Skip to content
arrow_back
ISM-1607policyASD Information Security Manual (ISM)

Integrity Monitoring and Logging for Isolation Mechanism

Ensure shared resources have integrity monitoring and logging for safety and transparency.

record_voice_over

Plain language

This control is about making sure that any software acting as a security barrier on shared resources is being watched and recorded. If this isn't done, someone might tamper with your software and you wouldn't even know, leading to data breaches or system failures.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.
policyASD Information Security Manual (ISM)ISM-1607
priority_high

Why it matters

If integrity monitoring isn't in place, systems might be tampered with to exploit weaknesses unnoticed, risking data theft or loss of trust.

settings

Operational notes

Ensure monitoring and logging processes are consistently maintained to quickly identify and respond to any suspicious activities or anomalies.

build

Implementation tips

  • The IT team should set up monitoring software to keep an eye on systems that use virtual resources. This involves choosing a tool that logs any changes or unusual activities and makes alerts to notify staff.
  • System owners should work with IT professionals to define clear roles for who responds to alerts. They need to train staff so they know what to do when something looks suspicious.
  • Managers should ensure regular checks of the logs by assigning someone on their team to review them weekly. Use a simple checklist to spot patterns suggesting the isolation mechanism has been compromised.
  • IT staff should develop a clear plan to regularly update and test the monitoring tools. This ensures the tools remain effective at spotting potential threats.
  • Organisation leaders should make sure there is a policy to log all access attempts. This involves writing a guideline that everyone must follow, capturing who accessed the systems and what they did.
fact_check

Audit / evidence tips

  • Askthe list of monitoring tools being used: Check the list includes details on what each tool does and when it was last updatedGoodincludes named tools, dates of updates, and how they are configured
  • Asktraining logs for staff who handle alertsLook atthe dates and content of this training to ensure it's recent and relevantGoodshows recent sessions covering how to handle specific threats or alerts
  • Goodshows comprehensive logs with patterns or suspicions being raised
  • Askevidence of regular log reviewsLook atrecords or reports showing reviews are happening on scheduleGoodincludes review records showing issues identified and resolved
  • Askthe policy document on integrity monitoring: Ensure it includes a clear outline of procedures for monitoring and responsesGoodshows a well-documented policy with executive approval and regular updates
link

Cross-framework mappings

How ISM-1607 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.16ISM-1607 focuses on integrity monitoring and centralised logging for server hardware shared via software isolation

E8

ControlNotesDetails
sync_altPartially overlaps(3)expand_less
E8-RA-ML2.6ISM-1607 mandates integrity monitoring and centralised event logging for isolation mechanisms and host OS on shared servers
E8-RA-ML2.9ISM-1607 requires integrity monitoring and centralised event logging for shared server hardware using software isolation
E8-AH-ML2.12E8-AH-ML2.12 requires centralised logging of command line process creation events on hosts
extensionDepends on(1)expand_less
E8-MF-ML2.7ISM-1607 requires monitoring and central logging for shared servers using software isolation

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls