Skip to content
arrow_back

swap_horizFree crosswalk tool

ISO 27001 to ASD ISM

Every ISO/IEC 27001:2022 Annex A control, with the ASD ISM controls that cover the same ground. Useful when you hold ISO 27001 and are asked to show ISM alignment, or the other way round.

93 of the 93 ISO 27001 controls (100%) have at least one ASD ISM counterpart, giving 2,645 control-to-control relationships across 1,070 distinct ASD ISM controls. ISO 27001 and the ISM overlap heavily in subject matter, so coverage here is high. What differs is depth: the ISM states specific technical requirements where Annex A states outcomes.

These relationships are generated from the Control Stack catalogue and reviewed for topic fidelity, then labelled with how the two controls relate rather than asserted as equivalent. Where no counterpart exists, the row says so plainly instead of stretching for a match. Some rows are read from the other framework’s own mappings, so the wording of those summaries leads with that side.

Control Stack is a free Australian reference covering 1,423 cyber security controls: all 1,143 ASD ISM controls, 149 Essential Eight controls across all four maturity levels, all 93 ISO/IEC 27001:2022 Annex A controls and all 38 ISO/IEC 42001:2023 Annex A controls. Every one of them is cross-mapped between the four frameworks and readable in full without an account.

Reviewed 16 September 2026 · Maps ISO/IEC 27001:2022 Annex A to the September 2026 ASD ISM

ISO 27001 to ASD ISM

ISO 27001 controlGroupASD ISM counterparts
Annex A 5.1
Policies for information security
Organisational controls
  • ISM-0009Depends on
    System Owners Identify Supplementary Controls With Authorising Officer
  • ISM-0027Depends on
    Mandatory Authorisation for System Operation
  • ISM-0039Partially overlaps
    Develop and Maintain a Cyber Security Strategy
  • ISM-0041Supports
    Develop a Detailed System Security Plan
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0047Partially overlaps
    Approval Process for Cyber Security Documentation
  • ISM-0264Partially overlaps
    Develop and Maintain an Email Usage Policy
  • ISM-0407Depends on
    Maintaining a Secure Lifetime Access Record for Each Human User
  • ISM-0499Depends on
    Ensure Compliance with ASD Communication Security Policies
  • ISM-0588Partially meets
    Develop and Maintain MFD Usage Policy
  • ISM-0718Depends on
    CISO Reporting to Board on Cyber Security
  • ISM-0725Depends on
    Cyber Security Steering Committee Coordination
  • ISM-0726Depends on
    Coordinate Security Risk Management Activities
  • ISM-0732Depends on
    Manage and Allocate Cyber Security Budget
  • ISM-0888Partially overlaps
    Annual Review of Cyber Security Documentation
  • ISM-1078Broader than
    Develop and Maintain Telephone System Usage Policy
  • ISM-1195Supports
    Enforce Policy with Evaluated Mobile Device Management
  • ISM-1359Broader than
    Establish and Maintain Removable Media Policy
  • ISM-1478Partially overlaps
    CISO Management of Cyber Security Compliance
  • ISM-1510Broader than
    Develop and Maintain a Digital Preservation Policy
  • ISM-1549Partially meets
    Develop and Maintain Media Management Policy
  • ISM-1551Partially meets
    Develop and Maintain IT Equipment Management Policy
  • ISM-1587Partially overlaps
    Annual Security Status Reporting for Systems
  • ISM-1602Partially overlaps
    Ensure Cyber Security Docs Are Communicated
  • ISM-1617Partially overlaps
    Regular Review of Cyber Security Program
  • ISM-1626Depends on
    Seek Legal Advice for Insider Threat Plans
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1829Broader than
    Prevent Password Storage in Group Policy Preferences
  • ISM-1864Broader than
    Develop and Enforce a System Usage Policy
  • ISM-1865Depends on
    Compliance with System Usage Policies for Access
  • ISM-1868Supports
    Restrictions on Mobile Device Removable Media
  • ISM-1997Depends on
    Define Cyber Security Roles for Leadership
  • ISM-1998Supports
    Integrate Cyber Security Across Business Functions
  • ISM-1999Partially overlaps
    Align Cyber Security with Business Strategy
  • ISM-2001Depends on
    Championing Cyber Security at an Executive Level
  • ISM-2002Depends on
    Ensure Board Cyber Security Literacy for Compliance
  • ISM-2008Supports
    Criteria for Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2074Broader than
    Develop and Maintain AI Usage Policy
  • ISM-2105Broader than
    Advise Staff to Limit Posting Work Information on Unauthorised Online Services
  • ISM-2106Depends on
    Advise Staff to Limit Posting Work Skills Online
  • ISM-2120Broader than
    Develop and Maintain Secure Software Policy
Annex A 5.2
Defining Information Security Roles and Responsibilities
Organisational controls
  • ISM-0041Supports
    Develop a Detailed System Security Plan
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0047Partially overlaps
    Approval Process for Cyber Security Documentation
  • ISM-0613Partially meets
    Requirement for Gateway System Administrators Nationality
  • ISM-0616Partially meets
    Ensure Separation of Duties for Gateway Admins
  • ISM-0701Supports
    Establish Mobile Device Emergency Sanitisation Processes and Procedures
  • ISM-0714Partially overlaps
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-0717Partially overlaps
    CISO Oversight of Cyber Security Personnel
  • ISM-0725Partially overlaps
    Cyber Security Steering Committee Coordination
  • ISM-0726Partially overlaps
    Coordinate Security Risk Management Activities
  • ISM-0732Partially overlaps
    Manage and Allocate Cyber Security Budget
  • ISM-0733Partially meets
    Ensure CISO Awareness of Cyber Incidents
  • ISM-0734Partially overlaps
    CISO Role in Disaster Recovery Planning
  • ISM-1071Partially overlaps
    Assign System Ownership for Better Oversight
  • ISM-1478Partially overlaps
    CISO Management of Cyber Security Compliance
  • ISM-1525Partially overlaps
    Register Systems with Authorising Officers
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1773Partially overlaps
    Eligibility Criteria for Gateway System Administrators
  • ISM-1997Equivalent
    Define Cyber Security Roles for Leadership
  • ISM-1998Supports
    Integrate Cyber Security Across Business Functions
  • ISM-1999Supports
    Align Cyber Security with Business Strategy
  • ISM-2001Partially overlaps
    Championing Cyber Security at an Executive Level
  • ISM-2003Supports
    Monitor Cyber Security Workforce and Skill Gaps
