Skip to content
arrow_back
search
ISM-2019 policy ASD Information Security Manual (ISM)

Routine Security Assessments for TOP SECRET Gateways

TOP SECRET gateways are reviewed for security by authorised assessors every two years.

record_voice_over

Plain language

Every two years, a special expert comes in to check the security of our systems that protect the most sensitive information on our network. It’s like a regular health check-up for our security, to make sure that we are protected against the latest threats. If we skip this, we risk leaving ourselves open to cyber attacks that could expose our most secret information, possibly harming the whole organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the assessment (or a subsequent release), at least every 24 months.
policy ASD Information Security Manual (ISM) ISM-2019
priority_high

Why it matters

Without ASD-led security assessments at least every 24 months, TOP SECRET gateways can drift from ISM requirements, leaving critical weaknesses unremediated.

settings

Operational notes

Maintain a 24‑month assessment calendar for each TOP SECRET gateway, book ASD assessors (or delegates) early, and baseline testing against the latest ISM release.

Mapping detail

Mapping

Direction

Controls