret Wall Outlet Boxes
ISM-1721 · ASD ISM
Red Colour Coding for TOP SECRET Outlet Boxes
ISM-1722 · ASD ISM
Methods for Destroying Electrostatic Memory Devices
ISM-1723 · ASD ISM
Methods for Destroying Magnetic Floppy Disks
ISM-1724 · ASD ISM
Methods for Destroying Magnetic Hard Disks
ISM-1725 · ASD ISM
Methods for Destroying Magnetic Tapes
ISM-1726 · ASD ISM
Methods for Destructing Optical Disks
ISM-1727 · ASD ISM
Methods for Destroying Semiconductor Memory
ISM-1728 · ASD ISM
Handling Media Waste Based on Particle Size
ISM-1729 · ASD ISM
Storage Classification of Media Waste Particles
ISM-1730 · ASD ISM
Provide a Software Bill of Materials to Consumers
ISM-1731 · ASD ISM
Coordinate Intrusion Remediation on Separate Systems
ISM-1732 · ASD ISM
Coordinated Intrusion Remediation During Planned Outages
ISM-1735 · ASD ISM
Destroy Unsanitised Media Before Disposal
ISM-1736 · ASD ISM
Maintain and Verify Managed Service Register
ISM-1737 · ASD ISM
Maintain a Comprehensive Managed Service Register
ISM-1738 · ASD ISM
Verify Compliance with Security Requirements
ISM-1739 · ASD ISM
Approve Security Architecture Before System Development
ISM-1740 · ASD ISM
Manage and Report Business Email Compromise
ISM-1741 · ASD ISM
Implement IT Equipment Destruction Procedures
ISM-1742 · ASD ISM
Destroy Un-sanitizable IT Equipment Safely
ISM-1743 · ASD ISM
Choose Secure Operating System Vendors
ISM-1745 · ASD ISM
Enable Security Features for System Protection
ISM-1746 · ASD ISM
Restrict File System Permission Changes
ISM-1748 · ASD ISM
Prevent Changes to Email Client Security Settings
ISM-1749 · ASD ISM
Limit Cached Credentials to Single Logon
ISM-1750 · ASD ISM
Segregation of Administrative Infrastructure for Server Security
ISM-1751 · ASD ISM
Timely Application of Vendor Patches for Non-Critical OS Vulnerabilities
ISM-1752 · ASD ISM
Fortnightly Vulnerability Scanning for Non-Workstations
ISM-1753 · ASD ISM
Replace Unsupported Internet-Facing Devices
ISM-1754 · ASD ISM
Timely Resolution of Identified Software Vulnerabilities
ISM-1755 · ASD ISM
Develop and Maintain a Vulnerability Disclosure Policy
ISM-1756 · ASD ISM
Develop and Maintain Vulnerability Disclosure Processes
ISM-1759 · ASD ISM
Ensure Strong Encryption with Diffie-Hellman
ISM-1761 · ASD ISM
Use NIST Curves for ECDH Encryption
ISM-1762 · ASD ISM
Use NIST P-384 Curve for ECDH Keys
ISM-1763 · ASD ISM
Use NIST P-384 Curve for ECDSA Signatures
ISM-1764 · ASD ISM
Use NIST P-384 Curve for ECDSA Signatures
ISM-1765 · ASD ISM
Use RSA with 3072-bit Modulus for Security
ISM-1766 · ASD ISM
Ensure Secure Hashing with SHA-2 Algorithm
ISM-1767 · ASD ISM
Use SHA-2 with Minimum 256-bit Output
ISM-1768 · ASD ISM
Use Appropriate SHA-2 Output Size for Hashing
ISM-1769 · ASD ISM
Using AES Encryption with Strong Key Lengths
ISM-1770 · ASD ISM
Utilise Strong AES Encryption Algorithms
ISM-1771 · ASD ISM
Use AES Encryption for IPsec Connections
ISM-1772 · ASD ISM
Use Secure Pseudorandom Functions for IPsec Connections
ISM-1773 · ASD ISM
Eligibility Criteria for Gateway System Administrators
ISM-1774 · ASD ISM
Secure Management Paths for Network Gateways
ISM-1778 · ASD ISM
Quarantine Security-Noncompliant Data for Review
ISM-1779 · ASD ISM
Quarantine Data Failing Security Checks During Manual Export
ISM-1780 · ASD ISM
Apply SecDevOps for Secure Software Development