  • ISM-2006Partially overlaps
    Board Plans for Major Cyber Security Incidents
  • ISM-2020Depends on
    Ensure Adequate Cyber Security Personnel Are Acquired
  • ISM-2035Partially meets
    Document Security Roles for Software Development
  • ISM-2036Broader than
    Document Security Duties for Software Developers
  • ISM-2038Supports
    Maintain Developer Cyber Security Skills Register
Annex A 5.3
Segregation of Duties
Organisational controls
  • ISM-0047Partially overlaps
    Approval Process for Cyber Security Documentation
  • ISM-0445Partially overlaps
    Dedicated Accounts for Privileged User Activities
  • ISM-1255Supports
    Restrict Database User Access Based on Duties
  • ISM-1705Partially overlaps
    Restrict Access to User Account Backups
  • ISM-1706Partially overlaps
    Prevent Backup Access by Privileged Users
  • ISM-1833Supports
    Limit Privileges for User Accounts in Active Directory
  • ISM-1835Supports
    Restrict Delegation of Privileged Active Directory Accounts
  • ISM-1958Partially overlaps
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-2048Supports
    Restrict Non-Admins from Changing Permissions
  • ISM-2093Supports
    Role-Based Access Controls in AI Applications
Annex A 5.4
Management responsibilities for information security
Organisational controls
  • ISM-0009Depends on
    System Owners Identify Supplementary Controls With Authorising Officer
  • ISM-0039Supports
    Develop and Maintain a Cyber Security Strategy
  • ISM-0047Supports
    Approval Process for Cyber Security Documentation
  • ISM-0264Partially overlaps
    Develop and Maintain an Email Usage Policy
  • ISM-0348Broader than
    Develop and Maintain Media Sanitisation Procedures
  • ISM-0408Depends on
    Logon Banner for Security Responsibilities
  • ISM-0499Depends on
    Ensure Compliance with ASD Communication Security Policies
  • ISM-0576Supports
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0588Supports
    Develop and Maintain MFD Usage Policy
  • ISM-0714Supports
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-0718Depends on
    CISO Reporting to Board on Cyber Security
  • ISM-0720Supports
    Develop and Maintain a Cyber Security Communication Strategy
  • ISM-0724Depends on
    Implement Cyber Security Metrics and KPIs
  • ISM-0725Supports
    Cyber Security Steering Committee Coordination
  • ISM-0726Depends on
    Coordinate Security Risk Management Activities
  • ISM-0820Partially meets
    Avoid Posting Work Data on Unauthorised Online Services
  • ISM-0824Depends on
    Avoid Using Unauthorised Online File Services
  • ISM-1078Partially overlaps
    Develop and Maintain Telephone System Usage Policy
  • ISM-1359Depends on
    Establish and Maintain Removable Media Policy
  • ISM-1478Partially overlaps
    CISO Management of Cyber Security Compliance
  • ISM-1510Supports
    Develop and Maintain a Digital Preservation Policy
  • ISM-1533Depends on
    Establish Mobile Device Management Policies
  • ISM-1549Partially overlaps
    Develop and Maintain Media Management Policy
  • ISM-1551Supports
    Develop and Maintain IT Equipment Management Policy
  • ISM-1602Partially overlaps
    Ensure Cyber Security Docs Are Communicated
  • ISM-1864Depends on
    Develop and Enforce a System Usage Policy
  • ISM-1865Depends on
    Compliance with System Usage Policies for Access
  • ISM-1884Supports
    Ensure Compliance with Emanation Security Doctrine
  • ISM-1998Partially meets
    Integrate Cyber Security Across Business Functions
  • ISM-1999Supports
    Align Cyber Security with Business Strategy
  • ISM-2001Depends on
    Championing Cyber Security at an Executive Level
  • ISM-2004Depends on
    Enhancing Cyber Security Skills and Experience
  • ISM-2036Depends on
    Document Security Duties for Software Developers
  • ISM-2074Depends on
    Develop and Maintain AI Usage Policy
  • ISM-2105Broader than
    Advise Staff to Limit Posting Work Information on Unauthorised Online Services
Annex A 5.5
Establish and Maintain Contact with Authorities
Organisational controls
  • ISM-0039Supports
    Develop and Maintain a Cyber Security Strategy
  • ISM-0043Supports
    Cyber Security Incident Response Plan Requirements
  • ISM-0138Depends on
    Maintaining Integrity of Evidence in Investigations
  • ISM-0140Partially meets
    Prompt Reporting of Cyber Incidents to ASD
  • ISM-0181Supports
    Ensure Cabling Meets Australian Standards
  • ISM-0249Supports
    Request ASD Emanation Security Assessments for Deployed Classified Systems
  • ISM-0576Supports
    Develop and Maintain Cyber Security Incident Plans
  • ISM-1137Supports
    Request Risk Assessment for Emanation Security
  • ISM-1755Partially overlaps
    Develop and Maintain a Vulnerability Disclosure Policy
Annex A 5.6
Contact with special interest groups
Organisational controls
  • ISM-0039Supports
    Develop and Maintain a Cyber Security Strategy
  • ISM-0720Supports
    Develop and Maintain a Cyber Security Communication Strategy
  • ISM-1617Supports
    Regular Review of Cyber Security Program
  • ISM-2000Partially overlaps
    Regular Cyber Security Briefings for Executives
Annex A 5.7
Threat Intelligence Collection and Analysis
Organisational controls
  • ISM-1163Supports
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1203Depends on
    Risk Assessment for System Security
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1683Supports
    Central Logging of Multi-factor Authentication Events
  • ISM-1696Depends on
    Apply Critical Patches Within 48 Hours
  • ISM-1697Depends on
    Apply Non-Critical Patches Within One Month
  • ISM-1987Depends on
    Timely Analysis of Security Event Logs
  • ISM-2039Supports
    Review Threat Model During Software Development
  • ISM-2073Supports
    Develop a Post-Quantum Cryptography Transition Plan
  • ISM-2116Partially overlaps
    Use Cyber Threat Intelligence for Event Detection
  • ISM-2153Supports
    Quarterly Threat Hunting Informed by Current Threat Intelligence
Annex A 5.8
Information security in project management
Organisational controls
  • ISM-0039Supports
    Develop and Maintain a Cyber Security Strategy
  • ISM-0041Supports
    Develop a Detailed System Security Plan
  • ISM-0432Supports
    Document System Access Requirements in Security Plans
  • ISM-0597Broader than
    Consult ASD Before Changing CDS Connectivity
  • ISM-0726Supports
    Coordinate Security Risk Management Activities
  • ISM-1203Depends on
    Risk Assessment for System Security
  • ISM-1420Depends on
    Ensure Non-Production Security Matches Production
