Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1034Deploy HIPS or EDR on Critical and High-Value Servers

Official control statement

A HIPS or EDR solution is implemented on critical servers and high-value servers.
policyASD Information Security Manual (ISM)ISM-1034

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

A host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution is deployed on all critical and high-value servers.

NCOSPASD Information Security ManualGuidelines for system hardening
record_voice_over

What this means in practice

This control ensures your most important servers run software that continuously watches for malicious activity and can stop or respond to it. A HIPS or EDR solution sits on each critical and high-value server, detecting suspicious behaviour and giving your team the visibility to investigate and contain threats quickly. Because these servers hold sensitive data or run essential services, catching an attack early greatly limits the damage it can cause.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2025

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Host-based intrusion detection and response solution

priority_high

Why it matters

Without HIPS or EDR on critical and high-value servers, malicious activity can run undetected on your most important systems, letting attackers persist, escalate, and cause serious damage before anyone responds.

settings

Operational notes

Regularly review the management console's coverage reports to confirm every critical and high-value server still has a healthy, reporting HIPS or EDR agent.

build

Implementation tips

  • Identify and document which servers are critical or high-value so administrators know exactly where a HIPS or EDR solution must be installed.
  • Select a HIPS or EDR product that supports your server operating systems and deploy its agent to every critical and high-value server.
  • Configure the solution to run in a prevention or active-response mode rather than detection-only, so it can block or contain malicious activity.
  • Forward HIPS and EDR alerts to your central logging or SIEM platform so the security team can triage detections promptly.
  • Establish a maintenance routine that keeps agents and detection content updated and verifies coverage whenever new critical or high-value servers are commissioned.
fact_check

Audit / evidence tips

  • AskAsk for the list of critical and high-value servers alongside evidence of HIPS or EDR coverage on each one.Look atThe asset inventory cross-referenced against the HIPS or EDR management console's list of protected endpoints.GoodEvery server classified as critical or high-value appears as an active, reporting agent with no coverage gaps.
  • AskAsk how the solution is configured to respond when a threat is detected.Look atThe product's policy settings showing prevention or automated response actions rather than passive logging only.GoodPolicies enable blocking or automated response on critical and high-value servers, with any exceptions justified and documented.
  • AskAsk to see recent detections and how they were handled.Look atThe alert or case history in the console and any associated incident tickets.GoodDetections are triaged and actioned within defined timeframes, with clear records of investigation and resolution.
  • AskAsk how agent health and detection content currency are maintained.Look atConsole reports on agent version, last check-in time, and definition or engine update status.GoodAgents are current, checking in regularly, and stale or offline agents are followed up and remediated.
  • AskAsk how newly built critical or high-value servers are brought into scope.Look atThe server build or commissioning process and recent change records.GoodHIPS or EDR deployment is a mandatory build step, so new critical and high-value servers are protected before go-live.
link

Cross-framework mappings

How ISM-1034 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.7ISM-1034 requires a host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution on critical servers a...
handshakeSupports(1)expand_less
Annex A 8.16ISM-1034 requires a HIPS or EDR solution on critical servers and high-value servers

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls