Guidelines for system access
123 controls in this part of the ASD ISM. Each control links to plain-English guidance, audit tips and cross-framework mappings.
Credential management
ISM-0418
Keep Physical Credentials Separate from Systems
ISM-0421
Require Minimum 15-Character Passwords for Security
ISM-0422
Ensuring Strong Passwords for TOP SECRET Systems
ISM-1227
Randomly Generate User Account Credentials
ISM-1402
Protecting Stored Credentials with Security Measures
ISM-1557
Ensure Strong Passwords for SECRET Systems
ISM-1558
Ensure Secure Construction of Passwords
ISM-1559
Minimum Password Length for Secure Systems
ISM-1560
Ensure Strong Passwords for SECRET System Authentication
ISM-1561
Ensure Strong Passwords for TOP SECRET Systems
ISM-1590
Changing User Account Credentials After Compromise, Exposure or Shared Membership Change
ISM-1593
Verify User Identity Before Issuing, Resetting, Disabling or Enrolling Credentials
ISM-1594
Delivering User Credentials via Secure Channel or Split Parts
ISM-1595
Credentials Issued to Human Users Are Changed on First Use
ISM-1596
Avoid Reusing Credentials Across Systems
ISM-1597
Ensuring Credential Input Obscurity
ISM-1619
Configure Service Accounts as Managed Service Accounts
ISM-1685
Strengthening Passwords for Critical Accounts
ISM-1686
Enable Credential Guard for Credential Protection
ISM-1749
Limit Cached Credentials to Single Logon
ISM-1795
Set 30-Character Minimum for Key Administrator Passwords
ISM-1847
Double KRBTGT Password Reset After Compromise or Six Months
ISM-1861
Enable Local Security Authority Protection
ISM-1875
Monthly System Scans to Detect Credentials Stored in the Clear
ISM-1897
Enable Remote Credential Guard for Credential Protection
ISM-1953
Ensure Strong Management of Admin Account Credentials
ISM-1954
Enforce Random Credentials for Administrator Accounts
ISM-1955
Regularly Change Compromised Credentials
ISM-1956
Regularly Update AD FS Certificates to Prevent Risks
ISM-1957
Hardware Security Module Protection for Microsoft AD CS Private Keys
ISM-1980
Avoid Using Credential Hints in Systems
ISM-2078
Ensure Passwords Are Not Common or Compromised
ISM-2079
Ensure Password Length is at Least 64 Characters
ISM-2080
No Password Complexity Requirements Enforced
ISM-2081
Enforce Use of All ASCII Characters in Passwords
ISM-2141
Prefer Short-Lived Dynamically Issued Credentials for Applications and Workloads
ISM-2142
Central Management of Application and Workload Credentials
ISM-2143
Unique Per-Application Credentials Not Shared Across Environments
ISM-2144
Change Application Static Credentials Found Compromised or Exposed in Clear
ISM-2145
Revoke User Account Credentials When No Longer Required
ISM-2146
Revoking Static Application and Workload Credentials When No Longer Required
ISM-2147
Cryptographically Bind Tokens and Session Cookies to Issuing Device
ISM-2148
Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In
Identity and access management
ISM-0078
Australian Supervision of AUSTEO/AGAO Data Systems
ISM-0405
Validation for Unprivileged System Access Requests
ISM-0407
Maintaining a Secure Lifetime Access Record for Each Human User
ISM-0408
Logon Banner for Security Responsibilities
ISM-0409
Restricting Foreign National Access to AUSTEO and REL Systems
ISM-0411
Restricting Foreign National Access to Systems Handling AGAO Data
ISM-0414
Uniquely Identifying Every User Granted System Access
ISM-0415
Strictly Controlling Shared Accounts and Identifying Their Users
ISM-0417
Use Passwords When Multi-Factor Authentication Isn't Supported
ISM-0420
Identify Nationality of Foreign Personnel in System
ISM-0428
Session Lock Timing, Content Blocking and Full Re-Authentication for Services
ISM-0430
Same-Day Removal or Suspension of Access No Longer Required
ISM-0432
Document System Access Requirements in Security Plans
ISM-0434
Ensure Personnel Employment Screening and Security Clearance
ISM-0435
Pre-Access Briefings for System Resources
ISM-0441
Restricting Temporary System Access to Data Required for Duties
ISM-0443
Restrict Temporary Access to Secure Systems
ISM-0445
Dedicated Privileged Accounts Used Solely for Privileged Duties
ISM-0446
Restrict Privileged Access for Foreign Nationals
ISM-0447
Restrict Privileged Access for Foreign Nationals
ISM-0853
Terminate Interactive User Sessions and Restart Workstations at Least Daily
ISM-0854
Access Restrictions for AUSTEO and AGAO Data
ISM-0974
Multi-Factor Authentication for Unprivileged Human Users of Systems
ISM-1055
Disable Insecure LAN Manager Authentication
ISM-1173
Multi-Factor Authentication for Privileged Human Users of Systems
ISM-1175
Restrict Privileged Users from Internet Access
ISM-1263
Enforce Unique Accounts for Server Administration
ISM-1401
Multi-Factor Authentication Combines Possession With Knowledge or Inherence
ISM-1403
Lock Accounts After Five Failed Logon Attempts
ISM-1404
Disabling Inactive User Access After 45 Days
ISM-1504
Multi-Factor Authentication for Human Users of Sensitive Data Online Services
ISM-1505
Multi-factor Authentication for Human Users of Data Repositories
ISM-1507
Ensure Requests for Privileged Access are Verified
ISM-1508
Restricting Privileged Access to What Duties Require
ISM-1509
Log Privileged Access Events Centrally for Monitoring
ISM-1546
Ensure User Authentication Before System Access
ISM-1566
Central Logging of Unprivileged System Access
ISM-1583
Ensure Contractors are Identified as Users
ISM-1591
Remove or Suspend Access When Users Are Detected Acting Maliciously
ISM-1603
Disabling Vulnerable Authentication Methods
ISM-1610
Document and Test Emergency System Access Procedures
ISM-1611
Use Break Glass Accounts Only in Emergencies
ISM-1612
Restricted Use of Break Glass Accounts for Emergencies
ISM-1613
Central Logging of Break Glass Account Usage
ISM-1614
Manage Emergency Account Access Changes
ISM-1615
Testing Break Glass Accounts Post Credential Change
ISM-1647
Disable Privileged Access After 12 Months
ISM-1648
Disabling Inactive Privileged Access to Systems
ISM-1649
Implement Just-in-Time Administration for System Access
ISM-1650
Log Management of Privileged User Activities
ISM-1679
Multi-factor Authentication for Third-party Services Handling Sensitive Data
ISM-1680
Multi-Factor Authentication for Human Users of Third-Party Services Holding Non-Sensitive Data
ISM-1681
Mandating Multi-Factor Authentication for Customer Services
ISM-1682
Phishing-resistant multi-factor authentication for human users of systems
ISM-1683
Central Logging of Multi-factor Authentication Events
ISM-1852
Limit Unprivileged Access to What Duties Require
ISM-1864
Develop and Enforce a System Usage Policy
ISM-1865
Compliance with System Usage Policies for Access
ISM-1872
Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services
ISM-1873
Enhance Security with Phishing-Resistant MFA
ISM-1874
Phishing-Resistant Multi-Factor Authentication for Customers
ISM-1883
Limit Authorised Privileged Account Online Service Access to Duties
ISM-1892
Multi-Factor Authentication for Organisation Users of Online Customer Services
ISM-1893
Multi-Factor Authentication for Third-Party Services Holding Sensitive Customer Data
ISM-1894
Phishing-Resistant Multi-Factor Authentication for Human Users of Data Repositories
ISM-1895
Log Single-factor Authentication Events
ISM-1919
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
ISM-1920
Blocking MFA Self-Enrolment From Untrustworthy Devices
ISM-2011
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
ISM-2012
Enforced Screen Lock With Full Re-Authentication After Inactivity
ISM-2076
Eliminating Security Questions for Authentication
ISM-2077
Avoid Email for Out-of-Band Authentication
ISM-2133
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
ISM-2134
Develop, Maintain and Regularly Verify an AI Agent Register
ISM-2135
Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent
ISM-2136
Enforcing Risk-Based Access Decisions Informed by Contextual Signals
ISM-2137
Block User OAuth Consent, Reserve It for Authorised Administrators
ISM-2138
Six-Monthly Review of OAuth Application Consents and Granted Permissions
ISM-2139
Central Logging of Third-Party OAuth Consent, Token Issuance and Use
ISM-2140
Disable OAuth Device Code Flow Unless Required and Restrict Its Use
Back to the full Australian Government Information Security Manual control list, or browse the complete control library.