| Annex A 5.1 Policies for information security | Organisational controls | - ISM-0009Depends on
System Owners Identify Supplementary Controls With Authorising Officer - ISM-0027Depends on
Mandatory Authorisation for System Operation - ISM-0039Partially overlaps
Develop and Maintain a Cyber Security Strategy - ISM-0041Supports
Develop a Detailed System Security Plan - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0047Partially overlaps
Approval Process for Cyber Security Documentation - ISM-0264Partially overlaps
Develop and Maintain an Email Usage Policy - ISM-0407Depends on
Maintaining a Secure Lifetime Access Record for Each Human User - ISM-0499Depends on
Ensure Compliance with ASD Communication Security Policies - ISM-0588Partially meets
Develop and Maintain MFD Usage Policy - ISM-0718Depends on
CISO Reporting to Board on Cyber Security - ISM-0725Depends on
Cyber Security Steering Committee Coordination - ISM-0726Depends on
Coordinate Security Risk Management Activities - ISM-0732Depends on
Manage and Allocate Cyber Security Budget - ISM-0888Partially overlaps
Annual Review of Cyber Security Documentation - ISM-1078Broader than
Develop and Maintain Telephone System Usage Policy - ISM-1195Supports
Enforce Policy with Evaluated Mobile Device Management - ISM-1359Broader than
Establish and Maintain Removable Media Policy - ISM-1478Partially overlaps
CISO Management of Cyber Security Compliance - ISM-1510Broader than
Develop and Maintain a Digital Preservation Policy - ISM-1549Partially meets
Develop and Maintain Media Management Policy - ISM-1551Partially meets
Develop and Maintain IT Equipment Management Policy - ISM-1587Partially overlaps
Annual Security Status Reporting for Systems - ISM-1602Partially overlaps
Ensure Cyber Security Docs Are Communicated - ISM-1617Partially overlaps
Regular Review of Cyber Security Program - ISM-1626Depends on
Seek Legal Advice for Insider Threat Plans - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1829Broader than
Prevent Password Storage in Group Policy Preferences - ISM-1864Broader than
Develop and Enforce a System Usage Policy - ISM-1865Depends on
Compliance with System Usage Policies for Access - ISM-1868Supports
Restrictions on Mobile Device Removable Media - ISM-1997Depends on
Define Cyber Security Roles for Leadership - ISM-1998Supports
Integrate Cyber Security Across Business Functions - ISM-1999Partially overlaps
Align Cyber Security with Business Strategy - ISM-2001Depends on
Championing Cyber Security at an Executive Level - ISM-2002Depends on
Ensure Board Cyber Security Literacy for Compliance - ISM-2008Supports
Criteria for Medical Devices in SECRET and TOP SECRET Areas - ISM-2074Broader than
Develop and Maintain AI Usage Policy - ISM-2105Broader than
Advise Staff to Limit Posting Work Information on Unauthorised Online Services - ISM-2106Depends on
Advise Staff to Limit Posting Work Skills Online - ISM-2120Broader than
Develop and Maintain Secure Software Policy
|
| Annex A 5.2 Defining Information Security Roles and Responsibilities | Organisational controls | - ISM-0041Supports
Develop a Detailed System Security Plan - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0047Partially overlaps
Approval Process for Cyber Security Documentation - ISM-0613Partially meets
Requirement for Gateway System Administrators Nationality - ISM-0616Partially meets
Ensure Separation of Duties for Gateway Admins - ISM-0701Supports
Establish Mobile Device Emergency Sanitisation Processes and Procedures - ISM-0714Partially overlaps
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-0717Partially overlaps
CISO Oversight of Cyber Security Personnel - ISM-0725Partially overlaps
Cyber Security Steering Committee Coordination - ISM-0726Partially overlaps
Coordinate Security Risk Management Activities - ISM-0732Partially overlaps
Manage and Allocate Cyber Security Budget - ISM-0733Partially meets
Ensure CISO Awareness of Cyber Incidents - ISM-0734Partially overlaps
CISO Role in Disaster Recovery Planning - ISM-1071Partially overlaps
Assign System Ownership for Better Oversight - ISM-1478Partially overlaps
CISO Management of Cyber Security Compliance - ISM-1525Partially overlaps
Register Systems with Authorising Officers - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1773Partially overlaps
Eligibility Criteria for Gateway System Administrators - ISM-1997Equivalent
Define Cyber Security Roles for Leadership - ISM-1998Supports
Integrate Cyber Security Across Business Functions - ISM-1999Supports
Align Cyber Security with Business Strategy - ISM-2001Partially overlaps
Championing Cyber Security at an Executive Level - ISM-2003Supports
Monitor Cyber Security Workforce and Skill Gaps - ISM-2006Partially overlaps
Board Plans for Major Cyber Security Incidents - ISM-2020Depends on
Ensure Adequate Cyber Security Personnel Are Acquired - ISM-2035Partially meets
Document Security Roles for Software Development - ISM-2036Broader than
Document Security Duties for Software Developers - ISM-2038Supports
Maintain Developer Cyber Security Skills Register
|
| Annex A 5.3 Segregation of Duties | Organisational controls | - ISM-0047Partially overlaps
Approval Process for Cyber Security Documentation - ISM-0445Partially overlaps
Dedicated Accounts for Privileged User Activities - ISM-1255Supports
Restrict Database User Access Based on Duties - ISM-1705Partially overlaps
Restrict Access to User Account Backups - ISM-1706Partially overlaps
Prevent Backup Access by Privileged Users - ISM-1833Supports
Limit Privileges for User Accounts in Active Directory - ISM-1835Supports
Restrict Delegation of Privileged Active Directory Accounts - ISM-1958Partially overlaps
Prevent Unauthorised Access for DCSync Accounts - ISM-2048Supports
Restrict Non-Admins from Changing Permissions - ISM-2093Supports
Role-Based Access Controls in AI Applications
|
| Annex A 5.4 Management responsibilities for information security | Organisational controls | - ISM-0009Depends on
System Owners Identify Supplementary Controls With Authorising Officer - ISM-0039Supports
Develop and Maintain a Cyber Security Strategy - ISM-0047Supports
Approval Process for Cyber Security Documentation - ISM-0264Partially overlaps
Develop and Maintain an Email Usage Policy - ISM-0348Broader than
Develop and Maintain Media Sanitisation Procedures - ISM-0408Depends on
Logon Banner for Security Responsibilities - ISM-0499Depends on
Ensure Compliance with ASD Communication Security Policies - ISM-0576Supports
Develop and Maintain Cyber Security Incident Plans - ISM-0588Supports
Develop and Maintain MFD Usage Policy - ISM-0714Supports
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-0718Depends on
CISO Reporting to Board on Cyber Security - ISM-0720Supports
Develop and Maintain a Cyber Security Communication Strategy - ISM-0724Depends on
Implement Cyber Security Metrics and KPIs - ISM-0725Supports
Cyber Security Steering Committee Coordination - ISM-0726Depends on
Coordinate Security Risk Management Activities - ISM-0820Partially meets
Avoid Posting Work Data on Unauthorised Online Services - ISM-0824Depends on
Avoid Using Unauthorised Online File Services - ISM-1078Partially overlaps
Develop and Maintain Telephone System Usage Policy - ISM-1359Depends on
Establish and Maintain Removable Media Policy - ISM-1478Partially overlaps
CISO Management of Cyber Security Compliance - ISM-1510Supports
Develop and Maintain a Digital Preservation Policy - ISM-1533Depends on
Establish Mobile Device Management Policies - ISM-1549Partially overlaps
Develop and Maintain Media Management Policy - ISM-1551Supports
Develop and Maintain IT Equipment Management Policy - ISM-1602Partially overlaps
Ensure Cyber Security Docs Are Communicated - ISM-1864Depends on
Develop and Enforce a System Usage Policy - ISM-1865Depends on
Compliance with System Usage Policies for Access - ISM-1884Supports
Ensure Compliance with Emanation Security Doctrine - ISM-1998Partially meets
Integrate Cyber Security Across Business Functions - ISM-1999Supports
Align Cyber Security with Business Strategy - ISM-2001Depends on
Championing Cyber Security at an Executive Level - ISM-2004Depends on
Enhancing Cyber Security Skills and Experience - ISM-2036Depends on
Document Security Duties for Software Developers - ISM-2074Depends on
Develop and Maintain AI Usage Policy - ISM-2105Broader than
Advise Staff to Limit Posting Work Information on Unauthorised Online Services
|
| Annex A 5.5 Establish and Maintain Contact with Authorities | Organisational controls | - ISM-0039Supports
Develop and Maintain a Cyber Security Strategy - ISM-0043Supports
Cyber Security Incident Response Plan Requirements - ISM-0138Depends on
Maintaining Integrity of Evidence in Investigations - ISM-0140Partially meets
Prompt Reporting of Cyber Incidents to ASD - ISM-0181Supports
Ensure Cabling Meets Australian Standards - ISM-0249Supports
Request ASD Emanation Security Assessments for Deployed Classified Systems - ISM-0576Supports
Develop and Maintain Cyber Security Incident Plans - ISM-1137Supports
Request Risk Assessment for Emanation Security - ISM-1755Partially overlaps
Develop and Maintain a Vulnerability Disclosure Policy
|
| Annex A 5.6 Contact with special interest groups | Organisational controls | - ISM-0039Supports
Develop and Maintain a Cyber Security Strategy - ISM-0720Supports
Develop and Maintain a Cyber Security Communication Strategy - ISM-1617Supports
Regular Review of Cyber Security Program - ISM-2000Partially overlaps
Regular Cyber Security Briefings for Executives
|
| Annex A 5.7 Threat Intelligence Collection and Analysis | Organisational controls | - ISM-1163Supports
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1203Depends on
Risk Assessment for System Security - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1683Supports
Central Logging of Multi-factor Authentication Events - ISM-1696Depends on
Apply Critical Patches Within 48 Hours - ISM-1697Depends on
Apply Non-Critical Patches Within One Month - ISM-1987Depends on
Timely Analysis of Security Event Logs - ISM-2039Supports
Review Threat Model During Software Development - ISM-2073Supports
Develop a Post-Quantum Cryptography Transition Plan - ISM-2116Partially overlaps
Use Cyber Threat Intelligence for Event Detection - ISM-2153Supports
Quarterly Threat Hunting Informed by Current Threat Intelligence
|
| Annex A 5.8 Information security in project management | Organisational controls | - ISM-0039Supports
Develop and Maintain a Cyber Security Strategy - ISM-0041Supports
Develop a Detailed System Security Plan - ISM-0432Supports
Document System Access Requirements in Security Plans - ISM-0597Broader than
Consult ASD Before Changing CDS Connectivity - ISM-0726Supports
Coordinate Security Risk Management Activities - ISM-1203Depends on
Risk Assessment for System Security - ISM-1420Depends on
Ensure Non-Production Security Matches Production - ISM-1478Supports
CISO Management of Cyber Security Compliance - ISM-1602Supports
Ensure Cyber Security Docs Are Communicated - ISM-1790Broader than
Ensure Integrity in IT and OT Deliveries - ISM-1998Broader than
Integrate Cyber Security Across Business Functions - ISM-2033Broader than
Document and Maintain Software Security Requirements - ISM-2084Broader than
Document AI Model and System Characteristics
|
| Annex A 5.9 Inventory management of information and associated assets | Organisational controls | - ISM-0336Partially overlaps
Develop and Maintain Networked IT Equipment Register - ISM-1071Supports
Assign System Ownership for Better Oversight - ISM-1243Partially overlaps
Develop and Verify Database Register - ISM-1493Partially overlaps
Maintain and Verify Software Registers - ISM-1525Supports
Register Systems with Authorising Officers - ISM-1543Partially meets
Register for RF and IR Devices in Secret Areas - ISM-1551Supports
Develop and Maintain IT Equipment Management Policy - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1635Depends on
System Owners Implement Security Controls for Each System and Environment - ISM-1637Partially overlaps
Maintain an Outsourced Cloud Service Register - ISM-1638Partially overlaps
Maintain a Comprehensive Outsourced Cloud Service Register - ISM-1713Partially overlaps
Develop and Maintain a Removable Media Register - ISM-1737Partially overlaps
Maintain a Comprehensive Managed Service Register - ISM-1869Broader than
Maintain Non-Networked IT Equipment Register - ISM-1966Partially overlaps
CISO Manages and Verifies System Register - ISM-2005Supports
Understanding Business Criticality of Organisation Systems - ISM-2007Partially meets
Authorised Medical Device Register for SECRET and TOP SECRET Areas
|
| Annex A 5.10 Acceptable Use Policies for Information and Assets | Organisational controls | - ISM-0039Depends on
Develop and Maintain a Cyber Security Strategy - ISM-0047Supports
Approval Process for Cyber Security Documentation - ISM-0161Depends on
Ensure Security of Unused IT Equipment and Media - ISM-0240Partially meets
Prevent Sensitive Data in Messaging Services - ISM-0258Broader than
Establish and Maintain a Web Usage Policy - ISM-0264Broader than
Develop and Maintain an Email Usage Policy - ISM-0337Supports
Ensure Media is Used with Authorised Systems - ISM-0348Partially overlaps
Develop and Maintain Media Sanitisation Procedures - ISM-0358Supports
Classification Retention for Sanitised EPROM and EEPROM - ISM-0588Broader than
Develop and Maintain MFD Usage Policy - ISM-0610Depends on
Training Human Users on Secure CDS Use Before Granting Access - ISM-0661Supports
User Accountability for Data Transfers - ISM-0824Broader than
Avoid Using Unauthorised Online File Services - ISM-0870Depends on
Secure Storage and Handling of Mobile Devices - ISM-1078Broader than
Develop and Maintain Telephone System Usage Policy - ISM-1083Partially overlaps
Advise Personnel on Mobile Communication Sensitivity - ISM-1146Broader than
Separate Personal and Work Accounts for Online Services - ISM-1187Supports
Check Data for Improper Markings Before Export - ISM-1314Depends on
Ensure Wireless Devices are Wi-Fi Alliance Certified - ISM-1359Broader than
Establish and Maintain Removable Media Policy - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1418Depends on
Disable Unnecessary Removable Media Access - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1549Partially overlaps
Develop and Maintain Media Management Policy - ISM-1551Partially overlaps
Develop and Maintain IT Equipment Management Policy - ISM-1599Broader than
Proper Handling of Sensitive IT Equipment - ISM-1602Depends on
Ensure Cyber Security Docs Are Communicated - ISM-1625Supports
Develop Insider Threat Mitigation Programs - ISM-1644Broader than
Secure Communication Practices in Public Areas - ISM-1864Broader than
Develop and Enforce a System Usage Policy - ISM-1865Supports
Compliance with System Usage Policies for Access - ISM-1868Supports
Restrictions on Mobile Device Removable Media - ISM-2074Broader than
Develop and Maintain AI Usage Policy - ISM-2075Broader than
Prohibit the Use of Fax Machines for Messages - ISM-2095Broader than
Block Personal Devices Granting AI Agents Access to Sensitive Systems - ISM-2104Partially overlaps
Do Not Post Security Clearance and Briefing Details Online - ISM-2105Broader than
Advise Staff to Limit Posting Work Information on Unauthorised Online Services - ISM-2106Broader than
Advise Staff to Limit Posting Work Skills Online
|
| Annex A 5.11 Return of Organisation's Assets upon Departure | Organisational controls | |
| Annex A 5.12 Information Classification Policy and Practices | Organisational controls | - ISM-0027Partially overlaps
Mandatory Authorisation for System Operation - ISM-0201Broader than
Labelling Requirements for TOP SECRET Conduits - ISM-0208Supports
Maintain a Comprehensive Cable Register - ISM-0233Depends on
Use Encrypted Cordless Systems for Sensitive Conversations - ISM-0240Supports
Prevent Sensitive Data in Messaging Services - ISM-0269Supports
Restrict Sensitive Emails to Verified Recipients - ISM-0270Broader than
Apply Protective Markings to Emails Based on Sensitivity - ISM-0271Supports
Prevent Automatic Email Marking by Protective Tools - ISM-0272Supports
Prevent Unauthorised Protective Marking Selection - ISM-0293Broader than
Classify IT Equipment by Data Sensitivity - ISM-0323Broader than
Classifying Media by Data Sensitivity - ISM-0325Depends on
Reclassify Media to Higher Sensitivity - ISM-0332Broader than
Label Media With Protective Markings Reflecting Sensitivity Or Classification - ISM-0358Supports
Classification Retention for Sanitised EPROM and EEPROM - ISM-0393Broader than
Classify Databases Based on Data Sensitivity - ISM-0462Depends on
Managing Encryption Access for IT Equipment and Media - ISM-0501Depends on
Transport of Keyed Cryptographic Equipment - ISM-0565Supports
Email Security for Protective Markings - ISM-0589Depends on
Limit Document Sensitivity on MFDs Based on Network Classification - ISM-0694Depends on
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0831Supports
Ensure Proper Handling of Sensitive Media - ISM-0835Supports
TOP SECRET Volatile Media Retains Classification After Sanitisation - ISM-1053Supports
Secure Physical Access for Classified Equipment - ISM-1083Broader than
Advise Personnel on Mobile Communication Sensitivity - ISM-1089Broader than
Block Downgrading Protective Markings on Email Replies and Forwards - ISM-1268Supports
Enforce Need-to-Know Access in Databases - ISM-1461Supports
Same Classification and Security Domain for Shared Isolation Hosts - ISM-1482Depends on
Ensure Separation of Classified and Personal Data on Devices - ISM-1530Supports
Secure Classified Equipment in Suitable Security Containers - ISM-1599Supports
Proper Handling of Sensitive IT Equipment - ISM-1719Depends on
Colour Code for TOP SECRET Cables - ISM-1729Broader than
Storage Classification of Media Waste Particles - ISM-1737Depends on
Recording Required Details for Each Managed Service in the Register - ISM-1893Depends on
Enforcing Multi-Factor Authentication for User Security - ISM-2008Supports
Criteria for Medical Devices in SECRET and TOP SECRET Areas - ISM-2046Depends on
Ensure Secure Impersonation Logging Practices - ISM-2100Depends on
Do Not View Classified Data on Mobile Devices
|
| Annex A 5.13 Labelling of Information | Organisational controls | - ISM-0201Broader than
Labelling Requirements for TOP SECRET Conduits - ISM-0208Depends on
Maintain a Comprehensive Cable Register - ISM-0218Broader than
Label and Protect Long TS Fibre-Optic Leads - ISM-0240Depends on
Prevent Sensitive Data in Messaging Services - ISM-0270Partially meets
Apply Protective Markings to Emails Based on Sensitivity - ISM-0271Partially overlaps
Prevent Automatic Email Marking by Protective Tools - ISM-0272Broader than
Restrict Protective Marking Tools to Authorised System Markings - ISM-0293Partially overlaps
Classify IT Equipment by Data Sensitivity - ISM-0294Partially meets
Label IT Equipment with Sensitivity Markings - ISM-0296Partially overlaps
Approval Required for High Assurance IT Equipment Labelling - ISM-0332Partially meets
Label Media With Protective Markings Reflecting Sensitivity Or Classification - ISM-0337Supports
Ensure Media is Used with Authorised Systems - ISM-0356Broader than
Classify Magnetic Media After Sanitisation - ISM-0358Supports
Classification Retention for Sanitised EPROM and EEPROM - ISM-0378Partially overlaps
Remove Labels from Media Before Disposal - ISM-0393Depends on
Classify Databases Based on Data Sensitivity - ISM-0501Supports
Transport of Keyed Cryptographic Equipment - ISM-0589Depends on
Limit Document Sensitivity on MFDs Based on Network Classification - ISM-0831Depends on
Ensure Proper Handling of Sensitive Media - ISM-0926Broader than
Ensure Cables Are Not Salmon Pink or Red - ISM-1089Broader than
Block Downgrading Protective Markings on Email Replies and Forwards - ISM-1107Broader than
Colour Restrictions for Wall Outlet Boxes - ISM-1216Broader than
Ensure Correct Labelling of Non-conformant Cables - ISM-1535Supports
Prevent Unsuitable Foreign Data Exports - ISM-2094Supports
AI Content Filtering to Block Sensitive Data Exposure
|
| Annex A 5.14 Information Transfer Policies and Procedures | Organisational controls | - ISM-0072Supports
Document Security Requirements in Contractual Arrangements - ISM-0109Partially meets
Timely Analysis of Workstation Event Logs - ISM-0240Supports
Prevent Sensitive Data in Messaging Services - ISM-0347Supports
Use Write-Once Media for Secure Data Transfers - ISM-0467Supports
Using HACE for Secure Communication of Data - ISM-0481Supports
Ensure Use of High Assurance Cryptographic Protocols - ISM-0490Partially meets
Ensure S/MIME 3.0 or Later is Used - ISM-0571Partially meets
Ensure Secure Email Transmission via Gateways - ISM-0626Supports
Implementing CDS for Secure Network Segmentation - ISM-0643Supports
Use of Diodes for Unidirectional Gateway Security - ISM-0649Partially meets
Filter Gateway Files for Allowed Types - ISM-0660Supports
Monthly Verification of Data Transfer Logs for SECRET Systems - ISM-0661Partially overlaps
User Accountability for Data Transfers - ISM-0663Equivalent
Develop and Maintain Data Transfer Procedures - ISM-0675Partially meets
Ensure Data Exports are Digitally Signed - ISM-0677Supports
Ensure File Integrity Through Signature Validation - ISM-0947Supports
Sanitise Media After Data Transfers Between Domains - ISM-1178Partially meets
Limit Network Documentation for Third Parties - ISM-1192Supports
Inspecting and Filtering Data with Gateways - ISM-1277Partially meets
Encrypt Database and Web Server Communications - ISM-1284Broader than
Ensure Content Validation for Gateway Files - ISM-1420Depends on
Ensure Non-Production Security Matches Production - ISM-1454Supports
Enhancing Security with Encrypted RADIUS Communications - ISM-1535Partially meets
Prevent Unsuitable Foreign Data Exports - ISM-1574Partially overlaps
Data Portability in Service Contracts - ISM-1589Partially meets
Enable MTA-STS for Secure Email Transport - ISM-1594Partially meets
Secure Delivery of User Account Credentials - ISM-1765Supports
Use RSA with 3072-bit Modulus for Security - ISM-1779Partially overlaps
Quarantine Data Failing Security Checks During Manual Export - ISM-1866Partially overlaps
Prevent Storing Classified Data on Privately Owned Devices - ISM-1908Supports
Responsible Disclosure of Software Vulnerabilities - ISM-2097Depends on
Configure Mobile Devices with Always On VPN - ISM-2098Broader than
Prevent Data Transfer Over USB on Mobile Devices
|
| Annex A 5.15 Access Control Policies and Procedures | Organisational controls | - ISM-0027Depends on
Mandatory Authorisation for System Operation - ISM-0217Broader than
Secure Separation of Non-TOP SECRET and TOP SECRET Panels - ISM-0258Partially overlaps
Establish and Maintain a Web Usage Policy - ISM-0269Broader than
Restrict Sensitive Emails to Verified Recipients - ISM-0343Broader than
Disabling Unnecessary Access to Removable Media - ISM-0382Broader than
Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications - ISM-0405Broader than
Validation for Unprivileged System Access Requests - ISM-0407Broader than
Maintaining a Secure Lifetime Access Record for Each Human User - ISM-0408Depends on
Logon Banner for Security Responsibilities - ISM-0409Supports
Restricting Foreign National Access to AUSTEO and REL Systems - ISM-0411Broader than
Restricting Foreign National Access to Systems Handling AGAO Data - ISM-0415Depends on
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0418Broader than
Keep Physical Credentials Separate from Systems - ISM-0428Broader than
Session Lock Timing, Content Blocking and Full Re-Authentication for Services - ISM-0430Depends on
Same-Day Removal or Suspension of Access No Longer Required - ISM-0432Broader than
Document System Access Requirements in Security Plans - ISM-0434Depends on
Ensure Personnel Employment Screening and Security Clearance - ISM-0441Broader than
Restricting Temporary System Access to Data Required for Duties - ISM-0443Broader than
Restrict Temporary Access to Secure Systems - ISM-0447Broader than
Restrict Privileged Access for Foreign Nationals - ISM-0484Depends on
Configure SSH for Secure Server Access - ISM-0487Broader than
Disable Certain Features for Passwordless SSH Logins - ISM-0489Broader than
Four-Hour Cached SSH Private Key Lifetime and Screen Locks - ISM-0530Broader than
Administer VLANs from Trusted Security Domains - ISM-0551Broader than
Ensure Secure IP Telephony Device Authentication - ISM-0610Depends on
Training Human Users on Secure CDS Use Before Granting Access - ISM-0611Broader than
Restrict Privileges for Gateway Administrators - ISM-0622Broader than
Ensuring Network Authentication via Gateways - ISM-0664Depends on
Authorisation of Secret Data Exports - ISM-0665Broader than
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-0687Broader than
Use Approved Platforms for Secure Mobile Access - ISM-0694Broader than
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0853Depends on
Terminate Interactive User Sessions and Restart Workstations at Least Daily - ISM-0854Broader than
Access Restrictions for AUSTEO and AGAO Data - ISM-1006Broader than
Prevent Unauthorised Access to Network Traffic - ISM-1014Broader than
Implement Individual Logins for Secure IP Phone Use - ISM-1053Depends on
Secure Physical Access for Classified Equipment - ISM-1182Partially meets
Implement Network Traffic Control Measures - ISM-1250Broader than
Limit Server Application User Account Privileges - ISM-1255Broader than
Restrict Database Content Access by User Duties and Functions - ISM-1256Broader than
Implement File-Based Access Controls for Databases - ISM-1323Depends on
Requiring X.509 Certificates for 802.1X Network Authentication - ISM-1327Partially overlaps
Secure Certificates for Network Authentication - ISM-1392Broader than
Restrict File Modifications via Path Rules - ISM-1403Broader than
Lock Accounts After Five Failed Logon Attempts - ISM-1404Broader than
Disabling Inactive User Access After 45 Days - ISM-1418Broader than
Disable Unnecessary Removable Media Access - ISM-1420Supports
Ensure Non-Production Security Matches Production - ISM-1432Broader than
Protect Online Services from Domain Hijacking - ISM-1439Supports
Restrict IP Disclosure in CDNs - ISM-1487Broader than
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1505Broader than
Multi-factor Authentication for Human Users of Data Repositories - ISM-1508Broader than
Restricting Privileged Access to What Duties Require - ISM-1530Broader than
Secure Classified Equipment in Suitable Security Containers - ISM-1603Depends on
Disabling Vulnerable Authentication Methods - ISM-1604Broader than
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1611Broader than
Use Break Glass Accounts Only in Emergencies - ISM-1612Broader than
Restricted Use of Break Glass Accounts for Emergencies - ISM-1633Supports
Determine System Boundary, Criticality and Security Objectives - ISM-1649Broader than
Implement Just-in-Time Administration for System Access - ISM-1746Broader than
Restrict File System Permission Changes - ISM-1748Depends on
Lock Email Client Security Settings Against User Changes - ISM-1773Depends on
Eligibility Criteria for Gateway System Administrators - ISM-1813Broader than
Prevent Unauthorised User Access to Backup Data - ISM-1816Depends on
Prevent Unauthorised Changes to Software Sources - ISM-1832Broader than
SPN Configuration for Active Directory Accounts - ISM-1839Broader than
Secure Account Properties in Active Directory - ISM-1841Broader than
Restrict Domain Joining to Admin Users Only - ISM-1844Broader than
Prevent Non-Controller Accounts from Delegating Services - ISM-1852Broader than
Limit Unprivileged Access to What Duties Require - ISM-1854Broader than
Human Users Authenticate to MFDs Before Printing, Scanning or Copying - ISM-1865Depends on
Compliance with System Usage Policies for Access - ISM-1866Depends on
Prevent Storing Classified Data on Privately Owned Devices - ISM-1888Broader than
Ensure Mobile Devices Have Secure Lock Screens - ISM-1920Broader than
Blocking MFA Self-Enrolment From Untrustworthy Devices - ISM-1927Broader than
Limit Identity Server Access to Privileged Users Requiring It - ISM-1928Broader than
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-1933Broader than
Restrict DCSync Permissions on Service Accounts - ISM-1934Broader than
Six-Monthly Review and Removal of DCSync User Permissions - ISM-1936Broader than
Prevent Usage of sIDHistory in User Accounts - ISM-1946Broader than
Restrict Write Access to Certificate Templates - ISM-1948Broader than
Certificate Manager Approval for Templates Allowing Supplied SANs - ISM-1957Depends on
Hardware Security Module Protection for Microsoft AD CS Private Keys - ISM-1958Broader than
Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments - ISM-1985Broader than
Protect Event Logs from Unauthorised Access - ISM-1990Depends on
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations - ISM-2005Depends on
Understanding Business Criticality of Organisation Systems - ISM-2014Broader than
Ensure API Client Authentication and Authorisation - ISM-2048Broader than
Restrict Non-Admins from Changing Permissions - ISM-2074Depends on
Develop and Maintain AI Usage Policy - ISM-2080Partially overlaps
No Password Complexity Requirements Enforced - ISM-2092Broader than
Enforce Fine-Grained Permissions for AI Applications - ISM-2093Broader than
Role-Based Access Controls in AI Applications - ISM-2095Broader than
Block Personal Devices Granting AI Agents Access to Sensitive Systems - ISM-2097Depends on
Configure Mobile Devices with Always On VPN - ISM-2098Broader than
Prevent Data Transfer Over USB on Mobile Devices - ISM-2100Broader than
Do Not View Classified Data on Mobile Devices - ISM-2112Broader than
Disable AI Applications' Direct Access to External Public Data Sources - ISM-2113Depends on
Configuring AI Applications to Require Human Approval Before High-Impact Actions - ISM-2124Broader than
Restricting Service Provider Access to Approved Tools, Addresses and Time Windows - ISM-2126Depends on
Positively Identify Requestors Before Actioning Account, Banking or Payment Requests - ISM-2128Broader than
Limit Kernel-Mode Code Installation to Privileged Users Who Need It - ISM-2133Broader than
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2135Broader than
Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent - ISM-2136Depends on
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2137Broader than
Block User OAuth Consent, Reserve It for Authorised Administrators - ISM-2138Broader than
Six-Monthly Review of OAuth Application Consents and Granted Permissions - ISM-2140Broader than
Disable OAuth Device Code Flow Unless Required and Restrict Its Use - ISM-2147Depends on
Cryptographically Bind Tokens and Session Cookies to Issuing Device - ISM-2149Depends on
Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List - ISM-2156Broader than
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions - ISM-2157Broader than
Agentic AI Tool Calls Limited by User Access and Task-Scoped Authorisation - ISM-2158Depends on
Treat Agentic AI Retrieved External Content as Untrusted Data - ISM-2165Broader than
Fresh EAP-TLS Authentication for Each New Connectivity Association Key
|
| Annex A 5.16 Identity life cycle management | Organisational controls | - ISM-0380Partially overlaps
Disable Unneeded OS Accounts and Services - ISM-0407Supports
Maintain Secure User Access Records - ISM-0414Depends on
Uniquely Identifying Every User Granted System Access - ISM-0415Broader than
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0420Partially meets
Identify Nationality of Foreign Personnel in System - ISM-0430Broader than
Immediate Suspension of Unneeded System Access - ISM-0446Partially overlaps
Restrict Privileged Access for Foreign Nationals - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-1263Supports
Enforce Unique Accounts for Server Administration - ISM-1508Depends on
Restricting Privileged Access to What Duties Require - ISM-1583Partially meets
Ensure Contractors are Identified as Users - ISM-1591Partially meets
Suspend User Access for Malicious Activity - ISM-1593Partially meets
Verifying User Identity for New Credentials - ISM-1619Partially meets
Configure Service Accounts as Managed Service Accounts - ISM-1834Partially meets
Ensure No Duplicate SPNs in Active Directory - ISM-1845Broader than
Disable User Security Group Access in Active Directory - ISM-1920Broader than
Blocking MFA Self-Enrolment From Untrustworthy Devices - ISM-1927Depends on
Limit Identity Server Access to Privileged Users Requiring It - ISM-1932Supports
Limit Service Accounts with SPNs in Active Directory - ISM-1934Broader than
Six-Monthly Review and Removal of DCSync User Permissions - ISM-1943Broader than
Enforce Certificate and User Mapping in AD Services - ISM-1945Partially meets
Remove Enrollee Supplies Subject Flag from Templates - ISM-1950Supports
Disable Soft Matching After Synchronisation - ISM-1951Partially meets
Disable Hard Match Takeover in Microsoft Entra Connect - ISM-2013Supports
Ensure Client Authentication for Internal Network APIs - ISM-2047Broader than
Secondary-Channel Notification of Authentication Factor Resets - ISM-2053Partially overlaps
End of Life Procedures for Software - ISM-2133Broader than
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2136Depends on
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2145Broader than
Revoke User Account Credentials When No Longer Required - ISM-2146Partially overlaps
Revoking Static Application and Workload Credentials When No Longer Required - ISM-2148Broader than
Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In - ISM-2156Depends on
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
|
| Annex A 5.17 Management of Authentication Information | Organisational controls | - ISM-0383Partially overlaps
Change Default OS User Accounts During Setup - ISM-0411Depends on
Restricting Foreign National Access to Systems Handling AGAO Data - ISM-0414Depends on
Uniquely Identifying Every User Granted System Access - ISM-0417Partially meets
Use Passwords When Multi-Factor Authentication Isn't Supported - ISM-0421Partially overlaps
Require Minimum 15-Character Passwords for Security - ISM-0422Partially overlaps
Ensuring Strong Passwords for TOP SECRET Systems - ISM-0485Broader than
Use Public Key Authentication for SSH Access - ISM-0553Partially overlaps
Authenticate Video Calls and Manage Settings - ISM-0554Supports
Secure Two-Way Authentication for Video Calls - ISM-0555Partially overlaps
Ensure Authentication for IP Telephony Actions - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-0974Depends on
Multi-Factor Authentication for Unprivileged Human Users of Systems - ISM-1014Broader than
Implement Individual Logins for Secure IP Phone Use - ISM-1321Supports
Implement EAP-TLS for Secure Wireless Authentication - ISM-1323Depends on
Requiring X.509 Certificates for 802.1X Network Authentication - ISM-1324Depends on
Generating X.509 Certificates With Evaluated CA or HSM - ISM-1327Partially overlaps
Secure Certificates for Network Authentication - ISM-1401Supports
Multi-Factor Authentication Combines Possession With Knowledge or Inherence - ISM-1402Partially overlaps
Protecting Stored Credentials with Security Measures - ISM-1449Partially overlaps
Protect SSH Private Keys with Passwords or Encryption - ISM-1505Supports
Implement Multi-factor Authentication for Data Repositories - ISM-1546Depends on
Ensure User Authentication Before System Access - ISM-1557Partially overlaps
Ensure Strong Passwords for SECRET Systems - ISM-1558Partially overlaps
Ensure Secure Construction of Passwords - ISM-1559Partially overlaps
Minimum Password Length for Secure Systems - ISM-1560Depends on
Ensure Strong Passwords for SECRET System Authentication - ISM-1561Partially overlaps
Ensure Strong Passwords for TOP SECRET Systems - ISM-1593Partially overlaps
Verify User Identity Before Issuing, Resetting, Disabling or Enrolling Credentials - ISM-1594Broader than
Delivering User Credentials via Secure Channel or Split Parts - ISM-1595Broader than
Credentials Issued to Human Users Are Changed on First Use - ISM-1596Partially overlaps
Avoid Reusing Credentials Across Systems - ISM-1597Partially overlaps
Ensuring Credential Input Obscurity - ISM-1603Depends on
Disabling Vulnerable Authentication Methods - ISM-1611Depends on
Use Break Glass Accounts Only in Emergencies - ISM-1614Broader than
Manage Emergency Account Access Changes - ISM-1615Depends on
Testing Break Glass Accounts Post Credential Change - ISM-1679Depends on
Multi-factor Authentication for Third-party Services Handling Sensitive Data - ISM-1685Partially overlaps
Strengthening Passwords for Critical Accounts - ISM-1817Depends on
Secure API Access with Authentication and Authorisation - ISM-1818Depends on
Client Authentication for Network API Access - ISM-1840Broader than
Prevent Reversible Encryption of User Passwords - ISM-1854Supports
Require User Authentication for Multifunction Devices - ISM-1875Broader than
Monthly System Scans to Detect Credentials Stored in the Clear - ISM-1888Broader than
Ensure Mobile Devices Have Secure Lock Screens - ISM-1892Depends on
Multi-Factor Authentication for Organisation Users of Online Customer Services - ISM-1893Supports
Enforcing Multi-Factor Authentication for User Security - ISM-1894Supports
Ensuring Phishing-Resistant Multi-factor Authentication - ISM-1920Broader than
Blocking MFA Self-Enrolment From Untrustworthy Devices - ISM-1929Supports
Ensure LDAP Signing on AD DS Domain Controllers - ISM-1930Broader than
Prevent Storing Passwords in Group Policy Preferences - ISM-1943Depends on
Enforce Certificate and User Mapping in AD Services - ISM-1953Broader than
Ensure Strong Management of Admin Account Credentials - ISM-1955Partially overlaps
Regularly Change Compromised Credentials - ISM-1957Depends on
Hardware Security Module Protection for Microsoft AD CS Private Keys - ISM-2011Broader than
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used - ISM-2013Supports
Ensure Client Authentication for Internal Network APIs - ISM-2030Depends on
Commit-Time Scanning Blocks Secrets From Source Repositories - ISM-2044Broader than
Prevent Default Credentials in Software Installations - ISM-2047Partially overlaps
Notify Users of Authentication Resets via Secondary Channel - ISM-2076Broader than
Eliminating Security Questions for Authentication - ISM-2078Partially overlaps
Ensure Passwords Are Not Common or Compromised - ISM-2079Partially overlaps
Ensure Password Length is at Least 64 Characters - ISM-2080Partially overlaps
No Password Complexity Requirements Enforced - ISM-2109Partially overlaps
Pre-Boot Authentication for Encrypted System Volume Media - ISM-2126Depends on
Positively Identify Requestors Before Actioning Account, Banking or Payment Requests - ISM-2130Partially overlaps
Disabling or Hardening AD CS Web Enrolment Interfaces - ISM-2133Depends on
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2135Partially overlaps
Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent - ISM-2136Supports
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2140Partially overlaps
Disable OAuth Device Code Flow Unless Required and Restrict Its Use - ISM-2141Broader than
Prefer Short-Lived Dynamically Issued Credentials for Applications and Workloads - ISM-2142Broader than
Central Management of Application and Workload Credentials - ISM-2143Broader than
Unique Per-Application Credentials Not Shared Across Environments - ISM-2144Broader than
Change Application Static Credentials Found Compromised or Exposed in Clear - ISM-2145Partially overlaps
Revoke User Account Credentials When No Longer Required - ISM-2146Broader than
Revoking Static Application and Workload Credentials When No Longer Required - ISM-2148Broader than
Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In - ISM-2165Depends on
Fresh EAP-TLS Authentication for Each New Connectivity Association Key
|
| Annex A 5.18 Managing Access Rights to Information Assets | Organisational controls | - ISM-0133Supports
Responding to Data Spills by Restricting Access - ISM-0269Broader than
Restrict Sensitive Emails to Verified Recipients - ISM-0405Broader than
Validation for Unprivileged System Access Requests - ISM-0407Broader than
Maintaining a Secure Lifetime Access Record for Each Human User - ISM-0409Partially meets
Restrict Foreign Nationals' Access to Sensitive Data - ISM-0411Broader than
Restricting Foreign National Access to Systems Handling AGAO Data - ISM-0414Supports
Ensure Unique Identification for System Access - ISM-0415Partially overlaps
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0430Partially meets
Immediate Suspension of Unneeded System Access - ISM-0432Depends on
Document System Access Requirements in Security Plans - ISM-0441Partially overlaps
Restricting Temporary System Access to Data Required for Duties - ISM-0443Broader than
Restrict Temporary Access to Secure Systems - ISM-0446Partially overlaps
Restrict Privileged Access for Foreign Nationals - ISM-0555Partially overlaps
Ensure Authentication for IP Telephony Actions - ISM-0610Depends on
Training Human Users on Secure CDS Use Before Granting Access - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-1199Partially overlaps
Remove Unnecessary Bluetooth Pairings on Devices - ISM-1255Broader than
Restrict Database User Access Based on Duties - ISM-1263Depends on
Enforce Unique Accounts for Server Administration - ISM-1268Supports
Enforce Need-to-Know Access in Databases - ISM-1327Broader than
Access Controls, Encryption and User Authentication for X.509 Certificates - ISM-1392Broader than
Restrict File Modifications via Path Rules - ISM-1404Broader than
Disabling Inactive User Access After 45 Days - ISM-1422Depends on
Prevent Unauthorised Access to Software Source - ISM-1432Broader than
Protect Online Services from Domain Hijacking - ISM-1487Broader than
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1583Depends on
Ensure Contractors are Identified as Users - ISM-1590Broader than
Changing User Account Credentials After Compromise, Exposure or Shared Membership Change - ISM-1591Partially meets
Suspend User Access for Malicious Activity - ISM-1592Depends on
Restrict Unprivileged Users From Installing Unapproved Applications - ISM-1593Supports
Verifying User Identity for New Credentials - ISM-1604Depends on
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1612Partially overlaps
Restricted Use of Break Glass Accounts for Emergencies - ISM-1647Partially meets
Disable Privileged Access After 12 Months - ISM-1648Broader than
Disabling Inactive Privileged Access to Systems - ISM-1649Broader than
Implement Just-in-Time Administration for System Access - ISM-1812Broader than
Restrict Backup Access to Unprivileged Users - ISM-1833Partially overlaps
Limit Privileges for User Accounts in Active Directory - ISM-1841Supports
Restrict Domain Joining to Admin Users Only - ISM-1843Broader than
Annual Review of Unconstrained Delegation in AD Accounts - ISM-1844Partially meets
Prevent Non-Controller Accounts from Delegating Services - ISM-1845Broader than
Disable User Security Group Access in Active Directory - ISM-1846Broader than
Restrict Pre-Windows 2000 Access Group Membership - ISM-1852Broader than
Limit Unprivileged Access to What Duties Require - ISM-1854Depends on
Human Users Authenticate to MFDs Before Printing, Scanning or Copying - ISM-1927Broader than
Restrict Access to Microsoft Active Directory Servers - ISM-1932Partially meets
Limit Service Accounts with SPNs in Active Directory - ISM-1933Broader than
Restrict DCSync Permissions on Service Accounts - ISM-1934Broader than
Six-Monthly Review and Removal of DCSync User Permissions - ISM-1936Partially meets
Prevent Usage of sIDHistory in User Accounts - ISM-1940Broader than
Restrict Service Accounts from Privileged Groups - ISM-1946Broader than
Restrict Write Access to Certificate Templates - ISM-1948Depends on
Certificate Manager Approval for Templates Allowing Supplied SANs - ISM-1958Broader than
Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments - ISM-2005Supports
Understanding Business Criticality of Organisation Systems - ISM-2013Supports
Ensure Client Authentication for Internal Network APIs - ISM-2048Supports
Restrict Non-Admins from Changing Permissions - ISM-2049Broader than
Enforcing Re-authentication After Permission Changes - ISM-2092Broader than
Enforce Fine-Grained Permissions for AI Applications - ISM-2093Partially overlaps
Role-Based Access Controls in AI Applications - ISM-2095Broader than
Block Personal Devices Granting AI Agents Access to Sensitive Systems - ISM-2124Partially overlaps
Restricting Service Provider Access to Approved Tools, Addresses and Time Windows - ISM-2126Partially overlaps
Positively Identify Requestors Before Actioning Account, Banking or Payment Requests - ISM-2131Depends on
Quarterly Certificate Template Reviews to Remediate Misconfigurations - ISM-2133Depends on
Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts - ISM-2135Depends on
Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent - ISM-2136Partially overlaps
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2137Broader than
Block User OAuth Consent, Reserve It for Authorised Administrators - ISM-2138Equivalent
Six-Monthly Review of OAuth Application Consents and Granted Permissions - ISM-2146Broader than
Revoking Static Application and Workload Credentials When No Longer Required - ISM-2156Broader than
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions - ISM-2158Depends on
Treat Agentic AI Retrieved External Content as Untrusted Data
|
| Annex A 5.19 Managing Information Security in Supplier Relationships | Organisational controls | - ISM-0072Partially overlaps
Document Security Requirements in Contractual Arrangements - ISM-0141Partially meets
Report Cyber Incidents Promptly to Designated Contacts - ISM-0280Partially meets
Choose PP-evaluated Products Over EAL-based Ones - ISM-0285Partially meets
Ensuring Evaluated Products Follow Delivery Procedures - ISM-0307Partially overlaps
Sanitise Equipment When Not Using Cleared Technician - ISM-0731Partially meets
CISO Oversight of Cyber Supply Chain Risks - ISM-0824Partially overlaps
Avoid Using Unauthorised Online File Services - ISM-0840Partially meets
Certified Services for Outsourced Media Destruction - ISM-1073Partially meets
Ensure Provider Contracts for System Access - ISM-1178Supports
Limit Network Documentation for Third Parties - ISM-1195Supports
Enforce Policy with Evaluated Mobile Device Management - ISM-1203Supports
Risk Assessment for System Security - ISM-1395Partially overlaps
Ensuring Data Protection by Service Providers - ISM-1451Partially meets
Document Data Ownership in Service Contracts - ISM-1452Partially meets
Perform Supply Chain Risk Assessments for System Suppliers - ISM-1480Supports
Ensure High Assurance for Peripheral Switches - ISM-1535Supports
Prevent Unsuitable Foreign Data Exports - ISM-1567Partially meets
Avoid High-Risk Suppliers in Cyber Supply Chain - ISM-1568Broader than
Ensure Security Commitment from Suppliers - ISM-1569Partially overlaps
Document and Share a Supplier Customer Shared Responsibility Model - ISM-1570Partially overlaps
Regular IRAP Assessment of Cloud Service Providers - ISM-1571Partially meets
Verify Security Compliance in Service Contracts - ISM-1572Partially meets
Document Service Provider Data Handling and Change Notifications - ISM-1573Partially meets
Log Access Documentation with Service Providers - ISM-1574Supports
Data Portability in Service Contracts - ISM-1575Partially meets
One-Month Notice for Service Termination - ISM-1576Partially overlaps
Notify Organisation of Unauthorised System Access - ISM-1577Supports
Ensure Network Segregation from Service Providers - ISM-1631Supports
Identify Suppliers in Cyber Supply Chain - ISM-1632Partially meets
Ensure Secure Procurement from Reliable Suppliers - ISM-1637Supports
Maintain an Outsourced Cloud Service Register - ISM-1638Supports
Maintain a Comprehensive Outsourced Cloud Service Register - ISM-1736Supports
Maintain and Verify Managed Service Register - ISM-1737Supports
Maintain a Comprehensive Managed Service Register - ISM-1738Partially overlaps
Verify Compliance with Security Requirements - ISM-1756Supports
Develop and Maintain Vulnerability Disclosure Processes - ISM-1785Partially overlaps
Develop and Maintain Supplier Management Policy - ISM-1786Partially meets
Maintain an Approved Supplier List - ISM-1787Partially meets
Ensure Suppliers are Approved for IT and OT Sourcing - ISM-1788Partially meets
Identify Multiple Suppliers for Critical IT Sourcing - ISM-1789Broader than
Maintain Reserve Spares of Critical IT and OT Equipment - ISM-1790Partially meets
Ensure Integrity in IT and OT Deliveries - ISM-1791Partially meets
Assess Integrity of Delivered IT and OT Products - ISM-1793Supports
Regular Assessment of Managed Service Providers - ISM-1794Partially meets
Notify Significant Changes to Service Provider Agreements - ISM-1797Supports
Ensure Software Updates are Securely Signed - ISM-1800Partially meets
Ensure Network Devices Have Trusted Firmware - ISM-1804Partially meets
Include Break Clauses in Cloud Service Contracts - ISM-1826Broader than
Select Vendors Committed to Secure Design for Servers - ISM-1882Partially meets
Procurement from Transparent Suppliers - ISM-1972Partially overlaps
Security Assessments for Top Secret Cloud Services - ISM-2008Partially meets
Criteria for Medical Devices in SECRET and TOP SECRET Areas - ISM-2027Supports
Verify Software Artefacts with Digital Signatures - ISM-2082Partially meets
Using Cryptographic BOM in Software Development - ISM-2088Supports
Ensure Accuracy of AI Model Training Data
|
| Annex A 5.20 Integrating security clauses in supplier agreements | Organisational controls | - ISM-0072Equivalent
Document Security Requirements in Contractual Arrangements - ISM-0141Partially meets
Report Cyber Incidents Promptly to Designated Contacts - ISM-0731Broader than
CISO Oversight of Cyber Supply Chain Risks - ISM-1178Partially overlaps
Limit Network Documentation for Third Parties - ISM-1395Depends on
Ensuring Data Protection by Service Providers - ISM-1451Broader than
Document Data Ownership in Service Contracts - ISM-1568Partially overlaps
Ensure Security Commitment from Suppliers - ISM-1569Partially overlaps
Document and Share a Supplier Customer Shared Responsibility Model - ISM-1571Broader than
Verify Security Compliance in Service Contracts - ISM-1572Partially meets
Document Service Provider Data Handling and Change Notifications - ISM-1575Partially meets
One-Month Notice for Service Termination - ISM-1576Supports
Treating Unauthorised Service Provider Access as a Reportable Incident - ISM-1631Depends on
Identify Suppliers in Cyber Supply Chain - ISM-1737Supports
Maintain a Comprehensive Managed Service Register - ISM-1738Partially meets
Verify Compliance with Security Requirements - ISM-1785Supports
Develop and Maintain Supplier Management Policy - ISM-1786Partially meets
Maintain an Approved Supplier List - ISM-1788Depends on
Identify Multiple Suppliers for Critical IT Sourcing - ISM-1793Depends on
Regular Assessment of Managed Service Providers - ISM-1794Partially meets
Notify Significant Changes to Service Provider Agreements - ISM-1804Partially meets
Include Break Clauses in Cloud Service Contracts - ISM-1882Partially overlaps
Procurement from Transparent Suppliers - ISM-2033Partially overlaps
Document and Maintain Software Security Requirements - ISM-2088Supports
Ensure Accuracy of AI Model Training Data
|
| Annex A 5.21 Managing Information Security in the ICT Supply Chain | Organisational controls | - ISM-0039Partially overlaps
Develop and Maintain a Cyber Security Strategy - ISM-0072Partially meets
Document Security Requirements in Contractual Arrangements - ISM-0280Broader than
Choose PP-evaluated Products Over EAL-based Ones - ISM-0285Broader than
Ensuring Evaluated Products Follow Delivery Procedures - ISM-0286Partially overlaps
Consult ASD for High Assurance IT Delivery Procedures - ISM-0305Partially overlaps
On-Site IT Equipment Maintenance by Cleared Technicians - ISM-0310Depends on
Off-Site IT Equipment Handling Approvals - ISM-0629Depends on
Manage Gateways Between Different Security Domains - ISM-0731Broader than
CISO Oversight of Cyber Supply Chain Risks - ISM-0840Broader than
Certified Services for Outsourced Media Destruction - ISM-0938Broader than
Select Secure-by-Design Committed Vendors - ISM-1073Partially overlaps
Ensure Provider Contracts for System Access - ISM-1195Depends on
Enforce Policy with Evaluated Mobile Device Management - ISM-1203Depends on
Risk Assessment for System Security - ISM-1395Broader than
Ensuring Data Protection by Service Providers - ISM-1452Equivalent
Perform Supply Chain Risk Assessments for System Suppliers - ISM-1535Depends on
Prevent Unsuitable Foreign Data Exports - ISM-1567Broader than
Avoid High-Risk Suppliers in Cyber Supply Chain - ISM-1568Broader than
Ensure Security Commitment from Suppliers - ISM-1570Partially overlaps
Regular IRAP Assessment of Cloud Service Providers - ISM-1631Supports
Identify Suppliers in Cyber Supply Chain - ISM-1632Broader than
Ensure Secure Procurement from Reliable Suppliers - ISM-1638Depends on
Outsourced Cloud Service Register Recording Eight Required Details - ISM-1736Depends on
Maintain and Verify Managed Service Register - ISM-1737Broader than
Maintain a Comprehensive Managed Service Register - ISM-1738Partially overlaps
Verify Compliance with Security Requirements - ISM-1743Broader than
Choose Secure Operating System Vendors - ISM-1786Broader than
Maintain an Approved Supplier List - ISM-1787Broader than
Ensure Suppliers are Approved for IT and OT Sourcing - ISM-1788Broader than
Identify Multiple Suppliers for Critical IT Sourcing - ISM-1789Partially meets
Maintain Reserve Spares of Critical IT and OT Equipment - ISM-1790Broader than
Ensure Integrity in IT and OT Deliveries - ISM-1791Broader than
Assess Integrity of Delivered IT and OT Products - ISM-1792Broader than
Assess Authenticity of IT and OT Deliveries - ISM-1797Depends on
Ensure Software Updates are Securely Signed - ISM-1800Broader than
Ensure Network Devices Have Trusted Firmware - ISM-1804Partially meets
Include Break Clauses in Cloud Service Contracts - ISM-1826Broader than
Select Vendors Committed to Secure Design for Servers - ISM-1882Broader than
Procurement from Transparent Suppliers - ISM-1972Partially overlaps
Security Assessments for Top Secret Cloud Services - ISM-2023Broader than
Maintain a Reliable Source for Software - ISM-2026Depends on
Scan Software Artefacts for Malicious Content - ISM-2027Depends on
Verify Software Artefacts with Digital Signatures - ISM-2073Depends on
Develop a Post-Quantum Cryptography Transition Plan - ISM-2082Broader than
Using Cryptographic BOM in Software Development - ISM-2083Depends on
Provide a Cryptographic Bill of Materials to Software Users - ISM-2086Broader than
Verify Integrity of AI Models, Structures, and Weights - ISM-2087Partially overlaps
Verify the Source and Integrity of AI Training Data - ISM-2088Depends on
Ensure Accuracy of AI Model Training Data - ISM-2124Depends on
Restricting Service Provider Access to Approved Tools, Addresses and Time Windows - ISM-2125Depends on
Independently Log and Analyse All Service Provider System Access - ISM-2154Broader than
Pinning Software Artefact Dependencies to Approved Versions in Source Code - ISM-2155Depends on
Reproducible Builds Enabling Independent Verification of Release Artefacts
|
| Annex A 5.22 Monitoring and Managing Supplier Services | Organisational controls | - ISM-0009Depends on
System Owners Identify Supplementary Controls With Authorising Officer - ISM-0072Depends on
Document Security Requirements in Contractual Arrangements - ISM-0280Supports
Choose PP-evaluated Products Over EAL-based Ones - ISM-0310Supports
Off-Site IT Equipment Handling Approvals - ISM-0629Supports
Manage Gateways Between Different Security Domains - ISM-0731Partially meets
CISO Oversight of Cyber Supply Chain Risks - ISM-1073Partially overlaps
Ensure Provider Contracts for System Access - ISM-1395Partially overlaps
Ensuring Data Protection by Service Providers - ISM-1452Partially overlaps
Perform Supply Chain Risk Assessments for System Suppliers - ISM-1567Supports
Avoid High-Risk Suppliers in Cyber Supply Chain - ISM-1570Partially overlaps
Regular IRAP Assessment of Cloud Service Providers - ISM-1571Supports
Verify Security Compliance in Service Contracts - ISM-1631Depends on
Identify Suppliers in Cyber Supply Chain - ISM-1637Supports
Maintain an Outsourced Cloud Service Register - ISM-1638Supports
Maintain a Comprehensive Outsourced Cloud Service Register - ISM-1736Supports
Maintain and Verify Managed Service Register - ISM-1737Supports
Maintain a Comprehensive Managed Service Register - ISM-1738Partially overlaps
Verify Compliance with Security Requirements - ISM-1743Partially meets
Choose Secure Operating System Vendors - ISM-1786Partially meets
Maintain an Approved Supplier List - ISM-1787Supports
Ensure Suppliers are Approved for IT and OT Sourcing - ISM-1790Supports
Ensure Integrity in IT and OT Deliveries - ISM-1793Supports
Regular Assessment of Managed Service Providers - ISM-1794Partially meets
Notify Significant Changes to Service Provider Agreements - ISM-1826Broader than
Select Vendors Committed to Secure Design for Servers - ISM-1882Partially overlaps
Procurement from Transparent Suppliers - ISM-1893Supports
Enforcing Multi-Factor Authentication for User Security - ISM-1972Partially overlaps
ASD Security Control Assessment of TOP SECRET Cloud Services Every 24 Months - ISM-2029Supports
Restrict Third-Party Libraries to Trustworthy Sources - ISM-2124Depends on
Restricting Service Provider Access to Approved Tools, Addresses and Time Windows - ISM-2125Depends on
Independently Log and Analyse All Service Provider System Access - ISM-2155Depends on
Reproducible Builds Enabling Independent Verification of Release Artefacts
|
| Annex A 5.23 Cloud Service Security Management | Organisational controls | - ISM-0043Depends on
Cyber Security Incident Response Plan Requirements - ISM-0576Supports
Develop and Maintain Cyber Security Incident Plans - ISM-1529Partially overlaps
Limit Cloud Services to Community or Private for SECRETS - ISM-1638Supports
Maintain a Comprehensive Outsourced Cloud Service Register - ISM-1909Partially overlaps
Perform Root Cause Analysis for Vulnerabilities
|
| Annex A 5.24 Information security incident management planning and preparation | Organisational controls | - ISM-0039Partially overlaps
Develop and Maintain a Cyber Security Strategy - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0123Partially meets
Report Cyber Security Incidents Promptly - ISM-0125Broader than
Maintaining a Cyber Security Incident Register - ISM-0137Supports
Seek Legal Advice for Intrusion Evidence Collection - ISM-0714Partially overlaps
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-0726Supports
Coordinate Security Risk Management Activities - ISM-0733Partially overlaps
Ensure CISO Awareness of Cyber Incidents - ISM-1019Broader than
Develop a Denial of Service Response Plan - ISM-1088Partially meets
Report Potential Compromises of Mobile Devices Overseas - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1556Depends on
Security Measures After Overseas Travel with Mobile Devices - ISM-1576Partially overlaps
Notify Organisation of Unauthorised System Access - ISM-1618Partially overlaps
CISO's Role in Cyber Security Incident Response - ISM-1625Partially overlaps
Develop Insider Threat Mitigation Programs - ISM-1717Depends on
Implement Security.txt for Vulnerability Disclosure - ISM-1731Broader than
Plan and Coordinate Intrusion Remediation From Trusted Separate Systems - ISM-1756Partially overlaps
Develop and Maintain Vulnerability Disclosure Processes - ISM-1784Partially overlaps
Annual Testing of Cyber Incident Response Plan - ISM-1819Broader than
Enact Cyber Security Incident Response Plans - ISM-1881Supports
Timely Reporting of Cyber Incidents Without Data Breach - ISM-1908Depends on
Responsible Disclosure of Software Vulnerabilities - ISM-1997Partially overlaps
Define Cyber Security Roles for Leadership - ISM-2006Partially overlaps
Board Plans for Major Cyber Security Incidents
|
| Annex A 5.25 Assessment and decision on information security events | Organisational controls | - ISM-0043Supports
Cyber Security Incident Response Plan Requirements - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Equivalent
Analyse Cyber Security Events Promptly - ISM-1784Supports
Annual Testing of Cyber Incident Response Plan - ISM-2116Depends on
Use Cyber Threat Intelligence for Event Detection - ISM-2125Depends on
Independently Log and Analyse All Service Provider System Access - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2148Partially overlaps
Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In
|
| Annex A 5.26 Response to Information Security Incidents | Organisational controls | - ISM-0043Supports
Cyber Security Incident Response Plan Requirements - ISM-0123Supports
Report Cyber Security Incidents Promptly - ISM-0137Supports
Seek Legal Advice for Intrusion Evidence Collection - ISM-0138Depends on
Maintaining Integrity of Evidence in Investigations - ISM-0576Supports
Develop and Maintain Cyber Security Incident Plans - ISM-0917Partially meets
Procedures for Handling Malicious Code Infections - ISM-1213Supports
Analyse Network Traffic Post-Intrusion Remediation - ISM-1300Partially meets
Mobile Device Security After Overseas Travel - ISM-1591Supports
Suspend User Access for Malicious Activity - ISM-1609Broader than
Consult System Owners Before Continuing Intrusions - ISM-1618Supports
CISO's Role in Cyber Security Incident Response - ISM-1731Broader than
Plan and Coordinate Intrusion Remediation From Trusted Separate Systems - ISM-1732Partially overlaps
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-1784Supports
Annual Testing of Cyber Incident Response Plan - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents - ISM-1880Depends on
Timely Reporting of Cyber Incidents Involving Customer Data - ISM-1955Supports
Regularly Change Compromised Credentials - ISM-1956Partially overlaps
Regularly Update AD FS Certificates to Prevent Risks - ISM-2006Depends on
Board Plans for Major Cyber Security Incidents - ISM-2104Depends on
Do Not Post Security Clearance and Briefing Details Online - ISM-2106Partially overlaps
Advise Staff to Limit Posting Work Skills Online
|
| Annex A 5.27 Learning from information security incidents | Organisational controls | - ISM-0043Supports
Cyber Security Incident Response Plan Requirements - ISM-0125Supports
Maintaining a Cyber Security Incident Register - ISM-0576Supports
Develop and Maintain Cyber Security Incident Plans
|
| Annex A 5.28 Procedures for Collecting and Preserving Evidence | Organisational controls | - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0137Partially overlaps
Seek Legal Advice for Intrusion Evidence Collection - ISM-0138Partially overlaps
Maintaining Integrity of Evidence in Investigations - ISM-0580Partially overlaps
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0585Supports
Capture Detailed Information in Event Logs - ISM-0660Supports
Monthly Verification of Data Transfer Logs for SECRET Systems - ISM-0917Supports
Procedures for Handling Malicious Code Infections - ISM-0988Supports
Ensure Accurate Time Source for Event Logs - ISM-1019Supports
Develop a Denial of Service Response Plan - ISM-1213Depends on
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1537Depends on
Log Security-Relevant Database Events Centrally - ISM-1566Supports
Central Logging of Unprivileged System Access - ISM-1609Partially overlaps
Consult System Owners Before Continuing Intrusions - ISM-1618Depends on
CISO's Role in Cyber Security Incident Response - ISM-1623Supports
Centralised Logging of PowerShell Activities - ISM-1624Supports
Protect PowerShell Script Block Logs - ISM-1625Supports
Develop Insider Threat Mitigation Programs - ISM-1683Supports
Central Logging of Multi-factor Authentication Events - ISM-1731Supports
Coordinate Intrusion Remediation on Separate Systems - ISM-1732Depends on
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-1784Supports
Annual Testing of Cyber Incident Response Plan - ISM-1805Supports
Develop a Denial of Service Response Plan - ISM-1819Depends on
Enact Cyber Security Incident Response Plans - ISM-1855Supports
Central Logging of Multifunction Device Use - ISM-1964Supports
Central Logging for Network Device Events - ISM-1976Supports
Central Logging of Security Events on macOS - ISM-1984Supports
Encrypt Event Logs in Transit Using ASD Cryptography - ISM-1988Supports
Ensure Event Logs Are Retained for 12 Months - ISM-2051Partially overlaps
Ensure Event Logs for Cybersecurity Event Detection - ISM-2089Supports
Monitor AI Model Performance and Investigate Anomalies - ISM-2125Depends on
Independently Log and Analyse All Service Provider System Access - ISM-2159Depends on
Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
|
| Annex A 5.29 Maintain information security during disruptions | Organisational controls | - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0570Depends on
Maintain Backup Email Gateways to Primary Standards - ISM-0576Partially overlaps
Develop and Maintain Cyber Security Incident Plans - ISM-0734Partially overlaps
CISO Role in Disaster Recovery Planning - ISM-1123Depends on
Ensure UPS Powers All Top Secret IT Equipment - ISM-1732Depends on
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-2006Depends on
Board Plans for Major Cyber Security Incidents
|
| Annex A 5.30 ICT Readiness for Business Continuity | Organisational controls | - ISM-0570Depends on
Maintain Backup Email Gateways to Primary Standards - ISM-0734Broader than
CISO Role in Disaster Recovery Planning - ISM-1019Partially meets
Develop a Denial of Service Response Plan - ISM-1123Supports
Ensure UPS Powers All Top Secret IT Equipment - ISM-1431Partially overlaps
Strategies for Mitigating Denial-of-Service Attacks - ISM-1437Supports
Utilising Cloud Providers for Hosting Online Services - ISM-1438Broader than
Ensure High Availability by Using CDNs - ISM-1511Partially overlaps
Conduct and Maintain Regular Data Backups - ISM-1547Partially overlaps
Develop and Maintain Data Backup Procedures - ISM-1548Depends on
Develop and Maintain Data Restoration Processes - ISM-1580Partially overlaps
Ensure High Availability for Online Services - ISM-1610Broader than
Document and Test Emergency System Access Procedures - ISM-1615Depends on
Testing Break Glass Accounts Post Credential Change - ISM-1633Supports
Determine System Boundary, Criticality and Security Objectives - ISM-1732Supports
Coordinated Intrusion Remediation During Planned Outages - ISM-1805Partially overlaps
Develop a Denial of Service Response Plan
|
| Annex A 5.31 Compliance with Information Security Legal Requirements | Organisational controls | - ISM-0009Depends on
System Owners Identify Supplementary Controls With Authorising Officer - ISM-0041Supports
Develop a Detailed System Security Plan - ISM-0047Depends on
Approval Process for Cyber Security Documentation - ISM-0137Supports
Seek Legal Advice for Intrusion Evidence Collection - ISM-0181Depends on
Ensure Cabling Meets Australian Standards - ISM-0499Depends on
Ensure Compliance with ASD Communication Security Policies - ISM-1478Supports
CISO Management of Cyber Security Compliance - ISM-1571Depends on
Verify Security Compliance in Service Contracts - ISM-1626Depends on
Seek Legal Advice for Insider Threat Plans - ISM-1880Depends on
Timely Reporting of Cyber Incidents Involving Customer Data - ISM-2002Supports
Ensure Board Cyber Security Literacy for Compliance - ISM-2008Supports
Criteria for Medical Devices in SECRET and TOP SECRET Areas - ISM-2033Supports
Document and Maintain Software Security Requirements
|
| Annex A 5.32 Intellectual Property Rights Protection | Organisational controls | - ISM-0072Depends on
Document Security Requirements in Contractual Arrangements - ISM-1625Supports
Develop Insider Threat Mitigation Programs - ISM-1730Supports
Provide a Software Bill of Materials to Consumers
|
| Annex A 5.33 Protection of Records | Organisational controls | - ISM-0316Supports
Formal Decision on IT Equipment Disposal - ISM-0371Depends on
Ensure Proper Supervision of Media Destruction - ISM-0373Supports
Supervise and Certify Accountable Material Destruction - ISM-0407Partially overlaps
Maintain Secure User Access Records - ISM-1059Depends on
Encrypt All Data Stored on Media Using ASD-Approved Cryptography - ISM-1080Supports
Use AACA or High Assurance Algorithms for Data Encryption - ISM-1505Depends on
Multi-factor Authentication for Human Users of Data Repositories - ISM-1586Partially overlaps
Record All Data Imports and Exports - ISM-1737Depends on
Recording Required Details for Each Managed Service in the Register - ISM-1814Supports
Prevent Backup Modifications by Unprivileged Users - ISM-1815Partially meets
Protect Event Logs from Unauthorised Access - ISM-1866Depends on
Prevent Storing Classified Data on Privately Owned Devices - ISM-1985Partially meets
Protect Event Logs from Unauthorised Access - ISM-1989Depends on
Ensure Event Logs Meet Retention Requirements
|
| Annex A 5.34 Privacy and Protection of Personally Identifiable Information | Organisational controls | - ISM-0821Supports
Advise on Risks of Posting Personal Information Online - ISM-1268Supports
Enforce Need-to-Know Access in Databases - ISM-1395Partially overlaps
Ensuring Data Protection by Service Providers - ISM-1478Supports
CISO Management of Cyber Security Compliance - ISM-1626Supports
Seek Legal Advice for Insider Threat Plans - ISM-1880Partially overlaps
Timely Reporting of Cyber Incidents Involving Customer Data - ISM-2002Supports
Ensure Board Cyber Security Literacy for Compliance - ISM-2021Partially overlaps
Implement and Maintain Data Minimisation Practices - ISM-2046Supports
Ensure Secure Impersonation Logging Practices - ISM-2103Partially overlaps
AI Data Use Requires Explicit Owner Consent - ISM-2107Depends on
Restrict Personal Information Viewing Online
|
| Annex A 5.35 Independent review of information security | Organisational controls | - ISM-0009Supports
Identify Supplementary Controls for System Security - ISM-0027Depends on
Mandatory Authorisation for System Operation - ISM-0718Partially overlaps
CISO Reporting to Board on Cyber Security - ISM-0724Depends on
Implement Cyber Security Metrics and KPIs - ISM-0725Supports
Cyber Security Steering Committee Coordination - ISM-0726Supports
Coordinate Security Risk Management Activities - ISM-0732Depends on
Manage and Allocate Cyber Security Budget - ISM-1037Partially overlaps
Regular Testing of Gateway Security Configurations - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1523Depends on
Regular Assessment of Security Events in CDS - ISM-1563Partially overlaps
Assessor Produces Security Assessment Report Covering Required Content - ISM-1570Partially meets
Regular IRAP Assessment of Cloud Service Providers - ISM-1587Partially overlaps
Annual Security Status Reporting for Systems - ISM-1617Partially overlaps
Regular Review of Cyber Security Program - ISM-1636Partially overlaps
Security Control Assessment of Systems by Own or IRAP Assessors - ISM-1793Broader than
Regular Assessment of Managed Service Providers - ISM-1918Partially overlaps
Regular Cyber Security Reporting to Audit Committee - ISM-1967Partially overlaps
Ensure Security Assessment of TOP SECRET Systems - ISM-1971Depends on
ASD-Led Security Assessment of TOP SECRET Managed Services Every 24 Months - ISM-1972Broader than
ASD Security Control Assessment of TOP SECRET Cloud Services Every 24 Months - ISM-1998Supports
Integrate Cyber Security Across Business Functions - ISM-1999Supports
Align Cyber Security with Business Strategy - ISM-2000Supports
Regular Cyber Security Briefings for Executives - ISM-2002Depends on
Ensure Board Cyber Security Literacy for Compliance - ISM-2005Supports
Understanding Business Criticality of Organisation Systems - ISM-2019Broader than
ASD Assessment of TOP SECRET Gateways Every 24 Months
|
| Annex A 5.36 Review compliance with information security policies | Organisational controls | - ISM-0039Depends on
Develop and Maintain a Cyber Security Strategy - ISM-0041Depends on
Maintain a System Security Plan With Overview and Controls Annex - ISM-0072Partially overlaps
Document Security Requirements in Contractual Arrangements - ISM-0264Depends on
Develop and Maintain an Email Usage Policy - ISM-0499Partially meets
Ensure Compliance with ASD Communication Security Policies - ISM-0588Supports
Develop and Maintain MFD Usage Policy - ISM-0718Partially overlaps
CISO Reporting to Board on Cyber Security - ISM-0724Depends on
Implement Cyber Security Metrics and KPIs - ISM-1037Broader than
Regular Testing of Gateway Security Configurations - ISM-1078Supports
Develop and Maintain Telephone System Usage Policy - ISM-1359Depends on
Establish and Maintain Removable Media Policy - ISM-1478Partially overlaps
CISO Management of Cyber Security Compliance - ISM-1523Broader than
Regular Assessment of Security Events in CDS - ISM-1533Depends on
Establish Mobile Device Management Policies - ISM-1549Depends on
Develop and Maintain Media Management Policy - ISM-1551Depends on
Develop and Maintain IT Equipment Management Policy - ISM-1617Depends on
Regular Review of Cyber Security Program - ISM-1738Partially overlaps
Verify Compliance with Security Requirements - ISM-1755Depends on
Develop and Maintain a Vulnerability Disclosure Policy - ISM-1763Depends on
Use NIST P-384 Curve for ECDSA Signatures - ISM-1864Depends on
Develop and Enforce a System Usage Policy - ISM-1884Depends on
Ensure Compliance with Emanation Security Doctrine - ISM-1956Depends on
Regularly Update AD FS Certificates to Prevent Risks - ISM-1971Partially overlaps
ASD-Led Security Assessment of TOP SECRET Managed Services Every 24 Months - ISM-1997Depends on
Define Cyber Security Roles for Leadership - ISM-1998Supports
Integrate Cyber Security Across Business Functions - ISM-2074Supports
Develop and Maintain AI Usage Policy - ISM-2120Depends on
Develop and Maintain Secure Software Policy
|
| Annex A 5.37 Documented Operating Procedures for Information Processing | Organisational controls | - ISM-0041Supports
Develop a Detailed System Security Plan - ISM-0042Supports
Maintain Effective System Administration Practices - ISM-0206Partially meets
Develop and Maintain Cable Labelling Processes - ISM-0348Broader than
Develop and Maintain Media Sanitisation Procedures - ISM-0362Supports
Follow Manufacturer's Directions for Degaussing - ISM-0372Broader than
Supervision of Media Destruction Procedures - ISM-0499Supports
Ensure Compliance with ASD Communication Security Policies - ISM-0576Partially overlaps
Develop and Maintain Cyber Security Incident Plans - ISM-0888Supports
Annual Review of Cyber Security Documentation - ISM-0912Partially overlaps
Establish and Manage System Configuration Changes - ISM-1359Supports
Establish and Maintain Removable Media Policy - ISM-1478Depends on
CISO Management of Cyber Security Compliance - ISM-1549Supports
Develop and Maintain Media Management Policy - ISM-1551Supports
Develop and Maintain IT Equipment Management Policy - ISM-1602Partially overlaps
Ensure Cyber Security Docs Are Communicated - ISM-1802Supports
Operate Approved High Assurance Cryptographic Equipment
|
| Annex A 6.1 Personnel Background Verification | People controls | - ISM-0269Depends on
Restrict Sensitive Emails to Verified Recipients - ISM-0434Partially overlaps
Ensure Personnel Employment Screening and Security Clearance - ISM-0613Partially meets
Requirement for Gateway System Administrators Nationality - ISM-1520Broader than
Employment Screening for Gateway Administrators - ISM-1773Depends on
Eligibility Criteria for Gateway System Administrators
|
| Annex A 6.2 Terms and conditions of employment for security | People controls | - ISM-0661Depends on
Holding Human Users Accountable for Data Transfers They Perform - ISM-0714Supports
Appoint a CISO to Lead Cyber Security Across IT and OT - ISM-1773Supports
Eligibility Criteria for Gateway System Administrators - ISM-2020Partially overlaps
Ensure Adequate Cyber Security Personnel Are Acquired - ISM-2035Partially overlaps
Document Security Roles for Software Development - ISM-2036Partially overlaps
Document Security Duties for Software Developers
|
| Annex A 6.3 Information security awareness, education and training program | People controls | - ISM-0229Partially meets
Guidelines for Discussing Sensitive Information Over Phones - ISM-0230Partially meets
Advising on Risks of Non-Secure Telephone Systems - ISM-0252Partially overlaps
Annual Cyber Security Awareness for Personnel - ISM-0370Supports
Supervise Media Destruction with Cleared Personnel - ISM-0435Partially meets
Pre-Access Briefings for System Resources - ISM-0610Partially meets
Train Users on Secure Use of CDSs - ISM-0612Broader than
Training for Gateway System Administrators - ISM-0661Depends on
Holding Human Users Accountable for Data Transfers They Perform - ISM-0701Supports
Establish Mobile Device Emergency Sanitisation Processes and Procedures - ISM-0817Broader than
Reporting Suspicious Online Contact Awareness - ISM-0821Broader than
Advise on Risks of Posting Personal Information Online - ISM-0824Supports
Avoid Using Unauthorised Online File Services - ISM-1083Broader than
Advise Personnel on Mobile Communication Sensitivity - ISM-1146Supports
Separate Personal and Work Accounts for Online Services - ISM-1298Broader than
Advise Personnel on Overseas Mobile Device Security - ISM-1554Supports
Guidelines for Using Mobile Devices Abroad - ISM-1565Broader than
Annual Tailored Training for All Privileged Access Holders - ISM-1602Partially overlaps
Ensure Cyber Security Docs Are Communicated - ISM-1644Partially meets
Secure Communication Practices in Public Areas - ISM-1740Broader than
Manage and Report Business Email Compromise - ISM-1864Supports
Develop and Enforce a System Usage Policy - ISM-1998Supports
Integrate Cyber Security Across Business Functions - ISM-2001Supports
Championing Cyber Security at an Executive Level - ISM-2003Supports
Monitor Cyber Security Workforce and Skill Gaps - ISM-2004Supports
Enhancing Cyber Security Skills and Experience - ISM-2022Partially meets
Develop and Maintain Cyber Security Training Register - ISM-2035Partially overlaps
Document Security Roles for Software Development - ISM-2037Partially meets
Train Software Developers Lacking Cyber Security Skills - ISM-2038Supports
Maintain Developer Cyber Security Skills Register - ISM-2071Broader than
Training on Managing Social Engineering Threats - ISM-2104Broader than
Do Not Post Security Clearance and Briefing Details Online - ISM-2105Broader than
Advise Staff to Limit Posting Work Information on Unauthorised Online Services - ISM-2106Broader than
Advise Staff to Limit Posting Work Skills Online - ISM-2107Broader than
Restrict Personal Information Viewing Online - ISM-2121Partially overlaps
Prevent Using Developers Without Cyber Security Skills
|
| Annex A 6.4 Disciplinary Process for Information Security Violations | People controls | - ISM-0661Depends on
Holding Human Users Accountable for Data Transfers They Perform - ISM-0820Supports
Avoid Posting Work Data on Unauthorised Online Services - ISM-1864Supports
Develop and Enforce a System Usage Policy - ISM-1865Depends on
Compliance with System Usage Policies for Access
|
| Annex A 6.5 Responsibilities after employment termination or role change | People controls | - ISM-0430Partially overlaps
Immediate Suspension of Unneeded System Access - ISM-1569Partially overlaps
Document and Share a Supplier Customer Shared Responsibility Model - ISM-1997Depends on
Define Cyber Security Roles for Leadership - ISM-2036Depends on
Document Security Duties for Software Developers
|
| Annex A 6.6 Confidentiality and Non-disclosure Agreements | People controls | |
| Annex A 6.7 Remote Working Security Measures | People controls | - ISM-0467Depends on
Using HACE for Secure Communication of Data - ISM-0487Depends on
Disable Certain Features for Passwordless SSH Logins - ISM-0488Partially meets
Use Forced Commands for SSH Without Passwords - ISM-0694Broader than
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0705Broader than
Disable Split Tunnelling for VPN Connections - ISM-0824Partially meets
Avoid Using Unauthorised Online File Services - ISM-0871Supports
Supervise Mobile Devices During Active Use - ISM-1006Partially overlaps
Prevent Unauthorised Access to Network Traffic - ISM-1084Supports
Transporting Mobile Devices Securely - ISM-1146Broader than
Separate Personal and Work Accounts for Online Services - ISM-1400Partially overlaps
Enforce Data Separation on Personal Devices - ISM-1482Partially overlaps
Ensure Separation of Classified and Personal Data on Devices - ISM-1504Partially meets
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1554Partially meets
Guidelines for Using Mobile Devices Abroad - ISM-1866Partially overlaps
Prevent Storing Classified Data on Privately Owned Devices - ISM-1887Broader than
Implement Remote Locate and Wipe for Mobile Security - ISM-1990Depends on
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations - ISM-2096Depends on
Separate Organisational and Personal Mobile Data - ISM-2098Depends on
Prevent Data Transfer Over USB on Mobile Devices - ISM-2101Depends on
Restrict Sensitive Conversations Near Vehicles - ISM-2149Depends on
Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
|
| Annex A 6.8 Mechanisms for Reporting Security Events | People controls | - ISM-0043Partially overlaps
Cyber Security Incident Response Plan Requirements - ISM-0123Partially overlaps
Report Cyber Security Incidents Promptly - ISM-0125Partially overlaps
Maintaining a Cyber Security Incident Register - ISM-0142Broader than
Report Cryptographic Equipment Compromises Promptly - ISM-0252Supports
Annual Cyber Security Awareness for Personnel - ISM-0820Broader than
Avoid Posting Work Data on Unauthorised Online Services - ISM-1088Partially overlaps
Report Potential Compromises of Mobile Devices Overseas - ISM-1523Supports
Regular Assessment of Security Events in CDS - ISM-1556Supports
Security Measures After Overseas Travel with Mobile Devices - ISM-1740Depends on
Manage and Report Business Email Compromise - ISM-1803Partially overlaps
Document and Report Cyber Security Incidents - ISM-1880Partially overlaps
Timely Reporting of Cyber Incidents Involving Customer Data - ISM-1881Partially overlaps
Timely Reporting of Cyber Incidents Without Data Breach - ISM-2001Depends on
Championing Cyber Security at an Executive Level - ISM-2071Partially overlaps
Training on Managing Social Engineering Threats - ISM-2105Partially overlaps
Advise Staff to Limit Posting Work Information on Unauthorised Online Services
|
| Annex A 7.1 Physical Security Perimeters | Physical controls | - ISM-0161Supports
Ensure Security of Unused IT Equipment and Media - ISM-0164Supports
Prevent Unauthorised Viewing of System Displays - ISM-0217Supports
Secure Separation of Non-TOP SECRET and TOP SECRET Panels - ISM-0225Broader than
Prevent Unauthorised RF and IR Device Entry - ISM-0235Partially meets
Use of Speakerphones in TOP SECRET Areas - ISM-0559Supports
Restrict Microphone and Webcam Use in SECRET Areas - ISM-0735Partially overlaps
CISO Oversees the Cyber Security Awareness Training Program - ISM-0810Partially meets
Secure Facilities Based on System Classification - ISM-0813Supports
Ensure Secure Access to Critical Infrastructure - ISM-0829Broader than
Detect Unauthorised RF Devices in Secure Areas - ISM-1053Broader than
Secure Physical Access for Classified Equipment - ISM-1074Partially meets
Controlling Access to Critical IT Infrastructure - ISM-1098Broader than
Terminate Cable Systems at Cabinet Boundaries - ISM-1103Depends on
Terminate Cables Outside Cabinets in Secure Areas - ISM-1137Partially overlaps
Request Risk Assessment for Emanation Security - ISM-1296Partially overlaps
Protect Network Devices in Public Areas - ISM-1633Supports
Determine System Boundary, Criticality and Security Objectives - ISM-1974Broader than
Securing Non-Classified IT Equipment in Secure Rooms - ISM-1975Supports
Secure Non-Classified Equipment in Safe Containers - ISM-2070Supports
Control Access to Recording Devices in Secure Areas
|
| Annex A 7.2 Physical access controls for secure areas | Physical controls | - ISM-0161Depends on
Ensure Security of Unused IT Equipment and Media - ISM-0164Partially meets
Prevent Unauthorised Viewing of System Displays - ISM-0225Broader than
Prevent Unauthorised RF and IR Device Entry - ISM-0306Partially overlaps
Escort Uncleared Technicians During IT Equipment Maintenance or Repairs - ISM-0345Depends on
Disable External Interfaces for Direct Memory Access - ISM-0418Supports
Keep Physical Credentials Separate from Systems - ISM-0810Broader than
Secure Facilities Based on System Classification - ISM-0813Partially overlaps
Ensure Secure Access to Critical Infrastructure - ISM-1053Partially overlaps
Secure Physical Access for Classified Equipment - ISM-1074Partially overlaps
Controlling Access to Critical IT Infrastructure - ISM-1105Partially meets
Ensure Wall Outlets Have Appropriate Cable Security - ISM-1296Partially overlaps
Protect Network Devices in Public Areas - ISM-1327Partially overlaps
Secure Certificates for Network Authentication - ISM-1957Supports
Ensure CA Servers Use Hardware Security Modules - ISM-1973Supports
Secure Facilities for Non-Classified Systems - ISM-1974Supports
Securing Non-Classified IT Equipment in Secure Rooms - ISM-1975Partially overlaps
Secure Non-Classified Equipment in Safe Containers - ISM-2007Supports
Authorised Medical Device Register for SECRET and TOP SECRET Areas - ISM-2070Broader than
Control Access to Recording Devices in Secure Areas
|
| Annex A 7.3 Physical Security for Offices and Facilities | Physical controls | - ISM-0161Supports
Ensure Security of Unused IT Equipment and Media - ISM-0164Broader than
Prevent Unauthorised Viewing of System Displays - ISM-0194Partially meets
Sealing Conduit Joints in Shared Facilities - ISM-0198Partially meets
Consultation for Penetrating Audio Secure Rooms - ISM-0216Partially meets
Ensure Separate Cabinets for TOP SECRET Patch Panels - ISM-0225Partially meets
Prevent Unauthorised RF and IR Device Entry - ISM-0735Partially meets
CISO Oversees the Cyber Security Awareness Training Program - ISM-0810Partially meets
Secure Facilities Based on System Classification - ISM-0813Partially meets
Ensure Secure Access to Critical Infrastructure - ISM-1036Partially meets
Place Multifunction Devices Where Their Use Can Be Observed - ISM-1053Partially meets
Secure Physical Access for Classified Equipment - ISM-1107Broader than
Colour Restrictions for Wall Outlet Boxes - ISM-1116Partially meets
Ensure Separation Between Top Secret and Other Cabinets - ISM-1130Partially meets
Use Enclosed Systems for Shared Facility Cables - ISM-1164Partially meets
Use Clear Plastic for Shared Facility Cabling Covers - ISM-1296Broader than
Protect Network Devices in Public Areas - ISM-1327Partially overlaps
Secure Certificates for Network Authentication - ISM-1645Partially meets
Maintain and Verify Floor Plan Diagrams - ISM-1720Partially meets
Colour Coding for Secret Wall Outlet Boxes - ISM-1973Partially meets
Secure Facilities for Non-Classified Systems - ISM-1974Partially meets
Securing Non-Classified IT Equipment in Secure Rooms - ISM-1975Partially meets
Secure Non-Classified Equipment in Safe Containers
|
| Annex A 7.4 Continuous monitoring of physical access to premises | Physical controls | - ISM-1053Partially overlaps
Secure Physical Access for Classified Equipment - ISM-1296Depends on
Protect Network Devices in Public Areas - ISM-1973Supports
Secure Facilities for Non-Classified Systems - ISM-1974Supports
Securing Non-Classified IT Equipment in Secure Rooms
|
| Annex A 7.5 Protecting against physical and environmental threats | Physical controls | - ISM-0164Partially meets
Prevent Unauthorised Viewing of System Displays - ISM-0194Broader than
Sealing Conduit Joints in Shared Facilities - ISM-0195Broader than
Seal Removable Covers on TOP SECRET Cables - ISM-0216Broader than
Ensure Separate Cabinets for TOP SECRET Patch Panels - ISM-0734Partially overlaps
CISO Role in Disaster Recovery Planning - ISM-0735Partially overlaps
CISO Oversees the Cyber Security Awareness Training Program - ISM-0810Supports
Secure Facilities Based on System Classification - ISM-0813Broader than
Ensure Secure Access to Critical Infrastructure - ISM-0829Partially meets
Detect Unauthorised RF Devices in Secure Areas - ISM-1053Supports
Secure Physical Access for Classified Equipment - ISM-1074Broader than
Controlling Access to Critical IT Infrastructure - ISM-1116Broader than
Ensure Separation Between Top Secret and Other Cabinets - ISM-1119Partially overlaps
Ensure Cables in TOP SECRET Areas are Inspectable - ISM-1164Broader than
Use Clear Plastic for Shared Facility Cabling Covers - ISM-1296Partially overlaps
Protect Network Devices in Public Areas - ISM-1645Broader than
Maintain and Verify Floor Plan Diagrams - ISM-1973Broader than
Secure Facilities for Non-Classified Systems - ISM-1975Partially meets
Secure Non-Classified Equipment in Safe Containers
|
| Annex A 7.6 Security Measures for Working in Secure Areas | Physical controls | - ISM-0164Broader than
Prevent Unauthorised Viewing of System Displays - ISM-0218Partially meets
Label and Protect Long TS Fibre-Optic Leads - ISM-0225Broader than
Prevent Unauthorised RF and IR Device Entry - ISM-0236Broader than
Implement Off-hook Audio Protection on Telephones - ISM-0559Broader than
Restrict Microphone and Webcam Use in SECRET Areas - ISM-0735Partially overlaps
CISO Oversees the Cyber Security Awareness Training Program - ISM-0810Partially overlaps
Secure Facilities Based on System Classification - ISM-0829Broader than
Detect Unauthorised RF Devices in Secure Areas - ISM-0931Partially meets
Off-hook Audio Protection Using Push-to-Talk Devices - ISM-1013Broader than
Limit Wireless Range with RF Shielding - ISM-1101Broader than
Terminate Cabling Closely in Top Secret Areas - ISM-1103Broader than
Terminate Cables Outside Cabinets in Secure Areas - ISM-1137Partially overlaps
Request Risk Assessment for Emanation Security - ISM-1296Partially overlaps
Protect Network Devices in Public Areas - ISM-1450Broader than
Restricting Devices in Top Secret Areas - ISM-1635Partially meets
System Owners Implement Security Controls for Each System and Environment - ISM-1720Partially meets
Colour Coding for Secret Wall Outlet Boxes - ISM-1721Supports
Red Colour Coding for TOP SECRET Outlet Boxes - ISM-1821Supports
Ensuring Exclusive Bundling for TOP SECRET Cables - ISM-1885Supports
Implement Emanation Security Measures for Systems - ISM-1973Partially overlaps
Secure Facilities for Non-Classified Systems - ISM-2008Broader than
Criteria for Medical Devices in SECRET and TOP SECRET Areas - ISM-2069Broader than
Maintain Register of Authorised Recording Devices in SECRET and TOP SECRET Areas - ISM-2070Broader than
Control Access to Recording Devices in Secure Areas
|
| Annex A 7.7 Clear desk and clear screen policies | Physical controls | - ISM-0161Partially overlaps
Ensure Security of Unused IT Equipment and Media - ISM-0164Partially overlaps
Prevent Unauthorised Viewing of System Displays - ISM-0831Partially overlaps
Ensure Proper Handling of Sensitive Media - ISM-0853Partially overlaps
Terminate User Sessions and Restart Workstations Daily - ISM-0866Partially overlaps
Ensure Privacy While Viewing Data in Public - ISM-0870Partially overlaps
Secure Storage and Handling of Mobile Devices - ISM-1076Partially overlaps
Sanitise Screen Burn-In With a Solid White Image - ISM-1145Partially overlaps
Apply Privacy Filters to Protect Device Screens - ISM-1299Supports
Personnel Awareness for Secure Mobile Device Usage - ISM-1359Partially overlaps
Establish and Maintain Removable Media Policy - ISM-1888Supports
Ensure Mobile Devices Have Secure Lock Screens - ISM-2012Partially overlaps
Ensure Secure Screen Locking on Systems
|
| Annex A 7.8 Equipment Siting and Protection | Physical controls | - ISM-0161Partially overlaps
Ensure Security of Unused IT Equipment and Media - ISM-0164Partially overlaps
Prevent Unauthorised Viewing of System Displays - ISM-0194Partially meets
Sealing Conduit Joints in Shared Facilities - ISM-0216Partially overlaps
Ensure Separate Cabinets for TOP SECRET Patch Panels - ISM-0345Supports
Disable External Interfaces for Direct Memory Access - ISM-0735Partially overlaps
CISO Oversees the Cyber Security Awareness Training Program - ISM-0810Partially overlaps
Secure Facilities Based on System Classification - ISM-0813Partially overlaps
Ensure Secure Access to Critical Infrastructure - ISM-0870Partially overlaps
Secure Storage and Handling of Mobile Devices - ISM-0871Partially overlaps
Supervise Mobile Devices During Active Use - ISM-1036Partially meets
Place Multifunction Devices Where Their Use Can Be Observed - ISM-1053Partially overlaps
Secure Physical Access for Classified Equipment - ISM-1074Partially overlaps
Controlling Access to Critical IT Infrastructure - ISM-1109Broader than
Ensure Clear Plastic Covers for Wall Outlets - ISM-1116Partially meets
Ensure Separation Between Top Secret and Other Cabinets - ISM-1119Partially overlaps
Ensure Cables in TOP SECRET Areas are Inspectable - ISM-1296Broader than
Protect Network Devices in Public Areas - ISM-1599Depends on
Proper Handling of Sensitive IT Equipment - ISM-1721Supports
Red Colour Coding for TOP SECRET Outlet Boxes - ISM-1973Partially overlaps
Secure Facilities for Non-Classified Systems - ISM-1974Partially overlaps
Securing Non-Classified IT Equipment in Secure Rooms - ISM-1975Partially overlaps
Secure Non-Classified Equipment in Safe Containers
|
| Annex A 7.9 Security of Off-Site Assets | Physical controls | - ISM-0161Supports
Ensure Security of Unused IT Equipment and Media - ISM-0457Partially overlaps
Use Evaluated Crypto for Sensitive Data Encryption - ISM-0465Partially overlaps
Use Evaluated Cryptographic Tools for Sensitive Data - ISM-1314Supports
Ensure Wireless Devices are Wi-Fi Alliance Certified - ISM-1400Partially meets
Enforce Data Separation on Personal Devices - ISM-1554Partially meets
Guidelines for Using Mobile Devices Abroad
|
| Annex A 7.10 Secure Management of Storage Media | Physical controls | - ISM-0307Partially meets
Sanitise Equipment When Not Using Cleared Technician - ISM-0311Partially overlaps
Ensuring Sanitisation of IT Equipment Media - ISM-0312Partially meets
Return Overseas Equipment for Destruction - ISM-0313Partially overlaps
Develop and Maintain IT Equipment Sanitisation Procedures - ISM-0315Partially overlaps
Ensure Destruction of High Assurance IT Equipment - ISM-0316Partially meets
Formal Decision on IT Equipment Disposal - ISM-0317Partially meets
Ensuring Data Erasure on Printer Cartridges and Drums - ISM-0318Partially meets
Safely Disposing of Unsanitised Printer Components - ISM-0321Partially meets
Contact ASD for Guidance on Secure IT Disposal - ISM-0323Supports
Classifying Media by Data Sensitivity - ISM-0325Broader than
Reclassify Media to Higher Sensitivity - ISM-0330Partially meets
Proper Sanitisation and Reclassification of Media - ISM-0337Broader than
Ensure Media is Used with Authorised Systems - ISM-0343Partially overlaps
Disabling Unnecessary Access to Removable Media - ISM-0348Partially overlaps
Develop and Maintain Media Sanitisation Procedures - ISM-0350Partially meets
Destroy Unsanitizable Media Before Disposal - ISM-0351Partially meets
Proper Method for Volatile Media Sanitisation - ISM-0352Partially meets
Secure Volatile Media by Overwriting with Random Data - ISM-0354Partially meets
Ensuring Proper Sanitisation of Magnetic Media - ISM-0356Partially meets
Classify Magnetic Media After Sanitisation - ISM-0357Partially meets
Sanitising Non-volatile EPROM Media - ISM-0358Partially meets
Classification Retention for Sanitised EPROM and EEPROM - ISM-0359Partially meets
Proper Sanitisation of Non-Volatile Flash Memory - ISM-0360Partially overlaps
Classification Retention After Flash Memory Sanitisation - ISM-0361Partially meets
Using Degaussers for Magnetic Media Destruction - ISM-0362Partially meets
Follow Manufacturer's Directions for Degaussing - ISM-0363Partially meets
Develop and Maintain Media Destruction Processes - ISM-0368Partially meets
Ensuring Media Particles Are No Larger Than 9 mm - ISM-0371Partially meets
Ensure Proper Supervision of Media Destruction - ISM-0374Partially meets
Develop and Maintain Media Disposal Procedures - ISM-0375Partially meets
Decide on Public Release of Data Storage Media - ISM-0378Partially meets
Remove Labels from Media Before Disposal - ISM-0462Partially overlaps
Managing Encryption Access for IT Equipment and Media - ISM-0831Equivalent
Ensure Proper Handling of Sensitive Media - ISM-0835Partially overlaps
TOP SECRET Volatile Media Retains Classification After Sanitisation - ISM-0836Partially meets
Overwriting EEPROM for Complete Data Sanitisation - ISM-0839Partially meets
Prohibit Outsourcing of Media Destruction - ISM-0840Partially overlaps
Certified Services for Outsourced Media Destruction - ISM-0947Partially meets
Sanitise Media After Data Transfers Between Domains - ISM-1059Partially meets
Encrypt All Data Stored on Media Using ASD-Approved Cryptography - ISM-1065Partially meets
Reset Device Settings Before Media Sanitisation - ISM-1067Supports
Secure Erase for Non-Volatile Magnetic Media - ISM-1084Partially meets
Transporting Mobile Devices Securely - ISM-1157Partially meets
Use Evaluated Diodes to Control Unidirectional Gateway Data Flow - ISM-1160Partially meets
Use NSA-evaluated Degaussers for Media Destruction - ISM-1217Partially overlaps
Remove Identifying Labels from IT Equipment Before Disposal - ISM-1222Partially meets
Destroy Unsanitised Televisions and Monitors - ISM-1299Supports
Personnel Awareness for Secure Mobile Device Usage - ISM-1300Partially overlaps
Mobile Device Security After Overseas Travel - ISM-1361Partially meets
Use Approved Equipment for Media Destruction - ISM-1418Partially overlaps
Disable Unnecessary Removable Media Access - ISM-1550Partially meets
Develop and Maintain IT Equipment Disposal Procedures - ISM-1600Partially meets
Ensure Media is Sanitised Before Initial Use - ISM-1641Partially meets
Ensure Degaussed Media is Physically Damaged - ISM-1722Partially meets
Methods for Destroying Electrostatic Memory Devices - ISM-1723Partially meets
Methods for Destroying Magnetic Floppy Disks - ISM-1724Partially meets
Methods for Destroying Magnetic Hard Disks - ISM-1725Partially meets
Methods for Destroying Magnetic Tapes - ISM-1726Partially meets
Methods for Destructing Optical Disks - ISM-1727Broader than
Methods for Destroying Semiconductor Memory - ISM-1728Partially meets
Handling Media Waste Based on Particle Size - ISM-1729Broader than
Storage Classification of Media Waste Particles - ISM-1735Partially meets
Destroy Unsanitised Media Before Disposal - ISM-1866Broader than
Prevent Storing Classified Data on Privately Owned Devices - ISM-2072Partially meets
Store AI Models In A Non-Executable File Format - ISM-2098Broader than
Prevent Data Transfer Over USB on Mobile Devices
|
| Annex A 7.11 Protection from Utility Failures | Physical controls | - ISM-1123Supports
Ensure UPS Powers All Top Secret IT Equipment - ISM-1438Partially overlaps
Ensure High Availability by Using CDNs - ISM-1580Partially overlaps
Ensure High Availability for Online Services
|
| Annex A 7.12 Secure Cabling for Power and Data | Physical controls | - ISM-0181Supports
Ensure Cabling Meets Australian Standards - ISM-0187Broader than
Exclusive Secret Cable Bundling in Infrastructure - ISM-0195Broader than
Seal Removable Covers on TOP SECRET Cables - ISM-0206Supports
Develop and Maintain Cable Labelling Processes - ISM-0213Partially overlaps
Segregate Patch Panels for Secret-Level Cables - ISM-0250Partially overlaps
Ensure IT Equipment Meets EMI/EMC Standards - ISM-0926Partially meets
Ensure Cables Are Not Salmon Pink or Red - ISM-1095Supports
Proper Labelling of Wall Outlet Boxes - ISM-1096Partially meets
Ensure Proper Labelling of Cables for Identification - ISM-1100Broader than
Terminating TOP SECRET Cables in Cabinets - ISM-1101Broader than
Terminate Cabling Closely in Top Secret Areas - ISM-1102Broader than
Terminate Cable Reticulation Close to Cabinet - ISM-1103Broader than
Terminate Cables Outside Cabinets in Secure Areas - ISM-1111Broader than
Ensure Fibre-Optic Cables Replace Copper Cables - ISM-1112Broader than
Ensure Cables Are Inspectable Every Five Metres - ISM-1114Broader than
Ensure Separation in Cable Reticulation Systems - ISM-1115Partially meets
Ensure Cables Use Conduits in Walls - ISM-1119Broader than
Ensure Cables in TOP SECRET Areas are Inspectable - ISM-1122Broader than
Secure TOP SECRET Cable Wall Exits - ISM-1130Partially meets
Use Enclosed Systems for Shared Facility Cables - ISM-1133Partially meets
Prevent Installation of TOP SECRET Cables in Shared Walls - ISM-1164Partially meets
Use Clear Plastic for Shared Facility Cabling Covers - ISM-1296Depends on
Protect Network Devices in Public Areas - ISM-1639Partially overlaps
Label Building Management Cables Clearly - ISM-1640Supports
Label Cables for Foreign Systems in Australia - ISM-1718Partially meets
Colour Code for SECRET Cables - ISM-1719Depends on
Colour Code for TOP SECRET Cables - ISM-1821Partially meets
Ensuring Exclusive Bundling for TOP SECRET Cables
|
| Annex A 7.13 Proper Maintenance of Equipment | Physical controls | - ISM-0206Supports
Develop and Maintain Cable Labelling Processes - ISM-0211Partially overlaps
Develop and Verify a Cable Register - ISM-0290Supports
Secure Configuration of High Assurance IT Equipment - ISM-0298Partially overlaps
Centralised System Patch and Update Management - ISM-0305Partially meets
On-Site IT Equipment Maintenance by Cleared Technicians - ISM-0306Supports
Escort Uncleared Technicians During IT Equipment Maintenance or Repairs - ISM-0307Partially overlaps
Sanitise Equipment When Not Using Cleared Technician - ISM-0310Partially overlaps
Off-Site IT Equipment Handling Approvals - ISM-1079Supports
Seek Approval for High Assurance IT Repairs - ISM-1598Partially overlaps
Inspect IT Equipment Post-Maintenance for Unauthorised Changes - ISM-1801Partially meets
Monthly Restart of Network Devices - ISM-1913Supports
Develop and Maintain Approved IT Configurations - ISM-1982Supports
Replace Unsupported Networked IT Equipment
|
| Annex A 7.14 Secure disposal or re-use of equipment | Physical controls | - ISM-0161Partially overlaps
Ensure Security of Unused IT Equipment and Media - ISM-0307Partially overlaps
Sanitise Equipment When Not Using Cleared Technician - ISM-0311Equivalent
Ensuring Sanitisation of IT Equipment Media - ISM-0312Partially meets
Return Overseas Equipment for Destruction - ISM-0313Partially overlaps
Develop and Maintain IT Equipment Sanitisation Procedures - ISM-0315Partially overlaps
Ensure Destruction of High Assurance IT Equipment - ISM-0316Partially overlaps
Formal Decision on IT Equipment Disposal - ISM-0317Partially meets
Ensuring Data Erasure on Printer Cartridges and Drums - ISM-0318Partially meets
Safely Disposing of Unsanitised Printer Components - ISM-0321Partially overlaps
Contact ASD for Guidance on Secure IT Disposal - ISM-0330Partially overlaps
Proper Sanitisation and Reclassification of Media - ISM-0350Partially overlaps
Destroy Unsanitizable Media Before Disposal - ISM-0351Partially meets
Proper Method for Volatile Media Sanitisation - ISM-0352Partially meets
Secure Volatile Media by Overwriting with Random Data - ISM-0354Partially meets
Ensuring Proper Sanitisation of Magnetic Media - ISM-0357Partially meets
Sanitising Non-volatile EPROM Media - ISM-0359Supports
Proper Sanitisation of Non-Volatile Flash Memory - ISM-0360Partially overlaps
Classification Retention After Flash Memory Sanitisation - ISM-0361Supports
Using Degaussers for Magnetic Media Destruction - ISM-0362Supports
Follow Manufacturer's Directions for Degaussing - ISM-0363Partially overlaps
Develop and Maintain Media Destruction Processes - ISM-0368Broader than
Ensuring Media Particles Are No Larger Than 9 mm - ISM-0371Partially overlaps
Ensure Proper Supervision of Media Destruction - ISM-0373Partially meets
Supervise and Certify Accountable Material Destruction - ISM-0374Partially overlaps
Develop and Maintain Media Disposal Procedures - ISM-0375Partially overlaps
Decide on Public Release of Data Storage Media - ISM-0378Partially overlaps
Remove Labels from Media Before Disposal - ISM-0835Partially overlaps
TOP SECRET Volatile Media Retains Classification After Sanitisation - ISM-0836Partially meets
Overwriting EEPROM for Complete Data Sanitisation - ISM-0839Partially overlaps
Prohibit Outsourcing of Media Destruction - ISM-0947Partially overlaps
Sanitise Media After Data Transfers Between Domains - ISM-1065Supports
Reset Device Settings Before Media Sanitisation - ISM-1067Partially meets
Secure Erase for Non-Volatile Magnetic Media - ISM-1157Partially meets
Use Evaluated Diodes to Control Unidirectional Gateway Data Flow - ISM-1160Partially meets
Use NSA-evaluated Degaussers for Media Destruction - ISM-1217Partially overlaps
Remove Identifying Labels from IT Equipment Before Disposal - ISM-1218Partially meets
Sanitise Overseas IT Equipment Handling Sensitive Data - ISM-1219Partially meets
Inspect and Destroy MFD Print Drums and Image Transfer Rollers - ISM-1220Partially meets
Inspect and Destroy Retained Images on Printer Platens - ISM-1221Supports
Check Printers and MFDs for Trapped Pages - ISM-1222Partially meets
Destroy Unsanitised Televisions and Monitors - ISM-1223Partially meets
Methods for Sanitising Network Device Memory - ISM-1361Partially overlaps
Use Approved Equipment for Media Destruction - ISM-1517Partially meets
Microform Destruction Using Fine Powder Method - ISM-1550Partially overlaps
Develop and Maintain IT Equipment Disposal Procedures - ISM-1599Partially overlaps
Proper Handling of Sensitive IT Equipment - ISM-1641Partially meets
Ensure Degaussed Media is Physically Damaged - ISM-1642Partially overlaps
Ensure Media is Sanitised Before Reuse - ISM-1724Partially overlaps
Methods for Destroying Magnetic Hard Disks - ISM-1726Partially meets
Methods for Destructing Optical Disks - ISM-1727Broader than
Methods for Destroying Semiconductor Memory - ISM-1729Partially overlaps
Storage Classification of Media Waste Particles - ISM-1735Partially overlaps
Destroy Unsanitised Media Before Disposal - ISM-1741Partially overlaps
Implement IT Equipment Destruction Procedures - ISM-1742Partially overlaps
Destroy Un-sanitizable IT Equipment Safely - ISM-2021Partially overlaps
Implement and Maintain Data Minimisation Practices - ISM-2053Supports
End of Life Procedures for Software
|
| Annex A 8.1 Protection of User Endpoint Devices | Technological controls | - ISM-0161Partially overlaps
Ensure Security of Unused IT Equipment and Media - ISM-0345Partially meets
Disable External Interfaces for Direct Memory Access - ISM-0489Broader than
Four-Hour Cached SSH Private Key Lifetime and Screen Locks - ISM-0591Partially meets
Use Evaluated Peripheral Switches Securely - ISM-0682Partially meets
Disable Bluetooth on SECRET/TS Mobile Devices - ISM-0687Partially meets
Use Approved Platforms for Secure Mobile Access - ISM-0853Broader than
Terminate Interactive User Sessions and Restart Workstations at Least Daily - ISM-0864Partially meets
Prevent Modifications to Security Settings on Mobile Devices - ISM-0866Partially meets
Ensure Privacy While Viewing Data in Public - ISM-0869Broader than
Encrypt Storage on Mobile Devices - ISM-0870Broader than
Secure Storage and Handling of Mobile Devices - ISM-0871Partially meets
Supervise Mobile Devices During Active Use - ISM-0874Broader than
Ensure Internet Access via Organisation's Gateway - ISM-1059Broader than
Encrypt All Data Stored on Media Using ASD-Approved Cryptography - ISM-1080Supports
Use AACA or High Assurance Algorithms for Data Encryption - ISM-1082Partially meets
Develop and Maintain Mobile Device Usage Policy - ISM-1084Partially meets
Transporting Mobile Devices Securely - ISM-1195Broader than
Enforce Policy with Evaluated Mobile Device Management - ISM-1196Broader than
Keep Mobile Devices Undiscoverable via Bluetooth - ISM-1198Partially meets
Secure Bluetooth Pairing for Mobile Devices - ISM-1199Partially meets
Remove Unnecessary Bluetooth Pairings on Devices - ISM-1200Broader than
Secure Bluetooth Pairing for Mobile Devices - ISM-1341Broader than
Implement HIPS or EDR on Workstations - ISM-1400Partially meets
Enforce Data Separation on Personal Devices - ISM-1450Supports
Restricting Devices in Top Secret Areas - ISM-1482Partially meets
Ensure Separation of Classified and Personal Data on Devices - ISM-1533Partially meets
Establish Mobile Device Management Policies - ISM-1554Partially meets
Guidelines for Using Mobile Devices Abroad - ISM-1585Depends on
Lock Web Browser Security Settings Against Human User Changes - ISM-1686Partially meets
Enable Credential Guard for Credential Protection - ISM-1809Depends on
Compensating Controls for Unsupported Systems Pending Removal or Replacement - ISM-1866Partially meets
Prevent Storing Classified Data on Privately Owned Devices - ISM-1867Broader than
Use Approved Mobile Platforms for Sensitive Access - ISM-1868Partially meets
Restrictions on Mobile Device Removable Media - ISM-1886Partially meets
Ensure Mobile Devices Operate in Supervised Mode - ISM-1887Broader than
Implement Remote Locate and Wipe for Mobile Security - ISM-1888Partially meets
Ensure Mobile Devices Have Secure Lock Screens - ISM-1896Partially meets
Enable Memory Integrity for Credential Protection - ISM-1898Partially meets
Use Secure Admin Workstations for Administration - ISM-2097Depends on
Configure Mobile Devices with Always On VPN
|
| Annex A 8.2 Management of Privileged Access Rights | Technological controls | - ISM-0078Supports
Australian Supervision of AUSTEO/AGAO Data Systems - ISM-0407Depends on
Maintaining a Secure Lifetime Access Record for Each Human User - ISM-0415Partially overlaps
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0432Depends on
Document System Access Requirements in Security Plans - ISM-0443Broader than
Restrict Temporary Access to Secure Systems - ISM-0445Broader than
Dedicated Privileged Accounts Used Solely for Privileged Duties - ISM-0446Partially overlaps
Restrict Privileged Access for Foreign Nationals - ISM-0447Broader than
Restrict Privileged Access for Foreign Nationals - ISM-0611Broader than
Restrict Privileges for Gateway Administrators - ISM-0629Depends on
Manage Gateways Between Different Security Domains - ISM-0665Depends on
CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems - ISM-1175Broader than
Restrict Privileged Users from Internet Access - ISM-1249Broader than
Limit Server Application User Privileges - ISM-1250Partially overlaps
Limit Server Application User Account Privileges - ISM-1263Broader than
Enforce Unique Accounts for Server Administration - ISM-1297Depends on
Seek Legal Advice for Personal Device Access - ISM-1392Depends on
Restrict File Modifications via Path Rules - ISM-1422Depends on
Prevent Unauthorised Access to Software Source - ISM-1487Partially overlaps
Restrict Macro Editing to Privileged Users - ISM-1507Broader than
Ensure Requests for Privileged Access are Verified - ISM-1508Partially overlaps
Limit Privileged Access to Essential Duties Only - ISM-1565Depends on
Annual Tailored Training for All Privileged Access Holders - ISM-1583Depends on
Ensure Contractors are Identified as Users - ISM-1591Partially overlaps
Remove or Suspend Access When Users Are Detected Acting Maliciously - ISM-1593Depends on
Verify User Identity Before Issuing, Resetting, Disabling or Enrolling Credentials - ISM-1604Depends on
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1612Broader than
Restricted Use of Break Glass Accounts for Emergencies - ISM-1614Partially overlaps
Manage Emergency Account Access Changes - ISM-1619Depends on
Configure Service Accounts as Managed Service Accounts - ISM-1620Broader than
Ensure Privileged Accounts are Secured in AD - ISM-1647Broader than
Disable Privileged Access After 12 Months - ISM-1648Broader than
Disabling Inactive Privileged Access to Systems - ISM-1649Broader than
Implement Just-in-Time Administration for System Access - ISM-1650Partially meets
Log Management of Privileged User Activities - ISM-1685Depends on
Strengthening Passwords for Critical Accounts - ISM-1688Broader than
Block Unprivileged Account Logons to Privileged Operating Environments - ISM-1689Broader than
Block Privileged Account Logons to Unprivileged Operating Environments - ISM-1706Partially overlaps
Prevent Backup Access by Privileged Users - ISM-1827Broader than
Use Dedicated Admin Accounts for Domain Controllers - ISM-1834Supports
Ensure No Duplicate SPNs in Active Directory - ISM-1835Broader than
Restrict Delegation of Privileged Active Directory Accounts - ISM-1842Broader than
Use Privileged Accounts for Domain Machine Addition - ISM-1846Broader than
Restrict Pre-Windows 2000 Access Group Membership - ISM-1883Broader than
Limit Authorised Privileged Account Online Service Access to Duties - ISM-1898Depends on
Use Secure Admin Workstations for Administration - ISM-1927Broader than
Limit Identity Server Access to Privileged Users Requiring It - ISM-1932Partially overlaps
Limit Service Accounts with SPNs in Active Directory - ISM-1934Broader than
Six-Monthly Review and Removal of DCSync User Permissions - ISM-1936Partially meets
Prevent Usage of sIDHistory in User Accounts - ISM-1939Broader than
Minimise Members in Privileged Security Groups - ISM-1940Broader than
Restrict Service Accounts from Privileged Groups - ISM-1942Broader than
Domain Computers Group Privilege Restriction - ISM-1946Broader than
Restrict Write Access to Certificate Templates - ISM-1948Depends on
Certificate Manager Approval for Templates Allowing Supplied SANs - ISM-1949Broader than
Use Dedicated Accounts for AD FS Administration - ISM-1950Depends on
Disable Soft Matching After Synchronisation - ISM-1952Broader than
Prevent Synchronisation of Privileged Accounts - ISM-1958Broader than
Prevent Unauthorised Access for DCSync Accounts - ISM-2005Depends on
Understanding Business Criticality of Organisation Systems - ISM-2048Broader than
Restrict Non-Admins from Changing Permissions - ISM-2113Depends on
Configuring AI Applications to Require Human Approval Before High-Impact Actions - ISM-2128Broader than
Limit Kernel-Mode Code Installation to Privileged Users Who Need It
|
| Annex A 8.3 Restrict access to information and assets | Technological controls | - ISM-0133Partially overlaps
Responding to Data Spills by Restricting Access - ISM-0217Partially meets
Secure Separation of Non-TOP SECRET and TOP SECRET Panels - ISM-0267Partially meets
Blocking Access to Unapproved Webmail Services - ISM-0343Partially meets
Disabling Unnecessary Access to Removable Media - ISM-0382Partially meets
Restrict Unprivileged User Actions on Applications - ISM-0409Partially meets
Restrict Foreign Nationals' Access to Sensitive Data - ISM-0411Partially meets
Restrict System Access for Foreign Nationals - ISM-0428Supports
Enforcement of Secure Session Locking Measures - ISM-0441Broader than
Restricting Temporary System Access to Data Required for Duties - ISM-0443Partially meets
Restrict Temporary Access to Secure Systems - ISM-0462Partially overlaps
Managing Encryption Access for IT Equipment and Media - ISM-0485Supports
Use Public Key Authentication for SSH Access - ISM-0488Partially meets
Use Forced Commands for SSH Without Passwords - ISM-0520Broader than
Prevent Unauthorised Network Device Connections - ISM-0530Partially meets
Administer VLANs from Trusted Security Domains - ISM-0551Broader than
Ensure Secure IP Telephony Device Authentication - ISM-0555Broader than
Ensure Authentication for IP Telephony Actions - ISM-0558Partially meets
Restrict IP Phone Network Access in Public Areas - ISM-0611Partially meets
Restrict Privileges for Gateway Administrators - ISM-0622Partially meets
Ensuring Network Authentication via Gateways - ISM-0694Partially meets
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0854Partially meets
Access Restrictions for AUSTEO and AGAO Data - ISM-0870Depends on
Secure Storage and Handling of Mobile Devices - ISM-1006Partially meets
Prevent Unauthorised Access to Network Traffic - ISM-1175Broader than
Restrict Privileged Users from Internet Access - ISM-1249Partially meets
Limit Server Application User Privileges - ISM-1250Partially meets
Limit Server Application User Account Privileges - ISM-1255Broader than
Restrict Database User Access Based on Duties - ISM-1256Partially meets
Implement File-Based Access Controls for Databases - ISM-1268Broader than
Enforce Need-to-Know Access in Databases - ISM-1323Partially meets
Requiring Certificates for Wireless Network Access - ISM-1327Broader than
Secure Certificates for Network Authentication - ISM-1386Partially meets
Restrict Network Management Traffic Origin - ISM-1392Partially meets
Restrict File Modifications via Path Rules - ISM-1403Partially meets
Lock Accounts After Five Failed Logon Attempts - ISM-1422Broader than
Prevent Unauthorised Access to Software Source - ISM-1439Broader than
Restrict IP Disclosure in CDNs - ISM-1449Supports
Protect SSH Private Keys with Passwords or Encryption - ISM-1487Broader than
Restrict Write Access to Trusted Locations to Macro Vetting Users - ISM-1508Broader than
Restricting Privileged Access to What Duties Require - ISM-1604Partially meets
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1611Partially meets
Use Break Glass Accounts Only in Emergencies - ISM-1612Partially meets
Restricted Use of Break Glass Accounts for Emergencies - ISM-1649Partially meets
Implement Just-in-Time Administration for System Access - ISM-1705Partially meets
Restrict Access to User Account Backups - ISM-1812Partially meets
Restrict Backup Access to Unprivileged Users - ISM-1813Partially meets
Prevent Unauthorised User Access to Backup Data - ISM-1814Partially meets
Prevent Backup Modifications by Unprivileged Users - ISM-1815Partially meets
Protect Event Logs from Unauthorised Access - ISM-1816Supports
Prevent Unauthorised Changes to Software Sources - ISM-1817Partially meets
Secure API Access with Authentication and Authorisation - ISM-1833Partially overlaps
Limit Privileges for User Accounts in Active Directory - ISM-1838Supports
Restrict UserPassword Attribute in AD Accounts - ISM-1839Partially meets
Secure Account Properties in Active Directory - ISM-1841Partially meets
Restrict Domain Joining to Admin Users Only - ISM-1846Partially meets
Restrict Pre-Windows 2000 Access Group Membership - ISM-1852Broader than
Limit Unprivileged Access to What Duties Require - ISM-1854Broader than
Human Users Authenticate to MFDs Before Printing, Scanning or Copying - ISM-1862Broader than
Restrict Access and Conceal Web Server IP Addresses - ISM-1866Partially overlaps
Prevent Storing Classified Data on Privately Owned Devices - ISM-1888Supports
Ensure Mobile Devices Have Secure Lock Screens - ISM-1927Partially meets
Restrict Access to Microsoft Active Directory Servers - ISM-1933Partially meets
Restrict DCSync Permissions on Service Accounts - ISM-1936Partially meets
Prevent Usage of sIDHistory in User Accounts - ISM-1985Partially meets
Protect Event Logs from Unauthorised Access - ISM-2009Partially meets
Restrict Medical Devices in SECRET and TOP SECRET Areas - ISM-2014Partially meets
Ensure API Client Authentication and Authorisation - ISM-2046Supports
Ensure Secure Impersonation Logging Practices - ISM-2048Partially meets
Restrict Non-Admins from Changing Permissions - ISM-2092Partially meets
Enforce Fine-Grained Permissions for AI Applications - ISM-2093Broader than
Role-Based Access Controls in AI Applications - ISM-2095Broader than
Block Personal Devices Granting AI Agents Access to Sensitive Systems - ISM-2124Broader than
Restricting Service Provider Access to Approved Tools, Addresses and Time Windows - ISM-2136Depends on
Enforcing Risk-Based Access Decisions Informed by Contextual Signals - ISM-2137Broader than
Block User OAuth Consent, Reserve It for Authorised Administrators - ISM-2156Broader than
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions - ISM-2157Broader than
Agentic AI Tool Calls Limited by User Access and Task-Scoped Authorisation
|
| Annex A 8.4 Access management for source code and tools | Technological controls | - ISM-0405Supports
Validation for Unprivileged System Access Requests - ISM-0414Depends on
Uniquely Identifying Every User Granted System Access - ISM-0415Depends on
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0430Supports
Immediate Suspension of Unneeded System Access - ISM-0441Partially overlaps
Restricting Temporary System Access to Data Required for Duties - ISM-1419Supports
Software Development in Development Environments - ISM-1422Broader than
Prevent Unauthorised Access to Software Source - ISM-1746Partially overlaps
Restrict File System Permission Changes - ISM-1780Depends on
Apply SecDevOps for Secure Software Development - ISM-1845Supports
Disable User Security Group Access in Active Directory - ISM-2024Supports
Utilise Authoritative Sources in Software Development - ISM-2033Supports
Document and Maintain Software Security Requirements - ISM-2048Supports
Restrict Non-Admins from Changing Permissions
|
| Annex A 8.5 Secure authentication technologies and procedures | Technological controls | - ISM-0417Partially meets
Use Passwords When Multi-Factor Authentication Isn't Supported - ISM-0418Partially overlaps
Keep Physical Credentials Separate from Systems - ISM-0421Broader than
Require Minimum 15-Character Passwords for Security - ISM-0428Supports
Enforcement of Secure Session Locking Measures - ISM-0484Partially meets
Configure SSH for Secure Server Access - ISM-0485Broader than
Use Public Key Authentication for SSH Access - ISM-0488Partially meets
Use Forced Commands for SSH Without Passwords - ISM-0520Depends on
Prevent Unauthorised Network Device Connections - ISM-0551Broader than
Ensure Secure IP Telephony Device Authentication - ISM-0554Partially meets
Secure Two-Way Authentication for Video Calls - ISM-0590Broader than
Ensure Strong Authentication for Multi-Function Devices - ISM-0619Partially meets
User Authentication for Network Gateway Access - ISM-0622Broader than
Ensuring Network Authentication via Gateways - ISM-0974Partially meets
Implement Multi-factor Authentication for User Access - ISM-1014Broader than
Implement Individual Logins for Secure IP Phone Use - ISM-1034Partially meets
Deploy HIPS or EDR on Critical and High-Value Servers - ISM-1055Broader than
Disable Insecure LAN Manager Authentication - ISM-1151Broader than
Verify Email Authenticity Using SPF - ISM-1173Partially meets
Use Multi-Factor Authentication for Privileged Users - ISM-1200Partially overlaps
Secure Bluetooth Pairing for Mobile Devices - ISM-1321Partially meets
Implement EAP-TLS for Secure Wireless Authentication - ISM-1322Partially meets
Assessing 802.1X Components in Wireless Networks - ISM-1323Broader than
Requiring X.509 Certificates for 802.1X Network Authentication - ISM-1324Depends on
Generating X.509 Certificates With Evaluated CA or HSM - ISM-1327Partially overlaps
Secure Certificates for Network Authentication - ISM-1330Broader than
Limit PMK Caching Duration on Wireless Networks - ISM-1504Broader than
Multi-Factor Authentication for Human Users of Sensitive Data Online Services - ISM-1505Partially meets
Implement Multi-factor Authentication for Data Repositories - ISM-1546Broader than
Ensure User Authentication Before System Access - ISM-1558Broader than
Ensure Secure Construction of Passwords - ISM-1559Broader than
Minimum Password Length for Secure Systems - ISM-1560Broader than
Ensure Strong Passwords for SECRET System Authentication - ISM-1603Broader than
Disabling Vulnerable Authentication Methods - ISM-1679Broader than
Multi-factor Authentication for Third-party Services Handling Sensitive Data - ISM-1680Partially meets
Use Multi-Factor Authentication for Online Services - ISM-1681Broader than
Mandating Multi-Factor Authentication for Customer Services - ISM-1682Broader than
Phishing-resistant multi-factor authentication for human users of systems - ISM-1711Broader than
Ensure User Identity Confidentiality in EAP-TLS - ISM-1817Broader than
Secure API Access with Authentication and Authorisation - ISM-1818Broader than
Client Authentication for Network API Access - ISM-1836Partially meets
Require Kerberos Pre-Authentication for User Accounts - ISM-1854Partially meets
Require User Authentication for Multifunction Devices - ISM-1872Broader than
Ensuring Phishing-Resistant Multi-Factor Authentication - ISM-1874Partially meets
Phishing-Resistant Multi-Factor Authentication for Customers - ISM-1892Broader than
Multi-Factor Authentication for Organisation Users of Online Customer Services - ISM-1893Partially meets
Enforcing Multi-Factor Authentication for User Security - ISM-1894Partially meets
Ensuring Phishing-Resistant Multi-factor Authentication - ISM-1919Broader than
Disable Authentication Protocols That Cannot Support Multi-Factor Authentication - ISM-1920Partially meets
Prevent Self-enrollment on Untrusted Devices - ISM-1929Partially meets
Ensure LDAP Signing on AD DS Domain Controllers - ISM-1943Broader than
Enforce Certificate and User Mapping in AD Services - ISM-1947Broader than
Remove User Authentication from Extended Key Usages - ISM-2009Partially meets
Restrict Medical Devices in SECRET and TOP SECRET Areas - ISM-2011Broader than
Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used - ISM-2012Partially overlaps
Enforced Screen Lock With Full Re-Authentication After Inactivity - ISM-2013Broader than
Ensure Client Authentication for Internal Network APIs - ISM-2014Broader than
Ensure API Client Authentication and Authorisation - ISM-2047Broader than
Notify Users of Authentication Resets via Secondary Channel - ISM-2049Partially overlaps
Enforcing Re-authentication After Permission Changes - ISM-2076Broader than
Eliminating Security Questions for Authentication - ISM-2077Broader than
Avoid Email for Out-of-Band Authentication - ISM-2081Broader than
Enforce Use of All ASCII Characters in Passwords - ISM-2092Depends on
Enforce Fine-Grained Permissions for AI Applications - ISM-2109Broader than
Pre-Boot Authentication for Encrypted System Volume Media - ISM-2126Depends on
Positively Identify Requestors Before Actioning Account, Banking or Payment Requests - ISM-2140Broader than
Disable OAuth Device Code Flow Unless Required and Restrict Its Use - ISM-2147Broader than
Cryptographically Bind Tokens and Session Cookies to Issuing Device - ISM-2165Broader than
Fresh EAP-TLS Authentication for Each New Connectivity Association Key - ISM-2167Broader than
Disabling Pre-Shared Key Fallback Authentication for MACsec
|
| Annex A 8.6 Capacity Management for Resource Use | Technological controls | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-0518Supports
Maintain Comprehensive Network Documentation - ISM-1431Partially overlaps
Strategies for Mitigating Denial-of-Service Attacks - ISM-1579Partially overlaps
Dynamic Resource Scaling for Demand Spikes - ISM-1581Partially overlaps
Monitor Capacity and Availability of Online Services - ISM-2090Supports
Rate Limiting for AI Inference Queries - ISM-2091Broader than
Enforce Resource Limits for AI Models - ISM-2114Partially overlaps
Monitor Baselines for AI Application Performance
|
| Annex A 8.7 Protection against malware | Technological controls | - ISM-0263Depends on
Inspect and Decrypt TLS Traffic through Gateways - ISM-0651Broader than
Block Malicious or Uninspectable Files - ISM-0652Broader than
Quarantine Suspicious Files for Review - ISM-0657Broader than
Scanning Data for Threats Before Manual Import - ISM-0917Partially overlaps
Procedures for Handling Malicious Code Infections - ISM-1234Broader than
Protect Email Systems with Content Filtering - ISM-1287Depends on
Ensure Gateway and CDS File Content Sanitisation - ISM-1288Broader than
Antivirus Scanning of Gateway Files - ISM-1289Broader than
Unpack Archive Files for Content Filtering at Gateways - ISM-1290Supports
Controlled Unpacking of Archive Files for Filtering - ISM-1299Depends on
Personnel Awareness for Secure Mobile Device Usage - ISM-1341Broader than
Implement HIPS or EDR on Workstations - ISM-1389Broader than
Analyse Executable Files in Sandboxes - ISM-1417Partially meets
Ensure Antivirus Protection on Workstations and Servers - ISM-1486Broader than
Restrict Java Processing in Web Browsers - ISM-1565Depends on
Annual Tailored Training for All Privileged Access Holders - ISM-1608Broader than
Scan Third-Party SOEs for Malicious Code - ISM-1659Supports
Implement Microsoft's Vulnerable Driver Blocklist - ISM-1672Broader than
Enable Antivirus Scanning for Office Macros - ISM-1745Partially overlaps
Enable Security Features for System Protection - ISM-1782Depends on
Use Protective DNS to Block Malicious Domains - ISM-1890Broader than
Ensure Macros Are Free of Malicious Code - ISM-1969Broader than
Preventing Accidental Execution of Malicious Code - ISM-2026Broader than
Scan Software Artefacts for Malicious Content
|
| Annex A 8.8 Management of Technical Vulnerabilities | Technological controls | - ISM-0290Depends on
Secure Configuration of High Assurance IT Equipment - ISM-0298Broader than
Centralised System Patch and Update Management - ISM-0300Broader than
Apply System Security Patches with Approval - ISM-0912Partially overlaps
Establish and Manage System Configuration Changes - ISM-1143Depends on
Develop and Maintain Patch Management Procedures - ISM-1163Partially overlaps
Continuous Monitoring Plan to Find and Fix Vulnerabilities - ISM-1211Depends on
System Administration Performed Under Change and Configuration Management Plan - ISM-1246Depends on
Apply Strict Server Application Hardening Guidelines - ISM-1316Broader than
Ensure Default Wireless SSIDs Are Changed - ISM-1366Broader than
Ensure Timely Security Updates for Mobile Devices - ISM-1424Depends on
Ensure Web Security Through Response Headers - ISM-1483Depends on
Use Latest Release of Internet-Facing Server Applications - ISM-1501Broader than
Replace Unsupported Operating Systems - ISM-1526Partially overlaps
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1585Depends on
Lock Web Browser Security Settings Against Human User Changes - ISM-1605Depends on
Harden the Operating System Beneath Software Isolation Mechanisms - ISM-1606Broader than
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1616Partially overlaps
Implementing a Vulnerability Disclosure Program - ISM-1622Broader than
Ensure PowerShell Uses Constrained Language Mode - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1635Partially meets
System Owners Implement Security Controls for Each System and Environment - ISM-1643Depends on
Maintain Detailed Software Version and Patch Records - ISM-1659Supports
Implement Microsoft's Vulnerable Driver Blocklist - ISM-1690Broader than
Timely Application of Non-Critical Vulnerability Patches - ISM-1691Broader than
Timely Vulnerability Patching in Software Tools - ISM-1692Broader than
Quick Apply Critical Patches for Vulnerabilities - ISM-1693Broader than
Timely Application of Patches to Mitigate Vulnerabilities - ISM-1694Broader than
Timely Application of Non-Critical Security Patches - ISM-1695Broader than
Timely Application of System Security Patches - ISM-1696Broader than
Apply Critical Patches Within 48 Hours - ISM-1697Broader than
Apply Non-Critical Patches Within One Month - ISM-1698Broader than
Daily Vulnerability Scanning for Missing Updates - ISM-1701Broader than
Daily Vulnerability Scanning for Internet-Facing Systems - ISM-1702Broader than
Regularly Scan for Missing Security Patches - ISM-1703Partially meets
Regular Vulnerability Scanning for Missing Patches - ISM-1704Depends on
Remove Unsupported Software to Ensure Security - ISM-1717Partially overlaps
Implement Security.txt for Vulnerability Disclosure - ISM-1745Depends on
Enable Security Features for System Protection - ISM-1751Broader than
Timely Application of Vendor Patches for Non-Critical OS Vulnerabilities - ISM-1752Broader than
Fortnightly Vulnerability Scanning for Non-Workstations - ISM-1754Broader than
Timely Resolution of Identified Software Vulnerabilities - ISM-1755Depends on
Develop and Maintain a Vulnerability Disclosure Policy - ISM-1756Partially overlaps
Develop and Maintain Vulnerability Disclosure Processes - ISM-1808Broader than
Vulnerability Scanning with Updated Tools - ISM-1809Partially overlaps
Implement Compensating Controls for Unsupported Systems - ISM-1829Broader than
Prevent Password Storage in Group Policy Preferences - ISM-1848Depends on
Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources - ISM-1876Partially meets
Apply Critical Patches Within 48 Hours - ISM-1877Broader than
Timely Application of Critical Security Patches - ISM-1878Broader than
Apply Critical Patches Within 48 Hours - ISM-1879Broader than
Timely Patching of Critical Driver Vulnerabilities - ISM-1900Broader than
Fortnightly System Vulnerability Scanning - ISM-1901Broader than
Timely Application of Non-Critical Security Patches - ISM-1903Broader than
Rapid Application of Critical Firmware Patches - ISM-1904Broader than
Apply Firmware Patches for Non-Critical Vulnerabilities - ISM-1905Partially meets
Remove Online Services No Longer Supported by Vendors - ISM-1913Partially overlaps
Develop and Maintain Approved IT Configurations - ISM-1914Partially meets
Ensure Operating Systems Have Approved Configurations - ISM-1915Partially meets
Ensure User Application Configurations are Approved - ISM-1916Partially meets
Ensure Server Application Configurations Are Approved - ISM-1931Supports
Ensure SID Filtering for Domain and Forest Trusts - ISM-1956Depends on
Regularly Update AD FS Certificates to Prevent Risks - ISM-2054Partially meets
Ensure No Vulnerabilities in Third-Party Software Components - ISM-2118Broader than
Conduct Vulnerability Assessments and Penetration Tests - ISM-2119Depends on
Utilise AI Models in Vulnerability Assessments and Penetration Tests - ISM-2131Partially overlaps
Quarterly Certificate Template Reviews to Remediate Misconfigurations - ISM-2161Depends on
Verify Network Device Firmware and Configuration Against Known-Good Baseline
|
| Annex A 8.9 Configuration Management for Secure IT Systems | Technological controls | - ISM-0042Partially overlaps
Maintain Effective System Administration Practices - ISM-0211Supports
Develop and Verify a Cable Register - ISM-0272Broader than
Restrict Protective Marking Tools to Authorised System Markings - ISM-0289Partially overlaps
Implement and Manage Evaluated Products Correctly - ISM-0290Partially overlaps
Secure Configuration of High Assurance IT Equipment - ISM-0341Partially meets
Disable Automatic Execution for Removable Media - ISM-0380Partially meets
Disable Unneeded OS Accounts and Services - ISM-0383Partially meets
Change Default OS User Accounts During Setup - ISM-0481Supports
Ensure Use of High Assurance Cryptographic Protocols - ISM-0484Partially meets
Configure SSH for Secure Server Access - ISM-0487Partially meets
Disable Certain Features for Passwordless SSH Logins - ISM-0498Broader than
Ensure Short Lifetimes for IPsec Associations - ISM-0516Supports
Comprehensive Network Diagrams for Critical Components - ISM-0518Supports
Maintain Comprehensive Network Documentation - ISM-0530Supports
Administer VLANs from Trusted Security Domains - ISM-0567Partially meets
Restrict Email Relay to Specific Domains - ISM-0570Partially meets
Maintain Backup Email Gateways to Primary Standards - ISM-0574Partially meets
Use SPF to Authorise Email Servers - ISM-0589Partially overlaps
Limit Document Sensitivity on MFDs Based on Network Classification - ISM-0591Supports
Use Evaluated Peripheral Switches Securely - ISM-0864Partially meets
Prevent Modifications to Security Settings on Mobile Devices - ISM-0912Partially overlaps
Establish and Manage System Configuration Changes - ISM-1027Partially meets
Configure Email Distribution Lists to Preserve DKIM Signatures - ISM-1034Partially meets
Deploy HIPS or EDR on Critical and High-Value Servers - ISM-1037Partially meets
Regular Testing of Gateway Security Configurations - ISM-1055Partially meets
Disable Insecure LAN Manager Authentication - ISM-1183Partially meets
Implement Hard Fail SPF Records for Email Security - ISM-1196Partially meets
Keep Mobile Devices Undiscoverable via Bluetooth - ISM-1211Partially meets
System Admin Activities Follow Change Management Plan - ISM-1260Partially meets
Secure Server Applications by Changing Default Credentials - ISM-1272Partially meets
Disable Database Networking for Local Access - ISM-1277Depends on
Encrypt Database and Web Server Communications - ISM-1304Partially meets
Secure Network Devices by Changing Default Credentials - ISM-1311Partially meets
Prevent Use of Insecure SNMP Versions on Networks - ISM-1312Partially meets
Changing Default SNMP Community Strings on Devices - ISM-1316Partially meets
Ensure Default Wireless SSIDs Are Changed - ISM-1319Partially meets
Avoid Static IP Addressing on Wireless Networks - ISM-1369Partially meets
Ensure TLS Connections Use AES-GCM Encryption - ISM-1406Broader than
Use SOEs for Workstations and Servers - ISM-1408Broader than
Use 64-bit Operating Systems - ISM-1409Partially meets
Implement Restrictive OS Hardening Guidelines - ISM-1419Supports
Software Development in Development Environments - ISM-1428Partially meets
Disable IPv6 Tunnelling Unless Necessary - ISM-1439Depends on
Restrict IP Disclosure in CDNs - ISM-1450Supports
Restricting Devices in Top Secret Areas - ISM-1489Depends on
Lock Microsoft Office Macro Security Settings Against User Changes - ISM-1493Supports
Maintain and Verify Software Registers - ISM-1536Partially meets
Centrally Log User-Initiated Database Queries and Errors - ISM-1540Partially meets
Configuring DMARC for Email Security - ISM-1552Depends on
Secure Web Content with HTTPS Only - ISM-1562Partially meets
Secure Video Conferencing and Telephony Systems - ISM-1585Broader than
Lock Web Browser Security Settings Against Human User Changes - ISM-1588Partially meets
Annual Review of Standard Operating Environments - ISM-1598Partially meets
Inspect IT Equipment Post-Maintenance for Unauthorised Changes - ISM-1604Partially meets
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1605Depends on
Harden the Operating System Beneath Software Isolation Mechanisms - ISM-1608Partially overlaps
Scan Third-Party SOEs for Malicious Code - ISM-1619Supports
Configure Service Accounts as Managed Service Accounts - ISM-1622Partially meets
Ensure PowerShell Uses Constrained Language Mode - ISM-1627Depends on
Block Inbound Traffic from Anonymity Networks - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1635Broader than
Ensure Security Controls for System Environments - ISM-1646Supports
Detail Cabling Paths and Points on Floor Plans - ISM-1669Partially meets
Prevent Microsoft Office from Injecting Code - ISM-1673Partially meets
Prevent Win32 API Calls by Office Macros - ISM-1696Supports
Apply Critical Patches Within 48 Hours - ISM-1710Partially meets
Secure Default Settings for Wireless Access Points - ISM-1730Supports
Provide a Software Bill of Materials to Consumers - ISM-1798Supports
Develop Secure Configuration Guidelines for Software - ISM-1806Partially meets
Change Default User Credentials During Setup - ISM-1809Depends on
Compensating Controls for Unsupported Systems Pending Removal or Replacement - ISM-1823Partially meets
Prevent Users from Changing Security Settings in Apps - ISM-1824Partially meets
Prevent Changes to PDF Application Security Settings - ISM-1825Partially meets
Ensure Security Configuration Is Immutable by Users - ISM-1828Partially meets
Disable Print Spooler on AD DS Domain Controllers - ISM-1832Partially meets
SPN Configuration for Active Directory Accounts - ISM-1834Partially meets
Ensure No Duplicate SPNs in Active Directory - ISM-1838Partially meets
Restrict UserPassword Attribute in AD Accounts - ISM-1860Partially meets
Harden PDF Applications Using ASD Guidance - ISM-1887Partially meets
Implement Remote Locate and Wipe for Mobile Security - ISM-1888Supports
Ensure Mobile Devices Have Secure Lock Screens - ISM-1912Partially overlaps
Document Device Settings for Critical and High-Value Servers - ISM-1913Equivalent
Develop and Maintain Approved IT Configurations - ISM-1914Broader than
Ensure Operating Systems Have Approved Configurations - ISM-1915Partially meets
Ensure User Application Configurations are Approved - ISM-1916Broader than
Ensure Server Application Configurations Are Approved - ISM-1926Partially meets
Ensure Exclusive Usage of Microsoft AD Servers - ISM-1931Partially meets
Ensure SID Filtering for Domain and Forest Trusts - ISM-1935Partially meets
Prevent Unconstrained Delegation in Domain Services - ISM-1944Broader than
Remove EDITF_ATTRIBUTESUBJECTALTNAME2 Flag From AD CS Certification Authorities - ISM-1951Partially meets
Disable Hard Match Takeover in Microsoft Entra Connect - ISM-1956Partially meets
Regularly Update AD FS Certificates to Prevent Risks - ISM-1981Supports
Replace Unsupportable Non-Internet Network Devices - ISM-2025Supports
Using Issue Tracking for Software Development Tasks - ISM-2031Supports
Secure System Build Tools Implementation - ISM-2033Supports
Document and Maintain Software Security Requirements - ISM-2045Supports
Ensure Backwards Compatibility Doesn't Weaken Security - ISM-2084Supports
Document AI Model and System Characteristics - ISM-2113Depends on
Configuring AI Applications to Require Human Approval Before High-Impact Actions - ISM-2127Broader than
Enforce Driver Digital Signature Verification Before Loading - ISM-2130Broader than
Disabling or Hardening AD CS Web Enrolment Interfaces - ISM-2131Broader than
Quarterly Certificate Template Reviews to Remediate Misconfigurations - ISM-2161Depends on
Verify Network Device Firmware and Configuration Against Known-Good Baseline - ISM-2162Broader than
Disabling or Removing Unneeded Network Device Components and Services - ISM-2167Broader than
Disabling Pre-Shared Key Fallback Authentication for MACsec
|
| Annex A 8.10 Secure deletion of information when no longer needed | Technological controls | - ISM-0307Partially overlaps
Sanitise Equipment When Not Using Cleared Technician - ISM-0311Partially overlaps
Ensuring Sanitisation of IT Equipment Media - ISM-0317Broader than
Ensuring Data Erasure on Printer Cartridges and Drums - ISM-0330Partially overlaps
Proper Sanitisation and Reclassification of Media - ISM-0348Supports
Develop and Maintain Media Sanitisation Procedures - ISM-0351Broader than
Proper Method for Volatile Media Sanitisation - ISM-0357Partially meets
Sanitising Non-volatile EPROM Media - ISM-0359Partially meets
Proper Sanitisation of Non-Volatile Flash Memory - ISM-0361Supports
Using Degaussers for Magnetic Media Destruction - ISM-0362Supports
Follow Manufacturer's Directions for Degaussing - ISM-0363Depends on
Develop and Maintain Media Destruction Processes - ISM-0371Partially overlaps
Ensure Proper Supervision of Media Destruction - ISM-0375Partially overlaps
Decide on Public Release of Data Storage Media - ISM-0835Partially overlaps
TOP SECRET Volatile Media Retains Classification After Sanitisation - ISM-0947Broader than
Sanitise Media After Data Transfers Between Domains - ISM-1065Supports
Reset Device Settings Before Media Sanitisation - ISM-1160Broader than
Use NSA-evaluated Degaussers for Media Destruction - ISM-1221Partially meets
Check Printers and MFDs for Trapped Pages - ISM-1223Broader than
Methods for Sanitising Network Device Memory - ISM-1574Partially overlaps
Data Portability in Service Contracts - ISM-1600Partially overlaps
Ensure Media is Sanitised Before Initial Use - ISM-1722Partially meets
Methods for Destroying Electrostatic Memory Devices - ISM-1723Partially meets
Methods for Destroying Magnetic Floppy Disks - ISM-2021Broader than
Implement and Maintain Data Minimisation Practices - ISM-2053Partially overlaps
End of Life Procedures for Software - ISM-2111Broader than
Remove Temporary Installation Files Post-Installation - ISM-2123Broader than
Delete AI Chat Session Prompts and Outputs
|
| Annex A 8.11 Data Masking for Sensitive Information | Technological controls | |
| Annex A 8.12 Data Leakage Prevention Measures | Technological controls | - ISM-0240Broader than
Prevent Sensitive Data in Messaging Services - ISM-0267Supports
Blocking Access to Unapproved Webmail Services - ISM-0325Depends on
Reclassify Media to Higher Sensitivity - ISM-0565Broader than
Email Security for Protective Markings - ISM-0589Partially meets
Limit Document Sensitivity on MFDs Based on Network Classification - ISM-0591Depends on
Use Evaluated Peripheral Switches Securely - ISM-0639Depends on
Use Evaluated Firewalls Between Security Domains - ISM-0659Partially overlaps
Filtering Content of Gateway and CDS Files - ISM-0661Partially overlaps
User Accountability for Data Transfers - ISM-0664Partially overlaps
Authorisation of Secret Data Exports - ISM-0669Partially overlaps
Security Measures for Manual Data Export - ISM-0682Broader than
Disable Bluetooth on SECRET/TS Mobile Devices - ISM-1024Supports
Verify Senders for Email Failure Notifications - ISM-1085Supports
Encrypt Sensitive Data Over Public Networks - ISM-1089Depends on
Block Downgrading Protective Markings on Email Replies and Forwards - ISM-1187Partially overlaps
Check Data for Improper Markings Before Export - ISM-1192Partially overlaps
Inspecting and Filtering Data with Gateways - ISM-1293Supports
Decrypt Encrypted Files for Content Filtering - ISM-1299Supports
Personnel Awareness for Secure Mobile Device Usage - ISM-1400Depends on
Enforce Data Separation on Personal Devices - ISM-1429Depends on
Block IPv6 Tunnelling at Externally Connected Network Boundaries - ISM-1482Supports
Ensure Separation of Classified and Personal Data on Devices - ISM-1534Broader than
Remove and Destroy Printer and MFD Ribbons - ISM-1535Partially overlaps
Prevent Unsuitable Foreign Data Exports - ISM-1565Depends on
Annual Tailored Training for All Privileged Access Holders - ISM-1778Depends on
Quarantine Security-Noncompliant Data for Review - ISM-1866Broader than
Prevent Storing Classified Data on Privately Owned Devices - ISM-1868Depends on
Restrictions on Mobile Device Removable Media - ISM-1875Broader than
Monthly System Scans to Detect Credentials Stored in the Clear - ISM-1885Partially overlaps
Implement Emanation Security Measures for Systems - ISM-1924Supports
Detect and Mitigate Adversarial Prompts in Generative AI Applications - ISM-1930Depends on
Prevent Storing Passwords in Group Policy Preferences - ISM-1965Supports
Content Checking for Imported or Exported Files - ISM-2052Partially overlaps
Ensure Event Logs Protect Sensitive Data - ISM-2094Broader than
AI Content Filtering to Block Sensitive Data Exposure
|
| Annex A 8.13 Backup and Recovery Procedures for Data | Technological controls | - ISM-0042Partially meets
Maintain Effective System Administration Practices - ISM-0917Partially overlaps
Procedures for Handling Malicious Code Infections - ISM-1511Partially overlaps
Conduct and Maintain Regular Data Backups - ISM-1515Broader than
Test Backup Restoration During Disaster Recovery - ISM-1547Partially overlaps
Develop and Maintain Data Backup Procedures - ISM-1548Partially overlaps
Develop and Maintain Data Restoration Processes - ISM-1555Partially meets
Prepare Mobile Devices Before Overseas Travel - ISM-1574Depends on
Data Portability in Service Contracts - ISM-1705Supports
Restrict Access to User Account Backups - ISM-1732Depends on
Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise - ISM-1810Broader than
Ensuring Data Backup Synchronisation - ISM-1928Broader than
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-2151Broader than
Technically Enforced Immutability Protecting Backups Through Their Retention Period
|
| Annex A 8.14 Redundancy of Information Processing Facilities | Technological controls | |
| Annex A 8.15 Logging of Activities and Events | Technological controls | - ISM-0138Depends on
Maintaining Integrity of Evidence in Investigations - ISM-0261Broader than
Log Web Proxy Activity for Security Analysis - ISM-0415Depends on
Strictly Controlling Shared Accounts and Identifying Their Users - ISM-0565Broader than
Email Security for Protective Markings - ISM-0580Partially overlaps
Develop, Implement and Maintain a Security Monitoring Policy - ISM-0582Broader than
Central Logging of Windows Security Events - ISM-0585Broader than
Capture Detailed Information in Event Logs - ISM-0634Broader than
Central Logging for Gateway Security Events - ISM-0661Supports
Holding Human Users Accountable for Data Transfers They Perform - ISM-0670Broader than
Central Logging of CDS Security Events - ISM-0988Supports
Ensure Accurate Time Source for Event Logs - ISM-1030Broader than
Deploy NIDS/NIPS for Gateway Traffic Monitoring - ISM-1213Broader than
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1228Supports
Analyse Cyber Security Events Promptly - ISM-1341Depends on
Implement HIPS or EDR on Workstations - ISM-1405Partially overlaps
Implement a Centralised Event Logging Facility - ISM-1509Broader than
Log Privileged Access Events Centrally for Monitoring - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1536Broader than
Central Logging of Software Database Queries and Errors - ISM-1537Broader than
Log Security-Relevant Database Events Centrally - ISM-1566Broader than
Central Logging of Unprivileged System Access - ISM-1586Broader than
Record All Data Imports and Exports - ISM-1611Depends on
Use Break Glass Accounts Only in Emergencies - ISM-1613Partially meets
Central Logging of Break Glass Account Usage - ISM-1623Broader than
Centralised Logging of PowerShell Activities - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1650Broader than
Log Management of Privileged User Activities - ISM-1683Broader than
Central Logging of Multi-factor Authentication Events - ISM-1805Depends on
Develop a Denial of Service Response Plan - ISM-1830Broader than
Central Logging of Security Events for Microsoft AD Infrastructure Servers - ISM-1855Partially meets
Central Logging of Multifunction Device Use - ISM-1889Broader than
Central Logging of Command Line Events - ISM-1895Broader than
Log Single-factor Authentication Events - ISM-1906Broader than
Timely Analysis of Internet-Facing Server Logs - ISM-1911Broader than
Centralised Logging of Software Errors and Usage - ISM-1937Broader than
Weekly Audit of sIDHistory in User Accounts - ISM-1941Supports
Restrict Computer Accounts in Privileged Security Groups - ISM-1959Broader than
Ensure Consistent Formatting for Event Logs - ISM-1963Broader than
Central Logging of Events on Internet-Facing Devices - ISM-1964Broader than
Central Logging for Network Device Events - ISM-1978Partially meets
Centralised Logging for Server Application Events - ISM-1979Broader than
Central Logging for Security Events on Servers - ISM-1983Broader than
Log Events Sent to Centralised Facility Quickly - ISM-1984Depends on
Encrypt Event Logs in Transit Using ASD Cryptography - ISM-1985Broader than
Protect Event Logs from Unauthorised Access - ISM-1986Broader than
Timely Analysis of Critical Server Event Logs - ISM-1987Broader than
Timely Analysis of Security Event Logs - ISM-1988Broader than
Ensure Event Logs Are Retained for 12 Months - ISM-1989Partially overlaps
Ensure Event Logs Meet Retention Requirements - ISM-2015Broader than
Central Logging of Non-Internet Network API Data Access - ISM-2046Partially overlaps
Ensure Secure Impersonation Logging Practices - ISM-2051Partially meets
Ensure Event Logs for Cyber security Event Detection - ISM-2052Broader than
Ensure Event Logs Protect Sensitive Data - ISM-2089Broader than
Monitor AI Model Performance and Investigate Anomalies - ISM-2094Depends on
AI Content Filtering to Block Sensitive Data Exposure - ISM-2116Depends on
Use Cyber Threat Intelligence for Event Detection - ISM-2117Supports
AI Models Augment Cyber Security Event Detection - ISM-2125Broader than
Independently Log and Analyse All Service Provider System Access - ISM-2129Broader than
Centrally Log WMI Activity and Event Subscriptions - ISM-2132Broader than
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2139Broader than
Central Logging of Third-Party OAuth Consent, Token Issuance and Use - ISM-2153Depends on
Quarterly Threat Hunting Informed by Current Threat Intelligence - ISM-2159Broader than
Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
|
| Annex A 8.16 Monitoring Networks and Systems for Anomalous Behaviour | Technological controls | - ISM-0120Supports
Access to Tools for Detecting Security Events - ISM-0261Depends on
Log Web Proxy Activity for Security Analysis - ISM-0263Depends on
Inspect and Decrypt TLS Traffic through Gateways - ISM-0582Partially meets
Central Logging of Windows Security Events - ISM-0585Depends on
Capture Detailed Information in Event Logs - ISM-0634Depends on
Central Logging for Gateway Security Events - ISM-0652Partially overlaps
Quarantine Suspicious Files for Review - ISM-1028Depends on
Use NIDS/NIPS for Gateway Network Security - ISM-1030Broader than
Deploy NIDS/NIPS for Gateway Traffic Monitoring - ISM-1213Broader than
Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed - ISM-1341Depends on
Implement HIPS or EDR on Workstations - ISM-1430Depends on
Configure IPv6 Addresses with DHCPv6 in Stateful Mode - ISM-1431Partially overlaps
Strategies for Mitigating Denial-of-Service Attacks - ISM-1526Depends on
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls - ISM-1537Depends on
Log Security-Relevant Database Events Centrally - ISM-1556Depends on
Security Measures After Overseas Travel with Mobile Devices - ISM-1566Depends on
Central Logging of Unprivileged System Access - ISM-1607Broader than
Integrity Monitoring and Logging for Isolation Mechanism - ISM-1650Depends on
Log Management of Privileged User Activities - ISM-1830Depends on
Central Logging of Security Events for Microsoft AD Infrastructure Servers - ISM-1889Depends on
Central Logging of Command Line Events - ISM-1911Depends on
Centralised Logging of Software Errors and Usage - ISM-1924Depends on
Detect and Mitigate Adversarial Prompts in Generative AI Applications - ISM-1963Depends on
Central Logging of Events on Internet-Facing Devices - ISM-1970Depends on
Segregated Environment for Malicious Code Analysis - ISM-1976Broader than
Central Logging of Security Events on macOS - ISM-1978Partially meets
Centralised Logging for Server Application Events - ISM-1979Partially meets
Central Logging for Security Events on Servers - ISM-1987Partially overlaps
Timely Analysis of Security Event Logs - ISM-2015Depends on
Central Logging of Non-Internet Network API Data Access - ISM-2051Depends on
Ensure Event Logs for Cyber security Event Detection - ISM-2089Broader than
Monitor AI Model Performance and Investigate Anomalies - ISM-2114Broader than
Monitor Baselines for AI Application Performance - ISM-2116Depends on
Use Cyber Threat Intelligence for Event Detection - ISM-2117Depends on
AI Models Augment Cyber Security Event Detection - ISM-2153Depends on
Quarterly Threat Hunting Informed by Current Threat Intelligence
|
| Annex A 8.17 Clock synchronisation for information systems | Technological controls | - ISM-0585Supports
Capture Detailed Information in Event Logs - ISM-0988Partially overlaps
Ensure Accurate Time Source for Event Logs - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2139Depends on
Central Logging of Third-Party OAuth Consent, Token Issuance and Use
|
| Annex A 8.18 Use of Privileged Utility Programs | Technological controls | - ISM-0382Supports
Restrict Unprivileged User Actions on Applications - ISM-0846Supports
Prevent Users Disabling, Bypassing or Exempting Application Control - ISM-1491Partially overlaps
Prevent Script Execution by Unprivileged Users - ISM-1584Depends on
Prevent Unauthorised Changes to Security Settings - ISM-1592Partially overlaps
Prevent Unauthorised Application Installations by Users - ISM-1657Partially overlaps
Restrict Application Execution to Approved Set - ISM-1658Partially overlaps
Restrict Execution of Drivers via Application Control - ISM-1746Depends on
Restrict File System Permission Changes - ISM-1748Depends on
Lock Email Client Security Settings Against User Changes - ISM-2023Supports
Maintain a Reliable Source for Software
|
| Annex A 8.19 Secure Software Installation Procedures | Technological controls | - ISM-0042Partially meets
Maintain Effective System Administration Practices - ISM-0289Partially overlaps
Implement and Manage Evaluated Products Correctly - ISM-0290Supports
Secure Configuration of High Assurance IT Equipment - ISM-0382Broader than
Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications - ISM-0912Partially overlaps
Establish and Manage System Configuration Changes - ISM-1143Partially overlaps
Develop and Maintain Patch Management Procedures - ISM-1211Depends on
System Administration Performed Under Change and Configuration Management Plan - ISM-1245Partially meets
Remove Temporary Files After Server Installation - ISM-1406Partially overlaps
Use SOEs for Workstations and Servers - ISM-1409Partially overlaps
Implement Restrictive OS Hardening Guidelines - ISM-1419Partially overlaps
Software Development in Development Environments - ISM-1493Partially overlaps
Maintain and Verify Software Registers - ISM-1592Partially overlaps
Prevent Unauthorised Application Installations by Users - ISM-1598Depends on
Inspect IT Equipment Post-Maintenance for Unauthorised Changes - ISM-1606Supports
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1608Supports
Scan Third-Party SOEs for Malicious Code - ISM-1635Partially meets
System Owners Implement Security Controls for Each System and Environment - ISM-1655Partially meets
Ensure .NET Framework 3.5 is Disabled or Removed - ISM-1796Supports
Digitally Sign Executable Software for Security - ISM-1797Partially meets
Ensure Software Updates are Securely Signed - ISM-1798Supports
Develop Secure Configuration Guidelines for Software - ISM-1800Partially overlaps
Ensure Network Devices Have Trusted Firmware - ISM-1871Depends on
Implement Application Control Exclusions for System Areas - ISM-1915Partially overlaps
Ensure User Application Configurations are Approved - ISM-1916Supports
Ensure Server Application Configurations Are Approved - ISM-1926Partially meets
Ensure Exclusive Usage of Microsoft AD Servers - ISM-2023Partially overlaps
Maintain a Reliable Source for Software - ISM-2027Supports
Verify Software Artefacts with Digital Signatures - ISM-2044Supports
Prevent Default Credentials in Software Installations - ISM-2045Supports
Ensure Backwards Compatibility Doesn't Weaken Security - ISM-2111Broader than
Remove Temporary Installation Files Post-Installation
|
| Annex A 8.20 Network and Network Devices Security | Technological controls | - ISM-0245Broader than
Prevent MFD Connections to Digital Phone Systems - ISM-0263Broader than
Inspect and Decrypt TLS Traffic through Gateways - ISM-0267Partially meets
Blocking Access to Unapproved Webmail Services - ISM-0467Depends on
Using HACE for Secure Communication of Data - ISM-0469Partially meets
Use Approved Cryptographic Protocols When Encrypting Data In Transit - ISM-0484Broader than
Configure SSH for Secure Server Access - ISM-0494Broader than
Use of IPsec Tunnel and Transport Modes - ISM-0516Supports
Comprehensive Network Diagrams for Critical Components - ISM-0518Supports
Maintain Comprehensive Network Documentation - ISM-0520Broader than
Prevent Unauthorised Network Device Connections - ISM-0529Depends on
Avoid Using VLANs for Different Security Domains - ISM-0530Broader than
Administer VLANs from Trusted Security Domains - ISM-0534Broader than
Disable Unused Network Device Ports - ISM-0548Depends on
Ensure Secure Protocols for Video and IP Calls - ISM-0551Broader than
Ensure Secure IP Telephony Device Authentication - ISM-0558Broader than
Restrict IP Phone Network Access in Public Areas - ISM-0569Broader than
Centralise Email Routing via Gateways - ISM-0572Broader than
Enable Opportunistic TLS for Email Server Encryption - ISM-0622Broader than
Ensuring Network Authentication via Gateways - ISM-0628Broader than
Implementing Secure Network Gateways - ISM-0629Depends on
Manage Gateways Between Different Security Domains - ISM-0631Broader than
Restrict Data Flows with Authorised Gateways - ISM-0639Depends on
Use Evaluated Firewalls Between Security Domains - ISM-0643Broader than
Use of Diodes for Unidirectional Gateway Security - ISM-0694Supports
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0874Broader than
Ensure Internet Access via Organisation's Gateway - ISM-1006Broader than
Prevent Unauthorised Access to Network Traffic - ISM-1028Broader than
Use NIDS/NIPS for Gateway Network Security - ISM-1030Broader than
Deploy NIDS/NIPS for Gateway Traffic Monitoring - ISM-1085Supports
Encrypt Sensitive Data Over Public Networks - ISM-1158Partially meets
High Assurance Evaluation for Network Diodes - ISM-1182Partially meets
Implement Network Traffic Control Measures - ISM-1192Broader than
Inspecting and Filtering Data with Gateways - ISM-1270Partially meets
Separate Network Segments for Database Servers - ISM-1271Broader than
Restrict Network Access to Database Servers - ISM-1272Partially meets
Disable Database Networking for Local Access - ISM-1284Depends on
Ensure Content Validation for Gateway Files - ISM-1286Supports
Ensure Content Conversion at Gateways - ISM-1289Supports
Unpack Archive Files for Content Filtering at Gateways - ISM-1296Partially overlaps
Protect Network Devices in Public Areas - ISM-1297Partially meets
Seek Legal Advice for Personal Device Access - ISM-1304Partially meets
Secure Network Devices by Changing Default Credentials - ISM-1311Broader than
Prevent Use of Insecure SNMP Versions on Networks - ISM-1312Broader than
Changing Default SNMP Community Strings on Devices - ISM-1314Broader than
Ensure Wireless Devices are Wi-Fi Alliance Certified - ISM-1315Partially meets
Disable Wireless Network Administrative Interfaces - ISM-1316Broader than
Ensure Default Wireless SSIDs Are Changed - ISM-1317Partially meets
Secure Naming of Non-Public Wireless Networks - ISM-1318Partially meets
Keep SSID Broadcasting Enabled on Wireless Access Points - ISM-1319Partially meets
Avoid Static IP Addressing on Wireless Networks - ISM-1320Broader than
Avoid Using MAC Filtering for Wireless Access Control - ISM-1321Partially meets
Implement EAP-TLS for Secure Wireless Authentication - ISM-1322Partially meets
Assessing 802.1X Components in Wireless Networks - ISM-1323Depends on
Requiring X.509 Certificates for 802.1X Network Authentication - ISM-1330Broader than
Limit PMK Caching Duration on Wireless Networks - ISM-1332Broader than
Ensure Wireless Traffic is Secure with WPA3-Enterprise - ISM-1334Broader than
Ensure Frequency Separation in Wireless Networks - ISM-1335Broader than
Enabling 802.11w to Protect Wireless Management Frames - ISM-1338Partially meets
Use Lower-Powered Wireless Access Points for Coverage - ISM-1364Partially meets
Separate VLANs by Security Domains - ISM-1386Partially meets
Restrict Network Management Traffic Origin - ISM-1416Partially meets
Implement Firewalls to Control Network Connections - ISM-1427Broader than
Prevent IP Source Address Spoofing in Gateways - ISM-1428Broader than
Disable IPv6 Tunnelling Unless Necessary - ISM-1430Broader than
Configure IPv6 Addresses with DHCPv6 in Stateful Mode - ISM-1439Broader than
Restrict IP Disclosure in CDNs - ISM-1506Broader than
Disable SSH Version 1 for Security - ISM-1521Partially meets
Use Protocol Breaks to Separate Network Layers - ISM-1522Depends on
Ensure CDSs Separate Upward and Downward Data Paths - ISM-1532Broader than
Avoid Using VLANs for Network Separation - ISM-1553Partially meets
Disable TLS Compression for Security - ISM-1562Broader than
Secure Video Conferencing and Telephony Systems - ISM-1604Depends on
Harden Software Isolation Mechanisms Sharing Physical Computing Resources - ISM-1628Broader than
Prevent Anonymity Network Traffic in Outbound Connections - ISM-1646Depends on
Detail Cabling Paths and Points on Floor Plans - ISM-1710Broader than
Secure Default Settings for Wireless Access Points - ISM-1753Broader than
Replace Unsupported Internet-Facing Devices - ISM-1772Broader than
Use Secure Pseudorandom Functions for IPsec Connections - ISM-1774Broader than
Secure Management Paths for Network Gateways - ISM-1781Broader than
Encrypt Network Data with ASD-Approved Cryptography - ISM-1782Partially meets
Use Protective DNS to Block Malicious Domains - ISM-1783Broader than
Secure BGP with Valid ROA for IP Addresses - ISM-1800Partially meets
Ensure Network Devices Have Trusted Firmware - ISM-1809Supports
Implement Compensating Controls for Unsupported Systems - ISM-1862Partially meets
Restrict Access and Conceal Web Server IP Addresses - ISM-1863Partially meets
Restrict Exposure of Network Management Interfaces - ISM-1899Broader than
Restrict Unauthorised Network Connections - ISM-1912Depends on
Document Device Settings for Critical and High-Value Servers - ISM-1929Partially meets
Ensure LDAP Signing on AD DS Domain Controllers - ISM-1962Broader than
Disable SMBv1 Protocol on Networks - ISM-1963Depends on
Central Logging of Events on Internet-Facing Devices - ISM-1964Partially meets
Central Logging for Network Device Events - ISM-1970Supports
Segregated Environment for Malicious Code Analysis - ISM-1981Broader than
Replace Unsupportable Non-Internet Network Devices - ISM-1982Supports
Replace Unsupported Networked IT Equipment - ISM-1984Supports
Encrypt Event Logs in Transit Using ASD Cryptography - ISM-2017Partially meets
Encrypt DNS Traffic Between Clients and Servers - ISM-2018Broader than
Secure BGP Routing with RPKI-Registered IP Addresses - ISM-2097Depends on
Configure Mobile Devices with Always On VPN - ISM-2130Broader than
Disabling or Hardening AD CS Web Enrolment Interfaces - ISM-2150Broader than
Gateways Block Connections for Unauthorised RMM and Remote Access Tools - ISM-2161Broader than
Verify Network Device Firmware and Configuration Against Known-Good Baseline - ISM-2162Broader than
Disabling or Removing Unneeded Network Device Components and Services - ISM-2163Broader than
Enable MACsec Confidentiality Mode Using GCM-AES Cipher Suites - ISM-2164Broader than
Set MACsec Connectivity Association Lifetime Below 24 Hours - ISM-2166Broader than
MACsec Secure Association Lifetime Limited To Under Four Hours - ISM-2167Broader than
Disabling Pre-Shared Key Fallback Authentication for MACsec
|
| Annex A 8.21 Security of Network Services | Technological controls | - ISM-0530Depends on
Administer VLANs from Trusted Security Domains - ISM-0558Broader than
Restrict IP Phone Network Access in Public Areas - ISM-1037Depends on
Regular Testing of Gateway Security Configurations - ISM-1182Partially overlaps
Implement Network Traffic Control Measures - ISM-1186Partially meets
Ensure IPv6 Network Security Appliances Are Used - ISM-1271Depends on
Restrict Network Access to Database Servers - ISM-1284Depends on
Ensure Content Validation for Gateway Files - ISM-1297Depends on
Seek Legal Advice for Personal Device Access - ISM-1314Broader than
Ensure Wireless Devices are Wi-Fi Alliance Certified - ISM-1323Depends on
Requiring X.509 Certificates for 802.1X Network Authentication - ISM-1335Broader than
Enabling 802.11w to Protect Wireless Management Frames - ISM-1364Supports
Separate VLANs by Security Domains - ISM-1428Supports
Disable IPv6 Tunnelling Unless Necessary - ISM-1479Partially overlaps
Minimise Server-to-Server Communication - ISM-1572Supports
Document Service Provider Data Handling and Change Notifications - ISM-1577Partially overlaps
Ensure Network Segregation from Service Providers - ISM-1579Partially overlaps
Dynamic Resource Scaling for Demand Spikes - ISM-1581Partially overlaps
Monitor Capacity and Availability of Online Services - ISM-1628Broader than
Prevent Anonymity Network Traffic in Outbound Connections - ISM-1738Supports
Verify Compliance with Security Requirements - ISM-1912Depends on
Document Device Settings for Critical and High-Value Servers - ISM-1960Depends on
Timely Analysis of Event Logs for Cyber security - ISM-1962Broader than
Disable SMBv1 Protocol on Networks - ISM-2068Supports
Restrict Internet Access for Networked Devices
|
| Annex A 8.22 Network Segregation for Security | Technological controls | - ISM-0213Broader than
Segregate Patch Panels for Secret-Level Cables - ISM-0385Depends on
Maintain Effective Functional Separation Between Servers - ISM-0409Depends on
Restricting Foreign National Access to AUSTEO and REL Systems - ISM-0411Depends on
Restricting Foreign National Access to Systems Handling AGAO Data - ISM-0441Supports
Ensuring Limited Access for Temporary System Use - ISM-0516Supports
Comprehensive Network Diagrams for Critical Components - ISM-0529Partially meets
Avoid Using VLANs for Different Security Domains - ISM-0530Supports
Administer VLANs from Trusted Security Domains - ISM-0535Broader than
Prevent VLAN Trunk Sharing Across Security Domains - ISM-0536Broader than
Segregate Public Wireless Networks from Organisation Networks - ISM-0549Partially meets
Separate Video Conferencing and IP Telephony Traffic From Other Data - ISM-0556Partially meets
Ensure Traffic Separation for Video Conferencing and Telephony - ISM-0558Partially meets
Restrict IP Phone Network Access in Public Areas - ISM-0591Depends on
Use Evaluated Peripheral Switches Securely - ISM-0626Broader than
Implementing CDS for Secure Network Segmentation - ISM-0628Broader than
Implementing Secure Network Gateways - ISM-0629Supports
Manage Gateways Between Different Security Domains - ISM-0631Depends on
Restrict Data Flows with Authorised Gateways - ISM-0635Partially meets
Ensure Network Paths are Isolated in CDSs - ISM-0637Broader than
Implementing Demilitarised Zones in Gateways - ISM-0639Depends on
Use Evaluated Firewalls Between Security Domains - ISM-0643Supports
Use of Diodes for Unidirectional Gateway Security - ISM-0645Partially meets
High Assurance Evaluation of Unidirectional Gateways - ISM-0694Supports
Block Privately Owned Devices From SECRET and TOP SECRET Systems - ISM-0874Depends on
Ensure Internet Access via Organisation's Gateway - ISM-1158Supports
High Assurance Evaluation for Network Diodes - ISM-1181Equivalent
Segregate Networks by Server Criticality - ISM-1182Partially overlaps
Implement Network Traffic Control Measures - ISM-1269Partially overlaps
Ensure Databases and Web Servers are Separated - ISM-1270Partially meets
Separate Network Segments for Database Servers - ISM-1271Partially overlaps
Restrict Network Access to Database Servers - ISM-1277Depends on
Encrypt Database and Web Server Communications - ISM-1315Supports
Disable Wireless Network Administrative Interfaces - ISM-1364Partially meets
Separate VLANs by Security Domains - ISM-1385Partially overlaps
Segregation of Administrative Infrastructure from Networks - ISM-1386Partially overlaps
Restrict Network Management Traffic Origin - ISM-1436Partially meets
Segregate Critical Services to Prevent DoS Attacks - ISM-1439Broader than
Restrict IP Disclosure in CDNs - ISM-1479Partially overlaps
Minimise Server-to-Server Communication - ISM-1521Supports
Use Protocol Breaks to Separate Network Layers - ISM-1522Supports
Ensure CDSs Separate Upward and Downward Data Paths - ISM-1528Supports
Utilising Evaluated Firewalls for Network Security - ISM-1532Partially meets
Avoid Using VLANs for Network Separation - ISM-1562Partially overlaps
Secure Video Conferencing and Telephony Systems - ISM-1577Partially overlaps
Ensure Network Segregation from Service Providers - ISM-1633Supports
Determine System Boundary, Criticality and Security Objectives - ISM-1750Partially overlaps
Segregation of Administrative Infrastructure for Server Security - ISM-1774Partially overlaps
Secure Management Paths for Network Gateways - ISM-1809Supports
Implement Compensating Controls for Unsupported Systems - ISM-1852Depends on
Limit Unprivileged Access to What Duties Require - ISM-1862Partially overlaps
Restrict Access and Conceal Web Server IP Addresses - ISM-1899Broader than
Restrict Unauthorised Network Connections - ISM-1970Partially meets
Segregated Environment for Malicious Code Analysis - ISM-2068Supports
Restrict Internet Access for Networked Devices - ISM-2152Depends on
Segregate Backup Infrastructure With Separate Administrative Authentication - ISM-2156Depends on
Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions - ISM-2160Broader than
Restricting Networked Management Interfaces to a Segregated Management Network
|
| Annex A 8.23 Web Filtering to Reduce Malicious Website Exposure | Technological controls | - ISM-0258Supports
Establish and Maintain a Web Usage Policy - ISM-0260Supports
Ensure All Web Access Uses Proxies - ISM-0267Broader than
Blocking Access to Unapproved Webmail Services - ISM-0659Partially overlaps
Filtering Content of Gateway and CDS Files - ISM-0874Depends on
Ensure Internet Access via Organisation's Gateway - ISM-0958Partially overlaps
Implement Domain Name Allow and Block Lists - ISM-0961Broader than
Restrict Active Content with Web Filters - ISM-0963Equivalent
Implementing Web Content Filters for Safety - ISM-1171Broader than
Block Direct IP Access to Websites - ISM-1236Broader than
Blocking Malicious and Anonymous Domain Names - ISM-1237Partially overlaps
Implement Web Content Filters for Outbound Traffic - ISM-1485Broader than
Prevent Web Browsers from Processing Ads - ISM-1782Broader than
Use Protective DNS to Block Malicious Domains - ISM-2068Partially overlaps
Restrict Internet Access for Networked Devices - ISM-2112Partially overlaps
Disable AI Applications' Direct Access to External Public Data Sources
|
| Annex A 8.24 Effective Use of Cryptography and Key Management | Technological controls | - ISM-0142Partially overlaps
Report Cryptographic Equipment Compromises Promptly - ISM-0231Depends on
Visual Indication for Secure Telephone Connections - ISM-0232Broader than
Encrypt External Traffic for Sensitive Calls - ISM-0233Broader than
Use Encrypted Cordless Systems for Sensitive Conversations - ISM-0263Depends on
Inspect and Decrypt TLS Traffic through Gateways - ISM-0455Partially overlaps
Enable Data Recovery for Encrypted Data - ISM-0457Partially meets
Use Evaluated Crypto for Sensitive Data Encryption - ISM-0459Partially meets
Implement Full or Partial Disk Encryption - ISM-0460Partially meets
Use HACE for Encrypting Sensitive Media - ISM-0465Broader than
Use Evaluated Cryptographic Tools for Sensitive Data - ISM-0467Broader than
Using HACE for Secure Communication of Data - ISM-0469Partially overlaps
Use Approved Cryptographic Protocols When Encrypting Data In Transit - ISM-0471Broader than
Use Only High Assurance Cryptographic Algorithms - ISM-0472Broader than
Using Proper Modulus Size for Diffie-Hellman Keys - ISM-0474Broader than
Using Secure Elliptic Curve Diffie-Hellman Encryption - ISM-0475Partially meets
Use P-384 Curve for Secure Digital Signatures - ISM-0476Broader than
Ensuring Strong RSA Modulus for Digital Security - ISM-0477Broader than
Separate RSA Key Pairs for Different Functions - ISM-0479Broader than
Avoid Using ECB Mode for Symmetric Encryption - ISM-0481Broader than
Ensure Use of High Assurance Cryptographic Protocols - ISM-0489Broader than
Four-Hour Cached SSH Private Key Lifetime and Screen Locks - ISM-0490Partially meets
Ensure S/MIME 3.0 or Later is Used - ISM-0496Partially meets
Use ESP Protocol for Secure IPsec Connections - ISM-0507Equivalent
Develop and Maintain Cryptographic Key Management Processes - ISM-0554Supports
Secure Two-Way Authentication for Video Calls - ISM-0571Supports
Ensure Secure Email Transmission via Gateways - ISM-0572Broader than
Enable Opportunistic TLS for Email Server Encryption - ISM-0675Supports
Ensure Data Exports are Digitally Signed - ISM-0677Depends on
Ensure File Integrity Through Signature Validation - ISM-0702Partially overlaps
Using Cryptographic Sanitisation on Mobile Devices - ISM-0869Supports
Encrypt Storage on Mobile Devices - ISM-0994Partially meets
Use ECDH for Secure Key Exchanges - ISM-0998Broader than
Using Integrity Algorithms for IPsec Connections - ISM-0999Partially meets
Use DH or ECDH for Secure Key Establishment - ISM-1000Broader than
Utilising Perfect Forward Secrecy for IPsec - ISM-1059Supports
Encrypt All Data Stored on Media Using ASD-Approved Cryptography - ISM-1080Partially overlaps
Use AACA or High Assurance Algorithms for Data Encryption - ISM-1085Partially meets
Encrypt Sensitive Data Over Public Networks - ISM-1091Broader than
Change Keying Material When Compromised - ISM-1139Partially meets
Require Latest Version of TLS for Security - ISM-1233Partially meets
Use IKE Version 2 for IPsec Key Exchange - ISM-1277Broader than
Encrypt Database and Web Server Communications - ISM-1324Broader than
Generating X.509 Certificates With Evaluated CA or HSM - ISM-1327Broader than
Access Controls, Encryption and User Authentication for X.509 Certificates - ISM-1332Broader than
Ensure Wireless Traffic is Secure with WPA3-Enterprise - ISM-1370Partially meets
Ensure Only Server-Initiated TLS Renegotiation - ISM-1372Broader than
Ephemeral DH or ECDH Key Establishment for TLS Connections - ISM-1373Broader than
Ensure TLS Connections do not use Anonymous DH - ISM-1374Broader than
Use SHA-2 Certificates for Secure TLS Connections - ISM-1375Broader than
Use SHA-2 for Secure TLS Connections - ISM-1402Partially meets
Protecting Stored Credentials with Security Measures - ISM-1446Partially meets
Use Approved Elliptic Curves for Encryption - ISM-1449Broader than
Protect SSH Private Keys with Passwords or Encryption - ISM-1453Broader than
Ensure PFS is Enabled for TLS Connections - ISM-1454Broader than
Enhancing Security with Encrypted RADIUS Communications - ISM-1629Partially meets
Select Correct Modulus for Diffie-Hellman Encryption - ISM-1712Partially meets
Ensure Secure Authenticator Communication for Wireless FT - ISM-1759Partially meets
Ensure Strong Encryption with Diffie-Hellman - ISM-1761Broader than
Use NIST Curves for ECDH Encryption - ISM-1762Broader than
Use NIST P-384 Curve for ECDH Keys - ISM-1763Broader than
Use NIST P-384 Curve for ECDSA Signatures - ISM-1764Broader than
Use NIST P-384 Curve for ECDSA Signatures - ISM-1765Broader than
Use RSA with 3072-bit Modulus for Security - ISM-1766Partially meets
Ensure Secure Hashing with SHA-2 Algorithm - ISM-1767Partially meets
Use SHA-2 with Minimum 256-bit Output - ISM-1768Broader than
Use Appropriate SHA-2 Output Size for Hashing - ISM-1769Broader than
Using AES Encryption with Strong Key Lengths - ISM-1770Broader than
Utilise Strong AES Encryption Algorithms - ISM-1771Broader than
Use AES Encryption for IPsec Connections - ISM-1772Partially meets
Use Secure Pseudorandom Functions for IPsec Connections - ISM-1796Supports
Digitally Sign Executable Software for Security - ISM-1797Partially meets
Ensure Software Updates are Securely Signed - ISM-1802Broader than
Operate Approved High Assurance Cryptographic Equipment - ISM-1917Partially overlaps
Support Post-Quantum Cryptographic Algorithms by 2030 - ISM-1928Supports
Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups - ISM-1957Broader than
Ensure CA Servers Use Hardware Security Modules - ISM-1984Partially meets
Encrypt Event Logs in Transit Using ASD Cryptography - ISM-1990Broader than
Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations - ISM-1991Broader than
Implement ML-DSA for Enhanced Digital Signature Security - ISM-1992Broader than
Using Hedged Variant of ML-DSA for Digital Signatures - ISM-1993Partially meets
Use Pre-Hashed ML-DSA Variants Only When Necessary - ISM-1994Partially meets
Use Correct Hashing for ML-DSA Pre-hashed Variants - ISM-1995Broader than
Use ML-KEM for Secure Key Encapsulation - ISM-1996Broader than
Using Hybrid Schemes for Secure Encryption - ISM-2010Partially meets
Ensure SPNs Use Strong Encryption in AD Services - ISM-2017Partially meets
Encrypt DNS Traffic Between Clients and Servers - ISM-2027Depends on
Verify Software Artefacts with Digital Signatures - ISM-2050Partially meets
Validate Digital Signature Certificates Securely - ISM-2073Supports
Develop a Post-Quantum Cryptography Transition Plan - ISM-2082Broader than
Using Cryptographic BOM in Software Development - ISM-2083Depends on
Provide a Cryptographic Bill of Materials to Software Users - ISM-2108Broader than
Mobile Apps Encrypt Sensitive Data Using ASD-Approved Cryptography - ISM-2109Partially overlaps
Pre-Boot Authentication for Encrypted System Volume Media - ISM-2163Broader than
Enable MACsec Confidentiality Mode Using GCM-AES Cipher Suites - ISM-2164Broader than
Set MACsec Connectivity Association Lifetime Below 24 Hours - ISM-2166Broader than
MACsec Secure Association Lifetime Limited To Under Four Hours
|
| Annex A 8.25 Secure Development Lifecycle | Technological controls | - ISM-0246Partially meets
Contact ASD for Emanation Security Assessment - ISM-0401Partially overlaps
Implement Secure by Design in Software Development - ISM-0402Partially meets
Software Vulnerability Testing Using SAST, DAST and SCA - ISM-0481Supports
Ensure Use of High Assurance Cryptographic Protocols - ISM-0938Broader than
Select Secure-by-Design Committed Vendors - ISM-0971Broader than
Use OWASP Standards in Web Application Development - ISM-1238Broader than
Incorporate Threat Modelling in Software Development - ISM-1239Partially meets
Ensure Use of Robust Web Application Frameworks - ISM-1240Partially meets
Ensure Input Validation and Sanitisation for Internet Data - ISM-1241Partially meets
Ensuring Secure Web Application Output Encoding - ISM-1275Broader than
Ensure Secure Database Queries in Software - ISM-1276Partially meets
Use Safe Database Query Methods - ISM-1278Partially meets
Minimise Database Error Information in Software - ISM-1419Partially meets
Software Development in Development Environments - ISM-1616Supports
Implementing a Vulnerability Disclosure Program - ISM-1730Broader than
Provide a Software Bill of Materials to Consumers - ISM-1780Partially overlaps
Apply SecDevOps for Secure Software Development - ISM-1796Partially meets
Digitally Sign Executable Software for Security - ISM-1797Supports
Ensure Software Updates are Securely Signed - ISM-1798Partially meets
Develop Secure Configuration Guidelines for Software - ISM-1826Depends on
Select Vendors Committed to Secure Design for Servers - ISM-1849Broader than
Implement OWASP Top 10 in Web Development - ISM-1850Broader than
Mitigate OWASP Top 10 in Web Applications - ISM-1851Partially meets
Secure Development Using OWASP API Security Top 10 - ISM-1917Partially meets
Support Post-Quantum Cryptographic Algorithms by 2030 - ISM-1922Partially meets
Use OWASP Standards in Mobile App Development - ISM-2016Partially meets
Ensure Input Validation and Sanitisation for Security - ISM-2025Depends on
Using Issue Tracking for Software Development Tasks - ISM-2028Broader than
Test Software Artefacts for Security Weaknesses - ISM-2030Broader than
Commit-Time Scanning Blocks Secrets From Source Repositories - ISM-2031Broader than
Secure System Build Tools Implementation - ISM-2033Partially meets
Document and Maintain Software Security Requirements - ISM-2034Broader than
Document and Review Security Design in Development - ISM-2036Broader than
Document Security Duties for Software Developers - ISM-2039Partially meets
Review Threat Model During Software Development - ISM-2040Broader than
Ensure Secure Programming Practices in Software Development - ISM-2041Partially meets
Ensure Use of Memory-Safe Programming Practices - ISM-2042Partially overlaps
Ensuring Security in Software Development Lifecycle - ISM-2043Partially meets
Ensuring Readable and Maintainable Software Architecture - ISM-2055Partially meets
Ensure Software Components Meet Build Standards - ISM-2056Partially meets
Provide Provenance for Software Builds - ISM-2057Partially meets
Document, Build and Test All Input Validation Rules - ISM-2060Partially meets
Ensure Code Reviews for Secure Software Design - ISM-2061Broader than
Peer Reviews of Critical and Security-Related Software Components - ISM-2064Partially meets
Ensure Secure Cookies with Signed Bearer Tokens - ISM-2083Partially overlaps
Provide a Cryptographic Bill of Materials to Software Users - ISM-2121Supports
Prevent Using Developers Without Cyber Security Skills - ISM-2122Broader than
Use Suitable AI Models to Augment Software Security Testing - ISM-2154Broader than
Pinning Software Artefact Dependencies to Approved Versions in Source Code - ISM-2155Broader than
Reproducible Builds Enabling Independent Verification of Release Artefacts
|
| Annex A 8.26 Defining Security Requirements for Applications | Technological controls | - ISM-0246Partially meets
Contact ASD for Emanation Security Assessment - ISM-0471Supports
Use Only High Assurance Cryptographic Algorithms - ISM-0481Supports
Ensure Use of High Assurance Cryptographic Protocols - ISM-0971Supports
Use OWASP Standards in Web Application Development - ISM-1238Supports
Incorporate Threat Modelling in Software Development - ISM-1239Partially meets
Ensure Use of Robust Web Application Frameworks - ISM-1424Partially meets
Ensure Web Security Through Response Headers - ISM-1552Partially meets
Secure Web Content with HTTPS Only - ISM-1568Supports
Ensure Security Commitment from Suppliers - ISM-1597Partially meets
Ensuring Credential Input Obscurity - ISM-1739Partially overlaps
Approve Security Architecture Before System Development - ISM-1806Partially meets
Change Default User Credentials During Setup - ISM-1849Supports
Implement OWASP Top 10 in Web Development - ISM-1850Partially meets
Mitigate OWASP Top 10 in Web Applications - ISM-1851Partially meets
Secure Development Using OWASP API Security Top 10 - ISM-1917Partially meets
Support Post-Quantum Cryptographic Algorithms by 2030 - ISM-1924Depends on
Detect and Mitigate Adversarial Prompts in Generative AI Applications - ISM-2027Supports
Verify Software Artefacts with Digital Signatures - ISM-2028Supports
Test Software Artefacts for Security Weaknesses - ISM-2030Depends on
Commit-Time Scanning Blocks Secrets From Source Repositories - ISM-2033Partially overlaps
Document and Maintain Software Security Requirements - ISM-2039Supports
Review Threat Model During Software Development - ISM-2041Supports
Ensure Use of Memory-Safe Programming Practices - ISM-2045Supports
Ensure Backwards Compatibility Doesn't Weaken Security - ISM-2046Partially meets
Ensure Secure Impersonation Logging Practices - ISM-2055Partially meets
Ensure Software Components Meet Build Standards - ISM-2059Supports
Restrict and Scan File Uploads for Security - ISM-2063Partially meets
Ensure Web App Cookies Have Security Flags - ISM-2064Partially meets
Ensure Secure Cookies with Signed Bearer Tokens - ISM-2065Partially meets
Ensure Secure Session Cookies with High Entropy Tokens - ISM-2067Depends on
Ensure Single Logout for Single Sign-On Web Applications - ISM-2072Partially meets
Store AI Models In A Non-Executable File Format - ISM-2110Partially overlaps
Hardening User Applications with ASD and Vendor Guidance - ISM-2113Broader than
Configuring AI Applications to Require Human Approval Before High-Impact Actions
|
| Annex A 8.27 Secure system architecture and engineering principles | Technological controls | - ISM-0246Depends on
Contact ASD for Emanation Security Assessment - ISM-0401Partially meets
Implement Secure by Design in Software Development - ISM-0479Depends on
Avoid Using ECB Mode for Symmetric Encryption - ISM-0548Depends on
Ensure Secure Protocols for Video and IP Calls - ISM-0591Broader than
Use Evaluated Peripheral Switches Securely - ISM-0597Depends on
Consult ASD Before Changing CDS Connectivity - ISM-0938Broader than
Select Secure-by-Design Committed Vendors - ISM-0971Broader than
Use OWASP Standards in Web Application Development - ISM-1238Partially meets
Incorporate Threat Modelling in Software Development - ISM-1457Supports
Evaluate Peripheral Switches for Security Domains - ISM-1460Broader than
Secure By Design Vendor Isolation Mechanisms - ISM-1522Depends on
Ensure CDSs Separate Upward and Downward Data Paths - ISM-1739Partially overlaps
Approve Security Architecture Before System Development - ISM-1780Partially overlaps
Apply SecDevOps for Secure Software Development - ISM-1798Broader than
Develop Secure Configuration Guidelines for Software - ISM-1826Depends on
Select Vendors Committed to Secure Design for Servers - ISM-1850Broader than
Mitigate OWASP Top 10 in Web Applications - ISM-1885Broader than
Implement Emanation Security Measures for Systems - ISM-1917Broader than
Support Post-Quantum Cryptographic Algorithms by 2030 - ISM-1996Partially meets
Using Hybrid Schemes for Secure Encryption - ISM-2031Broader than
Secure System Build Tools Implementation - ISM-2033Partially overlaps
Document and Maintain Software Security Requirements - ISM-2034Broader than
Document and Review Security Design in Development - ISM-2039Partially meets
Review Threat Model During Software Development - ISM-2042Partially overlaps
Ensuring Security in Software Development Lifecycle - ISM-2043Broader than
Ensuring Readable and Maintainable Software Architecture - ISM-2060Depends on
Ensure Code Reviews for Secure Software Design - ISM-2082Depends on
Using Cryptographic BOM in Software Development - ISM-2084Partially overlaps
Document AI Model and System Characteristics - ISM-2121Supports
Prevent Using Developers Without Cyber Security Skills - ISM-2122Depends on
Use Suitable AI Models to Augment Software Security Testing - ISM-2154Broader than
Pinning Software Artefact Dependencies to Approved Versions in Source Code - ISM-2158Broader than
Treat Agentic AI Retrieved External Content as Untrusted Data
|
| Annex A 8.28 Secure Coding Practices in Software Development | Technological controls | - ISM-0401Partially meets
Implement Secure by Design in Software Development - ISM-0402Supports
Software Vulnerability Testing Using SAST, DAST and SCA - ISM-0938Broader than
Select Secure-by-Design Committed Vendors - ISM-0971Supports
Use OWASP Standards in Web Application Development - ISM-1238Supports
Incorporate Threat Modelling in Software Development - ISM-1239Supports
Ensure Use of Robust Web Application Frameworks - ISM-1241Partially meets
Ensuring Secure Web Application Output Encoding - ISM-1275Partially meets
Ensure Secure Database Queries in Software - ISM-1276Partially meets
Use Safe Database Query Methods - ISM-1278Partially meets
Minimise Database Error Information in Software - ISM-1460Partially overlaps
Secure By Design Vendor Isolation Mechanisms - ISM-1780Partially meets
Apply SecDevOps for Secure Software Development - ISM-1826Depends on
Select Vendors Committed to Secure Design for Servers - ISM-1849Supports
Implement OWASP Top 10 in Web Development - ISM-1850Broader than
Mitigate OWASP Top 10 in Web Applications - ISM-1851Supports
Secure Development Using OWASP API Security Top 10 - ISM-1922Supports
Use OWASP Standards in Mobile App Development - ISM-1924Depends on
Detect and Mitigate Adversarial Prompts in Generative AI Applications - ISM-2016Partially meets
Ensure Input Validation and Sanitisation for Security - ISM-2024Supports
Utilise Authoritative Sources in Software Development - ISM-2030Broader than
Commit-Time Scanning Blocks Secrets From Source Repositories - ISM-2031Supports
Secure System Build Tools Implementation - ISM-2033Supports
Document and Maintain Software Security Requirements - ISM-2037Depends on
Train Software Developers Lacking Cyber Security Skills - ISM-2040Equivalent
Ensure Secure Programming Practices in Software Development - ISM-2041Partially overlaps
Ensure Use of Memory-Safe Programming Practices - ISM-2042Partially overlaps
Ensuring Security in Software Development Lifecycle - ISM-2055Partially meets
Ensure Software Components Meet Build Standards - ISM-2057Partially meets
Document, Build and Test All Input Validation Rules - ISM-2058Partially meets
Ensure Data Validation Before Deserialisation - ISM-2059Supports
Restrict and Scan File Uploads for Security - ISM-2060Supports
Ensure Code Reviews for Secure Software Design - ISM-2061Partially meets
Peer Reviews of Critical and Security-Related Software Components - ISM-2062Supports
Unit and Integration Testing for Code Quality - ISM-2064Partially meets
Ensure Secure Cookies with Signed Bearer Tokens - ISM-2066Partially meets
Centralised Management of Web Application Sessions - ISM-2085Partially meets
Prevent Exposure of AI Model Confidence Scores - ISM-2122Depends on
Use Suitable AI Models to Augment Software Security Testing - ISM-2158Broader than
Treat Agentic AI Retrieved External Content as Untrusted Data
|
| Annex A 8.29 Security testing in development and acceptance | Technological controls | - ISM-0400Supports
Segregation of Environments in Software Development - ISM-0401Partially meets
Implement Secure by Design in Software Development - ISM-0402Partially meets
Software Vulnerability Testing Using SAST, DAST and SCA - ISM-0971Partially meets
Use OWASP Standards in Web Application Development - ISM-1238Supports
Incorporate Threat Modelling in Software Development - ISM-1239Supports
Ensure Use of Robust Web Application Frameworks - ISM-1240Partially meets
Ensure Input Validation and Sanitisation for Internet Data - ISM-1419Supports
Software Development in Development Environments - ISM-1524Partially meets
Ensure Rigorous Testing of Content Filters - ISM-1597Supports
Ensuring Credential Input Obscurity - ISM-1780Partially meets
Apply SecDevOps for Secure Software Development - ISM-1791Partially overlaps
Assess Integrity of Delivered IT and OT Products - ISM-1850Supports
Mitigate OWASP Top 10 in Web Applications - ISM-1851Partially meets
Secure Development Using OWASP API Security Top 10 - ISM-1922Partially overlaps
Use OWASP Standards in Mobile App Development - ISM-2026Partially overlaps
Scan Software Artefacts for Malicious Content - ISM-2028Partially overlaps
Test Software Artefacts for Security Weaknesses - ISM-2029Supports
Restrict Third-Party Libraries to Trustworthy Sources - ISM-2031Partially overlaps
Secure System Build Tools Implementation - ISM-2032Partially meets
Ensure Automated Tests Are Completed Before Building - ISM-2033Supports
Document and Maintain Software Security Requirements - ISM-2039Supports
Review Threat Model During Software Development - ISM-2040Supports
Ensure Secure Programming Practices in Software Development - ISM-2042Partially meets
Ensuring Security in Software Development Lifecycle - ISM-2054Supports
Ensure No Vulnerabilities in Third-Party Software Components - ISM-2055Partially overlaps
Ensure Software Components Meet Build Standards - ISM-2057Partially meets
Document, Build and Test All Input Validation Rules - ISM-2059Supports
Restrict and Scan File Uploads for Security - ISM-2060Partially overlaps
Ensure Code Reviews for Secure Software Design - ISM-2061Partially overlaps
Peer Reviews of Critical and Security-Related Software Components - ISM-2062Partially meets
Unit and Integration Testing for Code Quality - ISM-2102Broader than
Periodically Test Software Artefacts for Weaknesses - ISM-2119Depends on
Utilise AI Models in Vulnerability Assessments and Penetration Tests - ISM-2122Broader than
Use Suitable AI Models to Augment Software Security Testing
|
| Annex A 8.30 Management of Outsourced System Development | Technological controls | - ISM-0401Partially overlaps
Implement Secure by Design in Software Development - ISM-0402Supports
Software Vulnerability Testing Using SAST, DAST and SCA - ISM-0731Partially overlaps
CISO Oversight of Cyber Supply Chain Risks - ISM-1239Supports
Ensure Use of Robust Web Application Frameworks - ISM-1395Partially overlaps
Ensuring Data Protection by Service Providers - ISM-1452Partially overlaps
Perform Supply Chain Risk Assessments for System Suppliers - ISM-1634Supports
Tailoring System Controls for Security and Resilience - ISM-1738Supports
Verify Compliance with Security Requirements - ISM-1780Partially overlaps
Apply SecDevOps for Secure Software Development - ISM-1791Supports
Assess Integrity of Delivered IT and OT Products - ISM-1826Partially overlaps
Select Vendors Committed to Secure Design for Servers - ISM-2024Supports
Utilise Authoritative Sources in Software Development - ISM-2028Depends on
Test Software Artefacts for Security Weaknesses - ISM-2029Supports
Restrict Third-Party Libraries to Trustworthy Sources - ISM-2031Partially overlaps
Secure System Build Tools Implementation - ISM-2033Partially overlaps
Document and Maintain Software Security Requirements - ISM-2039Supports
Review Threat Model During Software Development - ISM-2086Supports
Verify Integrity of AI Models, Structures, and Weights - ISM-2087Partially overlaps
Verify the Source and Integrity of AI Training Data - ISM-2102Depends on
Periodically Test Software Artefacts for Weaknesses
|
| Annex A 8.31 Separation of Development, Test, and Production Environments | Technological controls | - ISM-0385Partially overlaps
Maintain Effective Functional Separation Between Servers - ISM-0400Equivalent
Segregation of Environments in Software Development - ISM-1211Depends on
System Administration Performed Under Change and Configuration Management Plan - ISM-1273Partially overlaps
Segregate Environments for Database Servers - ISM-1274Supports
Ensure Non-Production Databases Match Production Security - ISM-1419Equivalent
Software Development in Development Environments - ISM-1420Partially overlaps
Ensure Non-Production Security Matches Production - ISM-1689Supports
Restrict Privileged Accounts Access to Non-Privileged Environments - ISM-1816Depends on
Prevent Unauthorised Changes to Software Sources - ISM-1852Depends on
Limit Unprivileged Access to What Duties Require - ISM-1970Partially meets
Segregated Environment for Malicious Code Analysis - ISM-2143Partially overlaps
Unique Per-Application Credentials Not Shared Across Environments
|
| Annex A 8.32 Change management procedures for information systems | Technological controls | - ISM-0042Partially meets
Maintain Effective System Administration Practices - ISM-0289Supports
Implement and Manage Evaluated Products Correctly - ISM-0300Partially overlaps
Apply System Security Patches with Approval - ISM-0518Depends on
Maintain Comprehensive Network Documentation - ISM-0597Broader than
Consult ASD Before Changing CDS Connectivity - ISM-0912Partially meets
Establish and Manage System Configuration Changes - ISM-1079Partially overlaps
Seek Approval for High Assurance IT Repairs - ISM-1143Supports
Develop and Maintain Patch Management Procedures - ISM-1211Partially overlaps
System Admin Activities Follow Change Management Plan - ISM-1297Depends on
Seek Legal Advice for Personal Device Access - ISM-1419Broader than
Software Development in Development Environments - ISM-1430Depends on
Configure IPv6 Addresses with DHCPv6 in Stateful Mode - ISM-1564Supports
System Owner Produces Plan of Action and Milestones After Assessment - ISM-1598Partially overlaps
Inspect IT Equipment Post-Maintenance for Unauthorised Changes - ISM-1606Depends on
Patch Isolation Mechanisms and Underlying Operating Systems Promptly - ISM-1610Depends on
Document and Test Emergency System Access Procedures - ISM-1615Depends on
Testing Break Glass Accounts Post Credential Change - ISM-1634Depends on
System Owners Select and Tailor Controls in Consultation with Authorising Officer - ISM-1732Supports
Coordinated Intrusion Remediation During Planned Outages - ISM-1816Depends on
Prevent Unauthorised Changes to Software Sources - ISM-1824Broader than
Lock PDF Application Security Settings Against User Changes - ISM-1944Broader than
Remove EDITF_ATTRIBUTESUBJECTALTNAME2 Flag From AD CS Certification Authorities - ISM-1948Broader than
Certificate Manager Approval for Templates Allowing Supplied SANs - ISM-2025Depends on
Using Issue Tracking for Software Development Tasks - ISM-2073Supports
Develop a Post-Quantum Cryptography Transition Plan - ISM-2113Supports
Configuring AI Applications to Require Human Approval Before High-Impact Actions - ISM-2132Depends on
Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes - ISM-2161Depends on
Verify Network Device Firmware and Configuration Against Known-Good Baseline
|
| Annex A 8.33 Test Information Selection and Protection | Technological controls | - ISM-0457Supports
Use Evaluated Crypto for Sensitive Data Encryption - ISM-0465Supports
Use Evaluated Cryptographic Tools for Sensitive Data - ISM-0631Supports
Restrict Data Flows with Authorised Gateways - ISM-0831Partially overlaps
Ensure Proper Handling of Sensitive Media - ISM-1273Supports
Segregate Environments for Database Servers - ISM-2021Partially overlaps
Implement and Maintain Data Minimisation Practices - ISM-2094Supports
AI Content Filtering to Block Sensitive Data Exposure
|
| Annex A 8.34 Protection of information systems during audits | Technological controls | - ISM-1524Partially overlaps
Ensure Rigorous Testing of Content Filters - ISM-1563Partially overlaps
Generate Comprehensive Security Assessment Reports - ISM-1564Depends on
System Owner Produces Plan of Action and Milestones After Assessment - ISM-1636Partially overlaps
Security Control Assessment of Systems by Own or IRAP Assessors - ISM-1967Partially overlaps
ASD Assessor Security Control Assessment of TOP SECRET Systems
|