  • ISM-1478Supports
    CISO Management of Cyber Security Compliance
  • ISM-1602Supports
    Ensure Cyber Security Docs Are Communicated
  • ISM-1790Broader than
    Ensure Integrity in IT and OT Deliveries
  • ISM-1998Broader than
    Integrate Cyber Security Across Business Functions
  • ISM-2033Broader than
    Document and Maintain Software Security Requirements
  • ISM-2084Broader than
    Document AI Model and System Characteristics
Annex A 5.9
Inventory management of information and associated assets
Organisational controls
  • ISM-0336Partially overlaps
    Develop and Maintain Networked IT Equipment Register
  • ISM-1071Supports
    Assign System Ownership for Better Oversight
  • ISM-1243Partially overlaps
    Develop and Verify Database Register
  • ISM-1493Partially overlaps
    Maintain and Verify Software Registers
  • ISM-1525Supports
    Register Systems with Authorising Officers
  • ISM-1543Partially meets
    Register for RF and IR Devices in Secret Areas
  • ISM-1551Supports
    Develop and Maintain IT Equipment Management Policy
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1635Depends on
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1637Partially overlaps
    Maintain an Outsourced Cloud Service Register
  • ISM-1638Partially overlaps
    Maintain a Comprehensive Outsourced Cloud Service Register
  • ISM-1713Partially overlaps
    Develop and Maintain a Removable Media Register
  • ISM-1737Partially overlaps
    Maintain a Comprehensive Managed Service Register
  • ISM-1869Broader than
    Maintain Non-Networked IT Equipment Register
  • ISM-1966Partially overlaps
    CISO Manages and Verifies System Register
  • ISM-2005Supports
    Understanding Business Criticality of Organisation Systems
  • ISM-2007Partially meets
    Authorised Medical Device Register for SECRET and TOP SECRET Areas
Annex A 5.10
Acceptable Use Policies for Information and Assets
Organisational controls
  • ISM-0039Depends on
    Develop and Maintain a Cyber Security Strategy
  • ISM-0047Supports
    Approval Process for Cyber Security Documentation
  • ISM-0161Depends on
    Ensure Security of Unused IT Equipment and Media
  • ISM-0240Partially meets
    Prevent Sensitive Data in Messaging Services
  • ISM-0258Broader than
    Establish and Maintain a Web Usage Policy
  • ISM-0264Broader than
    Develop and Maintain an Email Usage Policy
  • ISM-0337Supports
    Ensure Media is Used with Authorised Systems
  • ISM-0348Partially overlaps
    Develop and Maintain Media Sanitisation Procedures
  • ISM-0358Supports
    Classification Retention for Sanitised EPROM and EEPROM
  • ISM-0588Broader than
    Develop and Maintain MFD Usage Policy
  • ISM-0610Depends on
    Training Human Users on Secure CDS Use Before Granting Access
  • ISM-0661Supports
    User Accountability for Data Transfers
  • ISM-0824Broader than
    Avoid Using Unauthorised Online File Services
  • ISM-0870Depends on
    Secure Storage and Handling of Mobile Devices
  • ISM-1078Broader than
    Develop and Maintain Telephone System Usage Policy
  • ISM-1083Partially overlaps
    Advise Personnel on Mobile Communication Sensitivity
  • ISM-1146Broader than
    Separate Personal and Work Accounts for Online Services
  • ISM-1187Supports
    Check Data for Improper Markings Before Export
  • ISM-1314Depends on
    Ensure Wireless Devices are Wi-Fi Alliance Certified
  • ISM-1359Broader than
    Establish and Maintain Removable Media Policy
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1418Depends on
    Disable Unnecessary Removable Media Access
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1549Partially overlaps
    Develop and Maintain Media Management Policy
  • ISM-1551Partially overlaps
    Develop and Maintain IT Equipment Management Policy
  • ISM-1599Broader than
    Proper Handling of Sensitive IT Equipment
  • ISM-1602Depends on
    Ensure Cyber Security Docs Are Communicated
  • ISM-1625Supports
    Develop Insider Threat Mitigation Programs
  • ISM-1644Broader than
    Secure Communication Practices in Public Areas
  • ISM-1864Broader than
    Develop and Enforce a System Usage Policy
  • ISM-1865Supports
    Compliance with System Usage Policies for Access
  • ISM-1868Supports
    Restrictions on Mobile Device Removable Media
  • ISM-2074Broader than
    Develop and Maintain AI Usage Policy
  • ISM-2075Broader than
    Prohibit the Use of Fax Machines for Messages
  • ISM-2095Broader than
    Block Personal Devices Granting AI Agents Access to Sensitive Systems
  • ISM-2104Partially overlaps
    Do Not Post Security Clearance and Briefing Details Online
  • ISM-2105Broader than
    Advise Staff to Limit Posting Work Information on Unauthorised Online Services
  • ISM-2106Broader than
    Advise Staff to Limit Posting Work Skills Online
Annex A 5.11
Return of Organisation's Assets upon Departure
Organisational controls
  • ISM-0407Depends on
    Maintaining a Secure Lifetime Access Record for Each Human User
  • ISM-0430Partially overlaps
    Immediate Suspension of Unneeded System Access
Annex A 5.12
Information Classification Policy and Practices
Organisational controls
  • ISM-0027Partially overlaps
    Mandatory Authorisation for System Operation
  • ISM-0201Broader than
    Labelling Requirements for TOP SECRET Conduits
  • ISM-0208Supports
    Maintain a Comprehensive Cable Register
  • ISM-0233Depends on
    Use Encrypted Cordless Systems for Sensitive Conversations
  • ISM-0240Supports
    Prevent Sensitive Data in Messaging Services
  • ISM-0269Supports
    Restrict Sensitive Emails to Verified Recipients
  • ISM-0270Broader than
    Apply Protective Markings to Emails Based on Sensitivity
  • ISM-0271Supports
    Prevent Automatic Email Marking by Protective Tools
  • ISM-0272Supports
    Prevent Unauthorised Protective Marking Selection
  • ISM-0293Broader than
    Classify IT Equipment by Data Sensitivity
  • ISM-0323Broader than
    Classifying Media by Data Sensitivity
  • ISM-0325Depends on
    Reclassify Media to Higher Sensitivity
  • ISM-0332Broader than
    Label Media With Protective Markings Reflecting Sensitivity Or Classification
  • ISM-0358Supports
    Classification Retention for Sanitised EPROM and EEPROM
  • ISM-0393Broader than
    Classify Databases Based on Data Sensitivity
  • ISM-0462Depends on
    Managing Encryption Access for IT Equipment and Media
  • ISM-0501Depends on
    Transport of Keyed Cryptographic Equipment
  • ISM-0565Supports
    Email Security for Protective Markings
  • ISM-0589Depends on
    Limit Document Sensitivity on MFDs Based on Network Classification
  • ISM-0694Depends on
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0831Supports
    Ensure Proper Handling of Sensitive Media
  • ISM-0835Supports
    TOP SECRET Volatile Media Retains Classification After Sanitisation
  • ISM-1053Supports
    Secure Physical Access for Classified Equipment
  • ISM-1083Broader than
    Advise Personnel on Mobile Communication Sensitivity
  • ISM-1089Broader than
    Block Downgrading Protective Markings on Email Replies and Forwards
  • ISM-1268Supports
    Enforce Need-to-Know Access in Databases
  • ISM-1461Supports
    Same Classification and Security Domain for Shared Isolation Hosts
  • ISM-1482Depends on
    Ensure Separation of Classified and Personal Data on Devices
  • ISM-1530Supports
    Secure Classified Equipment in Suitable Security Containers
  • ISM-1599Supports
    Proper Handling of Sensitive IT Equipment
  • ISM-1719Depends on
    Colour Code for TOP SECRET Cables
  • ISM-1729Broader than
    Storage Classification of Media Waste Particles
  • ISM-1737Depends on
    Recording Required Details for Each Managed Service in the Register
  • ISM-1893Depends on
    Enforcing Multi-Factor Authentication for User Security
  • ISM-2008Supports
    Criteria for Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2046Depends on
    Ensure Secure Impersonation Logging Practices
  • ISM-2100Depends on
    Do Not View Classified Data on Mobile Devices
Annex A 5.13
Labelling of Information
Organisational controls
  • ISM-0201Broader than
    Labelling Requirements for TOP SECRET Conduits
  • ISM-0208Depends on
    Maintain a Comprehensive Cable Register
  • ISM-0218Broader than
    Label and Protect Long TS Fibre-Optic Leads
  • ISM-0240Depends on
    Prevent Sensitive Data in Messaging Services
  • ISM-0270Partially meets
    Apply Protective Markings to Emails Based on Sensitivity
  • ISM-0271Partially overlaps
    Prevent Automatic Email Marking by Protective Tools
  • ISM-0272Broader than
    Restrict Protective Marking Tools to Authorised System Markings
  • ISM-0293Partially overlaps
    Classify IT Equipment by Data Sensitivity
  • ISM-0294Partially meets
    Label IT Equipment with Sensitivity Markings
  • ISM-0296Partially overlaps
    Approval Required for High Assurance IT Equipment Labelling
  • ISM-0332Partially meets
    Label Media With Protective Markings Reflecting Sensitivity Or Classification
  • ISM-0337Supports
    Ensure Media is Used with Authorised Systems
  • ISM-0356Broader than
    Classify Magnetic Media After Sanitisation
  • ISM-0358Supports
    Classification Retention for Sanitised EPROM and EEPROM
  • ISM-0378Partially overlaps
    Remove Labels from Media Before Disposal
  • ISM-0393Depends on
    Classify Databases Based on Data Sensitivity
  • ISM-0501Supports
    Transport of Keyed Cryptographic Equipment
  • ISM-0589Depends on
    Limit Document Sensitivity on MFDs Based on Network Classification
  • ISM-0831Depends on
    Ensure Proper Handling of Sensitive Media
  • ISM-0926Broader than
    Ensure Cables Are Not Salmon Pink or Red
  • ISM-1089Broader than
    Block Downgrading Protective Markings on Email Replies and Forwards
  • ISM-1107Broader than
    Colour Restrictions for Wall Outlet Boxes
  • ISM-1216Broader than
    Ensure Correct Labelling of Non-conformant Cables
  • ISM-1535Supports
    Prevent Unsuitable Foreign Data Exports
  • ISM-2094Supports
    AI Content Filtering to Block Sensitive Data Exposure
Annex A 5.14
Information Transfer Policies and Procedures
Organisational controls
  • ISM-0072Supports
    Document Security Requirements in Contractual Arrangements
  • ISM-0109Partially meets
    Timely Analysis of Workstation Event Logs
  • ISM-0240Supports
    Prevent Sensitive Data in Messaging Services
  • ISM-0347Supports
    Use Write-Once Media for Secure Data Transfers
  • ISM-0467Supports
    Using HACE for Secure Communication of Data
  • ISM-0481Supports
    Ensure Use of High Assurance Cryptographic Protocols
  • ISM-0490Partially meets
    Ensure S/MIME 3.0 or Later is Used
  • ISM-0571Partially meets
    Ensure Secure Email Transmission via Gateways
  • ISM-0626Supports
    Implementing CDS for Secure Network Segmentation
  • ISM-0643Supports
    Use of Diodes for Unidirectional Gateway Security
  • ISM-0649Partially meets
    Filter Gateway Files for Allowed Types
  • ISM-0660Supports
    Monthly Verification of Data Transfer Logs for SECRET Systems
  • ISM-0661Partially overlaps
    User Accountability for Data Transfers
  • ISM-0663Equivalent
    Develop and Maintain Data Transfer Procedures
  • ISM-0675Partially meets
    Ensure Data Exports are Digitally Signed
  • ISM-0677Supports
    Ensure File Integrity Through Signature Validation
  • ISM-0947Supports
    Sanitise Media After Data Transfers Between Domains
  • ISM-1178Partially meets
    Limit Network Documentation for Third Parties
  • ISM-1192Supports
    Inspecting and Filtering Data with Gateways
  • ISM-1277Partially meets
    Encrypt Database and Web Server Communications
  • ISM-1284Broader than
    Ensure Content Validation for Gateway Files
  • ISM-1420Depends on
    Ensure Non-Production Security Matches Production
  • ISM-1454Supports
    Enhancing Security with Encrypted RADIUS Communications
  • ISM-1535Partially meets
    Prevent Unsuitable Foreign Data Exports
  • ISM-1574Partially overlaps
    Data Portability in Service Contracts
  • ISM-1589Partially meets
    Enable MTA-STS for Secure Email Transport
  • ISM-1594Partially meets
    Secure Delivery of User Account Credentials
  • ISM-1765Supports
    Use RSA with 3072-bit Modulus for Security
  • ISM-1779Partially overlaps
    Quarantine Data Failing Security Checks During Manual Export
  • ISM-1866Partially overlaps
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1908Supports
    Responsible Disclosure of Software Vulnerabilities
  • ISM-2097Depends on
    Configure Mobile Devices with Always On VPN
  • ISM-2098Broader than
    Prevent Data Transfer Over USB on Mobile Devices
Annex A 5.15
Access Control Policies and Procedures
Organisational controls
  • ISM-0027Depends on
    Mandatory Authorisation for System Operation
  • ISM-0217Broader than
    Secure Separation of Non-TOP SECRET and TOP SECRET Panels
  • ISM-0258Partially overlaps
    Establish and Maintain a Web Usage Policy
  • ISM-0269Broader than
    Restrict Sensitive Emails to Verified Recipients
  • ISM-0343Broader than
    Disabling Unnecessary Access to Removable Media
  • ISM-0382Broader than
    Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications
  • ISM-0405Broader than
    Validation for Unprivileged System Access Requests
  • ISM-0407Broader than
    Maintaining a Secure Lifetime Access Record for Each Human User
  • ISM-0408Depends on
    Logon Banner for Security Responsibilities
  • ISM-0409Supports
    Restricting Foreign National Access to AUSTEO and REL Systems
  • ISM-0411Broader than
    Restricting Foreign National Access to Systems Handling AGAO Data
  • ISM-0415Depends on
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0418Broader than
    Keep Physical Credentials Separate from Systems
  • ISM-0428Broader than
    Session Lock Timing, Content Blocking and Full Re-Authentication for Services
  • ISM-0430Depends on
    Same-Day Removal or Suspension of Access No Longer Required
  • ISM-0432Broader than
    Document System Access Requirements in Security Plans
  • ISM-0434Depends on
    Ensure Personnel Employment Screening and Security Clearance
  • ISM-0441Broader than
    Restricting Temporary System Access to Data Required for Duties
  • ISM-0443Broader than
    Restrict Temporary Access to Secure Systems
  • ISM-0447Broader than
    Restrict Privileged Access for Foreign Nationals
  • ISM-0484Depends on
    Configure SSH for Secure Server Access
  • ISM-0487Broader than
    Disable Certain Features for Passwordless SSH Logins
  • ISM-0489Broader than
    Four-Hour Cached SSH Private Key Lifetime and Screen Locks
  • ISM-0530Broader than
    Administer VLANs from Trusted Security Domains
  • ISM-0551Broader than
    Ensure Secure IP Telephony Device Authentication
  • ISM-0610Depends on
    Training Human Users on Secure CDS Use Before Granting Access
  • ISM-0611Broader than
    Restrict Privileges for Gateway Administrators
  • ISM-0622Broader than
    Ensuring Network Authentication via Gateways
  • ISM-0664Depends on
    Authorisation of Secret Data Exports
  • ISM-0665Broader than
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-0687Broader than
    Use Approved Platforms for Secure Mobile Access
  • ISM-0694Broader than
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0853Depends on
    Terminate Interactive User Sessions and Restart Workstations at Least Daily
  • ISM-0854Broader than
    Access Restrictions for AUSTEO and AGAO Data
  • ISM-1006Broader than
    Prevent Unauthorised Access to Network Traffic
  • ISM-1014Broader than
    Implement Individual Logins for Secure IP Phone Use
  • ISM-1053Depends on
    Secure Physical Access for Classified Equipment
  • ISM-1182Partially meets
    Implement Network Traffic Control Measures
  • ISM-1250Broader than
    Limit Server Application User Account Privileges
  • ISM-1255Broader than
    Restrict Database Content Access by User Duties and Functions
  • ISM-1256Broader than
    Implement File-Based Access Controls for Databases
  • ISM-1323Depends on
    Requiring X.509 Certificates for 802.1X Network Authentication
  • ISM-1327Partially overlaps
    Secure Certificates for Network Authentication
  • ISM-1392Broader than
    Restrict File Modifications via Path Rules
  • ISM-1403Broader than
    Lock Accounts After Five Failed Logon Attempts
  • ISM-1404Broader than
    Disabling Inactive User Access After 45 Days
  • ISM-1418Broader than
    Disable Unnecessary Removable Media Access
  • ISM-1420Supports
    Ensure Non-Production Security Matches Production
  • ISM-1432Broader than
    Protect Online Services from Domain Hijacking
  • ISM-1439Supports
    Restrict IP Disclosure in CDNs
  • ISM-1487Broader than
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1505Broader than
    Multi-factor Authentication for Human Users of Data Repositories
  • ISM-1508Broader than
    Restricting Privileged Access to What Duties Require
  • ISM-1530Broader than
    Secure Classified Equipment in Suitable Security Containers
  • ISM-1603Depends on
    Disabling Vulnerable Authentication Methods
  • ISM-1604Broader than
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1611Broader than
    Use Break Glass Accounts Only in Emergencies
  • ISM-1612Broader than
    Restricted Use of Break Glass Accounts for Emergencies
  • ISM-1633Supports
    Determine System Boundary, Criticality and Security Objectives
  • ISM-1649Broader than
    Implement Just-in-Time Administration for System Access
  • ISM-1746Broader than
    Restrict File System Permission Changes
  • ISM-1748Depends on
    Lock Email Client Security Settings Against User Changes
  • ISM-1773Depends on
    Eligibility Criteria for Gateway System Administrators
  • ISM-1813Broader than
    Prevent Unauthorised User Access to Backup Data
  • ISM-1816Depends on
    Prevent Unauthorised Changes to Software Sources
  • ISM-1832Broader than
    SPN Configuration for Active Directory Accounts
  • ISM-1839Broader than
    Secure Account Properties in Active Directory
  • ISM-1841Broader than
    Restrict Domain Joining to Admin Users Only
  • ISM-1844Broader than
    Prevent Non-Controller Accounts from Delegating Services
  • ISM-1852Broader than
    Limit Unprivileged Access to What Duties Require
  • ISM-1854Broader than
    Human Users Authenticate to MFDs Before Printing, Scanning or Copying
  • ISM-1865Depends on
    Compliance with System Usage Policies for Access
  • ISM-1866Depends on
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1888Broader than
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-1920Broader than
    Blocking MFA Self-Enrolment From Untrustworthy Devices
  • ISM-1927Broader than
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1928Broader than
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-1933Broader than
    Restrict DCSync Permissions on Service Accounts
  • ISM-1934Broader than
    Six-Monthly Review and Removal of DCSync User Permissions
  • ISM-1936Broader than
    Prevent Usage of sIDHistory in User Accounts
  • ISM-1946Broader than
    Restrict Write Access to Certificate Templates
  • ISM-1948Broader than
    Certificate Manager Approval for Templates Allowing Supplied SANs
  • ISM-1957Depends on
    Hardware Security Module Protection for Microsoft AD CS Private Keys
  • ISM-1958Broader than
    Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments
  • ISM-1985Broader than
    Protect Event Logs from Unauthorised Access
  • ISM-1990Depends on
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
  • ISM-2005Depends on
    Understanding Business Criticality of Organisation Systems
  • ISM-2014Broader than
    Ensure API Client Authentication and Authorisation
  • ISM-2048Broader than
    Restrict Non-Admins from Changing Permissions
  • ISM-2074Depends on
    Develop and Maintain AI Usage Policy
  • ISM-2080Partially overlaps
    No Password Complexity Requirements Enforced
  • ISM-2092Broader than
    Enforce Fine-Grained Permissions for AI Applications
  • ISM-2093Broader than
    Role-Based Access Controls in AI Applications
  • ISM-2095Broader than
    Block Personal Devices Granting AI Agents Access to Sensitive Systems
  • ISM-2097Depends on
    Configure Mobile Devices with Always On VPN
  • ISM-2098Broader than
    Prevent Data Transfer Over USB on Mobile Devices
  • ISM-2100Broader than
    Do Not View Classified Data on Mobile Devices
  • ISM-2112Broader than
    Disable AI Applications' Direct Access to External Public Data Sources
  • ISM-2113Depends on
    Configuring AI Applications to Require Human Approval Before High-Impact Actions
  • ISM-2124Broader than
    Restricting Service Provider Access to Approved Tools, Addresses and Time Windows
  • ISM-2126Depends on
    Positively Identify Requestors Before Actioning Account, Banking or Payment Requests
  • ISM-2128Broader than
    Limit Kernel-Mode Code Installation to Privileged Users Who Need It
  • ISM-2133Broader than
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2135Broader than
    Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent
  • ISM-2136Depends on
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2137Broader than
    Block User OAuth Consent, Reserve It for Authorised Administrators
  • ISM-2138Broader than
    Six-Monthly Review of OAuth Application Consents and Granted Permissions
  • ISM-2140Broader than
    Disable OAuth Device Code Flow Unless Required and Restrict Its Use
  • ISM-2147Depends on
    Cryptographically Bind Tokens and Session Cookies to Issuing Device
  • ISM-2149Depends on
    Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
  • ISM-2156Broader than
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
  • ISM-2157Broader than
    Agentic AI Tool Calls Limited by User Access and Task-Scoped Authorisation
  • ISM-2158Depends on
    Treat Agentic AI Retrieved External Content as Untrusted Data
  • ISM-2165Broader than
    Fresh EAP-TLS Authentication for Each New Connectivity Association Key
Annex A 5.16
Identity life cycle management
Organisational controls
  • ISM-0380Partially overlaps
    Disable Unneeded OS Accounts and Services
  • ISM-0407Supports
    Maintain Secure User Access Records
  • ISM-0414Depends on
    Uniquely Identifying Every User Granted System Access
  • ISM-0415Broader than
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0420Partially meets
    Identify Nationality of Foreign Personnel in System
  • ISM-0430Broader than
    Immediate Suspension of Unneeded System Access
  • ISM-0446Partially overlaps
    Restrict Privileged Access for Foreign Nationals
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-1263Supports
    Enforce Unique Accounts for Server Administration
  • ISM-1508Depends on
    Restricting Privileged Access to What Duties Require
  • ISM-1583Partially meets
    Ensure Contractors are Identified as Users
  • ISM-1591Partially meets
    Suspend User Access for Malicious Activity
  • ISM-1593Partially meets
    Verifying User Identity for New Credentials
  • ISM-1619Partially meets
    Configure Service Accounts as Managed Service Accounts
  • ISM-1834Partially meets
    Ensure No Duplicate SPNs in Active Directory
  • ISM-1845Broader than
    Disable User Security Group Access in Active Directory
  • ISM-1920Broader than
    Blocking MFA Self-Enrolment From Untrustworthy Devices
  • ISM-1927Depends on
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1932Supports
    Limit Service Accounts with SPNs in Active Directory
  • ISM-1934Broader than
    Six-Monthly Review and Removal of DCSync User Permissions
  • ISM-1943Broader than
    Enforce Certificate and User Mapping in AD Services
  • ISM-1945Partially meets
    Remove Enrollee Supplies Subject Flag from Templates
  • ISM-1950Supports
    Disable Soft Matching After Synchronisation
  • ISM-1951Partially meets
    Disable Hard Match Takeover in Microsoft Entra Connect
  • ISM-2013Supports
    Ensure Client Authentication for Internal Network APIs
  • ISM-2047Broader than
    Secondary-Channel Notification of Authentication Factor Resets
  • ISM-2053Partially overlaps
    End of Life Procedures for Software
  • ISM-2133Broader than
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2136Depends on
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2145Broader than
    Revoke User Account Credentials When No Longer Required
  • ISM-2146Partially overlaps
    Revoking Static Application and Workload Credentials When No Longer Required
  • ISM-2148Broader than
    Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In
  • ISM-2156Depends on
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
Annex A 5.17
Management of Authentication Information
Organisational controls
  • ISM-0383Partially overlaps
    Change Default OS User Accounts During Setup
  • ISM-0411Depends on
    Restricting Foreign National Access to Systems Handling AGAO Data
  • ISM-0414Depends on
    Uniquely Identifying Every User Granted System Access
  • ISM-0417Partially meets
    Use Passwords When Multi-Factor Authentication Isn't Supported
  • ISM-0421Partially overlaps
    Require Minimum 15-Character Passwords for Security
  • ISM-0422Partially overlaps
    Ensuring Strong Passwords for TOP SECRET Systems
  • ISM-0485Broader than
    Use Public Key Authentication for SSH Access
  • ISM-0553Partially overlaps
    Authenticate Video Calls and Manage Settings
  • ISM-0554Supports
    Secure Two-Way Authentication for Video Calls
  • ISM-0555Partially overlaps
    Ensure Authentication for IP Telephony Actions
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-0974Depends on
    Multi-Factor Authentication for Unprivileged Human Users of Systems
  • ISM-1014Broader than
    Implement Individual Logins for Secure IP Phone Use
  • ISM-1321Supports
    Implement EAP-TLS for Secure Wireless Authentication
  • ISM-1323Depends on
    Requiring X.509 Certificates for 802.1X Network Authentication
  • ISM-1324Depends on
    Generating X.509 Certificates With Evaluated CA or HSM
  • ISM-1327Partially overlaps
    Secure Certificates for Network Authentication
  • ISM-1401Supports
    Multi-Factor Authentication Combines Possession With Knowledge or Inherence
  • ISM-1402Partially overlaps
    Protecting Stored Credentials with Security Measures
  • ISM-1449Partially overlaps
    Protect SSH Private Keys with Passwords or Encryption
  • ISM-1505Supports
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1546Depends on
    Ensure User Authentication Before System Access
  • ISM-1557Partially overlaps
    Ensure Strong Passwords for SECRET Systems
  • ISM-1558Partially overlaps
    Ensure Secure Construction of Passwords
  • ISM-1559Partially overlaps
    Minimum Password Length for Secure Systems
  • ISM-1560Depends on
    Ensure Strong Passwords for SECRET System Authentication
  • ISM-1561Partially overlaps
    Ensure Strong Passwords for TOP SECRET Systems
  • ISM-1593Partially overlaps
    Verify User Identity Before Issuing, Resetting, Disabling or Enrolling Credentials
  • ISM-1594Broader than
    Delivering User Credentials via Secure Channel or Split Parts
  • ISM-1595Broader than
    Credentials Issued to Human Users Are Changed on First Use
  • ISM-1596Partially overlaps
    Avoid Reusing Credentials Across Systems
  • ISM-1597Partially overlaps
    Ensuring Credential Input Obscurity
  • ISM-1603Depends on
    Disabling Vulnerable Authentication Methods
  • ISM-1611Depends on
    Use Break Glass Accounts Only in Emergencies
  • ISM-1614Broader than
    Manage Emergency Account Access Changes
  • ISM-1615Depends on
    Testing Break Glass Accounts Post Credential Change
  • ISM-1679Depends on
    Multi-factor Authentication for Third-party Services Handling Sensitive Data
  • ISM-1685Partially overlaps
    Strengthening Passwords for Critical Accounts
  • ISM-1817Depends on
    Secure API Access with Authentication and Authorisation
  • ISM-1818Depends on
    Client Authentication for Network API Access
  • ISM-1840Broader than
    Prevent Reversible Encryption of User Passwords
  • ISM-1854Supports
    Require User Authentication for Multifunction Devices
  • ISM-1875Broader than
    Monthly System Scans to Detect Credentials Stored in the Clear
  • ISM-1888Broader than
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-1892Depends on
    Multi-Factor Authentication for Organisation Users of Online Customer Services
  • ISM-1893Supports
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1894Supports
    Ensuring Phishing-Resistant Multi-factor Authentication
  • ISM-1920Broader than
    Blocking MFA Self-Enrolment From Untrustworthy Devices
  • ISM-1929Supports
    Ensure LDAP Signing on AD DS Domain Controllers
  • ISM-1930Broader than
    Prevent Storing Passwords in Group Policy Preferences
  • ISM-1943Depends on
    Enforce Certificate and User Mapping in AD Services
  • ISM-1953Broader than
    Ensure Strong Management of Admin Account Credentials
  • ISM-1955Partially overlaps
    Regularly Change Compromised Credentials
  • ISM-1957Depends on
    Hardware Security Module Protection for Microsoft AD CS Private Keys
  • ISM-2011Broader than
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
  • ISM-2013Supports
    Ensure Client Authentication for Internal Network APIs
  • ISM-2030Depends on
    Commit-Time Scanning Blocks Secrets From Source Repositories
  • ISM-2044Broader than
    Prevent Default Credentials in Software Installations
  • ISM-2047Partially overlaps
    Notify Users of Authentication Resets via Secondary Channel
  • ISM-2076Broader than
    Eliminating Security Questions for Authentication
  • ISM-2078Partially overlaps
    Ensure Passwords Are Not Common or Compromised
  • ISM-2079Partially overlaps
    Ensure Password Length is at Least 64 Characters
  • ISM-2080Partially overlaps
    No Password Complexity Requirements Enforced
  • ISM-2109Partially overlaps
    Pre-Boot Authentication for Encrypted System Volume Media
  • ISM-2126Depends on
    Positively Identify Requestors Before Actioning Account, Banking or Payment Requests
  • ISM-2130Partially overlaps
    Disabling or Hardening AD CS Web Enrolment Interfaces
  • ISM-2133Depends on
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2135Partially overlaps
    Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent
  • ISM-2136Supports
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2140Partially overlaps
    Disable OAuth Device Code Flow Unless Required and Restrict Its Use
  • ISM-2141Broader than
    Prefer Short-Lived Dynamically Issued Credentials for Applications and Workloads
  • ISM-2142Broader than
    Central Management of Application and Workload Credentials
  • ISM-2143Broader than
    Unique Per-Application Credentials Not Shared Across Environments
  • ISM-2144Broader than
    Change Application Static Credentials Found Compromised or Exposed in Clear
  • ISM-2145Partially overlaps
    Revoke User Account Credentials When No Longer Required
  • ISM-2146Broader than
    Revoking Static Application and Workload Credentials When No Longer Required
  • ISM-2148Broader than
    Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In
  • ISM-2165Depends on
    Fresh EAP-TLS Authentication for Each New Connectivity Association Key
Annex A 5.18
Managing Access Rights to Information Assets
Organisational controls
  • ISM-0133Supports
    Responding to Data Spills by Restricting Access
  • ISM-0269Broader than
    Restrict Sensitive Emails to Verified Recipients
  • ISM-0405Broader than
    Validation for Unprivileged System Access Requests
  • ISM-0407Broader than
    Maintaining a Secure Lifetime Access Record for Each Human User
  • ISM-0409Partially meets
    Restrict Foreign Nationals' Access to Sensitive Data
  • ISM-0411Broader than
    Restricting Foreign National Access to Systems Handling AGAO Data
  • ISM-0414Supports
    Ensure Unique Identification for System Access
  • ISM-0415Partially overlaps
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0430Partially meets
    Immediate Suspension of Unneeded System Access
  • ISM-0432Depends on
    Document System Access Requirements in Security Plans
  • ISM-0441Partially overlaps
    Restricting Temporary System Access to Data Required for Duties
  • ISM-0443Broader than
    Restrict Temporary Access to Secure Systems
  • ISM-0446Partially overlaps
    Restrict Privileged Access for Foreign Nationals
  • ISM-0555Partially overlaps
    Ensure Authentication for IP Telephony Actions
  • ISM-0610Depends on
    Training Human Users on Secure CDS Use Before Granting Access
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-1199Partially overlaps
    Remove Unnecessary Bluetooth Pairings on Devices
  • ISM-1255Broader than
    Restrict Database User Access Based on Duties
  • ISM-1263Depends on
    Enforce Unique Accounts for Server Administration
