Integrity Monitoring and Logging for Isolation Mechanism
Ensure shared resources have integrity monitoring and logging for safety and transparency.
Plain language
This control is about making sure that any software acting as a security barrier on shared resources is being watched and recorded. If this isn't done, someone might tamper with your software and you wouldn't even know, leading to data breaches or system failures.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Virtualisation HardeningOfficial control statement
When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.
Why it matters
If integrity monitoring isn't in place, systems might be tampered with to exploit weaknesses unnoticed, risking data theft or loss of trust.
Operational notes
Ensure monitoring and logging processes are consistently maintained to quickly identify and respond to any suspicious activities or anomalies.
Implementation tips
- The IT team should set up monitoring software to keep an eye on systems that use virtual resources. This involves choosing a tool that logs any changes or unusual activities and makes alerts to notify staff.
- System owners should work with IT professionals to define clear roles for who responds to alerts. They need to train staff so they know what to do when something looks suspicious.
- Managers should ensure regular checks of the logs by assigning someone on their team to review them weekly. Use a simple checklist to spot patterns suggesting the isolation mechanism has been compromised.
- IT staff should develop a clear plan to regularly update and test the monitoring tools. This ensures the tools remain effective at spotting potential threats.
- Organisation leaders should make sure there is a policy to log all access attempts. This involves writing a guideline that everyone must follow, capturing who accessed the systems and what they did.
Audit / evidence tips
- Askthe list of monitoring tools being used: Check the list includes details on what each tool does and when it was last updatedGoodincludes named tools, dates of updates, and how they are configured
- Asktraining logs for staff who handle alertsLook atthe dates and content of this training to ensure it's recent and relevantGoodshows recent sessions covering how to handle specific threats or alerts
- Goodshows comprehensive logs with patterns or suspicions being raised
- Askevidence of regular log reviewsLook atrecords or reports showing reviews are happening on scheduleGoodincludes review records showing issues identified and resolved
- Askthe policy document on integrity monitoring: Ensure it includes a clear outline of procedures for monitoring and responsesGoodshows a well-documented policy with executive approval and regular updates
Cross-framework mappings
How ISM-1607 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.16 | ISM-1607 focuses on integrity monitoring and centralised logging for server hardware shared via software isolation | |
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(3)expand_less | ||
| E8-RA-ML2.6 | ISM-1607 mandates integrity monitoring and centralised event logging for isolation mechanisms and host OS on shared servers | |
| E8-RA-ML2.9 | ISM-1607 requires integrity monitoring and centralised event logging for shared server hardware using software isolation | |
| E8-AH-ML2.12 | E8-AH-ML2.12 requires centralised logging of command line process creation events on hosts | |
extensionDepends on(1)expand_less | ||
| E8-MF-ML2.7 | ISM-1607 requires monitoring and central logging for shared servers using software isolation | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.