Skip to content
arrow_back
search
ISM-1793 policy ASD Information Security Manual (ISM)

Regular Assessment of Managed Service Providers

Managed service providers must be assessed for security compliance every 24 months.

record_voice_over

Plain language

Managed service providers should have their security measures checked at least every two years to ensure they protect your data properly. If this isn't done, your confidential information might be at risk, leading to things like data breaches or operational disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
policy ASD Information Security Manual (ISM) ISM-1793
priority_high

Why it matters

Without a 24‑monthly IRAP assessment against the latest ISM, MSP services may drift from ISM requirements, increasing risk of data compromise.

settings

Operational notes

Book IRAP assessments for each MSP-managed service at least every 24 months and require assessors to use the latest ISM release available before assessment start.

Mapping detail

Mapping

Direction

Controls