ISM-1781 · ASD ISM
Encrypt Network Data with ASD-Approved Cryptography
ISM-1782 · ASD ISM
Use Protective DNS to Block Malicious Domains
ISM-1783 · ASD ISM
Secure BGP with Valid ROA for IP Addresses
ISM-1784 · ASD ISM
Annual Testing of Cyber Incident Response Plan
ISM-1785 · ASD ISM
Develop and Maintain Supplier Management Policy
ISM-1786 · ASD ISM
Maintain an Approved Supplier List
ISM-1787 · ASD ISM
Ensure Suppliers are Approved for IT and OT Sourcing
ISM-1788 · ASD ISM
Identify Multiple Suppliers for Critical IT Sourcing
ISM-1789 · ASD ISM
Verify Authenticity for Delivery Acceptance in Supply Chain
ISM-1790 · ASD ISM
Ensure Integrity in IT and OT Deliveries
ISM-1791 · ASD ISM
Assess Integrity of Delivered IT and OT Products
ISM-1792 · ASD ISM
Assess Authenticity of IT and OT Deliveries
ISM-1793 · ASD ISM
Regular Assessment of Managed Service Providers
ISM-1794 · ASD ISM
Notify Significant Changes to Service Provider Agreements
ISM-1795 · ASD ISM
Set 30-Character Minimum for Key Administrator Passwords
ISM-1796 · ASD ISM
Digitally Sign Executable Software for Security
ISM-1797 · ASD ISM
Ensure Software Updates are Securely Signed
ISM-1798 · ASD ISM
Develop Secure Configuration Guidelines for Software
ISM-1799 · ASD ISM
Enforce Email Rejection for Failed DMARC Checks
ISM-1800 · ASD ISM
Ensure Network Devices Have Trusted Firmware
ISM-1801 · ASD ISM
Monthly Restart of Network Devices
ISM-1802 · ASD ISM
Operate Approved High Assurance Cryptographic Equipment
ISM-1803 · ASD ISM
Document and Report Cyber Security Incidents
ISM-1804 · ASD ISM
Include Break Clauses in Cloud Service Contracts
ISM-1805 · ASD ISM
Develop a Denial of Service Response Plan
ISM-1806 · ASD ISM
Change Default User Credentials During Setup
ISM-1807 · ASD ISM
Automated Asset Discovery for Vulnerability Scanning
ISM-1808 · ASD ISM
Vulnerability Scanning with Updated Tools
ISM-1809 · ASD ISM
Implement Compensating Controls for Unsupported Systems
ISM-1810 · ASD ISM
Ensuring Data Backup Synchronisation
ISM-1811 · ASD ISM
Secure and Resilient Data Backup Retention
ISM-1812 · ASD ISM
Restrict Backup Access to Unprivileged Users
ISM-1813 · ASD ISM
Prevent Unauthorised User Access to Backup Data
ISM-1814 · ASD ISM
Prevent Backup Modifications by Unprivileged Users
ISM-1815 · ASD ISM
Protect Event Logs from Unauthorised Access
ISM-1816 · ASD ISM
Prevent Unauthorised Changes to Software Sources
ISM-1817 · ASD ISM
Secure API Access with Authentication and Authorisation
ISM-1818 · ASD ISM
Client Authentication for Network API Access
ISM-1819 · ASD ISM
Enact Cyber Security Incident Response Plans
ISM-1820 · ASD ISM
Ensure Consistent Cable Colours for Systems
ISM-1821 · ASD ISM
Ensuring Exclusive Bundling for TOP SECRET Cables
ISM-1822 · ASD ISM
Standardised Colour for Wall Outlet Boxes
ISM-1823 · ASD ISM
Prevent Users from Changing Security Settings in Apps
ISM-1824 · ASD ISM
Prevent Changes to PDF Application Security Settings
ISM-1825 · ASD ISM
Ensure Security Configuration Is Immutable by Users
ISM-1826 · ASD ISM
Select Vendors Committed to Secure Design for Servers
ISM-1827 · ASD ISM
Use Dedicated Admin Accounts for Domain Controllers
ISM-1828 · ASD ISM
Disable Print Spooler on AD DS Domain Controllers
ISM-1829 · ASD ISM
Prevent Password Storage in Group Policy Preferences
ISM-1830 · ASD ISM
Central Logging for Microsoft AD Server Activities
ISM-1832 · ASD ISM
SPN Configuration for Active Directory Accounts
ISM-1833 · ASD ISM
Limit Privileges for User Accounts in Active Directory
ISM-1834 · ASD ISM
Ensure No Duplicate SPNs in Active Directory
ISM-1835 · ASD ISM
Restrict Delegation of Privileged Active Directory Accounts
ISM-1836 · ASD ISM
Require Kerberos Pre-Authentication for User Accounts
ISM-1837 · ASD ISM
Ensure User Passwords Expire and Are Required
ISM-1838 · ASD ISM
Restrict UserPassword Attribute in AD Accounts
ISM-1839 · ASD ISM
Secure Account Properties in Active Directory
ISM-1840 · ASD ISM
Prevent Reversible Encryption of User Passwords
ISM-1841 · ASD ISM
Restrict Domain Joining to Admin Users Only
ISM-1842 · ASD ISM
Use Privileged Accounts for Domain Machine Addition
ISM-1843 · ASD ISM
Annual Review of Unconstrained Delegation in AD Accounts
ISM-1844 · ASD ISM
Prevent Non-Controller Accounts from Delegating Services
ISM-1845 · ASD ISM
Disable User Security Group Access in Active Directory
ISM-1846 · ASD ISM
Restrict Pre-Windows 2000 Access Group Membership
ISM-1847 · ASD ISM
Reset KRBTGT Account Password Twice After Compromise or Yearly
ISM-1848 · ASD ISM
Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
ISM-1849 · ASD ISM
Implement OWASP Top 10 in Web Development
ISM-1850 · ASD ISM
Mitigate OWASP Top 10 in Web Applications
ISM-1851 · ASD ISM
Secure Development Using OWASP API Security Top 10
ISM-1852 · ASD ISM
Limit Unprivileged Access to Essential Functions
ISM-1854 · ASD ISM
Require User Authentication for Multifunction Devices
ISM-1855 · ASD ISM
Central Logging of Multifunction Device Use
ISM-1858 · ASD ISM
Implement Strict IT Equipment Hardening Guidelines
ISM-1859 · ASD ISM
Hardening Office Productivity Suites
ISM-1860 · ASD ISM
Harden PDF Applications Using ASD Guidance
ISM-1861 · ASD ISM
Enable Local Security Authority Protection
ISM-1862 · ASD ISM
Restrict Access and Conceal Web Server IP Addresses
ISM-1863 · ASD ISM
Restrict Exposure of Network Management Interfaces
ISM-1864 · ASD ISM
Develop and Enforce a System Usage Policy
ISM-1865 · ASD ISM
Compliance with System Usage Policies for Access
ISM-1866 · ASD ISM
Prevent Storing Classified Data on Privately Owned Devices
ISM-1867 · ASD ISM
Use Approved Mobile Platforms for Sensitive Access
ISM-1868 · ASD ISM
Restrictions on Mobile Device Removable Media
ISM-1869 · ASD ISM
Maintain Non-Networked IT Equipment Register
ISM-1870 · ASD ISM
Implement Application Control for User Profiles and Folders
ISM-1871 · ASD ISM
Implement Application Control Exclusions for System Areas
ISM-1872 · ASD ISM
Ensuring Phishing-Resistant Multi-Factor Authentication
ISM-1873 · ASD ISM
Enhance Security with Phishing-Resistant MFA
ISM-1874 · ASD ISM
Phishing-Resistant Multi-Factor Authentication for Customers
ISM-1875 · ASD ISM
Monthly Network Scans for Clear-Text Credentials
ISM-1876 · ASD ISM
Apply Critical Patches Within 48 Hours
ISM-1877 · ASD ISM
Timely Application of Critical Security Patches
ISM-1878 · ASD ISM
Apply Critical Patches Within 48 Hours
ISM-1879 · ASD ISM
Timely Patching of Critical Driver Vulnerabilities
ISM-1880 · ASD ISM
Timely Reporting of Cyber Incidents Involving Customer Data
ISM-1881 · ASD ISM
Timely Reporting of Cyber Incidents Without Data Breach
