Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1034Deploy HIPS or EDR on Critical and High-Value Servers

A host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution is deployed on all critical and high-value servers.

record_voice_over

Plain language

This control ensures your most important servers run software that continuously watches for malicious activity and can stop or respond to it. A HIPS or EDR solution sits on each critical and high-value server, detecting suspicious behaviour and giving your team the visibility to investigate and contain threats quickly. Because these servers hold sensitive data or run essential services, catching an attack early greatly limits the damage it can cause.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2025

Control Stack last updated

10 Aug 2026

E8 maturity levels

N/A

Official control statement

A HIPS or EDR solution is implemented on critical servers and high-value servers.
policyASD Information Security Manual (ISM)ISM-1034
priority_high

Why it matters

Without HIPS or EDR on critical and high-value servers, malicious activity can run undetected on your most important systems, letting attackers persist, escalate, and cause serious damage before anyone responds.

settings

Operational notes

Regularly review the management console's coverage reports to confirm every critical and high-value server still has a healthy, reporting HIPS or EDR agent.

build

Implementation tips

  • Identify and document which servers are critical or high-value so administrators know exactly where a HIPS or EDR solution must be installed.
  • Select a HIPS or EDR product that supports your server operating systems and deploy its agent to every critical and high-value server.
  • Configure the solution to run in a prevention or active-response mode rather than detection-only, so it can block or contain malicious activity.
  • Forward HIPS and EDR alerts to your central logging or SIEM platform so the security team can triage detections promptly.
  • Establish a maintenance routine that keeps agents and detection content updated and verifies coverage whenever new critical or high-value servers are commissioned.
fact_check

Audit / evidence tips

  • AskAsk for the list of critical and high-value servers alongside evidence of HIPS or EDR coverage on each one.GoodEvery server classified as critical or high-value appears as an active, reporting agent with no coverage gaps.
  • AskAsk how the solution is configured to respond when a threat is detected.GoodPolicies enable blocking or automated response on critical and high-value servers, with any exceptions justified and documented.
  • AskAsk to see recent detections and how they were handled.GoodDetections are triaged and actioned within defined timeframes, with clear records of investigation and resolution.
  • AskAsk how agent health and detection content currency are maintained.GoodAgents are current, checking in regularly, and stale or offline agents are followed up and remediated.
  • AskAsk how newly built critical or high-value servers are brought into scope.GoodHIPS or EDR deployment is a mandatory build step, so new critical and high-value servers are protected before go-live.
link

Cross-framework mappings

How ISM-1034 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 8.5ISM-1034 requires organisations to disable legacy authentication methods on networks to prevent access via insecure paths
Annex A 8.9ISM-1034 mandates disabling legacy authentication methods to secure network services

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls