Skip to content
arrow_back
search
ISM-2023 policy ASD Information Security Manual (ISM)

Maintain a Reliable Source for Software

Ensure a trustworthy source for software is available and maintained consistently.

record_voice_over

Plain language

This control is about making sure your organisation gets software from a reliable and trusted place. It's important because using dodgy software sources can lead to installing harmful programs, resulting in data breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 May 2026

E8 maturity levels

N/A

Official control statement

An authoritative source for software is established and maintained.
policy ASD Information Security Manual (ISM) ISM-2023
priority_high

Why it matters

Using untrusted software sources could introduce malware, risking data breaches, operational disruptions, and financial loss.

settings

Operational notes

Maintain an approved software repository/vendor list; require signature/hash verification and restrict installs to these sources.

build

Implementation tips

  • The IT team should identify and document trusted sources for all software used in the organisation. This means listing vendors and websites where software is approved to be downloaded from, and making sure this list is easily accessible.
  • Procurement teams need to include checking the authorised software source list in their purchasing process. Before buying new software, they should verify it comes from one of the approved sources to prevent introducing unsafe software.
  • Managers should regularly review and update the list of trusted software sources. They can set up quarterly check-ins with the IT team to make sure the list reflects any changes in software vendors or business needs.
  • The IT team must educate staff on the importance of only using software from trusted sources. This can be done by running short training sessions explaining the risks of using unauthorised software and how to access the approved list.
  • System owners should set up alerts or controls that notify them if software is attempted to be installed from an unapproved source. This can ensure quick action is taken to prevent a potential security incident.
fact_check

Audit / evidence tips

  • AskThe list of approved software sources: Request to see the document or system that lists where software can be safely obtained. Look to ensure it's comprehensive and up-to-date GoodIs a detailed list with the date of the last review and who performed it
  • AskProcurement process records: Request documentation showing how software purchases are vetted against the approved sources list GoodIncludes records of checks and approvals for recent software acquisitions
  • AskStaff training materials: Request to see the content used to educate staff about using authorised software sources GoodIs easy-to-understand training resources used in the last 12 months
  • AskChange logs or alerts from IT systems: Request alert logs that show attempted installations from unapproved sources GoodShows timely interventions and follow-ups
  • AskManagement review records: Request minutes from meetings where software source lists were reviewed GoodShows regular reviews with actionable outcomes
link

Cross-framework mappings

How ISM-2023 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

Control Notes Details
sync_alt Partially overlaps (1) expand_less
Annex A 8.19 Annex A 8.19 requires organisations to implement controlled, secure procedures for installing software on operational systems
handshake Supports (2) expand_less
Annex A 5.21 ISM-2023 requires an organisation to establish and maintain an authoritative, trusted source for obtaining software
Annex A 8.18 Annex A 8.18 requires tight control over tools and utilities that can override system and application controls, including controlling how...

E8

Control Notes Details
handshake Supports (1) expand_less
E8-AC-ML1.1 ISM-2023 requires an organisation to establish and maintain an authoritative, trusted source for obtaining software

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

Mapping detail

Mapping

Direction

Controls