ISM-1882 · ASD ISM
Procurement from Transparent Suppliers
ISM-1883 · ASD ISM
Restrict Privileged Access to Necessary Service Duties
ISM-1884 · ASD ISM
Ensure Compliance with Emanation Security Doctrine
ISM-1885 · ASD ISM
Implement Emanation Security Measures for Systems
ISM-1886 · ASD ISM
Ensure Mobile Devices Operate in Supervised Mode
ISM-1887 · ASD ISM
Implement Remote Locate and Wipe for Mobile Security
ISM-1888 · ASD ISM
Ensure Mobile Devices Have Secure Lock Screens
ISM-1889 · ASD ISM
Central Logging of Command Line Events
ISM-1890 · ASD ISM
Ensure Macros Are Free of Malicious Code
ISM-1891 · ASD ISM
Restrict Non-V3 Signed Macros in Microsoft Office
ISM-1892 · ASD ISM
Implement Multi-factor Authentication for Customer Services
ISM-1893 · ASD ISM
Enforcing Multi-Factor Authentication for User Security
ISM-1894 · ASD ISM
Ensuring Phishing-Resistant Multi-factor Authentication
ISM-1895 · ASD ISM
Log Single-factor Authentication Events
ISM-1896 · ASD ISM
Enable Memory Integrity for Credential Protection
ISM-1897 · ASD ISM
Enable Remote Credential Guard for Credential Protection
ISM-1898 · ASD ISM
Use Secure Admin Workstations for Administration
ISM-1899 · ASD ISM
Restrict Unauthorised Network Connections
ISM-1900 · ASD ISM
Fortnightly System Vulnerability Scanning
ISM-1901 · ASD ISM
Timely Application of Non-Critical Security Patches
ISM-1902 · ASD ISM
Apply Non-Critical Patches to Non-Internet Systems Promptly
ISM-1903 · ASD ISM
Rapid Application of Critical Firmware Patches
ISM-1904 · ASD ISM
Apply Firmware Patches for Non-Critical Vulnerabilities
ISM-1905 · ASD ISM
Disclosure of Software Vulnerabilities Responsibly
ISM-1906 · ASD ISM
Timely Analysis of Internet-Facing Server Logs
ISM-1907 · ASD ISM
Timely Analysis of Non-Internet-Server Logs
ISM-1908 · ASD ISM
Responsible Disclosure of Software Vulnerabilities
ISM-1909 · ASD ISM
Perform Root Cause Analysis for Vulnerabilities
ISM-1910 · ASD ISM
Log Network API Calls for Data Protection
ISM-1911 · ASD ISM
Centralised Logging of Software Errors and Usage
ISM-1912 · ASD ISM
Document Device Settings for Critical and High-Value Servers
ISM-1913 · ASD ISM
Develop and Maintain Approved IT Configurations
ISM-1914 · ASD ISM
Ensure Operating Systems Have Approved Configurations
ISM-1915 · ASD ISM
Ensure User Application Configurations are Approved
ISM-1916 · ASD ISM
Ensure Server Application Configurations Are Approved
ISM-1917 · ASD ISM
Support Post-Quantum Cryptographic Algorithms by 2030
ISM-1918 · ASD ISM
Regular Cyber Security Reporting to Audit Committee
ISM-1919 · ASD ISM
Disable Non-MFA Authentication Protocols
ISM-1920 · ASD ISM
Prevent Self-enrollment on Untrusted Devices
ISM-1921 · ASD ISM
Assess System Compromise Risks Often
ISM-1922 · ASD ISM
Use OWASP Standards in Mobile App Development
ISM-1924 · ASD ISM
Detect and Mitigate Adversarial Prompts in Generative AI Applications
ISM-1926 · ASD ISM
Ensure Exclusive Usage of Microsoft AD Servers
ISM-1927 · ASD ISM
Restrict Access to Microsoft Active Directory Servers
ISM-1928 · ASD ISM
Encrypt Backups of Microsoft AD Servers
ISM-1929 · ASD ISM
Ensure LDAP Signing on AD DS Domain Controllers
ISM-1930 · ASD ISM
Prevent Storing Passwords in Group Policy Preferences
ISM-1931 · ASD ISM
Ensure SID Filtering for Domain and Forest Trusts
ISM-1932 · ASD ISM
Limit Service Accounts with SPNs in Active Directory
ISM-1933 · ASD ISM
Restrict DCSync Permissions on Service Accounts
ISM-1934 · ASD ISM
Annual Review of DCSync Permissions
ISM-1935 · ASD ISM
Prevent Unconstrained Delegation in Domain Services
ISM-1936 · ASD ISM
Prevent Usage of sIDHistory in User Accounts
ISM-1937 · ASD ISM
Weekly Audit of sIDHistory in User Accounts
ISM-1938 · ASD ISM
Restrict Domain Computers Group in Active Directory
ISM-1939 · ASD ISM
Minimise Members in Privileged Security Groups
ISM-1940 · ASD ISM
Restrict Service Accounts from Privileged Groups
ISM-1941 · ASD ISM
Restrict Computer Accounts in Privileged Security Groups
ISM-1942 · ASD ISM
Domain Computers Group Privilege Restriction
ISM-1943 · ASD ISM
Enforce Certificate and User Mapping in AD Services
ISM-1944 · ASD ISM
Configuration Changes in Active Directory Certificate Services
ISM-1945 · ASD ISM
Remove Enrollee Supplies Subject Flag from Templates
ISM-1946 · ASD ISM
Restrict Write Access to Certificate Templates
ISM-1947 · ASD ISM
Remove User Authentication from Extended Key Usages
ISM-1948 · ASD ISM
Approval for Certificate Template SANs in AD Services
ISM-1949 · ASD ISM
Use Dedicated Accounts for AD FS Administration
ISM-1950 · ASD ISM
Disable Soft Matching After Synchronisation
ISM-1951 · ASD ISM
Disable Hard Match Takeover in Microsoft Entra Connect
ISM-1952 · ASD ISM
Prevent Synchronisation of Privileged Accounts
ISM-1953 · ASD ISM
Ensure Strong Management of Admin Account Credentials
ISM-1954 · ASD ISM
Enforce Random Credentials for Administrator Accounts
ISM-1955 · ASD ISM
Regularly Change Compromised Credentials
ISM-1956 · ASD ISM
Regularly Update AD FS Certificates to Prevent Risks
ISM-1957 · ASD ISM
Ensure CA Servers Use Hardware Security Modules
ISM-1958 · ASD ISM
Prevent Unauthorised Access for DCSync Accounts
ISM-1959 · ASD ISM
Ensure Consistent Formatting for Event Logs
ISM-1960 · ASD ISM
Timely Analysis of Event Logs for Cybersecurity
ISM-1961 · ASD ISM
Timely Analysis of Network Device Event Logs
ISM-1962 · ASD ISM
Disable SMBv1 Protocol on Networks
ISM-1963 · ASD ISM
Central Logging of Events on Internet-Facing Devices
ISM-1964 · ASD ISM
Central Logging for Network Device Events
ISM-1965 · ASD ISM
Content Checking for Imported or Exported Files
ISM-1966 · ASD ISM
CISO Manages and Verifies System Register
ISM-1967 · ASD ISM
Ensure Security Assessment of TOP SECRET Systems
ISM-1968 · ASD ISM
Obtain Authorisation for TOP SECRET Systems
ISM-1969 · ASD ISM
Preventing Accidental Execution of Malicious Code
ISM-1970 · ASD ISM
Segregated Environment for Malicious Code Analysis
ISM-1971 · ASD ISM
Security Assessments for TOP SECRET Managed Services
ISM-1972 · ASD ISM
Security Assessments for Top Secret Cloud Services
ISM-1973 · ASD ISM
Secure Facilities for Non-Classified Systems
ISM-1974 · ASD ISM
Securing Non-Classified IT Equipment in Secure Rooms
ISM-1975 · ASD ISM
Secure Non-Classified Equipment in Safe Containers
ISM-1976 · ASD ISM
Central Logging of Security Events on macOS
ISM-1977 · ASD ISM
Central Logging of Linux System Events
ISM-1978 · ASD ISM
Centralised Logging for Server Application Events
ISM-1979 · ASD ISM
Central Logging for Security Events on Servers
ISM-1980 · ASD ISM
Avoid Using Credential Hints in Systems
ISM-1981 · ASD ISM
Replace Unsupportable Non-Internet Network Devices
ISM-1982 · ASD ISM
Replace Unsupported Networked IT Equipment
ISM-1983 · ASD ISM
Log Events Sent to Centralised Facility Quickly
ISM-1984 · ASD ISM
Encrypt Event Logs in Transit Using ASD Cryptography
ISM-1985 · ASD ISM
Protect Event Logs from Unauthorised Access
ISM-1986 · ASD ISM
Timely Analysis of Critical Server Event Logs
ISM-1987 · ASD ISM
Timely Analysis of Security Event Logs
ISM-1988 · ASD ISM
Ensure Event Logs Are Retained for 12 Months
ISM-1989 · ASD ISM
Ensure Event Logs Meet Retention Requirements
ISM-1990 · ASD ISM
Enforcing Separation of Mobile Apps and Data
ISM-1991 · ASD ISM
Implement ML-DSA for Enhanced Digital Signature Security
ISM-1992 · ASD ISM
Using Hedged Variant of ML-DSA for Digital Signatures
ISM-1993 · ASD ISM
Use Pre-Hashed ML-DSA Variants Only When Necessary
ISM-1994 · ASD ISM
Use Correct Hashing for ML-DSA Pre-hashed Variants
ISM-1995 · ASD ISM
Use ML-KEM for Secure Key Encapsulation
ISM-1996 · ASD ISM
Using Hybrid Schemes for Secure Encryption
ISM-1997 · ASD ISM
Define Cyber Security Roles for Leadership
ISM-1998 · ASD ISM
Integrate Cyber Security Across Business Functions
ISM-1999 · ASD ISM
Align Cyber Security with Business Strategy
ISM-2000 · ASD ISM
Regular Cyber Security Briefings for Executives
ISM-2001 · ASD ISM
Championing Cyber Security at an Executive Level
ISM-2002 · ASD ISM
Ensure Board Cyber Security Literacy for Compliance
ISM-2003 · ASD ISM
Monitor Cyber Security Workforce and Skill Gaps
ISM-2004 · ASD ISM
Enhancing Cyber Security Skills and Experience
ISM-2005 · ASD ISM
Understanding Business Criticality of Organisation Systems
ISM-2006 · ASD ISM
Board Plans for Major Cyber Security Incidents
ISM-2007 · ASD ISM
Authorised Medical Device Register for SECRET and TOP SECRET Areas
ISM-2008 · ASD ISM
Criteria for Medical Devices in SECRET and TOP SECRET Areas
ISM-2009 · ASD ISM
Secure Network API Client Authentication and Authorisation
ISM-2010 · ASD ISM
Ensure SPNs Use Strong Encryption in AD Services
ISM-2011 · ASD ISM
Restrict MFA Options to Phishing-resistant Only
ISM-2012 · ASD ISM
Ensure Secure Screen Locking on Systems
ISM-2013 · ASD ISM
Ensure Client Authentication for Internal Network APIs
ISM-2014 · ASD ISM
Ensure API Client Authentication and Authorisation
ISM-2015 · ASD ISM
Central Logging of Non-Internet Network API Data Access
ISM-2016 · ASD ISM
Ensure Input Validation and Sanitisation for Security
ISM-2017 · ASD ISM
Encrypt DNS Traffic Between Clients and Servers
ISM-2018 · ASD ISM
Secure BGP Routing with RPKI-Registered IP Addresses
ISM-2019 · ASD ISM
Routine Security Assessments for TOP SECRET Gateways
ISM-2020 · ASD ISM
Ensure Adequate Cyber Security Personnel Are Acquired
ISM-2021 · ASD ISM
Implement and Maintain Data Minimisation Practices
ISM-2022 · ASD ISM
Develop and Maintain Cyber Security Training Register
ISM-2023 · ASD ISM
Maintain a Reliable Source for Software
ISM-2024 · ASD ISM
Utilise Authoritative Sources in Software Development
ISM-2025 · ASD ISM
Using Issue Tracking for Software Development Tasks
ISM-2026 · ASD ISM
Scan Software Artefacts for Malicious Content
ISM-2027 · ASD ISM
Verify Software Artefacts with Digital Signatures
ISM-2028 · ASD ISM
Test Software Artefacts for Security Weaknesses
ISM-2029 · ASD ISM
Restrict Third-Party Libraries to Trustworthy Sources
ISM-2030 · ASD ISM
Prevent Storing Secrets in Software Repositories
ISM-2031 · ASD ISM
Secure System Build Tools Implementation
ISM-2032 · ASD ISM
Ensure Automated Tests Are Completed Before Building
ISM-2033 · ASD ISM
Document and Maintain Software Security Requirements
ISM-2034 · ASD ISM
Document and Review Security Design in Development
ISM-2035 · ASD ISM
Document Security Roles for Software Development
ISM-2036 · ASD ISM
Document Security Duties for Software Developers
ISM-2037 · ASD ISM
Train Software Developers Lacking Cyber Security Skills
ISM-2038 · ASD ISM
Maintain Developer Cyber Security Skills Register
ISM-2039 · ASD ISM
Review Threat Model During Software Development
ISM-2040 · ASD ISM
Ensure Secure Programming Practices in Software Development
ISM-2041 · ASD ISM
Ensure Use of Memory-Safe Programming Practices
ISM-2042 · ASD ISM
Ensuring Security in Software Development Lifecycle
ISM-2043 · ASD ISM
Ensuring Readable and Maintainable Software Architecture
ISM-2044 · ASD ISM
Prevent Default Credentials in Software Installations
ISM-2045 · ASD ISM
Ensure Backwards Compatibility Doesn't Weaken Security
ISM-2046 · ASD ISM
Ensure Secure Impersonation Logging Practices
ISM-2047 · ASD ISM
Notify Users of Authentication Resets via Secondary Channel
ISM-2048 · ASD ISM
Restrict Non-Admins from Changing Permissions
ISM-2049 · ASD ISM
Enforcing Re-authentication After Permission Changes
ISM-2050 · ASD ISM
Validate Digital Signature Certificates Securely
ISM-2051 · ASD ISM
Ensure Event Logs for Cybersecurity Event Detection
ISM-2052 · ASD ISM
Ensure Event Logs Protect Sensitive Data
ISM-2053 · ASD ISM
End of Life Procedures for Software
ISM-2054 · ASD ISM
Ensure No Vulnerabilities in Third-Party Software Components
ISM-2055 · ASD ISM
Ensure Software Components Meet Build Standards
ISM-2056 · ASD ISM
Provide Provenance for Software Builds
ISM-2057 · ASD ISM
Document, Build and Test All Input Validation Rules
ISM-2058 · ASD ISM
Ensure Data Validation Before Deserialisation
ISM-2059 · ASD ISM
Restrict and Scan File Uploads for Security
ISM-2060 · ASD ISM
Ensure Code Reviews for Secure Software Design
ISM-2061 · ASD ISM
Peer Reviews of Critical and Security-Related Software Components
ISM-2062 · ASD ISM
Unit and Integration Testing for Code Quality
ISM-2063 · ASD ISM
Ensure Web App Cookies Have Security Flags
ISM-2064 · ASD ISM
Ensure Secure Cookies with Signed Bearer Tokens
ISM-2065 · ASD ISM
Ensure Secure Session Cookies with High Entropy Tokens
ISM-2066 · ASD ISM
Centralised Management of Web Application Sessions
ISM-2067 · ASD ISM
Ensure Single Logout for Single Sign-On Web Applications
ISM-2068 · ASD ISM
Restrict Internet Access for Networked Devices
ISM-2069 · ASD ISM
Maintain Register of Authorised Recording Devices in SECRET and TOP SECRET Areas
ISM-2070 · ASD ISM
Control Access to Recording Devices in Secure Areas
ISM-2071 · ASD ISM
Training on Managing Social Engineering Threats
ISM-2072 · ASD ISM
Store AI Models In A Non-Executable File Format
ISM-2073 · ASD ISM
Develop a Post-Quantum Cryptography Transition Plan
ISM-2074 · ASD ISM
Develop and Maintain AI Usage Policy
ISM-2075 · ASD ISM
Prohibit the Use of Fax Machines for Messages
ISM-2076 · ASD ISM
Eliminating Security Questions for Authentication
ISM-2077 · ASD ISM
Avoid Email for Out-of-Band Authentication
ISM-2078 · ASD ISM
Ensure Passwords Are Not Common or Compromised
ISM-2079 · ASD ISM
Ensure Password Length is at Least 64 Characters
ISM-2080 · ASD ISM
No Password Complexity Requirements Enforced
ISM-2081 · ASD ISM
Enforce Use of All ASCII Characters in Passwords
ISM-2082 · ASD ISM
Using Cryptographic BOM in Software Development
ISM-2083 · ASD ISM
Provide a Cryptographic Bill of Materials to Software Users
ISM-2084 · ASD ISM
Document AI Model and System Characteristics
ISM-2085 · ASD ISM
Prevent Exposure of AI Model Confidence Scores
ISM-2086 · ASD ISM
Verify Integrity of AI Models, Structures, and Weights
ISM-2087 · ASD ISM
Verify the Source and Integrity of AI Training Data
ISM-2088 · ASD ISM
Ensure Accuracy of AI Model Training Data
ISM-2089 · ASD ISM
Monitor AI Model Performance and Investigate Anomalies
ISM-2090 · ASD ISM
Rate Limiting for AI Inference Queries
ISM-2091 · ASD ISM
Enforce Resource Limits for AI Models
ISM-2092 · ASD ISM
Enforce Fine-Grained Permissions for AI Applications
ISM-2093 · ASD ISM
Role-Based Access Controls in AI Applications
ISM-2094 · ASD ISM
AI Content Filtering to Block Sensitive Data Exposure
ISM-2095 · ASD ISM
Block Personal Devices Granting AI Agents Access to Sensitive Systems
ISM-2096 · ASD ISM
Separate Organisational and Personal Mobile Data
ISM-2097 · ASD ISM
Configure Mobile Devices with Always On VPN
ISM-2098 · ASD ISM
Prevent Data Transfer Over USB on Mobile Devices
ISM-2099 · ASD ISM
Prevent Connection of Mobile Devices to Infotainment
ISM-2100 · ASD ISM
Do Not View Classified Data on Mobile Devices
ISM-2101 · ASD ISM
Restrict Sensitive Conversations Near Vehicles
ISM-2102 · ASD ISM
Periodically Test Software Artefacts for Weaknesses
ISM-2103 · ASD ISM
AI Data Use Requires Explicit Owner Consent
ISM-2104 · ASD ISM
Do Not Post Security Clearance and Briefing Details Online
ISM-2105 · ASD ISM
Advise Staff to Limit Posting Work Information on Unauthorised Online Services
ISM-2106 · ASD ISM
Advise Staff to Limit Posting Work Skills Online
ISM-2107 · ASD ISM
Restrict Personal Information Viewing Online
ISM-2108 · ASD ISM
Mobile Apps Encrypt Sensitive Data Using ASD-Approved Cryptography
ISM-2109 · ASD ISM
Pre-Boot Authentication for Encrypted System Volume Media
ISM-2110 · ASD ISM
Hardening User Applications with ASD and Vendor Guidance
ISM-2111 · ASD ISM
Remove Temporary Installation Files Post-Installation
ISM-2112 · ASD ISM
Disable AI Applications' Direct Access to External Public Data Sources
ISM-2113 · ASD ISM
AI Applications Flag Risky Actions for Approval
ISM-2114 · ASD ISM
Monitor Baselines for AI Application Performance
ISM-2115 · ASD ISM
Restrict Server Application Extensions to an Approved Set
ISM-2116 · ASD ISM
Use Cyber Threat Intelligence for Event Detection
ISM-2117 · ASD ISM
AI Models Augment Cyber Security Event Detection
ISM-2118 · ASD ISM
Conduct Vulnerability Assessments and Penetration Tests Annually
ISM-2119 · ASD ISM
Utilise AI Models in Vulnerability Assessments
ISM-2120 · ASD ISM
Develop and Maintain Secure Software Policy
ISM-2121 · ASD ISM
Prevent Using Developers Without Cyber Security Skills
ISM-2122 · ASD ISM
Use Suitable AI Models to Augment Software Security Testing
ISM-2123 · ASD ISM
Delete AI Chat Session Prompts and Outputs