ASD ISM 1034Deploy HIPS or EDR on Critical and High-Value Servers
A host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution is deployed on all critical and high-value servers.
Plain language
This control ensures your most important servers run software that continuously watches for malicious activity and can stop or respond to it. A HIPS or EDR solution sits on each critical and high-value server, detecting suspicious behaviour and giving your team the visibility to investigate and contain threats quickly. Because these servers hold sensitive data or run essential services, catching an attack early greatly limits the damage it can cause.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2025
Control Stack last updated
10 Aug 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Operating system hardeningOfficial control statement
A HIPS or EDR solution is implemented on critical servers and high-value servers.
Why it matters
Without HIPS or EDR on critical and high-value servers, malicious activity can run undetected on your most important systems, letting attackers persist, escalate, and cause serious damage before anyone responds.
Operational notes
Regularly review the management console's coverage reports to confirm every critical and high-value server still has a healthy, reporting HIPS or EDR agent.
Implementation tips
- Identify and document which servers are critical or high-value so administrators know exactly where a HIPS or EDR solution must be installed.
- Select a HIPS or EDR product that supports your server operating systems and deploy its agent to every critical and high-value server.
- Configure the solution to run in a prevention or active-response mode rather than detection-only, so it can block or contain malicious activity.
- Forward HIPS and EDR alerts to your central logging or SIEM platform so the security team can triage detections promptly.
- Establish a maintenance routine that keeps agents and detection content updated and verifies coverage whenever new critical or high-value servers are commissioned.
Audit / evidence tips
- AskAsk for the list of critical and high-value servers alongside evidence of HIPS or EDR coverage on each one.GoodEvery server classified as critical or high-value appears as an active, reporting agent with no coverage gaps.
- AskAsk how the solution is configured to respond when a threat is detected.GoodPolicies enable blocking or automated response on critical and high-value servers, with any exceptions justified and documented.
- AskAsk to see recent detections and how they were handled.GoodDetections are triaged and actioned within defined timeframes, with clear records of investigation and resolution.
- AskAsk how agent health and detection content currency are maintained.GoodAgents are current, checking in regularly, and stale or offline agents are followed up and remediated.
- AskAsk how newly built critical or high-value servers are brought into scope.GoodHIPS or EDR deployment is a mandatory build step, so new critical and high-value servers are protected before go-live.
Cross-framework mappings
How ISM-1034 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 8.5 | ISM-1034 requires organisations to disable legacy authentication methods on networks to prevent access via insecure paths | |
| Annex A 8.9 | ISM-1034 mandates disabling legacy authentication methods to secure network services | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.