Skip to content
arrow_back

swap_horizFree crosswalk tool

Essential Eight to ASD ISM

Every Essential Eight requirement, across all maturity levels, with the ASD ISM controls that implement the same mitigation. Both frameworks come from ASD, so the relationships here are unusually direct.

149 of the 149 Essential Eight controls (100%) have at least one ASD ISM counterpart, giving 1,452 control-to-control relationships across 364 distinct ASD ISM controls. Coverage runs one way: nearly every Essential Eight requirement has ISM controls behind it, while most of the ISM sits outside the Essential Eight entirely.

These relationships are generated from the Control Stack catalogue and reviewed for topic fidelity, then labelled with how the two controls relate rather than asserted as equivalent. Where no counterpart exists, the row says so plainly instead of stretching for a match. Some rows are read from the other framework’s own mappings, so the wording of those summaries leads with that side.

Control Stack is a free Australian reference covering 1,423 cyber security controls: all 1,143 ASD ISM controls, 149 Essential Eight controls across all four maturity levels, all 93 ISO/IEC 27001:2022 Annex A controls and all 38 ISO/IEC 42001:2023 Annex A controls. Every one of them is cross-mapped between the four frameworks and readable in full without an account.

Reviewed 16 September 2026 · Maps the ASD Essential Eight Maturity Model to the September 2026 ASD ISM

Essential Eight to ASD ISM

Essential Eight controlGroupASD ISM counterparts
E8-AC-ML1.1
Application control is implemented on workstations.
Application control
  • ISM-0843Equivalent
    Ensure Workstation Security with Application Control
  • ISM-0846Supports
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-0955Supports
    Implementing Application Control Measures
  • ISM-1235Partially overlaps
    Restrict User Application Extensions
  • ISM-1490Partially overlaps
    Implement Application Control on Internet-Facing Servers
  • ISM-1491Partially overlaps
    Block Unprivileged Users From Running Script Execution Engines
  • ISM-1493Supports
    Maintain and Verify Software Registers
  • ISM-1544Supports
    Implement Microsoft's Application Blocklist
  • ISM-1656Partially overlaps
    Implement Application Control on Secure Servers
  • ISM-1657Partially meets
    Restrict Application Execution to Approved Set
  • ISM-1658Broader than
    Restrict Execution of Drivers via Application Control
  • ISM-2023Supports
    Maintain a Reliable Source for Software
  • ISM-2149Depends on
    Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
E8-AC-ML1.2
Application control is applied to user profiles and temporary folders
Application control
  • ISM-0382Partially overlaps
    Restrict Unprivileged User Actions on Applications
  • ISM-0843Partially meets
    Ensure Workstation Security with Application Control
  • ISM-0846Supports
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-0955Partially overlaps
    Implementing Application Control Measures
  • ISM-1235Supports
    Restrict User Application Extensions
  • ISM-1392Supports
    Restrict File Modifications via Path Rules
  • ISM-1491Depends on
    Block Unprivileged Users From Running Script Execution Engines
  • ISM-1544Supports
    Implement Microsoft's Application Blocklist
  • ISM-1592Partially overlaps
    Prevent Unauthorised Application Installations by Users
  • ISM-1635Partially meets
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1657Partially meets
    Restrict Application Execution to Approved Set
  • ISM-1658Partially overlaps
    Restrict Execution of Drivers via Application Control
  • ISM-1746Supports
    Restrict File System Permission Changes
  • ISM-1870Equivalent
    Implement Application Control for User Profiles and Folders
  • ISM-1871Partially overlaps
    Implement Application Control Exclusions for System Areas
E8-AC-ML1.3
Ensure only approved applications and scripts can run
Application control
  • ISM-0341Partially overlaps
    Disable Automatic Execution for Removable Media
  • ISM-0843Supports
    Ensure Workstation Security with Application Control
  • ISM-0846Supports
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-0863Partially meets
    Prevent Installation of Unapproved Mobile Apps
  • ISM-0955Supports
    Implementing Application Control Measures
  • ISM-1235Partially overlaps
    Restrict User Application Extensions
  • ISM-1392Supports
    Restrict File Modifications via Path Rules
  • ISM-1471Supports
    Utilise Publisher and Product Names in App Control
  • ISM-1491Partially meets
    Prevent Script Execution by Unprivileged Users
  • ISM-1592Partially overlaps
    Prevent Unauthorised Application Installations by Users
  • ISM-1622Partially overlaps
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1657Equivalent
    Restrict Application Execution to Approved Set
  • ISM-1658Broader than
    Restrict Execution of Drivers via Application Control
  • ISM-1668Partially overlaps
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1870Depends on
    Implement Application Control for User Profiles and Folders
  • ISM-2026Depends on
    Scan Software Artefacts for Malicious Content
  • ISM-2115Partially overlaps
    Restrict Server Application Extensions to an Approved Set
  • ISM-2149Depends on
    Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
E8-AC-ML2.1
Application control is implemented on internet-facing servers
Application control
  • ISM-0955Supports
    Implementing Application Control Measures
  • ISM-1392Depends on
    Restrict File Modifications via Path Rules
  • ISM-1483Depends on
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1490Equivalent
    Implement Application Control on Internet-Facing Servers
  • ISM-1656Partially overlaps
    Implement Application Control on Secure Servers
  • ISM-1657Supports
    Restrict Application Execution to Approved Set
  • ISM-1658Supports
    Restrict Execution of Drivers via Application Control
  • ISM-1746Depends on
    Restrict File System Permission Changes
  • ISM-1871Depends on
    Implement Application Control Exclusions for System Areas
  • ISM-2115Depends on
    Restrict Server Application Extensions to an Approved Set
  • ISM-2149Depends on
    Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
E8-AC-ML2.2
Application control excludes user profiles and temporary folders
Application control
  • ISM-0843Partially meets
    Ensure Workstation Security with Application Control
  • ISM-0846Partially overlaps
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-0955Partially overlaps
    Implementing Application Control Measures
  • ISM-1234Supports
    Protect Email Systems with Content Filtering
  • ISM-1392Depends on
    Restrict File Modifications via Path Rules
  • ISM-1490Depends on
    Implement Application Control on Internet-Facing Servers
  • ISM-1544Supports
    Implement Microsoft's Application Blocklist
  • ISM-1656Depends on
    Implement Application Control on Secure Servers
  • ISM-1657Partially overlaps
    Restrict Application Execution to Approved Set
  • ISM-1746Depends on
    Restrict File System Permission Changes
  • ISM-1871Equivalent
    Implement Application Control Exclusions for System Areas
  • ISM-2115Depends on
    Restrict Server Application Extensions to an Approved Set
E8-AC-ML2.3
Microsoft's recommended application blocklist is implemented
Application control
  • ISM-0843Partially meets
    Ensure Workstation Security with Application Control
  • ISM-0955Depends on
    Implementing Application Control Measures
  • ISM-1544Equivalent
    Implement Microsoft's Application Blocklist
  • ISM-1601Partially overlaps
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1657Partially meets
    Restrict Application Execution to Approved Set
  • ISM-1659Partially overlaps
    Implement Microsoft's Vulnerable Driver Blocklist
E8-AC-ML2.4
Annual validation of application control rulesets
Application control
  • ISM-0843Supports
    Ensure Workstation Security with Application Control
  • ISM-0955Supports
    Implementing Application Control Measures
  • ISM-1471Depends on
    Utilise Publisher and Product Names in App Control
  • ISM-1582Equivalent
    Annual Validation of Application Control Rulesets
  • ISM-1657Depends on
    Restrict Application Execution to Approved Set
  • ISM-1658Depends on
    Restrict Execution of Drivers via Application Control
  • ISM-1660Depends on
    Central Logging of Application Events
  • ISM-1676Partially overlaps
    Validate Microsoft Office Trusted Publishers List At Least Annually
  • ISM-2115Depends on
    Restrict Server Application Extensions to an Approved Set
E8-AC-ML2.5
Allowed and blocked application control events are centrally logged
Application control
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0670Partially meets
    Central Logging of CDS Security Events
  • ISM-0955Depends on
    Implementing Application Control Measures
  • ISM-0988Depends on
    Ensure Accurate Time Source for Event Logs
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
  • ISM-1660Equivalent
    Central Logging of Application Events
  • ISM-1976Partially overlaps
    Central Logging of Security Events on macOS
  • ISM-1977Partially overlaps
    Central Logging of Linux System Events
  • ISM-1978Partially overlaps
    Centralised Logging for Server Application Events
  • ISM-1979Partially overlaps
    Central Logging for Security Events on Servers
  • ISM-1983Supports
    Log Events Sent to Centralised Facility Quickly
  • ISM-2129Partially overlaps
    Centrally Log WMI Activity and Event Subscriptions
E8-AC-ML2.6
Event logs are protected from unauthorised modification and deletion
Application control
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0582Supports
    Central Logging of Windows Security Events
  • ISM-0585Depends on
    Capture Detailed Information in Event Logs
  • ISM-0634Supports
    Central Logging for Gateway Security Events
  • ISM-1405Supports
    Implement a Centralised Event Logging Facility
  • ISM-1624Broader than
    Protect PowerShell Script Block Logs
  • ISM-1660Depends on
    Central Logging of Application Events
  • ISM-1815Equivalent
    Protect Event Logs from Unauthorised Access
  • ISM-1910Depends on
    Log Network API Calls for Data Protection
  • ISM-1976Partially overlaps
    Central Logging of Security Events on macOS
  • ISM-1985Partially overlaps
    Protect Event Logs from Unauthorised Access
  • ISM-1989Depends on
    Ensure Event Logs Meet Retention Requirements
  • ISM-2015Depends on
    Central Logging of Non-Internet Network API Data Access
  • ISM-2046Partially overlaps
    Ensure Secure Impersonation Logging Practices
  • ISM-2052Partially overlaps
    Ensure Event Logs Protect Sensitive Data
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AC-ML2.7
Event logs from internet-facing servers are analysed to detect cyber security events
Application control
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1906Equivalent
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1910Supports
    Log Network API Calls for Data Protection
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cyber security
  • ISM-1978Depends on
    Centralised Logging for Server Application Events
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2144Depends on
    Change Application Static Credentials Found Compromised or Exposed in Clear
E8-AC-ML2.8
Cyber security events are analysed in a timely manner
Application control
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Equivalent
    Analyse Cyber Security Events Promptly
  • ISM-1430Depends on
    Configure IPv6 Addresses with DHCPv6 in Stateful Mode
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1906Partially meets
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially meets
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Supports
    Timely Analysis of Event Logs for Cybersecurity
  • ISM-1961Broader than
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially meets
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
  • ISM-2116Depends on
    Use Cyber Threat Intelligence for Event Detection
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AC-ML2.9
Cyber security incidents are reported promptly to CISO
Application control
  • ISM-0123Equivalent
    Report Cyber Security Incidents Promptly
  • ISM-0125Depends on
    Maintaining a Cyber Security Incident Register
  • ISM-0140Partially overlaps
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0142Broader than
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0714Partially meets
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-0733Supports
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1618Supports
    CISO's Role in Cyber Security Incident Response
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
  • ISM-1819Partially overlaps
    Enact Cyber Security Incident Response Plans
E8-AC-ML2.10
Report cyber security incidents to ASD quickly
Application control
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0140Equivalent
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0142Partially overlaps
    Report Cryptographic Equipment Compromises Promptly
E8-AC-ML2.11
Cyber security incident response plan is enacted after incident identification
Application control
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0576Depends on
    Develop and Maintain Cyber Security Incident Plans
  • ISM-1731Depends on
    Plan and Coordinate Intrusion Remediation From Trusted Separate Systems
  • ISM-1819Equivalent
    Enact Cyber Security Incident Response Plans
E8-AC-ML3.1
Application control is implemented on non-internet-facing servers
Application control
  • ISM-0955Broader than
    Implementing Application Control Measures
  • ISM-1490Partially overlaps
    Implement Application Control on Internet-Facing Servers
  • ISM-1493Supports
    Maintain and Verify Software Registers
  • ISM-1544Supports
    Implement Microsoft's Application Blocklist
  • ISM-1656Equivalent
    Implement Application Control on Secure Servers
  • ISM-1657Supports
    Restrict Application Execution to Approved Set
  • ISM-1658Depends on
    Restrict Execution of Drivers via Application Control
  • ISM-1871Partially overlaps
    Implement Application Control Exclusions for System Areas
  • ISM-1926Supports
    Ensure Exclusive Usage of Microsoft AD Servers
  • ISM-2115Depends on
    Restrict Server Application Extensions to an Approved Set
E8-AC-ML3.2
Application control restricts driver execution to an approved set
Application control
  • ISM-0955Partially overlaps
    Implementing Application Control Measures
  • ISM-1392Supports
    Restrict File Modifications via Path Rules
  • ISM-1656Broader than
    Implement Application Control on Secure Servers
  • ISM-1657Partially meets
    Restrict Application Execution to Approved Set
  • ISM-1658Equivalent
    Restrict Execution of Drivers via Application Control
  • ISM-1746Supports
    Restrict File System Permission Changes
E8-AC-ML3.3
Microsoft's vulnerable driver blocklist is implemented
Application control
  • ISM-0298Partially overlaps
    Centralised System Patch and Update Management
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially overlaps
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1492Partially overlaps
    Enable Exploit Protection in Operating Systems
  • ISM-1643Supports
    Maintain Detailed Software Version and Patch Records
  • ISM-1659Equivalent
    Implement Microsoft's Vulnerable Driver Blocklist
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
E8-AC-ML3.4
Event logs from non-internet-facing servers are analysed
Application control
  • ISM-0580Depends on
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1228Broader than
    Analyse Cyber Security Events Promptly
  • ISM-1830Depends on
    Central Logging for Microsoft AD Server Activities
  • ISM-1906Partially overlaps
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Equivalent
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1911Depends on
    Centralised Logging of Software Errors and Usage
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cyber security
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-2051Depends on
    Ensure Event Logs for Cybersecurity Event Detection
  • ISM-2129Depends on
    Centrally Log WMI Activity and Event Subscriptions
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AC-ML3.5
Workstation event logs are promptly analysed for security events
Application control
  • ISM-1228Partially meets
    Analyse Cyber Security Events Promptly
  • ISM-1889Supports
    Central Logging of Command Line Events
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
  • ISM-2051Depends on
    Ensure Event Logs for Cybersecurity Event Detection
  • ISM-2125Partially overlaps
    Independently Log and Analyse All Service Provider System Access
E8-AH-ML1.1
Disable or remove Internet Explorer 11
User application hardening
  • ISM-0380Partially meets
    Disable Unneeded OS Accounts and Services
  • ISM-1470Partially meets
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1654Equivalent
    Disable or Remove Internet Explorer 11
  • ISM-1798Partially meets
    Develop Secure Configuration Guidelines for Software
  • ISM-1809Depends on
    Compensating Controls for Unsupported Systems Pending Removal or Replacement
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
  • ISM-2110Partially meets
    Hardening User Applications with ASD and Vendor Guidance
E8-AH-ML1.2
Web browsers must not execute Java content from the internet
User application hardening
  • ISM-0260Supports
    Ensure All Web Access Uses Proxies
  • ISM-0958Supports
    Implement Domain Name Allow and Block Lists
  • ISM-0961Broader than
    Restrict Active Content with Web Filters
  • ISM-0963Partially overlaps
    Implementing Web Content Filters for Safety
  • ISM-1485Partially overlaps
    Prevent Web Browsers from Processing Ads
  • ISM-1486Equivalent
    Restrict Java Processing in Web Browsers
  • ISM-1585Supports
    Prevent User Changes to Browser Security Settings
  • ISM-2110Partially meets
    Hardening User Applications with ASD and Vendor Guidance
E8-AH-ML1.3
Web browsers block web ads from the internet
User application hardening
  • ISM-0958Supports
    Implement Domain Name Allow and Block Lists
  • ISM-0963Partially meets
    Implementing Web Content Filters for Safety
  • ISM-1485Equivalent
    Prevent Web Browsers from Processing Ads
E8-AH-ML1.4
Web browser security settings locked down to users
User application hardening
  • ISM-0382Partially overlaps
    Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications
  • ISM-1235Partially overlaps
    Restrict User Application Extensions
  • ISM-1412Partially meets
    Web Browser Hardening with Strict Guidelines
  • ISM-1486Depends on
    Restrict Java Processing in Web Browsers
  • ISM-1584Depends on
    Prevent Unauthorised Changes to Security Settings
  • ISM-1585Equivalent
    Prevent User Changes to Browser Security Settings
  • ISM-1748Partially overlaps
    Lock Email Client Security Settings Against User Changes
  • ISM-1825Partially overlaps
    Lock Security Product Settings Against Changes by Human Users
E8-AH-ML2.1
Web browsers are hardened with the most restrictive guidance
User application hardening
  • ISM-0290Supports
    Secure Configuration of High Assurance IT Equipment
  • ISM-1235Partially overlaps
    Restrict User Application Extensions
  • ISM-1246Broader than
    Apply Strict Server Application Hardening Guidelines
  • ISM-1412Equivalent
    Web Browser Hardening with Strict Guidelines
  • ISM-1470Partially overlaps
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1485Partially meets
    Prevent Web Browsers from Processing Ads
  • ISM-1486Partially meets
    Restrict Java Processing in Web Browsers
  • ISM-1585Supports
    Prevent User Changes to Browser Security Settings
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
  • ISM-1858Broader than
    Implement Strict IT Equipment Hardening Guidelines
E8-AH-ML2.2
Block Microsoft Office from creating child processes
User application hardening
  • ISM-0843Partially meets
    Ensure Workstation Security with Application Control
  • ISM-0955Partially meets
    Implementing Application Control Measures
  • ISM-1542Partially overlaps
    Disable OLE in Microsoft Office for Security
  • ISM-1601Equivalent
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1667Equivalent
    Prevent Child Processes in Microsoft Office
  • ISM-1668Partially overlaps
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1669Partially overlaps
    Prevent Microsoft Office from Injecting Code
  • ISM-1670Partially overlaps
    Prevent PDF Applications from Creating Child Processes
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1859Partially meets
    Hardening Office Productivity Suites
  • ISM-2110Partially meets
    Hardening User Applications with ASD and Vendor Guidance
E8-AH-ML2.3
Block Microsoft Office from creating executable content
User application hardening
  • ISM-1542Depends on
    Disable OLE in Microsoft Office for Security
  • ISM-1667Partially overlaps
    Prevent Child Processes in Microsoft Office
  • ISM-1668Equivalent
