ASD ISM 1034Deploy HIPS or EDR on Critical and High-Value Servers
Official control statement
A HIPS or EDR solution is implemented on critical servers and high-value servers.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
A host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution is deployed on all critical and high-value servers.
What this means in practice
This control ensures your most important servers run software that continuously watches for malicious activity and can stop or respond to it. A HIPS or EDR solution sits on each critical and high-value server, detecting suspicious behaviour and giving your team the visibility to investigate and contain threats quickly. Because these servers hold sensitive data or run essential services, catching an attack early greatly limits the damage it can cause.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2025
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Operating system hardeningTopic
Host-based intrusion detection and response solution
Why it matters
Without HIPS or EDR on critical and high-value servers, malicious activity can run undetected on your most important systems, letting attackers persist, escalate, and cause serious damage before anyone responds.
Operational notes
Regularly review the management console's coverage reports to confirm every critical and high-value server still has a healthy, reporting HIPS or EDR agent.
Implementation tips
- Identify and document which servers are critical or high-value so administrators know exactly where a HIPS or EDR solution must be installed.
- Select a HIPS or EDR product that supports your server operating systems and deploy its agent to every critical and high-value server.
- Configure the solution to run in a prevention or active-response mode rather than detection-only, so it can block or contain malicious activity.
- Forward HIPS and EDR alerts to your central logging or SIEM platform so the security team can triage detections promptly.
- Establish a maintenance routine that keeps agents and detection content updated and verifies coverage whenever new critical or high-value servers are commissioned.
Audit / evidence tips
- AskAsk for the list of critical and high-value servers alongside evidence of HIPS or EDR coverage on each one.Look atThe asset inventory cross-referenced against the HIPS or EDR management console's list of protected endpoints.GoodEvery server classified as critical or high-value appears as an active, reporting agent with no coverage gaps.
- AskAsk how the solution is configured to respond when a threat is detected.Look atThe product's policy settings showing prevention or automated response actions rather than passive logging only.GoodPolicies enable blocking or automated response on critical and high-value servers, with any exceptions justified and documented.
- AskAsk to see recent detections and how they were handled.Look atThe alert or case history in the console and any associated incident tickets.GoodDetections are triaged and actioned within defined timeframes, with clear records of investigation and resolution.
- AskAsk how agent health and detection content currency are maintained.Look atConsole reports on agent version, last check-in time, and definition or engine update status.GoodAgents are current, checking in regularly, and stale or offline agents are followed up and remediated.
- AskAsk how newly built critical or high-value servers are brought into scope.Look atThe server build or commissioning process and recent change records.GoodHIPS or EDR deployment is a mandatory build step, so new critical and high-value servers are protected before go-live.
Cross-framework mappings
How ISM-1034 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.7 | ISM-1034 requires a host-based intrusion prevention system (HIPS) or endpoint detection and response (EDR) solution on critical servers a... | |
handshakeSupports(1)expand_less | ||
| Annex A 8.16 | ISM-1034 requires a HIPS or EDR solution on critical servers and high-value servers | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.