| E8-AC-ML1.1 Application control is implemented on workstations. | Application control | - ISM-0843Equivalent
Ensure Workstation Security with Application Control - ISM-0846Supports
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-0955Supports
Implementing Application Control Measures - ISM-1235Partially overlaps
Restrict User Application Extensions - ISM-1490Partially overlaps
Implement Application Control on Internet-Facing Servers - ISM-1491Partially overlaps
Block Unprivileged Users From Running Script Execution Engines - ISM-1493Supports
Maintain and Verify Software Registers - ISM-1544Supports
Implement Microsoft's Application Blocklist - ISM-1656Partially overlaps
Implement Application Control on Secure Servers - ISM-1657Partially meets
Restrict Application Execution to Approved Set - ISM-1658Broader than
Restrict Execution of Drivers via Application Control - ISM-2023Supports
Maintain a Reliable Source for Software - ISM-2149Depends on
Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
|
| E8-AC-ML1.2 Application control is applied to user profiles and temporary folders | Application control | - ISM-0382Partially overlaps
Restrict Unprivileged User Actions on Applications - ISM-0843Partially meets
Ensure Workstation Security with Application Control - ISM-0846Supports
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-0955Partially overlaps
Implementing Application Control Measures - ISM-1235Supports
Restrict User Application Extensions - ISM-1392Supports
Restrict File Modifications via Path Rules - ISM-1491Depends on
Block Unprivileged Users From Running Script Execution Engines - ISM-1544Supports
Implement Microsoft's Application Blocklist - ISM-1592Partially overlaps
Prevent Unauthorised Application Installations by Users - ISM-1635Partially meets
System Owners Implement Security Controls for Each System and Environment - ISM-1657Partially meets
Restrict Application Execution to Approved Set - ISM-1658Partially overlaps
Restrict Execution of Drivers via Application Control - ISM-1746Supports
Restrict File System Permission Changes - ISM-1870Equivalent
Implement Application Control for User Profiles and Folders - ISM-1871Partially overlaps
Implement Application Control Exclusions for System Areas
|
| E8-AC-ML1.3 Ensure only approved applications and scripts can run | Application control | - ISM-0341Partially overlaps
Disable Automatic Execution for Removable Media - ISM-0843Supports
Ensure Workstation Security with Application Control - ISM-0846Supports
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-0863Partially meets
Prevent Installation of Unapproved Mobile Apps - ISM-0955Supports
Implementing Application Control Measures - ISM-1235Partially overlaps
Restrict User Application Extensions - ISM-1392Supports
Restrict File Modifications via Path Rules - ISM-1471Supports
Utilise Publisher and Product Names in App Control - ISM-1491Partially meets
Prevent Script Execution by Unprivileged Users - ISM-1592Partially overlaps
Prevent Unauthorised Application Installations by Users - ISM-1622Partially overlaps
Ensure PowerShell Uses Constrained Language Mode - ISM-1657Equivalent
Restrict Application Execution to Approved Set - ISM-1658Broader than
Restrict Execution of Drivers via Application Control - ISM-1668Partially overlaps
Prevent Microsoft Office from Creating Executable Files - ISM-1870Depends on
Implement Application Control for User Profiles and Folders - ISM-2026Depends on
Scan Software Artefacts for Malicious Content - ISM-2115Partially overlaps
Restrict Server Application Extensions to an Approved Set - ISM-2149Depends on
Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
|
| E8-AC-ML2.1 Application control is implemented on internet-facing servers | Application control | - ISM-0955Supports
Implementing Application Control Measures - ISM-1392Depends on
Restrict File Modifications via Path Rules - ISM-1483Depends on
Use Latest Release of Internet-Facing Server Applications - ISM-1490Equivalent
Implement Application Control on Internet-Facing Servers - ISM-1656Partially overlaps
Implement Application Control on Secure Servers - ISM-1657Supports
Restrict Application Execution to Approved Set - ISM-1658Supports
Restrict Execution of Drivers via Application Control - ISM-1746Depends on
Restrict File System Permission Changes - ISM-1871Depends on
Implement Application Control Exclusions for System Areas - ISM-2115Depends on
Restrict Server Application Extensions to an Approved Set - ISM-2149Depends on
Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
|
| E8-AC-ML2.2 Application control excludes user profiles and temporary folders | Application control | - ISM-0843Partially meets
Ensure Workstation Security with Application Control - ISM-0846Partially overlaps
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-0955Partially overlaps
Implementing Application Control Measures - ISM-1234Supports
Protect Email Systems with Content Filtering - ISM-1392Depends on
Restrict File Modifications via Path Rules - ISM-1490Depends on
Implement Application Control on Internet-Facing Servers - ISM-1544Supports
Implement Microsoft's Application Blocklist - ISM-1656Depends on
Implement Application Control on Secure Servers - ISM-1657Partially overlaps
Restrict Application Execution to Approved Set - ISM-1746Depends on
Restrict File System Permission Changes - ISM-1871Equivalent
Implement Application Control Exclusions for System Areas - ISM-2115Depends on
Restrict Server Application Extensions to an Approved Set
|
| E8-AC-ML2.3 Microsoft's recommended application blocklist is implemented | Application control | - ISM-0843Partially meets
Ensure Workstation Security with Application Control - ISM-0955Depends on
Implementing Application Control Measures - ISM-1544Equivalent
Implement Microsoft's Application Blocklist - ISM-1601Partially overlaps
Implement Microsoft Attack Surface Reduction Rules - ISM-1657Partially meets
Restrict Application Execution to Approved Set - ISM-1659Partially overlaps
Implement Microsoft's Vulnerable Driver Blocklist
|
| E8-AC-ML2.4 Annual validation of application control rulesets | Application control | - ISM-0843Supports
Ensure Workstation Security with Application Control - ISM-0955Supports
Implementing Application Control Measures - ISM-1471Depends on
Utilise Publisher and Product Names in App Control - ISM-1582Equivalent
Annual Validation of Application Control Rulesets - ISM-1657Depends on
Restrict Application Execution to Approved Set - ISM-1658Depends on
Restrict Execution of Drivers via Application Control - ISM-1660Depends on
Central Logging of Application Events - ISM-1676Partially overlaps
Validate Microsoft Office Trusted Publishers List At Least Annually - ISM-2115Depends on
Restrict Server Application Extensions to an Approved Set
|
| E8-AC-ML2.5 Allowed and blocked application control events are centrally logged | Application control | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0670Partially meets
Central Logging of CDS Security Events - ISM-0955Depends on
Implementing Application Control Measures - ISM-0988Depends on
Ensure Accurate Time Source for Event Logs - ISM-1405Depends on
Implement a Centralised Event Logging Facility - ISM-1660Equivalent
Central Logging of Application Events - ISM-1976Partially overlaps
Central Logging of Security Events on macOS - ISM-1977Partially overlaps
Central Logging of Linux System Events - ISM-1978Partially overlaps
Centralised Logging for Server Application Events - ISM-1979Partially overlaps
Central Logging for Security Events on Servers - ISM-1983Supports
Log Events Sent to Centralised Facility Quickly - ISM-2129Partially overlaps
Centrally Log WMI Activity and Event Subscriptions
|
| E8-AC-ML2.6 Event logs are protected from unauthorised modification and deletion | Application control | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0582Supports
Central Logging of Windows Security Events - ISM-0585Depends on
Capture Detailed Information in Event Logs - ISM-0634Supports
Central Logging for Gateway Security Events - ISM-1405Supports
Implement a Centralised Event Logging Facility - ISM-1624Broader than
Protect PowerShell Script Block Logs - ISM-1660Depends on
Central Logging of Application Events - ISM-1815Equivalent
Protect Event Logs from Unauthorised Access - ISM-1910Depends on
Log Network API Calls for Data Protection - ISM-1976Partially overlaps
Central Logging of Security Events on macOS - ISM-1985Partially overlaps
Protect Event Logs from Unauthorised Access - ISM-1989Depends on
Ensure Event Logs Meet Retention Requirements - ISM-2015Depends on
Central Logging of Non-Internet Network API Data Access - ISM-2046Partially overlaps
Ensure Secure Impersonation Logging Practices - ISM-2052Partially overlaps
Ensure Event Logs Protect Sensitive Data - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AC-ML2.7 Event logs from internet-facing servers are analysed to detect cyber security events | Application control | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1906Equivalent
Timely Analysis of Internet-Facing Server Logs - ISM-1910Supports
Log Network API Calls for Data Protection - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cyber security - ISM-1978Depends on
Centralised Logging for Server Application Events - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2144Depends on
Change Application Static Credentials Found Compromised or Exposed in Clear
|
| E8-AC-ML2.8 Cyber security events are analysed in a timely manner | Application control | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Equivalent
Analyse Cyber Security Events Promptly - ISM-1430Depends on
Configure IPv6 Addresses with DHCPv6 in Stateful Mode - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1906Partially meets
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially meets
Timely Analysis of Non-Internet-Server Logs - ISM-1960Supports
Timely Analysis of Event Logs for Cybersecurity - ISM-1961Broader than
Timely Analysis of Network Device Event Logs - ISM-1986Partially meets
Timely Analysis of Critical Server Event Logs - ISM-1987Partially meets
Timely Analysis of Security Event Logs - ISM-2116Depends on
Use Cyber Threat Intelligence for Event Detection - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AC-ML2.9 Cyber security incidents are reported promptly to CISO | Application control | - ISM-0123Equivalent
Report Cyber Security Incidents Promptly - ISM-0125Depends on
Maintaining a Cyber Security Incident Register - ISM-0140Partially overlaps
Prompt Reporting of Cyber Incidents to ASD - ISM-0142Broader than
Report Cryptographic Equipment Compromises Promptly - ISM-0714Partially meets
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-0733Supports
Ensure CISO Awareness of Cyber Incidents - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1618Supports
CISO's Role in Cyber Security Incident Response - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents - ISM-1819Partially overlaps
Enact Cyber Security Incident Response Plans
|
| E8-AC-ML2.10 Report cyber security incidents to ASD quickly | Application control | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0140Equivalent
Prompt Reporting of Cyber Incidents to ASD - ISM-0142Partially overlaps
Report Cryptographic Equipment Compromises Promptly
|
| E8-AC-ML2.11 Cyber security incident response plan is enacted after incident identification | Application control | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0576Depends on
Develop and Maintain Cyber Security Incident Plans - ISM-1731Depends on
Plan and Coordinate Intrusion Remediation From Trusted Separate Systems - ISM-1819Equivalent
Enact Cyber Security Incident Response Plans
|
| E8-AC-ML3.1 Application control is implemented on non-internet-facing servers | Application control | - ISM-0955Broader than
Implementing Application Control Measures - ISM-1490Partially overlaps
Implement Application Control on Internet-Facing Servers - ISM-1493Supports
Maintain and Verify Software Registers - ISM-1544Supports
Implement Microsoft's Application Blocklist - ISM-1656Equivalent
Implement Application Control on Secure Servers - ISM-1657Supports
Restrict Application Execution to Approved Set - ISM-1658Depends on
Restrict Execution of Drivers via Application Control - ISM-1871Partially overlaps
Implement Application Control Exclusions for System Areas - ISM-1926Supports
Ensure Exclusive Usage of Microsoft AD Servers - ISM-2115Depends on
Restrict Server Application Extensions to an Approved Set
|
| E8-AC-ML3.2 Application control restricts driver execution to an approved set | Application control | - ISM-0955Partially overlaps
Implementing Application Control Measures - ISM-1392Supports
Restrict File Modifications via Path Rules - ISM-1656Broader than
Implement Application Control on Secure Servers - ISM-1657Partially meets
Restrict Application Execution to Approved Set - ISM-1658Equivalent
Restrict Execution of Drivers via Application Control - ISM-1746Supports
Restrict File System Permission Changes
|
| E8-AC-ML3.3 Microsoft's vulnerable driver blocklist is implemented | Application control | - ISM-0298Partially overlaps
Centralised System Patch and Update Management - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1163Partially overlaps
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1492Partially overlaps
Enable Exploit Protection in Operating Systems - ISM-1643Supports
Maintain Detailed Software Version and Patch Records - ISM-1659Equivalent
Implement Microsoft's Vulnerable Driver Blocklist - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-1808Depends on
Vulnerability Scanning with Updated Tools
|
| E8-AC-ML3.4 Event logs from non-internet-facing servers are analysed | Application control | - ISM-0580Depends on
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1228Broader than
Analyse Cyber Security Events Promptly - ISM-1830Depends on
Central Logging for Microsoft AD Server Activities - ISM-1906Partially overlaps
Timely Analysis of Internet-Facing Server Logs - ISM-1907Equivalent
Timely Analysis of Non-Internet-Server Logs - ISM-1911Depends on
Centralised Logging of Software Errors and Usage - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cyber security - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-2051Depends on
Ensure Event Logs for Cybersecurity Event Detection - ISM-2129Depends on
Centrally Log WMI Activity and Event Subscriptions - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AC-ML3.5 Workstation event logs are promptly analysed for security events | Application control | - ISM-1228Partially meets
Analyse Cyber Security Events Promptly - ISM-1889Supports
Central Logging of Command Line Events - ISM-1987Partially meets
Timely Analysis of Security Event Logs - ISM-2051Depends on
Ensure Event Logs for Cybersecurity Event Detection - ISM-2125Partially overlaps
Independently Log and Analyse All Service Provider System Access
|
| E8-AH-ML1.1 Disable or remove Internet Explorer 11 | User application hardening | - ISM-0380Partially meets
Disable Unneeded OS Accounts and Services - ISM-1470Partially meets
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1654Equivalent
Disable or Remove Internet Explorer 11 - ISM-1798Partially meets
Develop Secure Configuration Guidelines for Software - ISM-1809Depends on
Compensating Controls for Unsupported Systems Pending Removal or Replacement - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1915Depends on
Ensure User Application Configurations are Approved - ISM-2110Partially meets
Hardening User Applications with ASD and Vendor Guidance
|
| E8-AH-ML1.2 Web browsers must not execute Java content from the internet | User application hardening | - ISM-0260Supports
Ensure All Web Access Uses Proxies - ISM-0958Supports
Implement Domain Name Allow and Block Lists - ISM-0961Broader than
Restrict Active Content with Web Filters - ISM-0963Partially overlaps
Implementing Web Content Filters for Safety - ISM-1485Partially overlaps
Prevent Web Browsers from Processing Ads - ISM-1486Equivalent
Restrict Java Processing in Web Browsers - ISM-1585Supports
Prevent User Changes to Browser Security Settings - ISM-2110Partially meets
Hardening User Applications with ASD and Vendor Guidance
|
| E8-AH-ML1.3 Web browsers block web ads from the internet | User application hardening | - ISM-0958Supports
Implement Domain Name Allow and Block Lists - ISM-0963Partially meets
Implementing Web Content Filters for Safety - ISM-1485Equivalent
Prevent Web Browsers from Processing Ads
|
| E8-AH-ML1.4 Web browser security settings locked down to users | User application hardening | - ISM-0382Partially overlaps
Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications - ISM-1235Partially overlaps
Restrict User Application Extensions - ISM-1412Partially meets
Web Browser Hardening with Strict Guidelines - ISM-1486Depends on
Restrict Java Processing in Web Browsers - ISM-1584Depends on
Prevent Unauthorised Changes to Security Settings - ISM-1585Equivalent
Prevent User Changes to Browser Security Settings - ISM-1748Partially overlaps
Lock Email Client Security Settings Against User Changes - ISM-1825Partially overlaps
Lock Security Product Settings Against Changes by Human Users
|
| E8-AH-ML2.1 Web browsers are hardened with the most restrictive guidance | User application hardening | - ISM-0290Supports
Secure Configuration of High Assurance IT Equipment - ISM-1235Partially overlaps
Restrict User Application Extensions - ISM-1246Broader than
Apply Strict Server Application Hardening Guidelines - ISM-1412Equivalent
Web Browser Hardening with Strict Guidelines - ISM-1470Partially overlaps
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1485Partially meets
Prevent Web Browsers from Processing Ads - ISM-1486Partially meets
Restrict Java Processing in Web Browsers - ISM-1585Supports
Prevent User Changes to Browser Security Settings - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software - ISM-1858Broader than
Implement Strict IT Equipment Hardening Guidelines
|
| E8-AH-ML2.2 Block Microsoft Office from creating child processes | User application hardening | - ISM-0843Partially meets
Ensure Workstation Security with Application Control - ISM-0955Partially meets
Implementing Application Control Measures - ISM-1542Partially overlaps
Disable OLE in Microsoft Office for Security - ISM-1601Equivalent
Implement Microsoft Attack Surface Reduction Rules - ISM-1667Equivalent
Prevent Child Processes in Microsoft Office - ISM-1668Partially overlaps
Prevent Microsoft Office from Creating Executable Files - ISM-1669Partially overlaps
Prevent Microsoft Office from Injecting Code - ISM-1670Partially overlaps
Prevent PDF Applications from Creating Child Processes - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1859Partially meets
Hardening Office Productivity Suites - ISM-2110Partially meets
Hardening User Applications with ASD and Vendor Guidance
|
| E8-AH-ML2.3 Block Microsoft Office from creating executable content | User application hardening | - ISM-1542Depends on
Disable OLE in Microsoft Office for Security - ISM-1667Partially overlaps
Prevent Child Processes in Microsoft Office - ISM-1668Equivalent
Prevent Microsoft Office from Creating Executable Files - ISM-1669Partially overlaps
Prevent Microsoft Office from Injecting Code - ISM-1672Partially overlaps
Enable Antivirus Scanning for Office Macros - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1823Depends on
Prevent Users from Changing Security Settings in Apps - ISM-1969Partially overlaps
Preventing Accidental Execution of Malicious Code
|
| E8-AH-ML2.4 Block Microsoft Office from injecting code into other processes | User application hardening | - ISM-1542Supports
Disable OLE in Microsoft Office for Security - ISM-1601Equivalent
Implement Microsoft Attack Surface Reduction Rules - ISM-1667Partially overlaps
Prevent Child Processes in Microsoft Office - ISM-1668Partially overlaps
Prevent Microsoft Office from Creating Executable Files - ISM-1669Equivalent
Prevent Microsoft Office from Injecting Code - ISM-1670Partially overlaps
Prevent PDF Applications from Creating Child Processes - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1858Broader than
Implement Strict IT Equipment Hardening Guidelines
|
| E8-AH-ML2.5 Configure Microsoft Office to prevent activation of OLE packages | User application hardening | - ISM-0289Partially overlaps
Implement and Manage Evaluated Products Correctly - ISM-1536Equivalent
Centrally Log User-Initiated Database Queries and Errors - ISM-1542Equivalent
Disable OLE in Microsoft Office for Security - ISM-1601Depends on
Implement Microsoft Attack Surface Reduction Rules - ISM-1667Partially overlaps
Prevent Child Processes in Microsoft Office - ISM-1668Partially overlaps
Prevent Microsoft Office from Creating Executable Files - ISM-1669Partially overlaps
Prevent Microsoft Office from Injecting Code - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software - ISM-1858Broader than
Implement Strict IT Equipment Hardening Guidelines - ISM-1913Depends on
Develop and Maintain Approved IT Configurations - ISM-1915Depends on
Ensure User Application Configurations are Approved - ISM-2110Partially meets
Hardening User Applications with ASD and Vendor Guidance
|
| E8-AH-ML2.6 Office productivity suites are hardened using ASD and vendor guidance | User application hardening | - ISM-0289Partially overlaps
Implement and Manage Evaluated Products Correctly - ISM-0290Depends on
Secure Configuration of High Assurance IT Equipment - ISM-1235Broader than
Restrict User Application Extensions - ISM-1246Partially meets
Apply Strict Server Application Hardening Guidelines - ISM-1668Partially meets
Prevent Microsoft Office from Creating Executable Files - ISM-1798Supports
Develop Secure Configuration Guidelines for Software - ISM-1823Depends on
Lock Office Productivity Suite Security Settings Against User Changes - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1859Equivalent
Hardening Office Productivity Suites - ISM-1915Partially meets
Ensure User Application Configurations are Approved
|
| E8-AH-ML2.7 Office productivity suite settings are immutable by users | User application hardening | - ISM-0382Partially overlaps
Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications - ISM-1489Partially overlaps
Prevent Users from Changing Office Macro Security Settings - ISM-1536Depends on
Central Logging of Software Database Queries and Errors - ISM-1542Supports
Disable OLE in Microsoft Office for Security - ISM-1585Partially overlaps
Lock Web Browser Security Settings Against Human User Changes - ISM-1669Broader than
Prevent Microsoft Office from Injecting Code - ISM-1673Supports
Prevent Win32 API Calls by Office Macros - ISM-1748Partially overlaps
Lock Email Client Security Settings Against User Changes - ISM-1823Equivalent
Prevent Users from Changing Security Settings in Apps - ISM-1824Partially overlaps
Lock PDF Application Security Settings Against User Changes - ISM-1825Partially overlaps
Lock Security Product Settings Against Changes by Human Users - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1859Partially meets
Hardening Office Productivity Suites - ISM-1915Depends on
Ensure User Application Configurations are Approved
|
| E8-AH-ML2.8 Block PDF software from creating child processes | User application hardening | - ISM-0843Supports
Ensure Workstation Security with Application Control - ISM-0846Supports
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-1470Broader than
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1670Equivalent
Prevent PDF Applications from Creating Child Processes - ISM-1824Supports
Prevent Changes to PDF Application Security Settings
|
| E8-AH-ML2.9 Ensure PDF software is securely configured using guidance. | User application hardening | - ISM-0289Partially overlaps
Implement and Manage Evaluated Products Correctly - ISM-1246Partially meets
Apply Strict Server Application Hardening Guidelines - ISM-1406Depends on
Use SOEs for Workstations and Servers - ISM-1470Partially overlaps
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1670Supports
Prevent PDF Applications from Creating Child Processes - ISM-1798Supports
Develop Secure Configuration Guidelines for Software - ISM-1824Partially overlaps
Prevent Changes to PDF Application Security Settings - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1859Partially overlaps
Hardening Office Productivity Suites - ISM-1860Equivalent
Harden PDF Applications Using ASD Guidance - ISM-1915Depends on
Ensure User Application Configurations are Approved
|
| E8-AH-ML2.10 PDF software security settings cannot be changed by users | User application hardening | - ISM-1406Depends on
Use SOEs for Workstations and Servers - ISM-1489Partially overlaps
Prevent Users from Changing Office Macro Security Settings - ISM-1585Partially overlaps
Prevent User Changes to Browser Security Settings - ISM-1670Supports
Prevent PDF Applications from Creating Child Processes - ISM-1748Partially overlaps
Lock Email Client Security Settings Against User Changes - ISM-1823Partially overlaps
Prevent Users from Changing Security Settings in Apps - ISM-1824Equivalent
Prevent Changes to PDF Application Security Settings - ISM-1825Partially meets
Lock Security Product Settings Against Changes by Human Users - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1915Depends on
Ensure User Application Configurations are Approved - ISM-2110Partially meets
Hardening User Applications with ASD and Vendor Guidance
|
| E8-AH-ML2.11 Centrally log PowerShell module, script block, and transcription events | User application hardening | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0582Partially overlaps
Central Logging of Windows Security Events - ISM-0988Depends on
Ensure Accurate Time Source for Event Logs - ISM-1405Depends on
Implement a Centralised Event Logging Facility - ISM-1621Depends on
Disable or Remove Windows PowerShell 2.0 - ISM-1622Partially overlaps
Ensure PowerShell Uses Constrained Language Mode - ISM-1623Equivalent
Centralised Logging of PowerShell Activities - ISM-1624Partially overlaps
Protect PowerShell Script Block Logs - ISM-1889Partially overlaps
Central Logging of Command Line Events - ISM-1983Depends on
Log Events Sent to Centralised Facility Quickly - ISM-1989Partially overlaps
Ensure Event Logs Meet Retention Requirements - ISM-2132Partially overlaps
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2159Partially overlaps
Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
|
| E8-AH-ML2.12 Command line process creation logging is centralised | User application hardening | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0582Supports
Central Logging of Windows Security Events - ISM-0585Supports
Capture Detailed Information in Event Logs - ISM-0670Partially meets
Central Logging of CDS Security Events - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Depends on
Analyse Cyber Security Events Promptly - ISM-1405Partially meets
Implement a Centralised Event Logging Facility - ISM-1607Partially overlaps
Integrity Monitoring and Logging for Isolation Mechanism - ISM-1623Partially overlaps
Centralised Logging of PowerShell Activities - ISM-1889Equivalent
Central Logging of Command Line Events - ISM-1907Supports
Timely Analysis of Non-Internet-Server Logs - ISM-1976Supports
Central Logging of Security Events on macOS - ISM-1977Supports
Central Logging of Linux System Events - ISM-1983Depends on
Log Events Sent to Centralised Facility Quickly - ISM-1986Supports
Timely Analysis of Critical Server Event Logs - ISM-2051Supports
Ensure Event Logs for Cybersecurity Event Detection - ISM-2132Partially overlaps
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AH-ML2.13 Protect event logs from unauthorised changes or deletion | User application hardening | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0138Supports
Maintaining Integrity of Evidence in Investigations - ISM-0582Partially overlaps
Central Logging of Windows Security Events - ISM-1509Depends on
Log Privileged Access Events Centrally for Monitoring - ISM-1624Partially meets
Protect PowerShell Script Block Logs - ISM-1815Equivalent
Protect Event Logs from Unauthorised Access - ISM-1830Depends on
Central Logging of Security Events for Microsoft AD Infrastructure Servers - ISM-1910Supports
Log Network API Calls for Data Protection - ISM-1985Partially meets
Protect Event Logs from Unauthorised Access - ISM-1989Supports
Ensure Event Logs Meet Retention Requirements - ISM-2125Partially overlaps
Independently Log and Analyse All Service Provider System Access - ISM-2132Partially overlaps
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2159Depends on
Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
|
| E8-AH-ML2.14 Timely Analysis of Event Logs from Internet-Facing Servers | User application hardening | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1228Partially meets
Analyse Cyber Security Events Promptly - ISM-1624Supports
Protect PowerShell Script Block Logs - ISM-1906Equivalent
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cybersecurity - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1963Partially overlaps
Central Logging of Events on Internet-Facing Devices - ISM-1978Depends on
Centralised Logging for Server Application Events - ISM-1983Depends on
Log Events Sent to Centralised Facility Quickly - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially overlaps
Timely Analysis of Security Event Logs - ISM-2051Depends on
Ensure Event Logs for Cybersecurity Event Detection - ISM-2125Partially overlaps
Independently Log and Analyse All Service Provider System Access - ISM-2129Depends on
Centrally Log WMI Activity and Event Subscriptions
|
| E8-AH-ML2.15 Timely Analysis of Cyber Security Events to Identify Incidents | User application hardening | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0634Depends on
Central Logging for Gateway Security Events - ISM-0660Supports
Monthly Verification of Data Transfer Logs for SECRET Systems - ISM-1030Depends on
Deploy NIDS/NIPS for Gateway Traffic Monitoring - ISM-1228Equivalent
Analyse Cyber Security Events Promptly - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1556Depends on
Security Measures After Overseas Travel with Mobile Devices - ISM-1625Depends on
Develop Insider Threat Mitigation Programs - ISM-1683Depends on
Central Logging of Multi-factor Authentication Events - ISM-1830Depends on
Central Logging for Microsoft AD Server Activities - ISM-1911Depends on
Centralised Logging of Software Errors and Usage - ISM-1986Partially meets
Timely Analysis of Critical Server Event Logs - ISM-2089Broader than
Monitor AI Model Performance and Investigate Anomalies - ISM-2117Depends on
AI Models Augment Cyber Security Event Detection - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AH-ML2.16 Cyber security incidents must be reported immediately to the CISO | User application hardening | - ISM-0043Partially meets
Cyber Security Incident Response Plan Requirements - ISM-0123Equivalent
Report Cyber Security Incidents Promptly - ISM-0125Supports
Maintaining a Cyber Security Incident Register - ISM-0140Partially overlaps
Prompt Reporting of Cyber Incidents to ASD - ISM-0141Supports
Report Cyber Incidents Promptly to Designated Contacts - ISM-0142Partially overlaps
Report Cryptographic Equipment Compromises Promptly - ISM-0576Partially meets
Develop and Maintain Cyber Security Incident Plans - ISM-0714Broader than
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-0733Equivalent
Ensure CISO Awareness of Cyber Incidents - ISM-1088Partially overlaps
Report Potential Compromises of Mobile Devices Overseas - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1618Partially overlaps
CISO's Role in Cyber Security Incident Response - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents - ISM-1819Partially overlaps
Enact Cyber Security Incident Response Plans - ISM-1881Supports
Timely Reporting of Cyber Incidents Without Data Breach
|
| E8-AH-ML2.17 Report cyber security incidents to ASD promptly | User application hardening | - ISM-0043Partially meets
Cyber Security Incident Response Plan Requirements - ISM-0123Supports
Report Cyber Security Incidents Promptly - ISM-0140Equivalent
Prompt Reporting of Cyber Incidents to ASD - ISM-0141Supports
Report Cyber Incidents Promptly to Designated Contacts
|
| E8-AH-ML2.18 Cyber incident response plan is enacted after identification | User application hardening | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0123Supports
Report Cyber Security Incidents Promptly - ISM-0576Depends on
Develop and Maintain Cyber Security Incident Plans - ISM-1618Depends on
CISO's Role in Cyber Security Incident Response - ISM-1819Equivalent
Enact Cyber Security Incident Response Plans
|
| E8-AH-ML3.1 .NET Framework 3.5, 3.0, 2.0 is disabled or removed | User application hardening | - ISM-1246Partially overlaps
Apply Strict Server Application Hardening Guidelines - ISM-1409Partially meets
Implement Restrictive OS Hardening Guidelines - ISM-1470Partially meets
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1621Partially overlaps
Disable or Remove Windows PowerShell 2.0 - ISM-1655Equivalent
Ensure .NET Framework 3.5 is Disabled or Removed - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software
|
| E8-AH-ML3.2 Ensure Windows PowerShell 2.0 is disabled or removed | User application hardening | - ISM-0380Partially meets
Disable Unneeded OS Accounts and Services - ISM-1246Partially overlaps
Apply Strict Server Application Hardening Guidelines - ISM-1247Partially meets
Disable or Remove Unneeded Server Features - ISM-1409Partially meets
Implement Restrictive OS Hardening Guidelines - ISM-1470Partially meets
Disable Unneeded Accounts, Components, Services and Application Functionality - ISM-1584Depends on
Prevent Unauthorised Changes to Security Settings - ISM-1621Equivalent
Disable or Remove Windows PowerShell 2.0 - ISM-1622Supports
Ensure PowerShell Uses Constrained Language Mode - ISM-1655Partially overlaps
Ensure .NET Framework 3.5 is Disabled or Removed - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1914Partially meets
Ensure Operating Systems Have Approved Configurations
|
| E8-AH-ML3.3 PowerShell is configured to use Constrained Language Mode | User application hardening | - ISM-0380Partially meets
Disable Unneeded OS Accounts and Services - ISM-1246Partially overlaps
Apply Strict Server Application Hardening Guidelines - ISM-1409Partially meets
Implement Restrictive OS Hardening Guidelines - ISM-1491Partially overlaps
Block Unprivileged Users From Running Script Execution Engines - ISM-1621Depends on
Disable or Remove Windows PowerShell 2.0 - ISM-1622Equivalent
Ensure PowerShell Uses Constrained Language Mode - ISM-1798Partially meets
Develop Secure Configuration Guidelines for Software - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines
|
| E8-AH-ML3.4 Analyse event logs from non-internet-facing servers for cyber threats | User application hardening | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0988Supports
Ensure Accurate Time Source for Event Logs - ISM-1228Partially meets
Analyse Cyber Security Events Promptly - ISM-1907Equivalent
Timely Analysis of Non-Internet-Server Logs - ISM-1979Depends on
Central Logging for Security Events on Servers - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-2125Partially overlaps
Independently Log and Analyse All Service Provider System Access - ISM-2129Depends on
Centrally Log WMI Activity and Event Subscriptions - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
|
| E8-AH-ML3.5 Timely Analysis of Workstation Event Logs for Cyber security | User application hardening | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0580Depends on
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1228Broader than
Analyse Cyber Security Events Promptly - ISM-1906Partially overlaps
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cyber security - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially overlaps
Timely Analysis of Security Event Logs - ISM-2051Depends on
Ensure Event Logs for Cybersecurity Event Detection
|
| E8-MF-ML1.1 Require multi-factor authentication for sensitive online services | Multi-factor authentication | - ISM-0553Supports
Authenticate Video Calls and Manage Settings - ISM-0619Depends on
User Authentication for Network Gateway Access - ISM-1401Supports
Implement Multi-Factor Authentication for Security - ISM-1504Equivalent
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1505Partially overlaps
Implement Multi-factor Authentication for Data Repositories - ISM-1546Partially meets
Ensure User Authentication Before System Access - ISM-1679Partially overlaps
Multi-factor Authentication for Third-party Services Handling Sensitive Data - ISM-1681Partially overlaps
Mandating Multi-Factor Authentication for Customer Services - ISM-1682Partially meets
Enhance User Security with Phishing-resistant MFA - ISM-1872Supports
Ensuring Phishing-Resistant Multi-Factor Authentication - ISM-1892Broader than
Implement Multi-factor Authentication for Customer Services - ISM-1893Partially overlaps
Enforcing Multi-Factor Authentication for User Security - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
|
| E8-MF-ML1.2 Multi-factor authentication for third-party services handling sensitive data | Multi-factor authentication | - ISM-1401Partially meets
Implement Multi-Factor Authentication for Security - ISM-1504Partially overlaps
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1679Equivalent
Multi-factor Authentication for Third-party Services Handling Sensitive Data - ISM-1680Partially overlaps
Use Multi-Factor Authentication for Online Services - ISM-1681Partially overlaps
Mandating Multi-Factor Authentication for Customer Services - ISM-1893Partially overlaps
Enforcing Multi-Factor Authentication for User Security - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
|
| E8-MF-ML1.3 Use multi-factor authentication for non-sensitive third-party services | Multi-factor authentication | - ISM-0417Supports
Use Passwords When Multi-Factor Authentication Isn't Supported - ISM-0553Supports
Authenticate Video Calls and Manage Settings - ISM-1401Depends on
Implement Multi-Factor Authentication for Security - ISM-1505Partially overlaps
Multi-factor Authentication for Human Users of Data Repositories - ISM-1680Equivalent
Use Multi-Factor Authentication for Online Services - ISM-1919Supports
Disable Non-MFA Authentication Protocols - ISM-2136Depends on
Enforcing Risk-Based Access Decisions Informed by Contextual Signals
|
| E8-MF-ML1.4 Use multi-factor authentication for online services handling customer data | Multi-factor authentication | - ISM-0553Depends on
Authenticate Video Calls and Manage Settings - ISM-1401Partially meets
Implement Multi-Factor Authentication for Security - ISM-1504Partially overlaps
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1505Partially overlaps
Implement Multi-factor Authentication for Data Repositories - ISM-1681Partially overlaps
Mandating Multi-Factor Authentication for Customer Services - ISM-1682Supports
Enhance User Security with Phishing-resistant MFA - ISM-1892Equivalent
Multi-Factor Authentication for Organisation Users of Online Customer Services - ISM-1893Partially overlaps
Multi-Factor Authentication for Third-Party Services Holding Sensitive Customer Data - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
|
| E8-MF-ML1.5 Multi-factor authentication for third-party services with sensitive customer data | Multi-factor authentication | - ISM-0974Partially overlaps
Implement Multi-factor Authentication for User Access - ISM-1173Partially overlaps
Use Multi-Factor Authentication for Privileged Users - ISM-1401Depends on
Implement Multi-Factor Authentication for Security - ISM-1452Supports
Perform Supply Chain Risk Assessments for System Suppliers - ISM-1504Partially overlaps
Implement Multi-factor Authentication - ISM-1679Equivalent
Use Multi-factor Authentication for Third-party Services - ISM-1680Partially overlaps
Use Multi-Factor Authentication for Online Services - ISM-1681Partially overlaps
Mandating Multi-Factor Authentication for Customer Services - ISM-1682Supports
Enhance User Security with Phishing-resistant MFA - ISM-1892Partially overlaps
Implement Multi-factor Authentication for Customer Services - ISM-1893Equivalent
Enforcing Multi-Factor Authentication for User Security - ISM-1919Supports
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
|
| E8-MF-ML1.6 Multi-factor authentication for customer access to online services handling sensitive data | Multi-factor authentication | - ISM-1401Depends on
Multi-Factor Authentication Combines Possession With Knowledge or Inherence - ISM-1504Partially overlaps
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1681Equivalent
Mandating Multi-Factor Authentication for Customer Services - ISM-1873Supports
Enhance Security with Phishing-Resistant MFA - ISM-1874Partially overlaps
Phishing-Resistant Multi-Factor Authentication for Customers - ISM-1892Equivalent
Implement Multi-factor Authentication for Customer Services - ISM-1893Partially overlaps
Enforcing Multi-Factor Authentication for User Security - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication - ISM-1920Partially overlaps
Prevent Self-enrollment on Untrusted Devices
|
| E8-MF-ML1.7 Multi-factor authentication combines two factors like a device and a PIN | Multi-factor authentication | - ISM-0553Supports
Authenticate Video Calls and Manage Settings - ISM-0974Partially meets
Implement Multi-factor Authentication for User Access - ISM-1173Partially meets
Use Multi-Factor Authentication for Privileged Users - ISM-1401Equivalent
Implement Multi-Factor Authentication for Security - ISM-1504Partially meets
Implement Multi-factor Authentication - ISM-1505Partially meets
Implement Multi-factor Authentication for Data Repositories - ISM-1546Partially meets
Ensure User Authentication Before System Access - ISM-1560Broader than
Ensure Strong Passwords for SECRET System Authentication - ISM-1679Partially meets
Use Multi-factor Authentication for Third-party Services - ISM-1680Partially meets
Use Multi-Factor Authentication for Online Services - ISM-1681Partially meets
Mandating Multi-Factor Authentication for Customer Services - ISM-1872Supports
Ensuring Phishing-Resistant Multi-Factor Authentication - ISM-1893Partially meets
Enforcing Multi-Factor Authentication for User Security - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication - ISM-2011Depends on
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
|
| E8-MF-ML2.1 Multi-factor authentication for privileged users of systems | Multi-factor authentication | - ISM-0445Depends on
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-0553Supports
Authenticate Video Calls and Manage Settings - ISM-1173Equivalent
Use Multi-Factor Authentication for Privileged Users - ISM-1401Depends on
Multi-Factor Authentication Combines Possession With Knowledge or Inherence - ISM-1620Supports
Ensure Privileged Accounts are Secured in AD - ISM-1816Depends on
Prevent Unauthorised Changes to Software Sources - ISM-1919Supports
Disable Non-MFA Authentication Protocols - ISM-1927Supports
Restrict Access to Microsoft Active Directory Servers
|
| E8-MF-ML2.2 Use multi-factor authentication for unprivileged user access | Multi-factor authentication | - ISM-0553Supports
Authenticate Video Calls and Manage Settings - ISM-0974Equivalent
Implement Multi-factor Authentication for User Access - ISM-1401Supports
Implement Multi-Factor Authentication for Security - ISM-1505Partially overlaps
Implement Multi-factor Authentication for Data Repositories - ISM-1682Partially overlaps
Enhance User Security with Phishing-resistant MFA - ISM-1854Partially overlaps
Human Users Authenticate to MFDs Before Printing, Scanning or Copying - ISM-1893Partially overlaps
Enforcing Multi-Factor Authentication for User Security - ISM-2077Supports
Avoid Email for Out-of-Band Authentication
|
| E8-MF-ML2.3 Multi-factor authentication online services must be phishing-resistant | Multi-factor authentication | - ISM-0555Partially overlaps
Ensure Authentication for IP Telephony Actions - ISM-1173Partially overlaps
Multi-Factor Authentication for Privileged Human Users of Systems - ISM-1401Depends on
Multi-Factor Authentication Combines Possession With Knowledge or Inherence - ISM-1504Depends on
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1680Supports
Use Multi-Factor Authentication for Online Services - ISM-1682Broader than
Enhance User Security with Phishing-resistant MFA - ISM-1872Equivalent
Ensuring Phishing-Resistant Multi-Factor Authentication - ISM-1874Partially overlaps
Phishing-Resistant Multi-Factor Authentication for Customers - ISM-1892Partially overlaps
Multi-Factor Authentication for Organisation Users of Online Customer Services - ISM-1893Supports
Enforcing Multi-Factor Authentication for User Security - ISM-1894Partially overlaps
Ensuring Phishing-Resistant Multi-factor Authentication - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication - ISM-1920Supports
Prevent Self-enrollment on Untrusted Devices - ISM-2011Partially overlaps
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used - ISM-2077Supports
Avoid Email for Out-of-Band Authentication
|
| E8-MF-ML2.5 Multi-factor authentication used for system access is phishing-resistant | Multi-factor authentication | - ISM-0974Supports
Implement Multi-factor Authentication for User Access - ISM-1173Partially overlaps
Use Multi-Factor Authentication for Privileged Users - ISM-1401Partially meets
Implement Multi-Factor Authentication for Security - ISM-1504Depends on
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1505Partially overlaps
Implement Multi-factor Authentication for Data Repositories - ISM-1680Partially overlaps
Use Multi-Factor Authentication for Online Services - ISM-1682Equivalent
Enhance User Security with Phishing-resistant MFA - ISM-1872Partially overlaps
Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services - ISM-1893Supports
Enforcing Multi-Factor Authentication for User Security - ISM-1894Partially overlaps
Ensuring Phishing-Resistant Multi-factor Authentication - ISM-2011Depends on
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used - ISM-2077Supports
Avoid Email for Out-of-Band Authentication
|
| E8-MF-ML2.6 MFA success and failure events are centrally logged | Multi-factor authentication | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0585Partially overlaps
Capture Detailed Information in Event Logs - ISM-1405Partially meets
Implement a Centralised Event Logging Facility - ISM-1504Depends on
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1505Depends on
Multi-factor Authentication for Human Users of Data Repositories - ISM-1509Partially overlaps
Log Privileged Access Events Centrally for Monitoring - ISM-1682Depends on
Phishing-resistant multi-factor authentication for human users of systems - ISM-1683Equivalent
Central Logging of Multi-factor Authentication Events - ISM-1892Depends on
Multi-Factor Authentication for Organisation Users of Online Customer Services - ISM-1893Depends on
Multi-Factor Authentication for Third-Party Services Holding Sensitive Customer Data - ISM-1894Depends on
Phishing-Resistant Multi-Factor Authentication for Human Users of Data Repositories - ISM-1895Partially overlaps
Log Single-factor Authentication Events - ISM-1976Partially overlaps
Central Logging of Security Events on macOS - ISM-1977Partially overlaps
Central Logging of Linux System Events
|
| E8-MF-ML2.7 Protect event logs from unauthorised changes | Multi-factor authentication | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1607Depends on
Integrity Monitoring and Logging for Isolation Mechanism - ISM-1624Supports
Protect PowerShell Script Block Logs - ISM-1815Equivalent
Protect Event Logs from Unauthorised Access - ISM-1830Partially overlaps
Central Logging for Microsoft AD Server Activities - ISM-1855Supports
Central Logging of Multifunction Device Use - ISM-1910Depends on
Log Network API Calls for Data Protection - ISM-1989Depends on
Ensure Event Logs Meet Retention Requirements - ISM-2015Supports
Central Logging of Non-Internet Network API Data Access - ISM-2139Depends on
Central Logging of Third-Party OAuth Consent, Token Issuance and Use
|
| E8-MF-ML2.8 Timely analysis of event logs from internet-facing servers | Multi-factor authentication | - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0634Partially overlaps
Central Logging for Gateway Security Events - ISM-0988Depends on
Ensure Accurate Time Source for Event Logs - ISM-1030Partially overlaps
Deploy NIDS/NIPS for Gateway Traffic Monitoring - ISM-1228Broader than
Analyse Cyber Security Events Promptly - ISM-1405Depends on
Implement a Centralised Event Logging Facility - ISM-1906Equivalent
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1978Depends on
Centralised Logging for Server Application Events - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially meets
Timely Analysis of Security Event Logs
|
| E8-MF-ML2.9 Cyber security events are analysed to identify incidents timely | Multi-factor authentication | - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Equivalent
Analyse Cyber Security Events Promptly - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1536Depends on
Central Logging of Software Database Queries and Errors - ISM-1906Depends on
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially meets
Timely Analysis of Non-Internet-Server Logs - ISM-1960Partially meets
Timely Analysis of Event Logs for Cyber security - ISM-1961Partially meets
Timely Analysis of Network Device Event Logs - ISM-1986Partially meets
Timely Analysis of Critical Server Event Logs - ISM-1987Partially meets
Timely Analysis of Security Event Logs - ISM-2089Broader than
Monitor AI Model Performance and Investigate Anomalies
|
| E8-MF-ML2.10 Report cyber security incidents to the Chief Information Security Officer promptly | Multi-factor authentication | - ISM-0043Supports
Cyber Security Incident Response Plan Requirements - ISM-0123Equivalent
Report Cyber Security Incidents Promptly - ISM-0140Partially overlaps
Prompt Reporting of Cyber Incidents to ASD - ISM-0142Broader than
Report Cryptographic Equipment Compromises Promptly - ISM-0252Depends on
Annual Cyber Security Awareness for Personnel - ISM-0733Equivalent
Ensure CISO Awareness of Cyber Incidents - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents
|
| E8-MF-ML2.11 Report cyber security incidents to ASD immediately | Multi-factor authentication | - ISM-0043Partially meets
Cyber Security Incident Response Plan Requirements - ISM-0123Partially overlaps
Report Cyber Security Incidents Promptly - ISM-0140Equivalent
Prompt Reporting of Cyber Incidents to ASD - ISM-0141Partially overlaps
Report Cyber Incidents Promptly to Designated Contacts - ISM-0142Partially overlaps
Report Cryptographic Equipment Compromises Promptly - ISM-1228Supports
Analyse Cyber Security Events Promptly
|
| E8-MF-ML2.12 Cyber security incident response plan enacted after incident identification | Multi-factor authentication | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0123Supports
Report Cyber Security Incidents Promptly - ISM-0576Depends on
Develop and Maintain Cyber Security Incident Plans - ISM-0733Supports
Ensure CISO Awareness of Cyber Incidents - ISM-1019Partially meets
Develop a Denial of Service Response Plan - ISM-1618Partially overlaps
CISO's Role in Cyber Security Incident Response - ISM-1784Supports
Annual Testing of Cyber Incident Response Plan - ISM-1805Broader than
Develop a Denial of Service Response Plan - ISM-1819Equivalent
Enact Cyber Security Incident Response Plans
|
| E8-MF-ML3.1 Multi-factor authentication is used to authenticate users of data repositories | Multi-factor authentication | - ISM-0974Partially overlaps
Implement Multi-factor Authentication for User Access - ISM-1173Partially overlaps
Use Multi-Factor Authentication for Privileged Users - ISM-1268Depends on
Enforce Need-to-Know Access in Databases - ISM-1401Supports
Implement Multi-Factor Authentication for Security - ISM-1504Partially meets
Implement Multi-factor Authentication - ISM-1505Equivalent
Implement Multi-factor Authentication for Data Repositories - ISM-1872Supports
Ensuring Phishing-Resistant Multi-Factor Authentication - ISM-1894Supports
Phishing-Resistant Multi-Factor Authentication for Human Users of Data Repositories - ISM-1919Depends on
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication - ISM-1920Supports
Prevent Self-enrollment on Untrusted Devices
|
| E8-MF-ML3.2 Phishing-resistant multi-factor authentication for online customer services | Multi-factor authentication | - ISM-1401Partially overlaps
Implement Multi-Factor Authentication for Security - ISM-1546Broader than
Ensure User Authentication Before System Access - ISM-1680Partially overlaps
Use Multi-Factor Authentication for Online Services - ISM-1681Broader than
Mandating Multi-Factor Authentication for Customer Services - ISM-1682Partially meets
Enhance User Security with Phishing-resistant MFA - ISM-1872Partially meets
Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services - ISM-1873Equivalent
Enhance Security with Phishing-Resistant MFA - ISM-1874Equivalent
Phishing-Resistant Multi-Factor Authentication for Customers - ISM-2011Depends on
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used - ISM-2077Supports
Avoid Email for Out-of-Band Authentication
|
| E8-MF-ML3.3 Phishing-resistant multi-factor authentication for data repositories | Multi-factor authentication | - ISM-1504Partially overlaps
Implement Multi-factor Authentication - ISM-1505Partially meets
Implement Multi-factor Authentication for Data Repositories - ISM-1679Partially overlaps
Multi-factor Authentication for Third-party Services Handling Sensitive Data - ISM-1682Partially meets
Enhance User Security with Phishing-resistant MFA - ISM-1872Partially overlaps
Phishing-Resistant Multi-Factor Authentication for Human Users of Online Services - ISM-1894Equivalent
Ensuring Phishing-Resistant Multi-factor Authentication - ISM-2011Supports
Restrict MFA Options to Phishing-resistant Only - ISM-2077Supports
Avoid Email for Out-of-Band Authentication
|
| E8-MF-ML3.4 Analyse event logs from non-internet-facing servers timely to detect security events | Multi-factor authentication | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-1228Broader than
Analyse Cyber Security Events Promptly - ISM-1830Depends on
Central Logging for Microsoft AD Server Activities - ISM-1906Partially overlaps
Timely Analysis of Internet-Facing Server Logs - ISM-1907Equivalent
Timely Analysis of Non-Internet-Server Logs - ISM-1911Depends on
Centralised Logging of Software Errors and Usage - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1979Depends on
Central Logging for Security Events on Servers - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially overlaps
Timely Analysis of Security Event Logs
|
| E8-MF-ML3.5 Timely analysis of workstation event logs for cyber security events | Multi-factor authentication | - ISM-0120Depends on
Access to Tools for Detecting Security Events - ISM-0582Depends on
Central Logging of Windows Security Events - ISM-1228Depends on
Analyse Cyber Security Events Promptly - ISM-1405Depends on
Implement a Centralised Event Logging Facility - ISM-1976Depends on
Central Logging of Security Events on macOS - ISM-1983Supports
Log Events Sent to Centralised Facility Quickly - ISM-2051Depends on
Ensure Event Logs for Cybersecurity Event Detection
|
| E8-PA-ML1.1 Automated asset discovery at least fortnightly | Patch applications | - ISM-0336Partially overlaps
Develop and Maintain Networked IT Equipment Register - ISM-1163Depends on
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1702Supports
Regularly Scan for Missing Security Patches - ISM-1703Supports
Regular Vulnerability Scanning for Missing Patches - ISM-1752Supports
Fortnightly Vulnerability Scanning for Non-Workstations - ISM-1807Equivalent
Automated Asset Discovery for Vulnerability Scanning - ISM-1966Supports
CISO Manages and Verifies System Register - ISM-2134Depends on
Develop, Maintain and Regularly Verify an AI Agent Register
|
| E8-PA-ML1.2 Up-to-date vulnerability scanner used for scanning activities | Patch applications | - ISM-0402Supports
Software Vulnerability Testing Using SAST, DAST and SCA - ISM-1163Partially meets
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1693Supports
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1698Partially meets
Daily Vulnerability Scanning for Missing Updates - ISM-1699Partially meets
Weekly Vulnerability Scanning for Software Updates - ISM-1700Partially meets
Regular Vulnerability Scanning for Applications - ISM-1701Partially meets
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1703Partially meets
Regular Vulnerability Scanning for Missing Patches - ISM-1808Equivalent
Vulnerability Scanning with Updated Tools
|
| E8-PA-ML1.3 Daily vulnerability scanning for missing patches in online services | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1698Equivalent
Daily Vulnerability Scanning for Missing Updates - ISM-1701Partially overlaps
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1808Depends on
Vulnerability Scanning with Updated Tools
|
| E8-PA-ML1.4 Weekly scanning for missing patches or updates in key software | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Partially meets
Develop and Maintain Patch Management Procedures - ISM-1163Partially overlaps
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1467Depends on
Use Latest Releases of User Applications - ISM-1526Partially meets
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1691Depends on
Timely Vulnerability Patching in Software Tools - ISM-1692Supports
Quick Apply Critical Patches for Vulnerabilities - ISM-1693Partially overlaps
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1699Equivalent
Weekly Vulnerability Scanning for Software Updates - ISM-1700Partially overlaps
Regular Vulnerability Scanning for Applications - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-1704Depends on
Remove Unsupported Software to Ensure Security - ISM-1754Supports
Timely Resolution of Identified Software Vulnerabilities - ISM-1901Depends on
Timely Application of Non-Critical Security Patches
|
| E8-PA-ML1.5 Apply Critical Online Service Patches Within 48 Hours | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1483Partially overlaps
Use Latest Release of Internet-Facing Server Applications - ISM-1698Supports
Daily Vulnerability Scanning for Missing Updates - ISM-1754Broader than
Timely Resolution of Identified Software Vulnerabilities - ISM-1876Equivalent
Apply Critical Patches Within 48 Hours - ISM-1877Partially overlaps
Timely Application of Critical Security Patches - ISM-1879Partially overlaps
Timely Patching of Critical Driver Vulnerabilities - ISM-1921Depends on
Assess System Compromise Risks Often
|
| E8-PA-ML1.6 Apply non-critical patches for online services within two weeks | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1163Partially meets
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1483Supports
Use Latest Release of Internet-Facing Server Applications - ISM-1690Equivalent
Timely Application of Non-Critical Vulnerability Patches - ISM-1694Partially overlaps
Timely Application of Non-Critical Security Patches - ISM-1697Partially overlaps
Apply Non-Critical Patches Within One Month - ISM-1698Depends on
Daily Vulnerability Scanning for Missing Updates - ISM-1876Partially overlaps
Apply Critical Patches Within 48 Hours
|
| E8-PA-ML1.8 Unsupported online services are removed by the organisation | Patch applications | - ISM-0304Partially overlaps
Remove Unsupported Applications for System Security - ISM-1704Partially overlaps
Remove Unsupported Software to Ensure Security - ISM-1809Partially overlaps
Implement Compensating Controls for Unsupported Systems - ISM-1905Equivalent
Remove Online Services No Longer Supported by Vendors - ISM-1981Partially overlaps
Replace Unsupportable Non-Internet Network Devices
|
| E8-PA-ML1.9 Removal of unsupported software and applications | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-0304Partially overlaps
Remove Unsupported Applications for System Security - ISM-1247Partially overlaps
Disable or Remove Unneeded Server Features - ISM-1467Partially overlaps
Use Latest Releases of User Applications - ISM-1643Supports
Maintain Detailed Software Version and Patch Records - ISM-1654Broader than
Disable or Remove Internet Explorer 11 - ISM-1704Equivalent
Remove Unsupported Software to Ensure Security - ISM-1753Partially overlaps
Replace Unsupported Internet-Facing Devices - ISM-1809Partially overlaps
Implement Compensating Controls for Unsupported Systems - ISM-1848Partially overlaps
Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources - ISM-1981Partially overlaps
Replace Unsupportable Non-Internet Network Devices
|
| E8-PA-ML2.1 Fortnightly vulnerability scanning for non-core applications | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-0304Supports
Remove Unsupported Applications for System Security - ISM-1693Partially overlaps
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1699Partially overlaps
Weekly Vulnerability Scanning for Software Updates - ISM-1700Equivalent
Regular Vulnerability Scanning for Applications - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-2118Partially meets
Conduct Vulnerability Assessments and Penetration Tests
|
| E8-PA-ML2.2 Timely Patching of Non-Critical Application Vulnerabilities | Patch applications | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-0304Partially overlaps
Remove Unsupported Applications for System Security - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1163Partially overlaps
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1555Supports
Prepare Mobile Devices Before Overseas Travel - ISM-1606Partially overlaps
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1643Supports
Maintain Detailed Software Version and Patch Records - ISM-1693Equivalent
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1700Supports
Regular Vulnerability Scanning for Applications
|
| E8-PA-ML3.1 Patch critical vulnerabilities in applications within 48 hours | Patch applications | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1163Supports
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1366Partially overlaps
Ensure Timely Security Updates for Mobile Devices - ISM-1467Partially overlaps
Use Latest Releases of User Applications - ISM-1691Partially overlaps
Timely Vulnerability Patching in Software Tools - ISM-1692Equivalent
Quick Apply Critical Patches for Vulnerabilities - ISM-1693Supports
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1699Supports
Weekly Vulnerability Scanning for Software Updates - ISM-1754Broader than
Timely Resolution of Identified Software Vulnerabilities - ISM-1901Partially overlaps
Timely Application of Non-Critical Security Patches - ISM-1921Supports
Assess System Compromise Risks Often - ISM-2118Depends on
Conduct Vulnerability Assessments and Penetration Tests
|
| E8-PA-ML3.2 Apply patches for non-critical vulnerabilities within two weeks | Patch applications | - ISM-1366Partially overlaps
Ensure Timely Security Updates for Mobile Devices - ISM-1467Partially overlaps
Use Latest Releases of User Applications - ISM-1643Depends on
Maintain Detailed Software Version and Patch Records - ISM-1691Partially overlaps
Timely Vulnerability Patching in Software Tools - ISM-1692Partially overlaps
Quick Apply Critical Patches for Vulnerabilities - ISM-1693Partially overlaps
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1754Partially meets
Timely Resolution of Identified Software Vulnerabilities - ISM-1901Equivalent
Timely Application of Non-Critical Security Patches
|
| E8-PA-ML3.3 Remove unsupported applications excluding certain categories | Patch applications | - ISM-0304Equivalent
Remove Unsupported Applications for System Security - ISM-1483Partially overlaps
Use Latest Release of Internet-Facing Server Applications - ISM-1493Supports
Maintain and Verify Software Registers - ISM-1655Partially meets
Ensure .NET Framework 3.5 is Disabled or Removed - ISM-1704Partially overlaps
Remove Unsupported Software to Ensure Security - ISM-1809Partially overlaps
Implement Compensating Controls for Unsupported Systems
|
| E8-PO-ML1.1 Automated bi-weekly asset discovery for vulnerability scanning | Patch operating systems | - ISM-0336Supports
Develop and Maintain Networked IT Equipment Register - ISM-1163Broader than
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1493Supports
Maintain and Verify Software Registers - ISM-1643Supports
Maintain Detailed Software Version and Patch Records - ISM-1696Supports
Apply Critical Patches Within 48 Hours - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1700Supports
Regular Vulnerability Scanning for Applications - ISM-1703Supports
Regular Vulnerability Scanning for Missing Patches - ISM-1807Equivalent
Automated Asset Discovery for Vulnerability Scanning - ISM-1966Depends on
CISO Manages and Verifies System Register - ISM-2118Partially meets
Conduct Vulnerability Assessments and Penetration Tests - ISM-2134Depends on
Develop, Maintain and Regularly Verify an AI Agent Register
|
| E8-PO-ML1.2 Use a vulnerability scanner with an updated database | Patch operating systems | - ISM-1696Depends on
Apply Critical Patches Within 48 Hours - ISM-1697Supports
Apply Non-Critical Patches Within One Month - ISM-1698Supports
Daily Vulnerability Scanning for Missing Updates - ISM-1699Partially meets
Weekly Vulnerability Scanning for Software Updates - ISM-1701Supports
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1702Supports
Regularly Scan for Missing Security Patches - ISM-1752Supports
Fortnightly Vulnerability Scanning for Non-Workstations - ISM-1808Equivalent
Vulnerability Scanning with Updated Tools - ISM-1879Depends on
Timely Patching of Critical Driver Vulnerabilities - ISM-1900Depends on
Fortnightly System Vulnerability Scanning
|
| E8-PO-ML1.3 Use a daily vulnerability scanner for internet-facing systems | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1163Partially meets
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1694Depends on
Timely Application of Non-Critical Security Patches - ISM-1698Partially overlaps
Daily Vulnerability Scanning for Missing Updates - ISM-1701Equivalent
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1702Partially overlaps
Regularly Scan for Missing Security Patches - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-1752Partially overlaps
Fortnightly Vulnerability Scanning for Non-Workstations - ISM-1808Depends on
Vulnerability Scanning with Updated Tools - ISM-1877Supports
Timely Application of Critical Security Patches - ISM-1900Partially overlaps
Fortnightly System Vulnerability Scanning
|
| E8-PO-ML1.4 Use a vulnerability scanner fortnightly to find missing OS patches | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1163Partially meets
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1696Supports
Apply Critical Patches Within 48 Hours - ISM-1702Equivalent
Regularly Scan for Missing Security Patches - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-1808Depends on
Vulnerability Scanning with Updated Tools
|
| E8-PO-ML1.5 Apply critical patches to internet-facing OS within 48 hours | Patch operating systems | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1163Supports
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1407Partially overlaps
Ensure Use of Current OS Versions - ISM-1606Partially overlaps
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1643Depends on
Maintain Detailed Software Version and Patch Records - ISM-1694Partially overlaps
Timely Application of Non-Critical Security Patches - ISM-1696Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1701Depends on
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1753Depends on
Replace Unsupported Internet-Facing Devices - ISM-1876Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1877Equivalent
Timely Application of Critical Security Patches - ISM-1878Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1879Partially overlaps
Timely Patching of Critical Driver Vulnerabilities - ISM-1902Partially overlaps
Apply Non-Critical Patches to Non-Internet Systems Promptly - ISM-1921Depends on
Assess System Compromise Risks Often
|
| E8-PO-ML1.6 Timely application of non-critical patches for internet-facing OS vulnerabilities | Patch operating systems | - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1606Partially overlaps
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1690Partially overlaps
Timely Application of Non-Critical Vulnerability Patches - ISM-1694Equivalent
Timely Application of Non-Critical Security Patches - ISM-1877Partially overlaps
Timely Application of Critical Security Patches - ISM-1902Partially overlaps
Apply Non-Critical Patches to Non-Internet Systems Promptly
|
| E8-PO-ML1.8 Replace unsupported operating systems | Patch operating systems | - ISM-0298Partially overlaps
Centralised System Patch and Update Management - ISM-0336Depends on
Develop and Maintain Networked IT Equipment Register - ISM-1366Supports
Ensure Timely Security Updates for Mobile Devices - ISM-1407Partially overlaps
Ensure Use of Current OS Versions - ISM-1408Supports
Use 64-bit Operating Systems Where Supported - ISM-1409Depends on
Implement Restrictive OS Hardening Guidelines - ISM-1501Equivalent
Replace Unsupported Operating Systems - ISM-1643Depends on
Maintain Detailed Software Version and Patch Records - ISM-1704Partially overlaps
Remove Unsupported Software to Ensure Security - ISM-1753Partially overlaps
Replace Unsupported Internet-Facing Devices - ISM-1807Supports
Automated Asset Discovery for Vulnerability Scanning - ISM-1809Partially overlaps
Implement Compensating Controls for Unsupported Systems - ISM-1848Partially overlaps
Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources - ISM-1981Partially overlaps
Replace Unsupportable Non-Internet Network Devices - ISM-1982Partially overlaps
Replace Unsupported Networked IT Equipment
|
| E8-PO-ML3.1 Vulnerability scanner used fortnightly to identify missing driver patches | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1163Partially meets
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1703Equivalent
Regular Vulnerability Scanning for Missing Patches - ISM-1808Depends on
Vulnerability Scanning with Updated Tools
|
| E8-PO-ML3.2 At least fortnightly use of a vulnerability scanner for firmware | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1703Partially overlaps
Regular Vulnerability Scanning for Missing Patches - ISM-1752Partially overlaps
Fortnightly Vulnerability Scanning for Non-Workstations - ISM-1807Supports
Automated Asset Discovery for Vulnerability Scanning - ISM-1808Depends on
Vulnerability Scanning with Updated Tools - ISM-1900Equivalent
Fortnightly System Vulnerability Scanning - ISM-1903Partially overlaps
Rapid Application of Critical Firmware Patches - ISM-1904Partially overlaps
Apply Firmware Patches for Non-Critical Vulnerabilities
|
| E8-PO-ML3.3 Apply critical patches to non-internet-facing OS within 48 hours | Patch operating systems | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1366Partially overlaps
Ensure Timely Security Updates for Mobile Devices - ISM-1605Depends on
Harden the Operating System Beneath Software Isolation Mechanisms - ISM-1606Partially overlaps
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1643Depends on
Maintain Detailed Software Version and Patch Records - ISM-1695Partially overlaps
Timely Application of System Security Patches - ISM-1696Equivalent
Apply Critical Patches Within 48 Hours - ISM-1702Depends on
Regularly Scan for Missing Security Patches - ISM-1800Supports
Ensure Network Devices Have Trusted Firmware - ISM-1876Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1877Partially overlaps
Timely Application of Critical Security Patches - ISM-1878Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1900Depends on
Fortnightly System Vulnerability Scanning - ISM-1902Partially overlaps
Apply Non-Critical Patches to Non-Internet Systems Promptly - ISM-1921Depends on
Assess System Compromise Risks Often - ISM-1981Depends on
Replace Unsupportable Non-Internet Network Devices
|
| E8-PO-ML3.4 Non-critical OS patches applied within one month if no exploits exist | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1694Partially overlaps
Timely Application of Non-Critical Security Patches - ISM-1695Broader than
Timely Application of System Security Patches - ISM-1696Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1697Partially overlaps
Apply Non-Critical Patches Within One Month - ISM-1702Depends on
Regularly Scan for Missing Security Patches - ISM-1751Partially overlaps
Timely Application of Vendor Patches for Non-Critical OS Vulnerabilities - ISM-1902Equivalent
Apply Non-Critical Patches to Non-Internet Systems Promptly - ISM-1904Partially overlaps
Apply Firmware Patches for Non-Critical Vulnerabilities
|
| E8-PO-ML3.5 Apply critical driver patches within 48 hours | Patch operating systems | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-0300Partially overlaps
Apply System Security Patches with Approval - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1163Supports
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1697Partially overlaps
Apply Non-Critical Patches Within One Month - ISM-1754Broader than
Timely Resolution of Identified Software Vulnerabilities - ISM-1879Equivalent
Timely Patching of Critical Driver Vulnerabilities - ISM-1921Supports
Assess System Compromise Risks Often
|
| E8-PO-ML3.6 Apply non-critical driver patches within one month | Patch operating systems | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1697Equivalent
Apply Non-Critical Patches Within One Month - ISM-1904Partially overlaps
Apply Firmware Patches for Non-Critical Vulnerabilities
|
| E8-PO-ML3.7 Apply critical firmware patches within 48 hours | Patch operating systems | - ISM-0298Depends on
Centralised System Patch and Update Management - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1697Partially overlaps
Apply Non-Critical Patches Within One Month - ISM-1754Partially overlaps
Timely Resolution of Identified Software Vulnerabilities - ISM-1876Partially overlaps
Apply Critical Patches Within 48 Hours - ISM-1903Equivalent
Rapid Application of Critical Firmware Patches - ISM-1904Partially overlaps
Apply Firmware Patches for Non-Critical Vulnerabilities - ISM-1921Supports
Assess System Compromise Risks Often
|
| E8-PO-ML3.8 Firmware vulnerabilities patched within one month if non-critical and no exploits | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-0300Partially overlaps
Apply System Security Patches with Approval - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1163Supports
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1697Partially overlaps
Apply Non-Critical Patches Within One Month - ISM-1900Supports
Fortnightly System Vulnerability Scanning - ISM-1903Partially overlaps
Rapid Application of Critical Firmware Patches - ISM-1904Equivalent
Apply Firmware Patches for Non-Critical Vulnerabilities
|
| E8-PO-ML3.9 The latest or previous OS release is used | Patch operating systems | - ISM-0298Supports
Centralised System Patch and Update Management - ISM-1407Equivalent
Ensure Use of Current OS Versions - ISM-1408Supports
Use 64-bit Operating Systems Where Supported - ISM-1409Supports
Implement Restrictive OS Hardening Guidelines - ISM-1483Partially overlaps
Use Latest Release of Internet-Facing Server Applications - ISM-1501Partially overlaps
Replace Unsupported Operating Systems - ISM-1605Depends on
Harden the Operating System Beneath Software Isolation Mechanisms - ISM-1848Partially overlaps
Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
|
| E8-RA-ML1.1 Validating privileged access requests upon initial request | Restrict admin privileges | - ISM-0407Supports
Maintain Secure User Access Records - ISM-0432Supports
Document System Access Requirements in Security Plans - ISM-0446Partially overlaps
Restrict Privileged Access for Foreign Nationals - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-1487Depends on
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1507Equivalent
Ensure Requests for Privileged Access are Verified - ISM-1508Partially overlaps
Limit Privileged Access to Essential Duties Only - ISM-1647Partially overlaps
Disable Privileged Access After 12 Months - ISM-1883Partially overlaps
Restrict Privileged Access to Necessary Service Duties - ISM-1927Partially overlaps
Restrict Access to Microsoft Active Directory Servers - ISM-1939Supports
Minimise Members in Privileged Security Groups - ISM-2128Depends on
Limit Kernel-Mode Code Installation to Privileged Users Who Need It - ISM-2133Depends on
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2136Partially overlaps
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2137Partially overlaps
Block User OAuth Consent, Reserve It for Authorised Administrators
|
| E8-RA-ML1.2 Dedicated privileged accounts for admin tasks | Restrict admin privileges | - ISM-0414Depends on
Uniquely Identifying Every User Granted System Access - ISM-0445Equivalent
Dedicated Accounts for Privileged User Activities - ISM-0616Supports
Ensure Separation of Duties for Gateway Admins - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-1175Supports
Restrict Privileged Users from Internet Access - ISM-1263Partially meets
Enforce Unique Accounts for Server Administration - ISM-1487Depends on
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1508Partially overlaps
Limit Privileged Access to Essential Duties Only - ISM-1590Supports
Mandate Credential Changes Upon Compromise - ISM-1620Supports
Ensure Privileged Accounts are Secured in AD - ISM-1750Supports
Segregation of Administrative Infrastructure for Server Security - ISM-1827Partially meets
Use Dedicated Admin Accounts for Domain Controllers - ISM-1841Supports
Restrict Domain Joining to Admin Users Only - ISM-1842Partially meets
Use Privileged Accounts for Domain Machine Addition - ISM-1846Supports
Restrict Pre-Windows 2000 Access Group Membership - ISM-1883Depends on
Limit Authorised Privileged Account Online Service Access to Duties - ISM-1898Supports
Use Secure Admin Workstations for Administration - ISM-1927Depends on
Limit Identity Server Access to Privileged Users Requiring It - ISM-1939Supports
Minimise Members in Privileged Security Groups - ISM-1949Broader than
Use Dedicated Accounts for AD FS Administration - ISM-1952Supports
Prevent Synchronisation of Privileged Accounts - ISM-1958Depends on
Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments - ISM-2133Partially overlaps
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
|
| E8-RA-ML1.3 Prevent privileged accounts from accessing internet, email, and web services | Restrict admin privileges | - ISM-0258Supports
Establish and Maintain a Web Usage Policy - ISM-0445Supports
Dedicated Accounts for Privileged User Activities - ISM-0874Partially overlaps
Ensure Internet Access via Organisation's Gateway - ISM-0963Supports
Implementing Web Content Filters for Safety - ISM-1175Equivalent
Restrict Privileged Users from Internet Access - ISM-1380Supports
Use Separate Privileged and Unprivileged Environments - ISM-1385Supports
Segregation of Administrative Infrastructure from Networks - ISM-1508Partially overlaps
Restricting Privileged Access to What Duties Require - ISM-1883Partially overlaps
Restrict Privileged Access to Necessary Service Duties
|
| E8-RA-ML1.4 Limit privileged accounts to essential online service access | Restrict admin privileges | - ISM-0258Supports
Establish and Maintain a Web Usage Policy - ISM-0441Partially overlaps
Ensuring Limited Access for Temporary System Use - ISM-0445Supports
Dedicated Accounts for Privileged User Activities - ISM-0611Depends on
Restrict Privileges for Gateway Administrators - ISM-1175Equivalent
Restrict Privileged Users from Internet Access - ISM-1507Depends on
Ensure Requests for Privileged Access are Verified - ISM-1508Partially meets
Limit Privileged Access to Essential Duties Only - ISM-1647Supports
Disable Privileged Access After 12 Months - ISM-1648Depends on
Disabling Inactive Privileged Access to Systems - ISM-1833Supports
Limit Privileges for User Accounts in Active Directory - ISM-1852Partially overlaps
Limit Unprivileged Access to Essential Functions - ISM-1883Equivalent
Limit Authorised Privileged Account Online Service Access to Duties - ISM-1927Partially overlaps
Limit Identity Server Access to Privileged Users Requiring It - ISM-1939Supports
Minimise Members in Privileged Security Groups - ISM-2068Partially overlaps
Restrict Internet Access for Networked Devices - ISM-2156Partially overlaps
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
|
| E8-RA-ML1.5 Privileged users use separate privileged and unprivileged environments | Restrict admin privileges | - ISM-0445Supports
Dedicated Accounts for Privileged User Activities - ISM-1380Equivalent
Use Separate Privileged and Unprivileged Environments - ISM-1387Partially overlaps
Use Jump Servers for Administrative Activities - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1508Depends on
Restricting Privileged Access to What Duties Require - ISM-1635Partially meets
System Owners Implement Security Controls for Each System and Environment - ISM-1687Supports
Prevent Virtualisation of Privileged Environments - ISM-1688Supports
Block Unprivileged Account Logons to Privileged Operating Environments - ISM-1689Supports
Restrict Privileged Accounts Access to Non-Privileged Environments - ISM-1958Supports
Prevent Unauthorised Access for DCSync Accounts - ISM-1990Depends on
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
|
| E8-RA-ML1.6 Unprivileged accounts restricted from logging into privileged environments | Restrict admin privileges | - ISM-0445Depends on
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-1380Partially overlaps
Use Separate Privileged and Unprivileged Environments - ISM-1387Supports
Use Jump Servers for Administrative Activities - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1687Supports
Prevent Virtualisation of Privileged Environments - ISM-1688Equivalent
Restrict Privileged Environment Access - ISM-1689Partially overlaps
Restrict Privileged Accounts Access to Non-Privileged Environments - ISM-1927Supports
Restrict Access to Microsoft Active Directory Servers - ISM-1958Partially overlaps
Prevent Unauthorised Access for DCSync Accounts - ISM-1990Depends on
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
|
| E8-RA-ML1.7 Prevent privileged accounts from accessing unprivileged environments | Restrict admin privileges | - ISM-0445Supports
Dedicated Accounts for Privileged User Activities - ISM-1380Supports
Use Separate Privileged and Unprivileged Environments - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1487Depends on
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1508Partially overlaps
Restricting Privileged Access to What Duties Require - ISM-1649Supports
Implement Just-in-Time Administration for System Access - ISM-1688Partially overlaps
Block Unprivileged Account Logons to Privileged Operating Environments - ISM-1689Equivalent
Restrict Privileged Accounts Access to Non-Privileged Environments - ISM-1827Partially overlaps
Use Dedicated Admin Accounts for Domain Controllers - ISM-1958Partially overlaps
Prevent Unauthorised Access for DCSync Accounts - ISM-1990Depends on
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
|
| E8-RA-ML2.1 Disable privileged access after 12 months without revalidation | Restrict admin privileges | - ISM-1487Depends on
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1507Partially overlaps
Ensure Requests for Privileged Access are Verified - ISM-1508Depends on
Restricting Privileged Access to What Duties Require - ISM-1647Equivalent
Disable Privileged Access After 12 Months - ISM-1649Supports
Implement Just-in-Time Administration for System Access - ISM-1843Partially overlaps
Annual Review of Unconstrained Delegation in AD Accounts - ISM-1934Partially overlaps
Six-Monthly Review and Removal of DCSync User Permissions
|
| E8-RA-ML2.2 Privileged access is disabled after 45 days of inactivity | Restrict admin privileges | - ISM-0445Supports
Dedicated Accounts for Privileged User Activities - ISM-1620Partially overlaps
Ensure Privileged Accounts are Secured in AD - ISM-1647Partially overlaps
Disable Privileged Access After 12 Months - ISM-1648Equivalent
Disabling Inactive Privileged Access to Systems - ISM-1927Depends on
Limit Identity Server Access to Privileged Users Requiring It - ISM-1940Partially overlaps
Restrict Service Accounts from Privileged Groups
|
| E8-RA-ML2.3 Privileged environments are not virtualised within unprivileged environments | Restrict admin privileges | - ISM-1380Supports
Use Separate Privileged and Unprivileged Environments - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1461Depends on
Same Classification and Security Domain for Shared Isolation Hosts - ISM-1687Equivalent
Prevent Virtualisation of Privileged Environments - ISM-1688Depends on
Block Unprivileged Account Logons to Privileged Operating Environments - ISM-1689Supports
Restrict Privileged Accounts Access to Non-Privileged Environments - ISM-1958Supports
Prevent Unauthorised Access for DCSync Accounts
|
| E8-RA-ML2.4 Conduct administrative activities through jump servers | Restrict admin privileges | - ISM-0445Partially overlaps
Dedicated Accounts for Privileged User Activities - ISM-0616Supports
Ensure Separation of Duties for Gateway Admins - ISM-1380Depends on
Privileged Users Work in Separate Privileged and Unprivileged Operating Environments - ISM-1387Equivalent
Use Jump Servers for Administrative Activities - ISM-1422Depends on
Prevent Unauthorised Access to Software Source - ISM-1509Supports
Log Privileged Access Events Centrally for Monitoring - ISM-1604Supports
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1689Depends on
Block Privileged Account Logons to Unprivileged Operating Environments - ISM-1731Supports
Coordinate Intrusion Remediation on Separate Systems - ISM-1750Supports
Segregation of Administrative Infrastructure for Server Security - ISM-1827Supports
Use Dedicated Admin Accounts for Domain Controllers - ISM-1898Partially overlaps
Use Secure Admin Workstations for Administration - ISM-1899Depends on
Restrict Unauthorised Network Connections - ISM-1927Supports
Restrict Access to Microsoft Active Directory Servers
|
| E8-RA-ML2.5 Long, unique, and managed credentials for admin accounts | Restrict admin privileges | - ISM-1227Depends on
Randomly Generate User Account Credentials - ISM-1590Partially overlaps
Changing User Account Credentials After Compromise, Exposure or Shared Membership Change - ISM-1612Partially overlaps
Restricted Use of Break Glass Accounts for Emergencies - ISM-1614Partially overlaps
Manage Emergency Account Access Changes - ISM-1615Depends on
Testing Break Glass Accounts Post Credential Change - ISM-1619Depends on
Configure Service Accounts as Managed Service Accounts - ISM-1685Equivalent
Strengthening Passwords for Critical Accounts - ISM-1795Partially overlaps
Set 30-Character Minimum for Key Administrator Passwords - ISM-1842Partially overlaps
Use Privileged Accounts for Domain Machine Addition - ISM-1847Partially overlaps
Double KRBTGT Password Reset After Compromise or Six Months - ISM-1875Depends on
Monthly System Scans to Detect Credentials Stored in the Clear - ISM-1949Partially overlaps
Use Dedicated Accounts for AD FS Administration - ISM-1953Broader than
Ensure Strong Management of Admin Account Credentials - ISM-1954Equivalent
Enforce Random Credentials for Administrator Accounts - ISM-2081Depends on
Enforce Use of All ASCII Characters in Passwords - ISM-2142Partially overlaps
Central Management of Application and Workload Credentials - ISM-2144Partially overlaps
Change Application Static Credentials Found Compromised or Exposed in Clear
|
| E8-RA-ML2.6 Privileged access events are centrally logged. | Restrict admin privileges | - ISM-0415Supports
Strict Control of Shared User Accounts - ISM-0445Depends on
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0582Partially overlaps
Central Logging of Windows Security Events - ISM-0585Partially overlaps
Capture Detailed Information in Event Logs - ISM-0670Broader than
Central Logging of CDS Security Events - ISM-1509Equivalent
Log Privileged Access Events Centrally for Monitoring - ISM-1537Partially overlaps
Log Security-Relevant Database Events Centrally - ISM-1607Partially overlaps
Integrity Monitoring and Logging for Isolation Mechanism - ISM-1613Partially meets
Central Logging of Break Glass Account Usage - ISM-1650Partially meets
Log Management of Privileged User Activities - ISM-1830Partially meets
Central Logging for Microsoft AD Server Activities - ISM-1895Partially overlaps
Log Single-factor Authentication Events - ISM-1976Partially overlaps
Central Logging of Security Events on macOS - ISM-1977Partially overlaps
Central Logging of Linux System Events - ISM-1983Depends on
Log Events Sent to Centralised Facility Quickly - ISM-1989Partially overlaps
Ensure Event Logs Meet Retention Requirements
|
| E8-RA-ML2.7 Centrally log privileged account and group management events | Restrict admin privileges | - ISM-0445Depends on
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-0580Depends on
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0585Partially overlaps
Capture Detailed Information in Event Logs - ISM-0988Supports
Ensure Accurate Time Source for Event Logs - ISM-1405Depends on
Implement a Centralised Event Logging Facility - ISM-1509Partially meets
Log Privileged Access Events Centrally for Monitoring - ISM-1537Partially overlaps
Log Security-Relevant Database Events Centrally - ISM-1613Partially overlaps
Central Logging of Break Glass Account Usage - ISM-1614Depends on
Manage Emergency Account Access Changes - ISM-1620Partially overlaps
Ensure Privileged Accounts are Secured in AD - ISM-1623Partially overlaps
Centralised Logging of PowerShell Activities - ISM-1650Equivalent
Log Management of Privileged User Activities - ISM-1939Supports
Minimise Members in Privileged Security Groups - ISM-1941Supports
Restrict Computer Accounts in Privileged Security Groups - ISM-1953Depends on
Ensure Strong Management of Admin Account Credentials - ISM-1976Partially overlaps
Central Logging of Security Events on macOS - ISM-1977Partially overlaps
Central Logging of Linux System Events - ISM-2128Depends on
Limit Kernel-Mode Code Installation to Privileged Users Who Need It
|
| E8-RA-ML2.8 Event logs are protected from unauthorised changes and losses | Restrict admin privileges | - ISM-1624Broader than
Protect PowerShell Script Block Logs - ISM-1815Equivalent
Protect Event Logs from Unauthorised Access - ISM-1910Depends on
Log Network API Calls for Data Protection - ISM-1985Partially overlaps
Protect Event Logs from Unauthorised Access
|
| E8-RA-ML2.9 Event logs are analysed promptly for security events | Restrict admin privileges | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-0580Supports
Develop, Implement and Maintain a Security Monitoring Policy - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Partially meets
Analyse Cyber Security Events Promptly - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1536Depends on
Central Logging of Software Database Queries and Errors - ISM-1607Partially overlaps
Integrity Monitoring and Logging for Isolation Mechanism - ISM-1906Equivalent
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cybersecurity - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1978Supports
Centralised Logging for Server Application Events - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially overlaps
Timely Analysis of Security Event Logs
|
| E8-RA-ML2.10 Timely analysis of cyber security events to identify incidents | Restrict admin privileges | - ISM-1228Equivalent
Analyse Cyber Security Events Promptly - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1906Partially overlaps
Timely Analysis of Internet-Facing Server Logs - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1960Depends on
Timely Analysis of Event Logs for Cyber security - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Depends on
Timely Analysis of Security Event Logs - ISM-2116Depends on
Use Cyber Threat Intelligence for Event Detection
|
| E8-RA-ML2.11 Report cyber incidents to the CISO promptly | Restrict admin privileges | - ISM-0043Partially meets
Cyber Security Incident Response Plan Requirements - ISM-0123Equivalent
Report Cyber Security Incidents Promptly - ISM-0140Partially overlaps
Prompt Reporting of Cyber Incidents to ASD - ISM-0141Partially overlaps
Report Cyber Incidents Promptly to Designated Contacts - ISM-0142Broader than
Report Cryptographic Equipment Compromises Promptly - ISM-0576Partially meets
Develop and Maintain Cyber Security Incident Plans - ISM-0733Partially overlaps
Ensure CISO Awareness of Cyber Incidents - ISM-1088Partially overlaps
Report Potential Compromises of Mobile Devices Overseas - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1618Supports
CISO's Role in Cyber Security Incident Response - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents
|
| E8-RA-ML2.12 Report cyber security incidents to ASD promptly | Restrict admin privileges | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0123Partially overlaps
Report Cyber Security Incidents Promptly - ISM-0140Equivalent
Prompt Reporting of Cyber Incidents to ASD - ISM-0141Supports
Report Cyber Incidents Promptly to Designated Contacts
|
| E8-RA-ML2.13 Enact cyber incident response plan after an incident is identified | Restrict admin privileges | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0123Supports
Report Cyber Security Incidents Promptly - ISM-0125Supports
Maintaining a Cyber Security Incident Register - ISM-0576Depends on
Develop and Maintain Cyber Security Incident Plans - ISM-1019Partially meets
Develop a Denial of Service Response Plan - ISM-1618Supports
CISO's Role in Cyber Security Incident Response - ISM-1731Depends on
Plan and Coordinate Intrusion Remediation From Trusted Separate Systems - ISM-1732Partially overlaps
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-1819Equivalent
Enact Cyber Security Incident Response Plans
|
| E8-RA-ML3.1 Limit privileged access to what is necessary for duties | Restrict admin privileges | - ISM-0133Partially overlaps
Responding to Data Spills by Restricting Access - ISM-0441Partially overlaps
Ensuring Limited Access for Temporary System Use - ISM-0446Partially overlaps
Restrict Privileged Access for Foreign Nationals - ISM-0488Supports
Use Forced Commands for SSH Without Passwords - ISM-0611Broader than
Restrict Privileges for Gateway Administrators - ISM-1249Broader than
Limit Server Application User Privileges - ISM-1250Broader than
Limit Server Application User Account Privileges - ISM-1255Broader than
Restrict Database Content Access by User Duties and Functions - ISM-1263Supports
Enforce Unique Accounts for Server Administration - ISM-1268Partially overlaps
Enforce Need-to-Know Access in Databases - ISM-1392Depends on
Restrict File Modifications via Path Rules - ISM-1507Partially overlaps
Ensure Requests for Privileged Access are Verified - ISM-1508Equivalent
Limit Privileged Access to Essential Duties Only - ISM-1565Depends on
Annual Tailored Training for All Privileged Access Holders - ISM-1746Depends on
Restrict File System Permission Changes - ISM-1833Broader than
Limit Privileges for User Accounts in Active Directory - ISM-1843Broader than
Annual Review of Unconstrained Delegation in AD Accounts - ISM-1852Partially overlaps
Limit Unprivileged Access to Essential Functions - ISM-1883Broader than
Limit Authorised Privileged Account Online Service Access to Duties - ISM-1927Broader than
Limit Identity Server Access to Privileged Users Requiring It - ISM-1933Broader than
Restrict DCSync Permissions on Service Accounts - ISM-1934Broader than
Six-Monthly Review and Removal of DCSync User Permissions - ISM-1938Broader than
Restrict Domain Computers Group in Active Directory - ISM-1939Partially meets
Minimise Members in Privileged Security Groups - ISM-1948Depends on
Certificate Manager Approval for Templates Allowing Supplied SANs - ISM-1958Partially overlaps
Prevent Unauthorised Access for DCSync Accounts - ISM-2093Partially overlaps
Role-Based Access Controls in AI Applications - ISM-2128Broader than
Limit Kernel-Mode Code Installation to Privileged Users Who Need It - ISM-2133Depends on
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2138Depends on
Six-Monthly Review of OAuth Application Consents and Granted Permissions
|
| E8-RA-ML3.2 Use Secure Admin Workstations for Administrative Tasks | Restrict admin privileges | - ISM-0445Depends on
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-0843Depends on
Ensure Workstation Security with Application Control - ISM-1341Depends on
Implement HIPS or EDR on Workstations - ISM-1385Depends on
Segregation of Administrative Infrastructure from Networks - ISM-1387Partially overlaps
Use Jump Servers for Administrative Activities - ISM-1406Depends on
Use SOEs for Workstations and Servers - ISM-1731Partially overlaps
Plan and Coordinate Intrusion Remediation From Trusted Separate Systems - ISM-1750Partially overlaps
Segregation of Administrative Infrastructure for Server Security - ISM-1827Depends on
Use Dedicated Admin Accounts for Domain Controllers - ISM-1898Equivalent
Use Secure Admin Workstations for Administration - ISM-1953Depends on
Ensure Strong Management of Admin Account Credentials
|
| E8-RA-ML3.3 Just-in-time administration is used for administering systems and applications. | Restrict admin privileges | - ISM-0441Supports
Ensuring Limited Access for Temporary System Use - ISM-0445Partially overlaps
Dedicated Accounts for Privileged User Activities - ISM-1006Supports
Prevent Unauthorised Access to Network Traffic - ISM-1387Depends on
Use Jump Servers for Administrative Activities - ISM-1487Depends on
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1508Partially overlaps
Limit Privileged Access to Essential Duties Only - ISM-1604Supports
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1649Equivalent
Implement Just-in-Time Administration for System Access - ISM-1688Supports
Restrict Privileged Environment Access - ISM-1835Supports
Restrict Delegation of Privileged Active Directory Accounts - ISM-1852Supports
Limit Unprivileged Access to Essential Functions - ISM-1927Supports
Restrict Access to Microsoft Active Directory Servers - ISM-1939Supports
Minimise Members in Privileged Security Groups - ISM-1948Supports
Approval for Certificate Template SANs in AD Services - ISM-2136Depends on
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2156Depends on
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
|
| E8-RA-ML3.4 Memory integrity functionality is enabled | Restrict admin privileges | - ISM-1409Partially meets
Implement Restrictive OS Hardening Guidelines - ISM-1492Partially meets
Enable Exploit Protection in Operating Systems - ISM-1745Partially overlaps
Enable Security Features for System Protection - ISM-1896Equivalent
Enable Memory Integrity for Credential Protection
|
| E8-RA-ML3.5 Local Security Authority protection functionality is enabled | Restrict admin privileges | - ISM-1402Supports
Protecting Stored Credentials with Security Measures - ISM-1492Partially overlaps
Enable Exploit Protection in Operating Systems - ISM-1584Depends on
Prevent Unauthorised Changes to Security Settings - ISM-1686Partially overlaps
Enable Credential Guard for Credential Protection - ISM-1749Supports
Limit Cached Credentials to Single Logon - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software - ISM-1829Depends on
Prevent Password Storage in Group Policy Preferences - ISM-1858Partially meets
Implement Strict IT Equipment Hardening Guidelines - ISM-1861Equivalent
Enable Local Security Authority Protection - ISM-1896Supports
Enable Memory Integrity for Credential Protection - ISM-1897Partially overlaps
Enable Remote Credential Guard for Credential Protection
|
| E8-RA-ML3.6 Enable Credential Guard for secure credential storage | Restrict admin privileges | - ISM-1402Depends on
Protecting Stored Credentials with Security Measures - ISM-1492Partially overlaps
Enable Exploit Protection in Operating Systems - ISM-1686Equivalent
Enable Credential Guard for Credential Protection - ISM-1745Depends on
Enable Security Features for System Protection - ISM-1749Depends on
Limit Cached Credentials to Single Logon - ISM-1829Depends on
Prevent Password Storage in Group Policy Preferences - ISM-1861Depends on
Enable Local Security Authority Protection - ISM-1896Depends on
Enable Memory Integrity for Credential Protection - ISM-1897Partially overlaps
Enable Remote Credential Guard for Credential Protection
|
| E8-RA-ML3.7 Enable Remote Credential Guard functionality | Restrict admin privileges | - ISM-1590Depends on
Changing User Account Credentials After Compromise, Exposure or Shared Membership Change - ISM-1686Partially overlaps
Enable Credential Guard for Credential Protection - ISM-1749Depends on
Limit Cached Credentials to Single Logon - ISM-1861Depends on
Enable Local Security Authority Protection - ISM-1896Depends on
Enable Memory Integrity for Credential Protection - ISM-1897Equivalent
Enable Remote Credential Guard for Credential Protection
|
| E8-RA-ML3.8 Timely analysis of event logs from non-internet-facing servers | Restrict admin privileges | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-1625Supports
Develop Insider Threat Mitigation Programs - ISM-1906Partially overlaps
Timely Analysis of Internet-Facing Server Logs - ISM-1907Equivalent
Timely Analysis of Non-Internet-Server Logs - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1979Depends on
Central Logging for Security Events on Servers - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially meets
Timely Analysis of Security Event Logs - ISM-2116Partially meets
Use Cyber Threat Intelligence for Event Detection
|
| E8-RA-ML3.9 Timely analysis of workstation event logs for security events | Restrict admin privileges | - ISM-1228Broader than
Analyse Cyber Security Events Promptly - ISM-1537Partially overlaps
Log Security-Relevant Database Events Centrally - ISM-1907Partially overlaps
Timely Analysis of Non-Internet-Server Logs - ISM-1960Partially overlaps
Timely Analysis of Event Logs for Cyber security - ISM-1961Partially overlaps
Timely Analysis of Network Device Event Logs - ISM-1986Partially overlaps
Timely Analysis of Critical Server Event Logs - ISM-1987Partially meets
Timely Analysis of Security Event Logs - ISM-2051Supports
Ensure Event Logs for Cyber security Event Detection
|
| E8-RB-ML1.1 Backups aligned with business continuity needs | Regular backups | - ISM-0734Depends on
CISO Role in Disaster Recovery Planning - ISM-1511Equivalent
Conduct and Maintain Regular Data Backups - ISM-1515Depends on
Test Backup Restoration During Disaster Recovery - ISM-1547Supports
Develop and Maintain Data Backup Procedures - ISM-1548Depends on
Develop and Maintain Data Restoration Processes - ISM-1555Partially meets
Prepare Mobile Devices Before Overseas Travel - ISM-1732Depends on
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-1811Broader than
Secure and Resilient Data Backup Retention
|
| E8-RB-ML1.2 Ensure backups are synchronised for restoration to a common point in time | Regular backups | - ISM-1511Partially meets
Conduct and Maintain Regular Data Backups - ISM-1515Supports
Test Backup Restoration During Disaster Recovery - ISM-1547Partially overlaps
Develop and Maintain Data Backup Procedures - ISM-1548Partially overlaps
Develop and Maintain Data Restoration Processes - ISM-1555Partially meets
Prepare Mobile Devices Before Overseas Travel - ISM-1810Equivalent
Ensuring Data Backup Synchronisation - ISM-1811Partially overlaps
Secure and Resilient Data Backup Retention
|
| E8-RB-ML1.3 Backups retained securely and resiliently | Regular backups | - ISM-1511Partially overlaps
Conduct and Maintain Regular Data Backups - ISM-1515Supports
Test Backup Restoration During Disaster Recovery - ISM-1547Partially overlaps
Develop and Maintain Data Backup Procedures - ISM-1548Depends on
Develop and Maintain Data Restoration Processes - ISM-1769Depends on
Using AES Encryption with Strong Key Lengths - ISM-1810Partially overlaps
Ensuring Data Backup Synchronisation - ISM-1811Equivalent
Secure and Resilient Data Backup Retention - ISM-1928Partially overlaps
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-2151Broader than
Technically Enforced Immutability Protecting Backups Through Their Retention Period
|
| E8-RB-ML1.4 Test backup restoration to a common point during disaster recovery | Regular backups | - ISM-0917Supports
Procedures for Handling Malicious Code Infections - ISM-1511Depends on
Conduct and Maintain Regular Data Backups - ISM-1515Equivalent
Test Backup Restoration During Disaster Recovery - ISM-1547Depends on
Develop and Maintain Data Backup Procedures - ISM-1548Depends on
Develop and Maintain Data Restoration Processes - ISM-1555Partially meets
Prepare Mobile Devices Before Overseas Travel - ISM-1810Depends on
Ensuring Data Backup Synchronisation - ISM-1811Depends on
Secure and Resilient Data Backup Retention
|
| E8-RB-ML1.5 Unprivileged accounts cannot access others' backups | Regular backups | - ISM-1812Equivalent
Restrict Backup Access to Unprivileged Users - ISM-1813Partially overlaps
Prevent Unauthorised User Access to Backup Data - ISM-1852Broader than
Limit Unprivileged Access to What Duties Require
|
| E8-RB-ML1.6 Prevent unprivileged accounts from modifying and deleting backups | Regular backups | - ISM-1707Partially overlaps
Restrict Backup Modifications by Privileged Users - ISM-1708Partially overlaps
Prevent Backup Modifications During Retention - ISM-1811Partially meets
Secure and Resilient Data Backup Retention - ISM-1814Equivalent
Prevent Backup Modifications by Unprivileged Users - ISM-1928Partially overlaps
Encrypt Backups of Microsoft AD Servers - ISM-2151Partially overlaps
Technically Enforced Immutability Protecting Backups Through Their Retention Period - ISM-2152Depends on
Segregate Backup Infrastructure With Separate Administrative Authentication
|
| E8-RB-ML2.1 Prevent privileged accounts from accessing others' backups | Regular backups | - ISM-1705Equivalent
Restrict Access to User Account Backups - ISM-1706Partially overlaps
Prevent Backup Access by Privileged Users - ISM-1812Partially overlaps
Restrict Backup Access to Unprivileged Users - ISM-1928Partially overlaps
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-2152Depends on
Segregate Backup Infrastructure With Separate Administrative Authentication
|
| E8-RB-ML2.2 Privileged accounts cannot modify or delete backups. | Regular backups | - ISM-1705Supports
Restrict Access to User Account Backups - ISM-1706Partially overlaps
Prevent Backup Access by Privileged Users - ISM-1707Equivalent
Restrict Backup Modifications by Privileged Users - ISM-1708Partially overlaps
Prevent Backup Modifications During Retention - ISM-1811Partially meets
Secure and Resilient Data Backup Retention - ISM-1814Partially overlaps
Prevent Backup Modifications by Unprivileged Users - ISM-1928Supports
Encrypt Backups of Microsoft AD Servers - ISM-2151Partially overlaps
Technically Enforced Immutability Protecting Backups Through Their Retention Period - ISM-2152Depends on
Segregate Backup Infrastructure With Separate Administrative Authentication
|
| E8-RB-ML3.1 Unprivileged accounts cannot access their own backups | Regular backups | - ISM-1811Partially meets
Secure and Resilient Data Backup Retention - ISM-1813Equivalent
Prevent Unauthorised User Access to Backup Data - ISM-1928Partially overlaps
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
|
| E8-RB-ML3.2 Privileged accounts cannot access their own backups | Regular backups | - ISM-1508Partially overlaps
Restricting Privileged Access to What Duties Require - ISM-1706Equivalent
Prevent Backup Access by Privileged Users - ISM-1708Supports
Prevent Backup Modifications During Retention - ISM-1811Supports
Secure and Resilient Data Backup Retention - ISM-1813Partially overlaps
Prevent Unauthorised User Access to Backup Data - ISM-1928Partially meets
Encrypt Backups of Microsoft AD Servers - ISM-2152Depends on
Segregate Backup Infrastructure With Separate Administrative Authentication
|
| E8-RB-ML3.3 Backup administrators cannot modify or delete backups during retention | Regular backups | - ISM-1707Partially overlaps
Restrict Backup Modifications by Privileged Users - ISM-1708Equivalent
Prevent Backup Modifications During Retention - ISM-1811Partially meets
Secure and Resilient Data Backup Retention - ISM-1814Partially overlaps
Prevent Backup Modifications by Unprivileged Users - ISM-1928Partially overlaps
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-2151Partially overlaps
Technically Enforced Immutability Protecting Backups Through Their Retention Period
|
| E8-RM-ML1.1 Disable Microsoft Office macros for users without a business need | Configure macro settings | - ISM-1489Supports
Prevent Users from Changing Office Macro Security Settings - ISM-1671Equivalent
Disabling Microsoft Office Macros for Unauthorised Users - ISM-1674Partially overlaps
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Partially overlaps
Prevent Enabling Untrusted Microsoft Office Macros - ISM-2156Partially overlaps
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
|
| E8-RM-ML1.2 Block Microsoft Office macros from the internet | Configure macro settings | - ISM-1234Supports
Protect Email Systems with Content Filtering - ISM-1488Equivalent
Blocking Internet-Originating Macros in Office Files - ISM-1489Supports
Prevent Users from Changing Office Macro Security Settings - ISM-1671Supports
Disabling Microsoft Office Macros for Unauthorised Users - ISM-1672Partially overlaps
Enable Antivirus Scanning for Office Macros - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Supports
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1891Depends on
Restrict Non-V3 Signed Macros in Microsoft Office
|
| E8-RM-ML1.3 Enable antivirus scanning for Microsoft Office macros | Configure macro settings | - ISM-1417Depends on
Ensure Antivirus Protection on Workstations and Servers - ISM-1672Equivalent
Enable Antivirus Scanning for Office Macros - ISM-1969Depends on
Preventing Accidental Execution of Malicious Code
|
| E8-RM-ML1.4 Prevent users from changing Microsoft Office macro security settings | Configure macro settings | - ISM-1488Supports
Blocking Internet-Originating Macros in Office Files - ISM-1489Equivalent
Prevent Users from Changing Office Macro Security Settings - ISM-1584Depends on
Prevent Unauthorised Changes to Security Settings - ISM-1601Partially overlaps
Implement Microsoft Attack Surface Reduction Rules - ISM-1671Depends on
Disable Office Macros for Users Lacking a Demonstrated Business Requirement - ISM-1672Depends on
Enable Antivirus Scanning for Office Macros - ISM-1673Depends on
Prevent Win32 API Calls by Office Macros - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Depends on
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1748Partially overlaps
Lock Email Client Security Settings Against User Changes - ISM-1823Partially meets
Lock Office Productivity Suite Security Settings Against User Changes - ISM-1825Partially overlaps
Lock Security Product Settings Against Changes by Human Users - ISM-1915Depends on
Ensure User Application Configurations are Approved
|
| E8-RM-ML2.1 Microsoft Office macros are blocked from making Win32 API calls | Configure macro settings | - ISM-1489Supports
Prevent Users from Changing Office Macro Security Settings - ISM-1601Partially overlaps
Implement Microsoft Attack Surface Reduction Rules - ISM-1667Partially overlaps
Prevent Child Processes in Microsoft Office - ISM-1669Partially overlaps
Prevent Microsoft Office from Injecting Code - ISM-1673Equivalent
Prevent Win32 API Calls by Office Macros - ISM-1915Broader than
Ensure User Application Configurations are Approved
|
| E8-RM-ML3.1 Restrict Microsoft Office macros to only trusted or sandboxed environments | Configure macro settings | - ISM-0843Supports
Ensure Workstation Security with Application Control - ISM-1487Supports
Restrict Macro Editing to Privileged Users - ISM-1488Partially meets
Blocking Internet-Originating Macros in Office Files - ISM-1671Supports
Disabling Microsoft Office Macros for Unauthorised Users - ISM-1672Partially overlaps
Enable Antivirus Scanning for Office Macros - ISM-1673Partially overlaps
Prevent Win32 API Calls by Office Macros - ISM-1674Equivalent
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Supports
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1676Depends on
Validate Microsoft Office Trusted Publishers List At Least Annually - ISM-1796Supports
Digitally Sign Executable Software for Security - ISM-1890Supports
Ensure Macros Are Free of Malicious Code - ISM-1891Supports
Restrict Non-V3 Signed Macros in Microsoft Office - ISM-2050Supports
Validate Digital Signature Certificates Securely
|
| E8-RM-ML3.2 Check Microsoft Office macros for malicious code before signing or trusting | Configure macro settings | - ISM-1487Supports
Restrict Macro Editing to Privileged Users - ISM-1672Supports
Enable Antivirus Scanning for Office Macros - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Supports
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1796Partially overlaps
Digitally Sign Executable Software for Security - ISM-1890Equivalent
Ensure Macros Are Free of Malicious Code - ISM-1891Supports
Restrict Non-V3 Signed Macros in Microsoft Office - ISM-1969Supports
Preventing Accidental Execution of Malicious Code - ISM-2026Broader than
Scan Software Artefacts for Malicious Content - ISM-2050Supports
Validate Digital Signature Certificates Securely
|
| E8-RM-ML3.3 Only privileged users can modify content in Trusted Locations | Configure macro settings | - ISM-1392Partially overlaps
Restrict File Modifications via Path Rules - ISM-1487Equivalent
Restrict Macro Editing to Privileged Users - ISM-1508Partially overlaps
Restricting Privileged Access to What Duties Require - ISM-1671Supports
Disabling Microsoft Office Macros for Unauthorised Users - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1890Partially overlaps
Ensure Macros Are Free of Malicious Code
|
| E8-RM-ML3.4 Untrusted Publisher Macros Cannot Be Enabled via Message Bar or Backstage View | Configure macro settings | - ISM-1489Supports
Prevent Users from Changing Office Macro Security Settings - ISM-1674Partially meets
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Equivalent
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1676Supports
Validate Microsoft Office Trusted Publishers List At Least Annually - ISM-1891Partially overlaps
Restrict Non-V3 Signed Macros in Microsoft Office
|
| E8-RM-ML3.5 Block enabling of non-V3 signed Microsoft Office macros via Message Bar | Configure macro settings | - ISM-1489Depends on
Prevent Users from Changing Office Macro Security Settings - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Partially overlaps
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1823Depends on
Lock Office Productivity Suite Security Settings Against User Changes - ISM-1891Equivalent
Restrict Non-V3 Signed Macros in Microsoft Office
|
| E8-RM-ML3.6 Validate list of trusted publishers in Microsoft Office annually | Configure macro settings | - ISM-1582Partially meets
Annual Validation of Application Control Rulesets - ISM-1674Depends on
Ensuring Secure Execution of Microsoft Office Macros - ISM-1675Supports
Prevent Enabling Untrusted Microsoft Office Macros - ISM-1676Equivalent
Validate Microsoft Office Trusted Publishers List At Least Annually
|