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1669Partially overlaps
    Prevent Microsoft Office from Injecting Code
  • ISM-1672Partially overlaps
    Enable Antivirus Scanning for Office Macros
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1823Depends on
    Prevent Users from Changing Security Settings in Apps
  • ISM-1969Partially overlaps
    Preventing Accidental Execution of Malicious Code
E8-AH-ML2.4
Block Microsoft Office from injecting code into other processes
User application hardening
  • ISM-1542Supports
    Disable OLE in Microsoft Office for Security
  • ISM-1601Equivalent
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1667Partially overlaps
    Prevent Child Processes in Microsoft Office
  • ISM-1668Partially overlaps
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1669Equivalent
    Prevent Microsoft Office from Injecting Code
  • ISM-1670Partially overlaps
    Prevent PDF Applications from Creating Child Processes
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1858Broader than
    Implement Strict IT Equipment Hardening Guidelines
E8-AH-ML2.5
Configure Microsoft Office to prevent activation of OLE packages
User application hardening
  • ISM-0289Partially overlaps
    Implement and Manage Evaluated Products Correctly
  • ISM-1536Equivalent
    Centrally Log User-Initiated Database Queries and Errors
  • ISM-1542Equivalent
    Disable OLE in Microsoft Office for Security
  • ISM-1601Depends on
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1667Partially overlaps
    Prevent Child Processes in Microsoft Office
  • ISM-1668Partially overlaps
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1669Partially overlaps
    Prevent Microsoft Office from Injecting Code
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
  • ISM-1858Broader than
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1913Depends on
    Develop and Maintain Approved IT Configurations
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
  • ISM-2110Partially meets
    Hardening User Applications with ASD and Vendor Guidance
E8-AH-ML2.6
Office productivity suites are hardened using ASD and vendor guidance
User application hardening
  • ISM-0289Partially overlaps
    Implement and Manage Evaluated Products Correctly
  • ISM-0290Depends on
    Secure Configuration of High Assurance IT Equipment
  • ISM-1235Broader than
    Restrict User Application Extensions
  • ISM-1246Partially meets
    Apply Strict Server Application Hardening Guidelines
  • ISM-1668Partially meets
    Prevent Microsoft Office from Creating Executable Files
  • ISM-1798Supports
    Develop Secure Configuration Guidelines for Software
  • ISM-1823Depends on
    Lock Office Productivity Suite Security Settings Against User Changes
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1859Equivalent
    Hardening Office Productivity Suites
  • ISM-1915Partially meets
    Ensure User Application Configurations are Approved
E8-AH-ML2.7
Office productivity suite settings are immutable by users
User application hardening
  • ISM-0382Partially overlaps
    Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications
  • ISM-1489Partially overlaps
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1536Depends on
    Central Logging of Software Database Queries and Errors
  • ISM-1542Supports
    Disable OLE in Microsoft Office for Security
  • ISM-1585Partially overlaps
    Lock Web Browser Security Settings Against Human User Changes
  • ISM-1669Broader than
    Prevent Microsoft Office from Injecting Code
  • ISM-1673Supports
    Prevent Win32 API Calls by Office Macros
  • ISM-1748Partially overlaps
    Lock Email Client Security Settings Against User Changes
  • ISM-1823Equivalent
    Prevent Users from Changing Security Settings in Apps
  • ISM-1824Partially overlaps
    Lock PDF Application Security Settings Against User Changes
  • ISM-1825Partially overlaps
    Lock Security Product Settings Against Changes by Human Users
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1859Partially meets
    Hardening Office Productivity Suites
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
E8-AH-ML2.8
Block PDF software from creating child processes
User application hardening
  • ISM-0843Supports
    Ensure Workstation Security with Application Control
  • ISM-0846Supports
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-1470Broader than
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1670Equivalent
    Prevent PDF Applications from Creating Child Processes
  • ISM-1824Supports
    Prevent Changes to PDF Application Security Settings
E8-AH-ML2.9
Ensure PDF software is securely configured using guidance.
User application hardening
  • ISM-0289Partially overlaps
    Implement and Manage Evaluated Products Correctly
  • ISM-1246Partially meets
    Apply Strict Server Application Hardening Guidelines
  • ISM-1406Depends on
    Use SOEs for Workstations and Servers
  • ISM-1470Partially overlaps
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1670Supports
    Prevent PDF Applications from Creating Child Processes
  • ISM-1798Supports
    Develop Secure Configuration Guidelines for Software
  • ISM-1824Partially overlaps
    Prevent Changes to PDF Application Security Settings
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1859Partially overlaps
    Hardening Office Productivity Suites
  • ISM-1860Equivalent
    Harden PDF Applications Using ASD Guidance
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
E8-AH-ML2.10
PDF software security settings cannot be changed by users
User application hardening
  • ISM-1406Depends on
    Use SOEs for Workstations and Servers
  • ISM-1489Partially overlaps
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1585Partially overlaps
    Prevent User Changes to Browser Security Settings
  • ISM-1670Supports
    Prevent PDF Applications from Creating Child Processes
  • ISM-1748Partially overlaps
    Lock Email Client Security Settings Against User Changes
  • ISM-1823Partially overlaps
    Prevent Users from Changing Security Settings in Apps
  • ISM-1824Equivalent
    Prevent Changes to PDF Application Security Settings
  • ISM-1825Partially meets
    Lock Security Product Settings Against Changes by Human Users
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
  • ISM-2110Partially meets
    Hardening User Applications with ASD and Vendor Guidance
E8-AH-ML2.11
Centrally log PowerShell module, script block, and transcription events
User application hardening
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0582Partially overlaps
    Central Logging of Windows Security Events
  • ISM-0988Depends on
    Ensure Accurate Time Source for Event Logs
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
  • ISM-1621Depends on
    Disable or Remove Windows PowerShell 2.0
  • ISM-1622Partially overlaps
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1623Equivalent
    Centralised Logging of PowerShell Activities
  • ISM-1624Partially overlaps
    Protect PowerShell Script Block Logs
  • ISM-1889Partially overlaps
    Central Logging of Command Line Events
  • ISM-1983Depends on
    Log Events Sent to Centralised Facility Quickly
  • ISM-1989Partially overlaps
    Ensure Event Logs Meet Retention Requirements
  • ISM-2132Partially overlaps
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2159Partially overlaps
    Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
E8-AH-ML2.12
Command line process creation logging is centralised
User application hardening
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0582Supports
    Central Logging of Windows Security Events
  • ISM-0585Supports
    Capture Detailed Information in Event Logs
  • ISM-0670Partially meets
    Central Logging of CDS Security Events
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Depends on
    Analyse Cyber Security Events Promptly
  • ISM-1405Partially meets
    Implement a Centralised Event Logging Facility
  • ISM-1607Partially overlaps
    Integrity Monitoring and Logging for Isolation Mechanism
  • ISM-1623Partially overlaps
    Centralised Logging of PowerShell Activities
  • ISM-1889Equivalent
    Central Logging of Command Line Events
  • ISM-1907Supports
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1976Supports
    Central Logging of Security Events on macOS
  • ISM-1977Supports
    Central Logging of Linux System Events
  • ISM-1983Depends on
    Log Events Sent to Centralised Facility Quickly
  • ISM-1986Supports
    Timely Analysis of Critical Server Event Logs
  • ISM-2051Supports
    Ensure Event Logs for Cybersecurity Event Detection
  • ISM-2132Partially overlaps
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AH-ML2.13
Protect event logs from unauthorised changes or deletion
User application hardening
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0138Supports
    Maintaining Integrity of Evidence in Investigations
  • ISM-0582Partially overlaps
    Central Logging of Windows Security Events
  • ISM-1509Depends on
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1624Partially meets
    Protect PowerShell Script Block Logs
  • ISM-1815Equivalent
    Protect Event Logs from Unauthorised Access
  • ISM-1830Depends on
    Central Logging of Security Events for Microsoft AD Infrastructure Servers
  • ISM-1910Supports
    Log Network API Calls for Data Protection
  • ISM-1985Partially meets
    Protect Event Logs from Unauthorised Access
  • ISM-1989Supports
    Ensure Event Logs Meet Retention Requirements
  • ISM-2125Partially overlaps
    Independently Log and Analyse All Service Provider System Access
  • ISM-2132Partially overlaps
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2159Depends on
    Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
E8-AH-ML2.14
Timely Analysis of Event Logs from Internet-Facing Servers
User application hardening
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1228Partially meets
    Analyse Cyber Security Events Promptly
  • ISM-1624Supports
    Protect PowerShell Script Block Logs
  • ISM-1906Equivalent
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cybersecurity
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1963Partially overlaps
    Central Logging of Events on Internet-Facing Devices
  • ISM-1978Depends on
    Centralised Logging for Server Application Events
  • ISM-1983Depends on
    Log Events Sent to Centralised Facility Quickly
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially overlaps
    Timely Analysis of Security Event Logs
  • ISM-2051Depends on
    Ensure Event Logs for Cybersecurity Event Detection
  • ISM-2125Partially overlaps
    Independently Log and Analyse All Service Provider System Access
  • ISM-2129Depends on
    Centrally Log WMI Activity and Event Subscriptions
E8-AH-ML2.15
Timely Analysis of Cyber Security Events to Identify Incidents
User application hardening
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0634Depends on
    Central Logging for Gateway Security Events
  • ISM-0660Supports
    Monthly Verification of Data Transfer Logs for SECRET Systems
  • ISM-1030Depends on
    Deploy NIDS/NIPS for Gateway Traffic Monitoring
  • ISM-1228Equivalent
    Analyse Cyber Security Events Promptly
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1556Depends on
    Security Measures After Overseas Travel with Mobile Devices
  • ISM-1625Depends on
    Develop Insider Threat Mitigation Programs
  • ISM-1683Depends on
    Central Logging of Multi-factor Authentication Events
  • ISM-1830Depends on
    Central Logging for Microsoft AD Server Activities
  • ISM-1911Depends on
    Centralised Logging of Software Errors and Usage
  • ISM-1986Partially meets
    Timely Analysis of Critical Server Event Logs
  • ISM-2089Broader than
    Monitor AI Model Performance and Investigate Anomalies
  • ISM-2117Depends on
    AI Models Augment Cyber Security Event Detection
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AH-ML2.16
Cyber security incidents must be reported immediately to the CISO
User application hardening
  • ISM-0043Partially meets
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Equivalent
    Report Cyber Security Incidents Promptly
  • ISM-0125Supports
    Maintaining a Cyber Security Incident Register
  • ISM-0140Partially overlaps
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0141Supports
    Report Cyber Incidents Promptly to Designated Contacts
  • ISM-0142Partially overlaps
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0576Partially meets
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0714Broader than
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-0733Equivalent
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1088Partially overlaps
    Report Potential Compromises of Mobile Devices Overseas
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1618Partially overlaps
    CISO's Role in Cyber Security Incident Response
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
  • ISM-1819Partially overlaps
    Enact Cyber Security Incident Response Plans
  • ISM-1881Supports
    Timely Reporting of Cyber Incidents Without Data Breach
E8-AH-ML2.17
Report cyber security incidents to ASD promptly
User application hardening
  • ISM-0043Partially meets
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Supports
    Report Cyber Security Incidents Promptly
  • ISM-0140Equivalent
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0141Supports
    Report Cyber Incidents Promptly to Designated Contacts
E8-AH-ML2.18
Cyber incident response plan is enacted after identification
User application hardening
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Supports
    Report Cyber Security Incidents Promptly
  • ISM-0576Depends on
    Develop and Maintain Cyber Security Incident Plans
  • ISM-1618Depends on
    CISO's Role in Cyber Security Incident Response
  • ISM-1819Equivalent
    Enact Cyber Security Incident Response Plans
E8-AH-ML3.1
.NET Framework 3.5, 3.0, 2.0 is disabled or removed
User application hardening
  • ISM-1246Partially overlaps
    Apply Strict Server Application Hardening Guidelines
  • ISM-1409Partially meets
    Implement Restrictive OS Hardening Guidelines
  • ISM-1470Partially meets
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1621Partially overlaps
    Disable or Remove Windows PowerShell 2.0
  • ISM-1655Equivalent
    Ensure .NET Framework 3.5 is Disabled or Removed
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
E8-AH-ML3.2
Ensure Windows PowerShell 2.0 is disabled or removed
User application hardening
  • ISM-0380Partially meets
    Disable Unneeded OS Accounts and Services
  • ISM-1246Partially overlaps
    Apply Strict Server Application Hardening Guidelines
  • ISM-1247Partially meets
    Disable or Remove Unneeded Server Features
  • ISM-1409Partially meets
    Implement Restrictive OS Hardening Guidelines
  • ISM-1470Partially meets
    Disable Unneeded Accounts, Components, Services and Application Functionality
  • ISM-1584Depends on
    Prevent Unauthorised Changes to Security Settings
  • ISM-1621Equivalent
    Disable or Remove Windows PowerShell 2.0
  • ISM-1622Supports
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1655Partially overlaps
    Ensure .NET Framework 3.5 is Disabled or Removed
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1914Partially meets
    Ensure Operating Systems Have Approved Configurations
E8-AH-ML3.3
PowerShell is configured to use Constrained Language Mode
User application hardening
  • ISM-0380Partially meets
    Disable Unneeded OS Accounts and Services
  • ISM-1246Partially overlaps
    Apply Strict Server Application Hardening Guidelines
  • ISM-1409Partially meets
    Implement Restrictive OS Hardening Guidelines
  • ISM-1491Partially overlaps
    Block Unprivileged Users From Running Script Execution Engines
  • ISM-1621Depends on
    Disable or Remove Windows PowerShell 2.0
  • ISM-1622Equivalent
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1798Partially meets
    Develop Secure Configuration Guidelines for Software
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
E8-AH-ML3.4
Analyse event logs from non-internet-facing servers for cyber threats
User application hardening
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0988Supports
    Ensure Accurate Time Source for Event Logs
  • ISM-1228Partially meets
    Analyse Cyber Security Events Promptly
  • ISM-1907Equivalent
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1979Depends on
    Central Logging for Security Events on Servers
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-2125Partially overlaps
    Independently Log and Analyse All Service Provider System Access
  • ISM-2129Depends on
    Centrally Log WMI Activity and Event Subscriptions
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
E8-AH-ML3.5
Timely Analysis of Workstation Event Logs for Cyber security
User application hardening
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0580Depends on
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1228Broader than
    Analyse Cyber Security Events Promptly
  • ISM-1906Partially overlaps
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cyber security
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially overlaps
    Timely Analysis of Security Event Logs
  • ISM-2051Depends on
    Ensure Event Logs for Cybersecurity Event Detection
E8-MF-ML1.1
Require multi-factor authentication for sensitive online services
Multi-factor authentication
  • ISM-0553Supports
    Authenticate Video Calls and Manage Settings
  • ISM-0619Depends on
    User Authentication for Network Gateway Access
  • ISM-1401Supports
    Implement Multi-Factor Authentication for Security
  • ISM-1504Equivalent
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1505Partially overlaps
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1546Partially meets
    Ensure User Authentication Before System Access
  • ISM-1679Partially overlaps
    Multi-factor Authentication for Third-party Services Handling Sensitive Data
  • ISM-1681Partially overlaps
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1682Partially meets
    Enhance User Security with Phishing-resistant MFA
  • ISM-1872Supports
    Ensuring Phishing-Resistant Multi-Factor Authentication
  • ISM-1892Broader than
    Implement Multi-factor Authentication for Customer Services
  • ISM-1893Partially overlaps
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
E8-MF-ML1.2
Multi-factor authentication for third-party services handling sensitive data
Multi-factor authentication
  • ISM-1401Partially meets
    Implement Multi-Factor Authentication for Security
  • ISM-1504Partially overlaps
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1679Equivalent
    Multi-factor Authentication for Third-party Services Handling Sensitive Data
  • ISM-1680Partially overlaps
    Use Multi-Factor Authentication for Online Services
  • ISM-1681Partially overlaps
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1893Partially overlaps
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
E8-MF-ML1.3
Use multi-factor authentication for non-sensitive third-party services
Multi-factor authentication
  • ISM-0417Supports
    Use Passwords When Multi-Factor Authentication Isn't Supported
  • ISM-0553Supports
    Authenticate Video Calls and Manage Settings
  • ISM-1401Depends on
    Implement Multi-Factor Authentication for Security
  • ISM-1505Partially overlaps
    Multi-factor Authentication for Human Users of Data Repositories
  • ISM-1680Equivalent
    Use Multi-Factor Authentication for Online Services
  • ISM-1919Supports
    Disable Non-MFA Authentication Protocols
  • ISM-2136Depends on
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
E8-MF-ML1.4
Use multi-factor authentication for online services handling customer data
Multi-factor authentication
  • ISM-0553Depends on
    Authenticate Video Calls and Manage Settings
  • ISM-1401Partially meets
    Implement Multi-Factor Authentication for Security
  • ISM-1504Partially overlaps
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1505Partially overlaps
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1681Partially overlaps
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1682Supports
    Enhance User Security with Phishing-resistant MFA
  • ISM-1892Equivalent
    Multi-Factor Authentication for Organisation Users of Online Customer Services
  • ISM-1893Partially overlaps
    Multi-Factor Authentication for Third-Party Services Holding Sensitive Customer Data
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
E8-MF-ML1.5
Multi-factor authentication for third-party services with sensitive customer data
Multi-factor authentication
  • ISM-0974Partially overlaps
    Implement Multi-factor Authentication for User Access
  • ISM-1173Partially overlaps
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1401Depends on
    Implement Multi-Factor Authentication for Security
  • ISM-1452Supports
    Perform Supply Chain Risk Assessments for System Suppliers
  • ISM-1504Partially overlaps
    Implement Multi-factor Authentication
  • ISM-1679Equivalent
    Use Multi-factor Authentication for Third-party Services
  • ISM-1680Partially overlaps
    Use Multi-Factor Authentication for Online Services
  • ISM-1681Partially overlaps
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1682Supports
    Enhance User Security with Phishing-resistant MFA
  • ISM-1892Partially overlaps
    Implement Multi-factor Authentication for Customer Services
  • ISM-1893Equivalent
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1919Supports
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
E8-MF-ML1.6
Multi-factor authentication for customer access to online services handling sensitive data
Multi-factor authentication
  • ISM-1401Depends on
    Multi-Factor Authentication Combines Possession With Knowledge or Inherence
  • ISM-1504Partially overlaps
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1681Equivalent
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1873Supports
    Enhance Security with Phishing-Resistant MFA
  • ISM-1874Partially overlaps
    Phishing-Resistant Multi-Factor Authentication for Customers
  • ISM-1892Equivalent
    Implement Multi-factor Authentication for Customer Services
  • ISM-1893Partially overlaps
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
  • ISM-1920Partially overlaps
    Prevent Self-enrollment on Untrusted Devices
E8-MF-ML1.7
Multi-factor authentication combines two factors like a device and a PIN
Multi-factor authentication
  • ISM-0553Supports
    Authenticate Video Calls and Manage Settings
  • ISM-0974Partially meets
    Implement Multi-factor Authentication for User Access
  • ISM-1173Partially meets
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1401Equivalent
    Implement Multi-Factor Authentication for Security
  • ISM-1504Partially meets
    Implement Multi-factor Authentication
  • ISM-1505Partially meets
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1546Partially meets
    Ensure User Authentication Before System Access
  • ISM-1560Broader than
    Ensure Strong Passwords for SECRET System Authentication
  • ISM-1679Partially meets
    Use Multi-factor Authentication for Third-party Services
  • ISM-1680Partially meets
    Use Multi-Factor Authentication for Online Services
  • ISM-1681Partially meets
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1872Supports
    Ensuring Phishing-Resistant Multi-Factor Authentication
  • ISM-1893Partially meets
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
  • ISM-2011Depends on
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
E8-MF-ML2.1
Multi-factor authentication for privileged users of systems
Multi-factor authentication
  • ISM-0445Depends on
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-0553Supports
    Authenticate Video Calls and Manage Settings
  • ISM-1173Equivalent
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1401Depends on
    Multi-Factor Authentication Combines Possession With Knowledge or Inherence
  • ISM-1620Supports
    Ensure Privileged Accounts are Secured in AD
  • ISM-1816Depends on
    Prevent Unauthorised Changes to Software Sources
  • ISM-1919Supports
    Disable Non-MFA Authentication Protocols
  • ISM-1927Supports
    Restrict Access to Microsoft Active Directory Servers
E8-MF-ML2.2
Use multi-factor authentication for unprivileged user access
Multi-factor authentication
  • ISM-0553Supports
    Authenticate Video Calls and Manage Settings
  • ISM-0974Equivalent
    Implement Multi-factor Authentication for User Access
  • ISM-1401Supports
    Implement Multi-Factor Authentication for Security
  • ISM-1505Partially overlaps
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1682Partially overlaps
    Enhance User Security with Phishing-resistant MFA
  • ISM-1854Partially overlaps
    Human Users Authenticate to MFDs Before Printing, Scanning or Copying
  • ISM-1893Partially overlaps
    Enforcing Multi-Factor Authentication for User Security
  • ISM-2077Supports
    Avoid Email for Out-of-Band Authentication
E8-MF-ML2.3
Multi-factor authentication online services must be phishing-resistant
Multi-factor authentication
  • ISM-0555Partially overlaps
    Ensure Authentication for IP Telephony Actions
  • ISM-1173Partially overlaps
    Multi-Factor Authentication for Privileged Human Users of Systems
  • ISM-1401Depends on
    Multi-Factor Authentication Combines Possession With Knowledge or Inherence
  • ISM-1504Depends on
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1680Supports
    Use Multi-Factor Authentication for Online Services
  • ISM-1682Broader than
    Enhance User Security with Phishing-resistant MFA
  • ISM-1872Equivalent
    Ensuring Phishing-Resistant Multi-Factor Authentication
  • ISM-1874Partially overlaps
    Phishing-Resistant Multi-Factor Authentication for Customers
  • ISM-1892Partially overlaps
    Multi-Factor Authentication for Organisation Users of Online Customer Services
  • ISM-1893Supports
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1894Partially overlaps
    Ensuring Phishing-Resistant Multi-factor Authentication
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
  • ISM-1920Supports
    Prevent Self-enrollment on Untrusted Devices
  • ISM-2011Partially overlaps
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
  • ISM-2077Supports
    Avoid Email for Out-of-Band Authentication
E8-MF-ML2.5
Multi-factor authentication used for system access is phishing-resistant
Multi-factor authentication
  • ISM-0974Supports
    Implement Multi-factor Authentication for User Access
  • ISM-1173Partially overlaps
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1401Partially meets
    Implement Multi-Factor Authentication for Security
  • ISM-1504Depends on
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1505Partially overlaps
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1680Partially overlaps
    Use Multi-Factor Authentication for Online Services
  • ISM-1682Equivalent
    Enhance User Security with Phishing-resistant MFA
  • ISM-1872Partially overlaps
    Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services
  • ISM-1893Supports
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1894Partially overlaps
    Ensuring Phishing-Resistant Multi-factor Authentication
  • ISM-2011Depends on
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
  • ISM-2077Supports
    Avoid Email for Out-of-Band Authentication
E8-MF-ML2.6
MFA success and failure events are centrally logged
Multi-factor authentication
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0585Partially overlaps
    Capture Detailed Information in Event Logs
  • ISM-1405Partially meets
    Implement a Centralised Event Logging Facility
  • ISM-1504Depends on
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1505Depends on
    Multi-factor Authentication for Human Users of Data Repositories
  • ISM-1509Partially overlaps
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1682Depends on
    Phishing-resistant multi-factor authentication for human users of systems
  • ISM-1683Equivalent
    Central Logging of Multi-factor Authentication Events
  • ISM-1892Depends on
    Multi-Factor Authentication for Organisation Users of Online Customer Services
  • ISM-1893Depends on
    Multi-Factor Authentication for Third-Party Services Holding Sensitive Customer Data
  • ISM-1894Depends on
    Phishing-Resistant Multi-Factor Authentication for Human Users of Data Repositories
  • ISM-1895Partially overlaps
    Log Single-factor Authentication Events
  • ISM-1976Partially overlaps
    Central Logging of Security Events on macOS
  • ISM-1977Partially overlaps
    Central Logging of Linux System Events
E8-MF-ML2.7
Protect event logs from unauthorised changes
Multi-factor authentication
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1607Depends on
    Integrity Monitoring and Logging for Isolation Mechanism
  • ISM-1624Supports
    Protect PowerShell Script Block Logs
  • ISM-1815Equivalent
    Protect Event Logs from Unauthorised Access
  • ISM-1830Partially overlaps
    Central Logging for Microsoft AD Server Activities
  • ISM-1855Supports
    Central Logging of Multifunction Device Use
  • ISM-1910Depends on
    Log Network API Calls for Data Protection
  • ISM-1989Depends on
    Ensure Event Logs Meet Retention Requirements
  • ISM-2015Supports
    Central Logging of Non-Internet Network API Data Access
  • ISM-2139Depends on
    Central Logging of Third-Party OAuth Consent, Token Issuance and Use
E8-MF-ML2.8
Timely analysis of event logs from internet-facing servers
Multi-factor authentication
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0634Partially overlaps
    Central Logging for Gateway Security Events
  • ISM-0988Depends on
    Ensure Accurate Time Source for Event Logs
  • ISM-1030Partially overlaps
    Deploy NIDS/NIPS for Gateway Traffic Monitoring
  • ISM-1228Broader than
    Analyse Cyber Security Events Promptly
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
  • ISM-1906Equivalent
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1978Depends on
    Centralised Logging for Server Application Events
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
E8-MF-ML2.9
Cyber security events are analysed to identify incidents timely
Multi-factor authentication
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Equivalent
    Analyse Cyber Security Events Promptly
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1536Depends on
    Central Logging of Software Database Queries and Errors
  • ISM-1906Depends on
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially meets
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Partially meets
    Timely Analysis of Event Logs for Cyber security
  • ISM-1961Partially meets
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially meets
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
  • ISM-2089Broader than
    Monitor AI Model Performance and Investigate Anomalies
E8-MF-ML2.10
Report cyber security incidents to the Chief Information Security Officer promptly
Multi-factor authentication
  • ISM-0043Supports
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Equivalent
    Report Cyber Security Incidents Promptly
  • ISM-0140Partially overlaps
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0142Broader than
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0252Depends on
    Annual Cyber Security Awareness for Personnel
  • ISM-0733Equivalent
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
E8-MF-ML2.11
Report cyber security incidents to ASD immediately
Multi-factor authentication
  • ISM-0043Partially meets
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Partially overlaps
    Report Cyber Security Incidents Promptly
  • ISM-0140Equivalent
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0141Partially overlaps
    Report Cyber Incidents Promptly to Designated Contacts
  • ISM-0142Partially overlaps
    Report Cryptographic Equipment Compromises Promptly
  • ISM-1228Supports
    Analyse Cyber Security Events Promptly
E8-MF-ML2.12
Cyber security incident response plan enacted after incident identification
Multi-factor authentication
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Supports
    Report Cyber Security Incidents Promptly
  • ISM-0576Depends on
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0733Supports
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1019Partially meets
    Develop a Denial of Service Response Plan
  • ISM-1618Partially overlaps
    CISO's Role in Cyber Security Incident Response
  • ISM-1784Supports
    Annual Testing of Cyber Incident Response Plan
  • ISM-1805Broader than
    Develop a Denial of Service Response Plan
  • ISM-1819Equivalent
    Enact Cyber Security Incident Response Plans
E8-MF-ML3.1
Multi-factor authentication is used to authenticate users of data repositories
Multi-factor authentication
  • ISM-0974Partially overlaps
    Implement Multi-factor Authentication for User Access
  • ISM-1173Partially overlaps
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1268Depends on
    Enforce Need-to-Know Access in Databases
  • ISM-1401Supports
    Implement Multi-Factor Authentication for Security
  • ISM-1504Partially meets
    Implement Multi-factor Authentication
  • ISM-1505Equivalent
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1872Supports
    Ensuring Phishing-Resistant Multi-Factor Authentication
  • ISM-1894Supports
    Phishing-Resistant Multi-Factor Authentication for Human Users of Data Repositories
  • ISM-1919Depends on
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
  • ISM-1920Supports
    Prevent Self-enrollment on Untrusted Devices
E8-MF-ML3.2
Phishing-resistant multi-factor authentication for online customer services
Multi-factor authentication
  • ISM-1401Partially overlaps
    Implement Multi-Factor Authentication for Security
  • ISM-1546Broader than
    Ensure User Authentication Before System Access
  • ISM-1680Partially overlaps
    Use Multi-Factor Authentication for Online Services
  • ISM-1681Broader than
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1682Partially meets
    Enhance User Security with Phishing-resistant MFA
  • ISM-1872Partially meets
    Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services
  • ISM-1873Equivalent
    Enhance Security with Phishing-Resistant MFA
  • ISM-1874Equivalent
    Phishing-Resistant Multi-Factor Authentication for Customers
  • ISM-2011Depends on
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
  • ISM-2077Supports
    Avoid Email for Out-of-Band Authentication
E8-MF-ML3.3
Phishing-resistant multi-factor authentication for data repositories
Multi-factor authentication
  • ISM-1504Partially overlaps
    Implement Multi-factor Authentication
  • ISM-1505Partially meets
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1679Partially overlaps
    Multi-factor Authentication for Third-party Services Handling Sensitive Data
  • ISM-1682Partially meets
    Enhance User Security with Phishing-resistant MFA
  • ISM-1872Partially overlaps
    Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services
  • ISM-1894Equivalent
    Ensuring Phishing-Resistant Multi-factor Authentication
  • ISM-2011Supports
    Restrict MFA Options to Phishing-resistant Only
  • ISM-2077Supports
    Avoid Email for Out-of-Band Authentication
E8-MF-ML3.4
Analyse event logs from non-internet-facing servers timely to detect security events
Multi-factor authentication
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-1228Broader than
    Analyse Cyber Security Events Promptly
  • ISM-1830Depends on
    Central Logging for Microsoft AD Server Activities
  • ISM-1906Partially overlaps
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Equivalent
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1911Depends on
    Centralised Logging of Software Errors and Usage
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1979Depends on
    Central Logging for Security Events on Servers
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially overlaps
    Timely Analysis of Security Event Logs
E8-MF-ML3.5
Timely analysis of workstation event logs for cyber security events
Multi-factor authentication
  • ISM-0120Depends on
    Access to Tools for Detecting Security Events
  • ISM-0582Depends on
    Central Logging of Windows Security Events
  • ISM-1228Depends on
    Analyse Cyber Security Events Promptly
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
  • ISM-1976Depends on
    Central Logging of Security Events on macOS
  • ISM-1983Supports
    Log Events Sent to Centralised Facility Quickly
  • ISM-2051Depends on
    Ensure Event Logs for Cybersecurity Event Detection
E8-PA-ML1.1
Automated asset discovery at least fortnightly
Patch applications
  • ISM-0336Partially overlaps
    Develop and Maintain Networked IT Equipment Register
  • ISM-1163Depends on
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1702Supports
    Regularly Scan for Missing Security Patches
  • ISM-1703Supports
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1752Supports
    Fortnightly Vulnerability Scanning for Non-Workstations
  • ISM-1807Equivalent
    Automated Asset Discovery for Vulnerability Scanning
  • ISM-1966Supports
    CISO Manages and Verifies System Register
  • ISM-2134Depends on
    Develop, Maintain and Regularly Verify an AI Agent Register
E8-PA-ML1.2
Up-to-date vulnerability scanner used for scanning activities
Patch applications
  • ISM-0402Supports
    Software Vulnerability Testing Using SAST, DAST and SCA
  • ISM-1163Partially meets
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1693Supports
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1698Partially meets
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1699Partially meets
    Weekly Vulnerability Scanning for Software Updates
  • ISM-1700Partially meets
    Regular Vulnerability Scanning for Applications
  • ISM-1701Partially meets
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1703Partially meets
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1808Equivalent
    Vulnerability Scanning with Updated Tools
E8-PA-ML1.3
Daily vulnerability scanning for missing patches in online services
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1698Equivalent
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1701Partially overlaps
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
E8-PA-ML1.4
Weekly scanning for missing patches or updates in key software
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Partially meets
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially overlaps
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1467Depends on
    Use Latest Releases of User Applications
  • ISM-1526Partially meets
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1691Depends on
    Timely Vulnerability Patching in Software Tools
  • ISM-1692Supports
    Quick Apply Critical Patches for Vulnerabilities
  • ISM-1693Partially overlaps
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1699Equivalent
    Weekly Vulnerability Scanning for Software Updates
  • ISM-1700Partially overlaps
    Regular Vulnerability Scanning for Applications
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1704Depends on
    Remove Unsupported Software to Ensure Security
  • ISM-1754Supports
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1901Depends on
    Timely Application of Non-Critical Security Patches
E8-PA-ML1.5
Apply Critical Online Service Patches Within 48 Hours
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1483Partially overlaps
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1698Supports
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1754Broader than
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1876Equivalent
    Apply Critical Patches Within 48 Hours
  • ISM-1877Partially overlaps
    Timely Application of Critical Security Patches
  • ISM-1879Partially overlaps
    Timely Patching of Critical Driver Vulnerabilities
  • ISM-1921Depends on
    Assess System Compromise Risks Often
E8-PA-ML1.6
Apply non-critical patches for online services within two weeks
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially meets
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1483Supports
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1690Equivalent
    Timely Application of Non-Critical Vulnerability Patches
  • ISM-1694Partially overlaps
    Timely Application of Non-Critical Security Patches
  • ISM-1697Partially overlaps
    Apply Non-Critical Patches Within One Month
  • ISM-1698Depends on
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1876Partially overlaps
    Apply Critical Patches Within 48 Hours
E8-PA-ML1.8
Unsupported online services are removed by the organisation
Patch applications
  • ISM-0304Partially overlaps
    Remove Unsupported Applications for System Security
  • ISM-1704Partially overlaps
    Remove Unsupported Software to Ensure Security
  • ISM-1809Partially overlaps
    Implement Compensating Controls for Unsupported Systems
  • ISM-1905Equivalent
    Remove Online Services No Longer Supported by Vendors
  • ISM-1981Partially overlaps
    Replace Unsupportable Non-Internet Network Devices
E8-PA-ML1.9
Removal of unsupported software and applications
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-0304Partially overlaps
    Remove Unsupported Applications for System Security
  • ISM-1247Partially overlaps
    Disable or Remove Unneeded Server Features
  • ISM-1467Partially overlaps
    Use Latest Releases of User Applications
  • ISM-1643Supports
    Maintain Detailed Software Version and Patch Records
  • ISM-1654Broader than
    Disable or Remove Internet Explorer 11
  • ISM-1704Equivalent
    Remove Unsupported Software to Ensure Security
  • ISM-1753Partially overlaps
    Replace Unsupported Internet-Facing Devices
  • ISM-1809Partially overlaps
    Implement Compensating Controls for Unsupported Systems
  • ISM-1848Partially overlaps
    Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
  • ISM-1981Partially overlaps
    Replace Unsupportable Non-Internet Network Devices
E8-PA-ML2.1
Fortnightly vulnerability scanning for non-core applications
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-0304Supports
    Remove Unsupported Applications for System Security
  • ISM-1693Partially overlaps
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1699Partially overlaps
    Weekly Vulnerability Scanning for Software Updates
  • ISM-1700Equivalent
    Regular Vulnerability Scanning for Applications
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-2118Partially meets
    Conduct Vulnerability Assessments and Penetration Tests
E8-PA-ML2.2
Timely Patching of Non-Critical Application Vulnerabilities
Patch applications
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-0304Partially overlaps
    Remove Unsupported Applications for System Security
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially overlaps
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1555Supports
    Prepare Mobile Devices Before Overseas Travel
  • ISM-1606Partially overlaps
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1643Supports
    Maintain Detailed Software Version and Patch Records
  • ISM-1693Equivalent
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1700Supports
    Regular Vulnerability Scanning for Applications
E8-PA-ML3.1
Patch critical vulnerabilities in applications within 48 hours
Patch applications
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1163Supports
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1366Partially overlaps
    Ensure Timely Security Updates for Mobile Devices
  • ISM-1467Partially overlaps
    Use Latest Releases of User Applications
  • ISM-1691Partially overlaps
    Timely Vulnerability Patching in Software Tools
  • ISM-1692Equivalent
    Quick Apply Critical Patches for Vulnerabilities
  • ISM-1693Supports
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1699Supports
    Weekly Vulnerability Scanning for Software Updates
  • ISM-1754Broader than
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1901Partially overlaps
    Timely Application of Non-Critical Security Patches
  • ISM-1921Supports
    Assess System Compromise Risks Often
  • ISM-2118Depends on
    Conduct Vulnerability Assessments and Penetration Tests
E8-PA-ML3.2
Apply patches for non-critical vulnerabilities within two weeks
Patch applications
  • ISM-1366Partially overlaps
    Ensure Timely Security Updates for Mobile Devices
  • ISM-1467Partially overlaps
    Use Latest Releases of User Applications
  • ISM-1643Depends on
    Maintain Detailed Software Version and Patch Records
  • ISM-1691Partially overlaps
    Timely Vulnerability Patching in Software Tools
  • ISM-1692Partially overlaps
    Quick Apply Critical Patches for Vulnerabilities
  • ISM-1693Partially overlaps
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1754Partially meets
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1901Equivalent
    Timely Application of Non-Critical Security Patches
E8-PA-ML3.3
Remove unsupported applications excluding certain categories
Patch applications
  • ISM-0304Equivalent
    Remove Unsupported Applications for System Security
  • ISM-1483Partially overlaps
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1493Supports
    Maintain and Verify Software Registers
  • ISM-1655Partially meets
    Ensure .NET Framework 3.5 is Disabled or Removed
  • ISM-1704Partially overlaps
    Remove Unsupported Software to Ensure Security
  • ISM-1809Partially overlaps
    Implement Compensating Controls for Unsupported Systems
E8-PO-ML1.1
Automated bi-weekly asset discovery for vulnerability scanning
Patch operating systems
  • ISM-0336Supports
    Develop and Maintain Networked IT Equipment Register
  • ISM-1163Broader than
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1493Supports
    Maintain and Verify Software Registers
  • ISM-1643Supports
    Maintain Detailed Software Version and Patch Records
  • ISM-1696Supports
    Apply Critical Patches Within 48 Hours
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1700Supports
    Regular Vulnerability Scanning for Applications
  • ISM-1703Supports
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1807Equivalent
    Automated Asset Discovery for Vulnerability Scanning
  • ISM-1966Depends on
    CISO Manages and Verifies System Register
  • ISM-2118Partially meets
    Conduct Vulnerability Assessments and Penetration Tests
  • ISM-2134Depends on
    Develop, Maintain and Regularly Verify an AI Agent Register
E8-PO-ML1.2
Use a vulnerability scanner with an updated database
Patch operating systems
  • ISM-1696Depends on
    Apply Critical Patches Within 48 Hours
  • ISM-1697Supports
    Apply Non-Critical Patches Within One Month
  • ISM-1698Supports
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1699Partially meets
    Weekly Vulnerability Scanning for Software Updates
  • ISM-1701Supports
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1702Supports
    Regularly Scan for Missing Security Patches
  • ISM-1752Supports
    Fortnightly Vulnerability Scanning for Non-Workstations
  • ISM-1808Equivalent
    Vulnerability Scanning with Updated Tools
  • ISM-1879Depends on
    Timely Patching of Critical Driver Vulnerabilities
  • ISM-1900Depends on
    Fortnightly System Vulnerability Scanning
E8-PO-ML1.3
Use a daily vulnerability scanner for internet-facing systems
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1163Partially meets
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1694Depends on
    Timely Application of Non-Critical Security Patches
  • ISM-1698Partially overlaps
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1701Equivalent
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1702Partially overlaps
    Regularly Scan for Missing Security Patches
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1752Partially overlaps
    Fortnightly Vulnerability Scanning for Non-Workstations
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
  • ISM-1877Supports
    Timely Application of Critical Security Patches
  • ISM-1900Partially overlaps
    Fortnightly System Vulnerability Scanning
E8-PO-ML1.4
Use a vulnerability scanner fortnightly to find missing OS patches
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1163Partially meets
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1696Supports
    Apply Critical Patches Within 48 Hours
  • ISM-1702Equivalent
    Regularly Scan for Missing Security Patches
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
E8-PO-ML1.5
Apply critical patches to internet-facing OS within 48 hours
Patch operating systems
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1163Supports
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1407Partially overlaps
    Ensure Use of Current OS Versions
  • ISM-1606Partially overlaps
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1643Depends on
    Maintain Detailed Software Version and Patch Records
  • ISM-1694Partially overlaps
    Timely Application of Non-Critical Security Patches
  • ISM-1696Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1701Depends on
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1753Depends on
    Replace Unsupported Internet-Facing Devices
  • ISM-1876Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1877Equivalent
    Timely Application of Critical Security Patches
  • ISM-1878Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1879Partially overlaps
    Timely Patching of Critical Driver Vulnerabilities
  • ISM-1902Partially overlaps
    Apply Non-Critical Patches to Non-Internet Systems Promptly
  • ISM-1921Depends on
    Assess System Compromise Risks Often
E8-PO-ML1.6
Timely application of non-critical patches for internet-facing OS vulnerabilities
Patch operating systems
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1606Partially overlaps
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1690Partially overlaps
    Timely Application of Non-Critical Vulnerability Patches
  • ISM-1694Equivalent
    Timely Application of Non-Critical Security Patches
  • ISM-1877Partially overlaps
    Timely Application of Critical Security Patches
  • ISM-1902Partially overlaps
    Apply Non-Critical Patches to Non-Internet Systems Promptly
E8-PO-ML1.8
Replace unsupported operating systems
Patch operating systems
  • ISM-0298Partially overlaps
    Centralised System Patch and Update Management
  • ISM-0336Depends on
    Develop and Maintain Networked IT Equipment Register
  • ISM-1366Supports
    Ensure Timely Security Updates for Mobile Devices
  • ISM-1407Partially overlaps
    Ensure Use of Current OS Versions
  • ISM-1408Supports
    Use 64-bit Operating Systems Where Supported
  • ISM-1409Depends on
    Implement Restrictive OS Hardening Guidelines
  • ISM-1501Equivalent
    Replace Unsupported Operating Systems
  • ISM-1643Depends on
    Maintain Detailed Software Version and Patch Records
  • ISM-1704Partially overlaps
    Remove Unsupported Software to Ensure Security
  • ISM-1753Partially overlaps
    Replace Unsupported Internet-Facing Devices
  • ISM-1807Supports
    Automated Asset Discovery for Vulnerability Scanning
  • ISM-1809Partially overlaps
    Implement Compensating Controls for Unsupported Systems
  • ISM-1848Partially overlaps
    Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
  • ISM-1981Partially overlaps
    Replace Unsupportable Non-Internet Network Devices
  • ISM-1982Partially overlaps
    Replace Unsupported Networked IT Equipment
E8-PO-ML3.1
Vulnerability scanner used fortnightly to identify missing driver patches
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially meets
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1703Equivalent
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
E8-PO-ML3.2
At least fortnightly use of a vulnerability scanner for firmware
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1703Partially overlaps
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1752Partially overlaps
    Fortnightly Vulnerability Scanning for Non-Workstations
  • ISM-1807Supports
    Automated Asset Discovery for Vulnerability Scanning
  • ISM-1808Depends on
    Vulnerability Scanning with Updated Tools
  • ISM-1900Equivalent
    Fortnightly System Vulnerability Scanning
  • ISM-1903Partially overlaps
    Rapid Application of Critical Firmware Patches
  • ISM-1904Partially overlaps
    Apply Firmware Patches for Non-Critical Vulnerabilities
E8-PO-ML3.3
Apply critical patches to non-internet-facing OS within 48 hours
Patch operating systems
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1366Partially overlaps
    Ensure Timely Security Updates for Mobile Devices
  • ISM-1605Depends on
    Harden the Operating System Beneath Software Isolation Mechanisms
  • ISM-1606Partially overlaps
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1643Depends on
    Maintain Detailed Software Version and Patch Records
  • ISM-1695Partially overlaps
    Timely Application of System Security Patches
  • ISM-1696Equivalent
    Apply Critical Patches Within 48 Hours
  • ISM-1702Depends on
    Regularly Scan for Missing Security Patches
  • ISM-1800Supports
    Ensure Network Devices Have Trusted Firmware
  • ISM-1876Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1877Partially overlaps
    Timely Application of Critical Security Patches
  • ISM-1878Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1900Depends on
    Fortnightly System Vulnerability Scanning
  • ISM-1902Partially overlaps
    Apply Non-Critical Patches to Non-Internet Systems Promptly
  • ISM-1921Depends on
    Assess System Compromise Risks Often
  • ISM-1981Depends on
    Replace Unsupportable Non-Internet Network Devices
E8-PO-ML3.4
Non-critical OS patches applied within one month if no exploits exist
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1694Partially overlaps
    Timely Application of Non-Critical Security Patches
  • ISM-1695Broader than
    Timely Application of System Security Patches
  • ISM-1696Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1697Partially overlaps
    Apply Non-Critical Patches Within One Month
  • ISM-1702Depends on
    Regularly Scan for Missing Security Patches
  • ISM-1751Partially overlaps
    Timely Application of Vendor Patches for Non-Critical OS Vulnerabilities
  • ISM-1902Equivalent
    Apply Non-Critical Patches to Non-Internet Systems Promptly
  • ISM-1904Partially overlaps
    Apply Firmware Patches for Non-Critical Vulnerabilities
E8-PO-ML3.5
Apply critical driver patches within 48 hours
Patch operating systems
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-0300Partially overlaps
    Apply System Security Patches with Approval
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1163Supports
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1697Partially overlaps
    Apply Non-Critical Patches Within One Month
  • ISM-1754Broader than
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1879Equivalent
    Timely Patching of Critical Driver Vulnerabilities
  • ISM-1921Supports
    Assess System Compromise Risks Often
E8-PO-ML3.6
Apply non-critical driver patches within one month
Patch operating systems
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1697Equivalent
    Apply Non-Critical Patches Within One Month
  • ISM-1904Partially overlaps
    Apply Firmware Patches for Non-Critical Vulnerabilities
E8-PO-ML3.7
Apply critical firmware patches within 48 hours
Patch operating systems
  • ISM-0298Depends on
    Centralised System Patch and Update Management
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1697Partially overlaps
    Apply Non-Critical Patches Within One Month
  • ISM-1754Partially overlaps
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1876Partially overlaps
    Apply Critical Patches Within 48 Hours
  • ISM-1903Equivalent
    Rapid Application of Critical Firmware Patches
  • ISM-1904Partially overlaps
    Apply Firmware Patches for Non-Critical Vulnerabilities
  • ISM-1921Supports
    Assess System Compromise Risks Often
E8-PO-ML3.8
Firmware vulnerabilities patched within one month if non-critical and no exploits
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-0300Partially overlaps
    Apply System Security Patches with Approval
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1163Supports
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1697Partially overlaps
    Apply Non-Critical Patches Within One Month
  • ISM-1900Supports
    Fortnightly System Vulnerability Scanning
  • ISM-1903Partially overlaps
    Rapid Application of Critical Firmware Patches
  • ISM-1904Equivalent
    Apply Firmware Patches for Non-Critical Vulnerabilities
E8-PO-ML3.9
The latest or previous OS release is used
Patch operating systems
  • ISM-0298Supports
    Centralised System Patch and Update Management
  • ISM-1407Equivalent
    Ensure Use of Current OS Versions
  • ISM-1408Supports
    Use 64-bit Operating Systems Where Supported
  • ISM-1409Supports
    Implement Restrictive OS Hardening Guidelines
  • ISM-1483Partially overlaps
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1501Partially overlaps
    Replace Unsupported Operating Systems
  • ISM-1605Depends on
    Harden the Operating System Beneath Software Isolation Mechanisms
  • ISM-1848Partially overlaps
    Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
E8-RA-ML1.1
Validating privileged access requests upon initial request
Restrict admin privileges
  • ISM-0407Supports
    Maintain Secure User Access Records
  • ISM-0432Supports
    Document System Access Requirements in Security Plans
  • ISM-0446Partially overlaps
    Restrict Privileged Access for Foreign Nationals
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-1487Depends on
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1507Equivalent
    Ensure Requests for Privileged Access are Verified
  • ISM-1508Partially overlaps
    Limit Privileged Access to Essential Duties Only
  • ISM-1647Partially overlaps
    Disable Privileged Access After 12 Months
  • ISM-1883Partially overlaps
    Restrict Privileged Access to Necessary Service Duties
  • ISM-1927Partially overlaps
    Restrict Access to Microsoft Active Directory Servers
  • ISM-1939Supports
    Minimise Members in Privileged Security Groups
  • ISM-2128Depends on
    Limit Kernel-Mode Code Installation to Privileged Users Who Need It
  • ISM-2133Depends on
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2136Partially overlaps
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2137Partially overlaps
    Block User OAuth Consent, Reserve It for Authorised Administrators
E8-RA-ML1.2
Dedicated privileged accounts for admin tasks
Restrict admin privileges
  • ISM-0414Depends on
    Uniquely Identifying Every User Granted System Access
  • ISM-0445Equivalent
    Dedicated Accounts for Privileged User Activities
  • ISM-0616Supports
    Ensure Separation of Duties for Gateway Admins
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-1175Supports
    Restrict Privileged Users from Internet Access
  • ISM-1263Partially meets
    Enforce Unique Accounts for Server Administration
  • ISM-1487Depends on
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1508Partially overlaps
    Limit Privileged Access to Essential Duties Only
  • ISM-1590Supports
    Mandate Credential Changes Upon Compromise
  • ISM-1620Supports
    Ensure Privileged Accounts are Secured in AD
  • ISM-1750Supports
    Segregation of Administrative Infrastructure for Server Security
  • ISM-1827Partially meets
    Use Dedicated Admin Accounts for Domain Controllers
  • ISM-1841Supports
    Restrict Domain Joining to Admin Users Only
  • ISM-1842Partially meets
    Use Privileged Accounts for Domain Machine Addition
  • ISM-1846Supports
    Restrict Pre-Windows 2000 Access Group Membership
  • ISM-1883Depends on
    Limit Authorised Privileged Account Online Service Access to Duties
  • ISM-1898Supports
    Use Secure Admin Workstations for Administration
  • ISM-1927Depends on
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1939Supports
    Minimise Members in Privileged Security Groups
  • ISM-1949Broader than
    Use Dedicated Accounts for AD FS Administration
  • ISM-1952Supports
    Prevent Synchronisation of Privileged Accounts
  • ISM-1958Depends on
    Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments
  • ISM-2133Partially overlaps
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
E8-RA-ML1.3
Prevent privileged accounts from accessing internet, email, and web services
Restrict admin privileges
  • ISM-0258Supports
    Establish and Maintain a Web Usage Policy
  • ISM-0445Supports
    Dedicated Accounts for Privileged User Activities
  • ISM-0874Partially overlaps
    Ensure Internet Access via Organisation's Gateway
  • ISM-0963Supports
    Implementing Web Content Filters for Safety
  • ISM-1175Equivalent
    Restrict Privileged Users from Internet Access
  • ISM-1380Supports
    Use Separate Privileged and Unprivileged Environments
  • ISM-1385Supports
    Segregation of Administrative Infrastructure from Networks
  • ISM-1508Partially overlaps
    Restricting Privileged Access to What Duties Require
  • ISM-1883Partially overlaps
    Restrict Privileged Access to Necessary Service Duties
E8-RA-ML1.4
Limit privileged accounts to essential online service access
Restrict admin privileges
  • ISM-0258Supports
    Establish and Maintain a Web Usage Policy
  • ISM-0441Partially overlaps
    Ensuring Limited Access for Temporary System Use
  • ISM-0445Supports
    Dedicated Accounts for Privileged User Activities
  • ISM-0611Depends on
    Restrict Privileges for Gateway Administrators
  • ISM-1175Equivalent
    Restrict Privileged Users from Internet Access
  • ISM-1507Depends on
    Ensure Requests for Privileged Access are Verified
  • ISM-1508Partially meets
    Limit Privileged Access to Essential Duties Only
  • ISM-1647Supports
    Disable Privileged Access After 12 Months
  • ISM-1648Depends on
    Disabling Inactive Privileged Access to Systems
  • ISM-1833Supports
    Limit Privileges for User Accounts in Active Directory
  • ISM-1852Partially overlaps
    Limit Unprivileged Access to Essential Functions
  • ISM-1883Equivalent
    Limit Authorised Privileged Account Online Service Access to Duties
  • ISM-1927Partially overlaps
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1939Supports
    Minimise Members in Privileged Security Groups
  • ISM-2068Partially overlaps
    Restrict Internet Access for Networked Devices
  • ISM-2156Partially overlaps
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
E8-RA-ML1.5
Privileged users use separate privileged and unprivileged environments
Restrict admin privileges
  • ISM-0445Supports
    Dedicated Accounts for Privileged User Activities
  • ISM-1380Equivalent
    Use Separate Privileged and Unprivileged Environments
  • ISM-1387Partially overlaps
    Use Jump Servers for Administrative Activities
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1508Depends on
    Restricting Privileged Access to What Duties Require
  • ISM-1635Partially meets
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1687Supports
    Prevent Virtualisation of Privileged Environments
  • ISM-1688Supports
    Block Unprivileged Account Logons to Privileged Operating Environments
  • ISM-1689Supports
    Restrict Privileged Accounts Access to Non-Privileged Environments
  • ISM-1958Supports
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-1990Depends on
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
E8-RA-ML1.6
Unprivileged accounts restricted from logging into privileged environments
Restrict admin privileges
  • ISM-0445Depends on
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-1380Partially overlaps
    Use Separate Privileged and Unprivileged Environments
  • ISM-1387Supports
    Use Jump Servers for Administrative Activities
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1687Supports
    Prevent Virtualisation of Privileged Environments
  • ISM-1688Equivalent
    Restrict Privileged Environment Access
  • ISM-1689Partially overlaps
    Restrict Privileged Accounts Access to Non-Privileged Environments
  • ISM-1927Supports
    Restrict Access to Microsoft Active Directory Servers
  • ISM-1958Partially overlaps
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-1990Depends on
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
E8-RA-ML1.7
Prevent privileged accounts from accessing unprivileged environments
Restrict admin privileges
  • ISM-0445Supports
    Dedicated Accounts for Privileged User Activities
  • ISM-1380Supports
    Use Separate Privileged and Unprivileged Environments
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1487Depends on
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1508Partially overlaps
    Restricting Privileged Access to What Duties Require
  • ISM-1649Supports
    Implement Just-in-Time Administration for System Access
  • ISM-1688Partially overlaps
    Block Unprivileged Account Logons to Privileged Operating Environments
  • ISM-1689Equivalent
    Restrict Privileged Accounts Access to Non-Privileged Environments
  • ISM-1827Partially overlaps
    Use Dedicated Admin Accounts for Domain Controllers
  • ISM-1958Partially overlaps
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-1990Depends on
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
E8-RA-ML2.1
Disable privileged access after 12 months without revalidation
Restrict admin privileges
  • ISM-1487Depends on
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1507Partially overlaps
    Ensure Requests for Privileged Access are Verified
  • ISM-1508Depends on
    Restricting Privileged Access to What Duties Require
  • ISM-1647Equivalent
    Disable Privileged Access After 12 Months
  • ISM-1649Supports
    Implement Just-in-Time Administration for System Access
  • ISM-1843Partially overlaps
    Annual Review of Unconstrained Delegation in AD Accounts
  • ISM-1934Partially overlaps
    Six-Monthly Review and Removal of DCSync User Permissions
E8-RA-ML2.2
Privileged access is disabled after 45 days of inactivity
Restrict admin privileges
  • ISM-0445Supports
    Dedicated Accounts for Privileged User Activities
  • ISM-1620Partially overlaps
    Ensure Privileged Accounts are Secured in AD
  • ISM-1647Partially overlaps
    Disable Privileged Access After 12 Months
  • ISM-1648Equivalent
    Disabling Inactive Privileged Access to Systems
  • ISM-1927Depends on
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1940Partially overlaps
    Restrict Service Accounts from Privileged Groups
E8-RA-ML2.3
Privileged environments are not virtualised within unprivileged environments
Restrict admin privileges
  • ISM-1380Supports
    Use Separate Privileged and Unprivileged Environments
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1461Depends on
    Same Classification and Security Domain for Shared Isolation Hosts
  • ISM-1687Equivalent
    Prevent Virtualisation of Privileged Environments
  • ISM-1688Depends on
    Block Unprivileged Account Logons to Privileged Operating Environments
  • ISM-1689Supports
    Restrict Privileged Accounts Access to Non-Privileged Environments
  • ISM-1958Supports
    Prevent Unauthorised Access for DCSync Accounts
E8-RA-ML2.4
Conduct administrative activities through jump servers
Restrict admin privileges
  • ISM-0445Partially overlaps
    Dedicated Accounts for Privileged User Activities
  • ISM-0616Supports
    Ensure Separation of Duties for Gateway Admins
  • ISM-1380Depends on
    Privileged Users Work in Separate Privileged and Unprivileged Operating Environments
  • ISM-1387Equivalent
    Use Jump Servers for Administrative Activities
  • ISM-1422Depends on
    Prevent Unauthorised Access to Software Source
  • ISM-1509Supports
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1604Supports
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1689Depends on
    Block Privileged Account Logons to Unprivileged Operating Environments
  • ISM-1731Supports
    Coordinate Intrusion Remediation on Separate Systems
  • ISM-1750Supports
    Segregation of Administrative Infrastructure for Server Security
  • ISM-1827Supports
    Use Dedicated Admin Accounts for Domain Controllers
  • ISM-1898Partially overlaps
    Use Secure Admin Workstations for Administration
  • ISM-1899Depends on
    Restrict Unauthorised Network Connections
  • ISM-1927Supports
    Restrict Access to Microsoft Active Directory Servers
E8-RA-ML2.5
Long, unique, and managed credentials for admin accounts
Restrict admin privileges
  • ISM-1227Depends on
    Randomly Generate User Account Credentials
  • ISM-1590Partially overlaps
    Changing User Account Credentials After Compromise, Exposure or Shared Membership Change
  • ISM-1612Partially overlaps
    Restricted Use of Break Glass Accounts for Emergencies
  • ISM-1614Partially overlaps
    Manage Emergency Account Access Changes
  • ISM-1615Depends on
    Testing Break Glass Accounts Post Credential Change
  • ISM-1619Depends on
    Configure Service Accounts as Managed Service Accounts
  • ISM-1685Equivalent
    Strengthening Passwords for Critical Accounts
  • ISM-1795Partially overlaps
    Set 30-Character Minimum for Key Administrator Passwords
  • ISM-1842Partially overlaps
    Use Privileged Accounts for Domain Machine Addition
  • ISM-1847Partially overlaps
    Double KRBTGT Password Reset After Compromise or Six Months
  • ISM-1875Depends on
    Monthly System Scans to Detect Credentials Stored in the Clear
  • ISM-1949Partially overlaps
    Use Dedicated Accounts for AD FS Administration
  • ISM-1953Broader than
    Ensure Strong Management of Admin Account Credentials
  • ISM-1954Equivalent
    Enforce Random Credentials for Administrator Accounts
  • ISM-2081Depends on
    Enforce Use of All ASCII Characters in Passwords
  • ISM-2142Partially overlaps
    Central Management of Application and Workload Credentials
  • ISM-2144Partially overlaps
    Change Application Static Credentials Found Compromised or Exposed in Clear
E8-RA-ML2.6
Privileged access events are centrally logged.
Restrict admin privileges
  • ISM-0415Supports
    Strict Control of Shared User Accounts
  • ISM-0445Depends on
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0582Partially overlaps
    Central Logging of Windows Security Events
  • ISM-0585Partially overlaps
    Capture Detailed Information in Event Logs
  • ISM-0670Broader than
    Central Logging of CDS Security Events
  • ISM-1509Equivalent
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1537Partially overlaps
    Log Security-Relevant Database Events Centrally
  • ISM-1607Partially overlaps
    Integrity Monitoring and Logging for Isolation Mechanism
  • ISM-1613Partially meets
    Central Logging of Break Glass Account Usage
  • ISM-1650Partially meets
    Log Management of Privileged User Activities
  • ISM-1830Partially meets
    Central Logging for Microsoft AD Server Activities
  • ISM-1895Partially overlaps
    Log Single-factor Authentication Events
  • ISM-1976Partially overlaps
    Central Logging of Security Events on macOS
  • ISM-1977Partially overlaps
    Central Logging of Linux System Events
  • ISM-1983Depends on
    Log Events Sent to Centralised Facility Quickly
  • ISM-1989Partially overlaps
    Ensure Event Logs Meet Retention Requirements
E8-RA-ML2.7
Centrally log privileged account and group management events
Restrict admin privileges
  • ISM-0445Depends on
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-0580Depends on
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0585Partially overlaps
    Capture Detailed Information in Event Logs
  • ISM-0988Supports
    Ensure Accurate Time Source for Event Logs
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
  • ISM-1509Partially meets
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1537Partially overlaps
    Log Security-Relevant Database Events Centrally
  • ISM-1613Partially overlaps
    Central Logging of Break Glass Account Usage
  • ISM-1614Depends on
    Manage Emergency Account Access Changes
  • ISM-1620Partially overlaps
    Ensure Privileged Accounts are Secured in AD
  • ISM-1623Partially overlaps
    Centralised Logging of PowerShell Activities
  • ISM-1650Equivalent
    Log Management of Privileged User Activities
  • ISM-1939Supports
    Minimise Members in Privileged Security Groups
  • ISM-1941Supports
    Restrict Computer Accounts in Privileged Security Groups
  • ISM-1953Depends on
    Ensure Strong Management of Admin Account Credentials
  • ISM-1976Partially overlaps
    Central Logging of Security Events on macOS
  • ISM-1977Partially overlaps
    Central Logging of Linux System Events
  • ISM-2128Depends on
    Limit Kernel-Mode Code Installation to Privileged Users Who Need It
E8-RA-ML2.8
Event logs are protected from unauthorised changes and losses
Restrict admin privileges
  • ISM-1624Broader than
    Protect PowerShell Script Block Logs
  • ISM-1815Equivalent
    Protect Event Logs from Unauthorised Access
  • ISM-1910Depends on
    Log Network API Calls for Data Protection
  • ISM-1985Partially overlaps
    Protect Event Logs from Unauthorised Access
E8-RA-ML2.9
Event logs are analysed promptly for security events
Restrict admin privileges
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-0580Supports
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Partially meets
    Analyse Cyber Security Events Promptly
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1536Depends on
    Central Logging of Software Database Queries and Errors
  • ISM-1607Partially overlaps
    Integrity Monitoring and Logging for Isolation Mechanism
  • ISM-1906Equivalent
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cybersecurity
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1978Supports
    Centralised Logging for Server Application Events
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially overlaps
    Timely Analysis of Security Event Logs
E8-RA-ML2.10
Timely analysis of cyber security events to identify incidents
Restrict admin privileges
  • ISM-1228Equivalent
    Analyse Cyber Security Events Promptly
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1906Partially overlaps
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Depends on
    Timely Analysis of Event Logs for Cyber security
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Depends on
    Timely Analysis of Security Event Logs
  • ISM-2116Depends on
    Use Cyber Threat Intelligence for Event Detection
E8-RA-ML2.11
Report cyber incidents to the CISO promptly
Restrict admin privileges
  • ISM-0043Partially meets
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Equivalent
    Report Cyber Security Incidents Promptly
  • ISM-0140Partially overlaps
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0141Partially overlaps
    Report Cyber Incidents Promptly to Designated Contacts
  • ISM-0142Broader than
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0576Partially meets
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0733Partially overlaps
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1088Partially overlaps
    Report Potential Compromises of Mobile Devices Overseas
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1618Supports
    CISO's Role in Cyber Security Incident Response
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
E8-RA-ML2.12
Report cyber security incidents to ASD promptly
Restrict admin privileges
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Partially overlaps
    Report Cyber Security Incidents Promptly
  • ISM-0140Equivalent
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0141Supports
    Report Cyber Incidents Promptly to Designated Contacts
E8-RA-ML2.13
Enact cyber incident response plan after an incident is identified
Restrict admin privileges
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Supports
    Report Cyber Security Incidents Promptly
  • ISM-0125Supports
    Maintaining a Cyber Security Incident Register
  • ISM-0576Depends on
    Develop and Maintain Cyber Security Incident Plans
  • ISM-1019Partially meets
    Develop a Denial of Service Response Plan
  • ISM-1618Supports
    CISO's Role in Cyber Security Incident Response
  • ISM-1731Depends on
    Plan and Coordinate Intrusion Remediation From Trusted Separate Systems
  • ISM-1732Partially overlaps
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-1819Equivalent
    Enact Cyber Security Incident Response Plans
E8-RA-ML3.1
Limit privileged access to what is necessary for duties
Restrict admin privileges
  • ISM-0133Partially overlaps
    Responding to Data Spills by Restricting Access
  • ISM-0441Partially overlaps
    Ensuring Limited Access for Temporary System Use
  • ISM-0446Partially overlaps
    Restrict Privileged Access for Foreign Nationals
  • ISM-0488Supports
    Use Forced Commands for SSH Without Passwords
  • ISM-0611Broader than
    Restrict Privileges for Gateway Administrators
  • ISM-1249Broader than
    Limit Server Application User Privileges
  • ISM-1250Broader than
    Limit Server Application User Account Privileges
  • ISM-1255Broader than
    Restrict Database Content Access by User Duties and Functions
  • ISM-1263Supports
    Enforce Unique Accounts for Server Administration
  • ISM-1268Partially overlaps
    Enforce Need-to-Know Access in Databases
  • ISM-1392Depends on
    Restrict File Modifications via Path Rules
  • ISM-1507Partially overlaps
    Ensure Requests for Privileged Access are Verified
  • ISM-1508Equivalent
    Limit Privileged Access to Essential Duties Only
  • ISM-1565Depends on
    Annual Tailored Training for All Privileged Access Holders
  • ISM-1746Depends on
    Restrict File System Permission Changes
  • ISM-1833Broader than
    Limit Privileges for User Accounts in Active Directory
  • ISM-1843Broader than
    Annual Review of Unconstrained Delegation in AD Accounts
  • ISM-1852Partially overlaps
    Limit Unprivileged Access to Essential Functions
  • ISM-1883Broader than
    Limit Authorised Privileged Account Online Service Access to Duties
  • ISM-1927Broader than
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1933Broader than
    Restrict DCSync Permissions on Service Accounts
  • ISM-1934Broader than
    Six-Monthly Review and Removal of DCSync User Permissions
  • ISM-1938Broader than
    Restrict Domain Computers Group in Active Directory
  • ISM-1939Partially meets
    Minimise Members in Privileged Security Groups
  • ISM-1948Depends on
    Certificate Manager Approval for Templates Allowing Supplied SANs
  • ISM-1958Partially overlaps
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-2093Partially overlaps
    Role-Based Access Controls in AI Applications
  • ISM-2128Broader than
    Limit Kernel-Mode Code Installation to Privileged Users Who Need It
  • ISM-2133Depends on
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2138Depends on
    Six-Monthly Review of OAuth Application Consents and Granted Permissions
E8-RA-ML3.2
Use Secure Admin Workstations for Administrative Tasks
Restrict admin privileges
  • ISM-0445Depends on
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-0843Depends on
    Ensure Workstation Security with Application Control
  • ISM-1341Depends on
    Implement HIPS or EDR on Workstations
  • ISM-1385Depends on
    Segregation of Administrative Infrastructure from Networks
  • ISM-1387Partially overlaps
    Use Jump Servers for Administrative Activities
  • ISM-1406Depends on
    Use SOEs for Workstations and Servers
  • ISM-1731Partially overlaps
    Plan and Coordinate Intrusion Remediation From Trusted Separate Systems
  • ISM-1750Partially overlaps
    Segregation of Administrative Infrastructure for Server Security
  • ISM-1827Depends on
    Use Dedicated Admin Accounts for Domain Controllers
  • ISM-1898Equivalent
    Use Secure Admin Workstations for Administration
  • ISM-1953Depends on
    Ensure Strong Management of Admin Account Credentials
E8-RA-ML3.3
Just-in-time administration is used for administering systems and applications.
Restrict admin privileges
  • ISM-0441Supports
    Ensuring Limited Access for Temporary System Use
  • ISM-0445Partially overlaps
    Dedicated Accounts for Privileged User Activities
  • ISM-1006Supports
    Prevent Unauthorised Access to Network Traffic
  • ISM-1387Depends on
    Use Jump Servers for Administrative Activities
  • ISM-1487Depends on
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1508Partially overlaps
    Limit Privileged Access to Essential Duties Only
  • ISM-1604Supports
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1649Equivalent
    Implement Just-in-Time Administration for System Access
  • ISM-1688Supports
    Restrict Privileged Environment Access
  • ISM-1835Supports
    Restrict Delegation of Privileged Active Directory Accounts
  • ISM-1852Supports
    Limit Unprivileged Access to Essential Functions
  • ISM-1927Supports
    Restrict Access to Microsoft Active Directory Servers
  • ISM-1939Supports
    Minimise Members in Privileged Security Groups
  • ISM-1948Supports
    Approval for Certificate Template SANs in AD Services
  • ISM-2136Depends on
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2156Depends on
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
E8-RA-ML3.4
Memory integrity functionality is enabled
Restrict admin privileges
  • ISM-1409Partially meets
    Implement Restrictive OS Hardening Guidelines
  • ISM-1492Partially meets
    Enable Exploit Protection in Operating Systems
  • ISM-1745Partially overlaps
    Enable Security Features for System Protection
  • ISM-1896Equivalent
    Enable Memory Integrity for Credential Protection
E8-RA-ML3.5
Local Security Authority protection functionality is enabled
Restrict admin privileges
  • ISM-1402Supports
    Protecting Stored Credentials with Security Measures
  • ISM-1492Partially overlaps
    Enable Exploit Protection in Operating Systems
  • ISM-1584Depends on
    Prevent Unauthorised Changes to Security Settings
  • ISM-1686Partially overlaps
    Enable Credential Guard for Credential Protection
  • ISM-1749Supports
    Limit Cached Credentials to Single Logon
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
  • ISM-1829Depends on
    Prevent Password Storage in Group Policy Preferences
  • ISM-1858Partially meets
    Implement Strict IT Equipment Hardening Guidelines
  • ISM-1861Equivalent
    Enable Local Security Authority Protection
  • ISM-1896Supports
    Enable Memory Integrity for Credential Protection
  • ISM-1897Partially overlaps
    Enable Remote Credential Guard for Credential Protection
E8-RA-ML3.6
Enable Credential Guard for secure credential storage
Restrict admin privileges
  • ISM-1402Depends on
    Protecting Stored Credentials with Security Measures
  • ISM-1492Partially overlaps
    Enable Exploit Protection in Operating Systems
  • ISM-1686Equivalent
    Enable Credential Guard for Credential Protection
  • ISM-1745Depends on
    Enable Security Features for System Protection
  • ISM-1749Depends on
    Limit Cached Credentials to Single Logon
  • ISM-1829Depends on
    Prevent Password Storage in Group Policy Preferences
  • ISM-1861Depends on
    Enable Local Security Authority Protection
  • ISM-1896Depends on
    Enable Memory Integrity for Credential Protection
  • ISM-1897Partially overlaps
    Enable Remote Credential Guard for Credential Protection
E8-RA-ML3.7
Enable Remote Credential Guard functionality
Restrict admin privileges
  • ISM-1590Depends on
    Changing User Account Credentials After Compromise, Exposure or Shared Membership Change
  • ISM-1686Partially overlaps
    Enable Credential Guard for Credential Protection
  • ISM-1749Depends on
    Limit Cached Credentials to Single Logon
  • ISM-1861Depends on
    Enable Local Security Authority Protection
  • ISM-1896Depends on
    Enable Memory Integrity for Credential Protection
  • ISM-1897Equivalent
    Enable Remote Credential Guard for Credential Protection
E8-RA-ML3.8
Timely analysis of event logs from non-internet-facing servers
Restrict admin privileges
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-1625Supports
    Develop Insider Threat Mitigation Programs
  • ISM-1906Partially overlaps
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1907Equivalent
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1979Depends on
    Central Logging for Security Events on Servers
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
  • ISM-2116Partially meets
    Use Cyber Threat Intelligence for Event Detection
E8-RA-ML3.9
Timely analysis of workstation event logs for security events
Restrict admin privileges
  • ISM-1228Broader than
    Analyse Cyber Security Events Promptly
  • ISM-1537Partially overlaps
    Log Security-Relevant Database Events Centrally
  • ISM-1907Partially overlaps
    Timely Analysis of Non-Internet-Server Logs
  • ISM-1960Partially overlaps
    Timely Analysis of Event Logs for Cyber security
  • ISM-1961Partially overlaps
    Timely Analysis of Network Device Event Logs
  • ISM-1986Partially overlaps
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Partially meets
    Timely Analysis of Security Event Logs
  • ISM-2051Supports
    Ensure Event Logs for Cyber security Event Detection
E8-RB-ML1.1
Backups aligned with business continuity needs
Regular backups
  • ISM-0734Depends on
    CISO Role in Disaster Recovery Planning
  • ISM-1511Equivalent
    Conduct and Maintain Regular Data Backups
  • ISM-1515Depends on
    Test Backup Restoration During Disaster Recovery
  • ISM-1547Supports
    Develop and Maintain Data Backup Procedures
  • ISM-1548Depends on
    Develop and Maintain Data Restoration Processes
  • ISM-1555Partially meets
    Prepare Mobile Devices Before Overseas Travel
  • ISM-1732Depends on
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-1811Broader than
    Secure and Resilient Data Backup Retention
E8-RB-ML1.2
Ensure backups are synchronised for restoration to a common point in time
Regular backups
  • ISM-1511Partially meets
    Conduct and Maintain Regular Data Backups
  • ISM-1515Supports
    Test Backup Restoration During Disaster Recovery
  • ISM-1547Partially overlaps
    Develop and Maintain Data Backup Procedures
  • ISM-1548Partially overlaps
    Develop and Maintain Data Restoration Processes
  • ISM-1555Partially meets
    Prepare Mobile Devices Before Overseas Travel
  • ISM-1810Equivalent
    Ensuring Data Backup Synchronisation
  • ISM-1811Partially overlaps
    Secure and Resilient Data Backup Retention
E8-RB-ML1.3
Backups retained securely and resiliently
Regular backups
  • ISM-1511Partially overlaps
    Conduct and Maintain Regular Data Backups
  • ISM-1515Supports
    Test Backup Restoration During Disaster Recovery
  • ISM-1547Partially overlaps
    Develop and Maintain Data Backup Procedures
  • ISM-1548Depends on
    Develop and Maintain Data Restoration Processes
  • ISM-1769Depends on
    Using AES Encryption with Strong Key Lengths
  • ISM-1810Partially overlaps
    Ensuring Data Backup Synchronisation
  • ISM-1811Equivalent
    Secure and Resilient Data Backup Retention
  • ISM-1928Partially overlaps
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-2151Broader than
    Technically Enforced Immutability Protecting Backups Through Their Retention Period
E8-RB-ML1.4
Test backup restoration to a common point during disaster recovery
Regular backups
  • ISM-0917Supports
    Procedures for Handling Malicious Code Infections
  • ISM-1511Depends on
    Conduct and Maintain Regular Data Backups
  • ISM-1515Equivalent
    Test Backup Restoration During Disaster Recovery
  • ISM-1547Depends on
    Develop and Maintain Data Backup Procedures
  • ISM-1548Depends on
    Develop and Maintain Data Restoration Processes
  • ISM-1555Partially meets
    Prepare Mobile Devices Before Overseas Travel
  • ISM-1810Depends on
    Ensuring Data Backup Synchronisation
  • ISM-1811Depends on
    Secure and Resilient Data Backup Retention
E8-RB-ML1.5
Unprivileged accounts cannot access others' backups
Regular backups
  • ISM-1812Equivalent
    Restrict Backup Access to Unprivileged Users
  • ISM-1813Partially overlaps
    Prevent Unauthorised User Access to Backup Data
  • ISM-1852Broader than
    Limit Unprivileged Access to What Duties Require
E8-RB-ML1.6
Prevent unprivileged accounts from modifying and deleting backups
Regular backups
  • ISM-1707Partially overlaps
    Restrict Backup Modifications by Privileged Users
  • ISM-1708Partially overlaps
    Prevent Backup Modifications During Retention
  • ISM-1811Partially meets
    Secure and Resilient Data Backup Retention
  • ISM-1814Equivalent
    Prevent Backup Modifications by Unprivileged Users
  • ISM-1928Partially overlaps
    Encrypt Backups of Microsoft AD Servers
  • ISM-2151Partially overlaps
    Technically Enforced Immutability Protecting Backups Through Their Retention Period
  • ISM-2152Depends on
    Segregate Backup Infrastructure With Separate Administrative Authentication
E8-RB-ML2.1
Prevent privileged accounts from accessing others' backups
Regular backups
  • ISM-1705Equivalent
    Restrict Access to User Account Backups
  • ISM-1706Partially overlaps
    Prevent Backup Access by Privileged Users
  • ISM-1812Partially overlaps
    Restrict Backup Access to Unprivileged Users
  • ISM-1928Partially overlaps
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-2152Depends on
    Segregate Backup Infrastructure With Separate Administrative Authentication
E8-RB-ML2.2
Privileged accounts cannot modify or delete backups.
Regular backups
  • ISM-1705Supports
    Restrict Access to User Account Backups
  • ISM-1706Partially overlaps
    Prevent Backup Access by Privileged Users
  • ISM-1707Equivalent
    Restrict Backup Modifications by Privileged Users
  • ISM-1708Partially overlaps
    Prevent Backup Modifications During Retention
  • ISM-1811Partially meets
    Secure and Resilient Data Backup Retention
  • ISM-1814Partially overlaps
    Prevent Backup Modifications by Unprivileged Users
  • ISM-1928Supports
    Encrypt Backups of Microsoft AD Servers
  • ISM-2151Partially overlaps
    Technically Enforced Immutability Protecting Backups Through Their Retention Period
  • ISM-2152Depends on
    Segregate Backup Infrastructure With Separate Administrative Authentication
E8-RB-ML3.1
Unprivileged accounts cannot access their own backups
Regular backups
  • ISM-1811Partially meets
    Secure and Resilient Data Backup Retention
  • ISM-1813Equivalent
    Prevent Unauthorised User Access to Backup Data
  • ISM-1928Partially overlaps
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
E8-RB-ML3.2
Privileged accounts cannot access their own backups
Regular backups
  • ISM-1508Partially overlaps
    Restricting Privileged Access to What Duties Require
  • ISM-1706Equivalent
    Prevent Backup Access by Privileged Users
  • ISM-1708Supports
    Prevent Backup Modifications During Retention
  • ISM-1811Supports
    Secure and Resilient Data Backup Retention
  • ISM-1813Partially overlaps
    Prevent Unauthorised User Access to Backup Data
  • ISM-1928Partially meets
    Encrypt Backups of Microsoft AD Servers
  • ISM-2152Depends on
    Segregate Backup Infrastructure With Separate Administrative Authentication
E8-RB-ML3.3
Backup administrators cannot modify or delete backups during retention
Regular backups
  • ISM-1707Partially overlaps
    Restrict Backup Modifications by Privileged Users
  • ISM-1708Equivalent
    Prevent Backup Modifications During Retention
  • ISM-1811Partially meets
    Secure and Resilient Data Backup Retention
  • ISM-1814Partially overlaps
    Prevent Backup Modifications by Unprivileged Users
  • ISM-1928Partially overlaps
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-2151Partially overlaps
    Technically Enforced Immutability Protecting Backups Through Their Retention Period
E8-RM-ML1.1
Disable Microsoft Office macros for users without a business need
Configure macro settings
  • ISM-1489Supports
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1671Equivalent
    Disabling Microsoft Office Macros for Unauthorised Users
  • ISM-1674Partially overlaps
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Partially overlaps
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-2156Partially overlaps
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
E8-RM-ML1.2
Block Microsoft Office macros from the internet
Configure macro settings
  • ISM-1234Supports
    Protect Email Systems with Content Filtering
  • ISM-1488Equivalent
    Blocking Internet-Originating Macros in Office Files
  • ISM-1489Supports
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1671Supports
    Disabling Microsoft Office Macros for Unauthorised Users
  • ISM-1672Partially overlaps
    Enable Antivirus Scanning for Office Macros
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Supports
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1891Depends on
    Restrict Non-V3 Signed Macros in Microsoft Office
E8-RM-ML1.3
Enable antivirus scanning for Microsoft Office macros
Configure macro settings
  • ISM-1417Depends on
    Ensure Antivirus Protection on Workstations and Servers
  • ISM-1672Equivalent
    Enable Antivirus Scanning for Office Macros
  • ISM-1969Depends on
    Preventing Accidental Execution of Malicious Code
E8-RM-ML1.4
Prevent users from changing Microsoft Office macro security settings
Configure macro settings
  • ISM-1488Supports
    Blocking Internet-Originating Macros in Office Files
  • ISM-1489Equivalent
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1584Depends on
    Prevent Unauthorised Changes to Security Settings
  • ISM-1601Partially overlaps
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1671Depends on
    Disable Office Macros for Users Lacking a Demonstrated Business Requirement
  • ISM-1672Depends on
    Enable Antivirus Scanning for Office Macros
  • ISM-1673Depends on
    Prevent Win32 API Calls by Office Macros
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Depends on
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1748Partially overlaps
    Lock Email Client Security Settings Against User Changes
  • ISM-1823Partially meets
    Lock Office Productivity Suite Security Settings Against User Changes
  • ISM-1825Partially overlaps
    Lock Security Product Settings Against Changes by Human Users
  • ISM-1915Depends on
    Ensure User Application Configurations are Approved
E8-RM-ML2.1
Microsoft Office macros are blocked from making Win32 API calls
Configure macro settings
  • ISM-1489Supports
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1601Partially overlaps
    Implement Microsoft Attack Surface Reduction Rules
  • ISM-1667Partially overlaps
    Prevent Child Processes in Microsoft Office
  • ISM-1669Partially overlaps
    Prevent Microsoft Office from Injecting Code
  • ISM-1673Equivalent
    Prevent Win32 API Calls by Office Macros
  • ISM-1915Broader than
    Ensure User Application Configurations are Approved
E8-RM-ML3.1
Restrict Microsoft Office macros to only trusted or sandboxed environments
Configure macro settings
  • ISM-0843Supports
    Ensure Workstation Security with Application Control
  • ISM-1487Supports
    Restrict Macro Editing to Privileged Users
  • ISM-1488Partially meets
    Blocking Internet-Originating Macros in Office Files
  • ISM-1671Supports
    Disabling Microsoft Office Macros for Unauthorised Users
  • ISM-1672Partially overlaps
    Enable Antivirus Scanning for Office Macros
  • ISM-1673Partially overlaps
    Prevent Win32 API Calls by Office Macros
  • ISM-1674Equivalent
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Supports
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1676Depends on
    Validate Microsoft Office Trusted Publishers List At Least Annually
  • ISM-1796Supports
    Digitally Sign Executable Software for Security
  • ISM-1890Supports
    Ensure Macros Are Free of Malicious Code
  • ISM-1891Supports
    Restrict Non-V3 Signed Macros in Microsoft Office
  • ISM-2050Supports
    Validate Digital Signature Certificates Securely
E8-RM-ML3.2
Check Microsoft Office macros for malicious code before signing or trusting
Configure macro settings
  • ISM-1487Supports
    Restrict Macro Editing to Privileged Users
  • ISM-1672Supports
    Enable Antivirus Scanning for Office Macros
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Supports
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1796Partially overlaps
    Digitally Sign Executable Software for Security
  • ISM-1890Equivalent
    Ensure Macros Are Free of Malicious Code
  • ISM-1891Supports
    Restrict Non-V3 Signed Macros in Microsoft Office
  • ISM-1969Supports
    Preventing Accidental Execution of Malicious Code
  • ISM-2026Broader than
    Scan Software Artefacts for Malicious Content
  • ISM-2050Supports
    Validate Digital Signature Certificates Securely
E8-RM-ML3.3
Only privileged users can modify content in Trusted Locations
Configure macro settings
  • ISM-1392Partially overlaps
    Restrict File Modifications via Path Rules
  • ISM-1487Equivalent
    Restrict Macro Editing to Privileged Users
  • ISM-1508Partially overlaps
    Restricting Privileged Access to What Duties Require
  • ISM-1671Supports
    Disabling Microsoft Office Macros for Unauthorised Users
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1890Partially overlaps
    Ensure Macros Are Free of Malicious Code
E8-RM-ML3.4
Untrusted Publisher Macros Cannot Be Enabled via Message Bar or Backstage View
Configure macro settings
  • ISM-1489Supports
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1674Partially meets
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Equivalent
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1676Supports
    Validate Microsoft Office Trusted Publishers List At Least Annually
  • ISM-1891Partially overlaps
    Restrict Non-V3 Signed Macros in Microsoft Office
E8-RM-ML3.5
Block enabling of non-V3 signed Microsoft Office macros via Message Bar
Configure macro settings
  • ISM-1489Depends on
    Prevent Users from Changing Office Macro Security Settings
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Partially overlaps
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1823Depends on
    Lock Office Productivity Suite Security Settings Against User Changes
  • ISM-1891Equivalent
    Restrict Non-V3 Signed Macros in Microsoft Office
E8-RM-ML3.6
Validate list of trusted publishers in Microsoft Office annually
Configure macro settings
  • ISM-1582Partially meets
    Annual Validation of Application Control Rulesets
  • ISM-1674Depends on
    Ensuring Secure Execution of Microsoft Office Macros
  • ISM-1675Supports
    Prevent Enabling Untrusted Microsoft Office Macros
  • ISM-1676Equivalent
    Validate Microsoft Office Trusted Publishers List At Least Annually

How to use this mapping

Read it in whichever direction you are being assessed. If Essential Eight is your primary framework, use the table to find the ASD ISM controls that cover the same ground, so evidence you already hold can be reused instead of rebuilt. If ASD ISM is what you are being held to, work back from the counterpart column to see which Essential Eight controls contribute. A mapping means the two controls address related risk, not that satisfying one satisfies the other, so always read the relationship label before relying on it.

Frequently asked questions

How do the Essential Eight and the ASD ISM relate?

Both are published by the Australian Signals Directorate. The Essential Eight is a prioritised set of eight mitigation strategies drawn from ASD’s Strategies to Mitigate Cyber Security Incidents, and the ISM carries controls that implement those strategies in detail. This mapping shows which ISM controls sit behind each Essential Eight requirement.

If I reach Maturity Level Two, how much of the ISM have I covered?

A small share. The Essential Eight concentrates on eight technical areas, mostly patching, application control, macros, hardening, administrative privileges, multi-factor authentication and backups. The ISM spans governance, personnel security, physical security, cryptography, gateways, software development and data transfers as well, so most ISM controls have no Essential Eight counterpart at all.

Why are Essential Eight controls numbered by maturity level?

Control Stack renders the Essential Eight Maturity Model as separate, testable controls, one per requirement per level, using keys such as E8-AC-ML2.3. That makes each requirement individually trackable and lets a mapping point at the exact maturity level a given ISM control supports, rather than at a whole strategy.

Is this mapping official?

No. ASD does not publish a control-level crosswalk between the Essential Eight Maturity Model and the ISM. This mapping is produced by Control Stack from the control text of both and reviewed for topic fidelity. Use it for planning and evidence reuse rather than as an authoritative statement from ASD.