  • ISM-1268Supports
    Enforce Need-to-Know Access in Databases
  • ISM-1327Broader than
    Access Controls, Encryption and User Authentication for X.509 Certificates
  • ISM-1392Broader than
    Restrict File Modifications via Path Rules
  • ISM-1404Broader than
    Disabling Inactive User Access After 45 Days
  • ISM-1422Depends on
    Prevent Unauthorised Access to Software Source
  • ISM-1432Broader than
    Protect Online Services from Domain Hijacking
  • ISM-1487Broader than
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1583Depends on
    Ensure Contractors are Identified as Users
  • ISM-1590Broader than
    Changing User Account Credentials After Compromise, Exposure or Shared Membership Change
  • ISM-1591Partially meets
    Suspend User Access for Malicious Activity
  • ISM-1592Depends on
    Restrict Unprivileged Users From Installing Unapproved Applications
  • ISM-1593Supports
    Verifying User Identity for New Credentials
  • ISM-1604Depends on
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1612Partially overlaps
    Restricted Use of Break Glass Accounts for Emergencies
  • ISM-1647Partially meets
    Disable Privileged Access After 12 Months
  • ISM-1648Broader than
    Disabling Inactive Privileged Access to Systems
  • ISM-1649Broader than
    Implement Just-in-Time Administration for System Access
  • ISM-1812Broader than
    Restrict Backup Access to Unprivileged Users
  • ISM-1833Partially overlaps
    Limit Privileges for User Accounts in Active Directory
  • ISM-1841Supports
    Restrict Domain Joining to Admin Users Only
  • ISM-1843Broader than
    Annual Review of Unconstrained Delegation in AD Accounts
  • ISM-1844Partially meets
    Prevent Non-Controller Accounts from Delegating Services
  • ISM-1845Broader than
    Disable User Security Group Access in Active Directory
  • ISM-1846Broader than
    Restrict Pre-Windows 2000 Access Group Membership
  • ISM-1852Broader than
    Limit Unprivileged Access to What Duties Require
  • ISM-1854Depends on
    Human Users Authenticate to MFDs Before Printing, Scanning or Copying
  • ISM-1927Broader than
    Restrict Access to Microsoft Active Directory Servers
  • ISM-1932Partially meets
    Limit Service Accounts with SPNs in Active Directory
  • ISM-1933Broader than
    Restrict DCSync Permissions on Service Accounts
  • ISM-1934Broader than
    Six-Monthly Review and Removal of DCSync User Permissions
  • ISM-1936Partially meets
    Prevent Usage of sIDHistory in User Accounts
  • ISM-1940Broader than
    Restrict Service Accounts from Privileged Groups
  • ISM-1946Broader than
    Restrict Write Access to Certificate Templates
  • ISM-1948Depends on
    Certificate Manager Approval for Templates Allowing Supplied SANs
  • ISM-1958Broader than
    Block DCSync-Permitted Accounts From Logging On To Unprivileged Environments
  • ISM-2005Supports
    Understanding Business Criticality of Organisation Systems
  • ISM-2013Supports
    Ensure Client Authentication for Internal Network APIs
  • ISM-2048Supports
    Restrict Non-Admins from Changing Permissions
  • ISM-2049Broader than
    Enforcing Re-authentication After Permission Changes
  • ISM-2092Broader than
    Enforce Fine-Grained Permissions for AI Applications
  • ISM-2093Partially overlaps
    Role-Based Access Controls in AI Applications
  • ISM-2095Broader than
    Block Personal Devices Granting AI Agents Access to Sensitive Systems
  • ISM-2124Partially overlaps
    Restricting Service Provider Access to Approved Tools, Addresses and Time Windows
  • ISM-2126Partially overlaps
    Positively Identify Requestors Before Actioning Account, Banking or Payment Requests
  • ISM-2131Depends on
    Quarterly Certificate Template Reviews to Remediate Misconfigurations
  • ISM-2133Depends on
    Assign Each AI Agent a Unique Identity Distinct from Personnel Accounts
  • ISM-2135Depends on
    Recording Identifier, Owner, Identities, Credentials and Access for Each AI Agent
  • ISM-2136Partially overlaps
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2137Broader than
    Block User OAuth Consent, Reserve It for Authorised Administrators
  • ISM-2138Equivalent
    Six-Monthly Review of OAuth Application Consents and Granted Permissions
  • ISM-2146Broader than
    Revoking Static Application and Workload Credentials When No Longer Required
  • ISM-2156Broader than
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
  • ISM-2158Depends on
    Treat Agentic AI Retrieved External Content as Untrusted Data
Annex A 5.19
Managing Information Security in Supplier Relationships
Organisational controls
  • ISM-0072Partially overlaps
    Document Security Requirements in Contractual Arrangements
  • ISM-0141Partially meets
    Report Cyber Incidents Promptly to Designated Contacts
  • ISM-0280Partially meets
    Choose PP-evaluated Products Over EAL-based Ones
  • ISM-0285Partially meets
    Ensuring Evaluated Products Follow Delivery Procedures
  • ISM-0307Partially overlaps
    Sanitise Equipment When Not Using Cleared Technician
  • ISM-0731Partially meets
    CISO Oversight of Cyber Supply Chain Risks
  • ISM-0824Partially overlaps
    Avoid Using Unauthorised Online File Services
  • ISM-0840Partially meets
    Certified Services for Outsourced Media Destruction
  • ISM-1073Partially meets
    Ensure Provider Contracts for System Access
  • ISM-1178Supports
    Limit Network Documentation for Third Parties
  • ISM-1195Supports
    Enforce Policy with Evaluated Mobile Device Management
  • ISM-1203Supports
    Risk Assessment for System Security
  • ISM-1395Partially overlaps
    Ensuring Data Protection by Service Providers
  • ISM-1451Partially meets
    Document Data Ownership in Service Contracts
  • ISM-1452Partially meets
    Perform Supply Chain Risk Assessments for System Suppliers
  • ISM-1480Supports
    Ensure High Assurance for Peripheral Switches
  • ISM-1535Supports
    Prevent Unsuitable Foreign Data Exports
  • ISM-1567Partially meets
    Avoid High-Risk Suppliers in Cyber Supply Chain
  • ISM-1568Broader than
    Ensure Security Commitment from Suppliers
  • ISM-1569Partially overlaps
    Document and Share a Supplier Customer Shared Responsibility Model
  • ISM-1570Partially overlaps
    Regular IRAP Assessment of Cloud Service Providers
  • ISM-1571Partially meets
    Verify Security Compliance in Service Contracts
  • ISM-1572Partially meets
    Document Service Provider Data Handling and Change Notifications
  • ISM-1573Partially meets
    Log Access Documentation with Service Providers
  • ISM-1574Supports
    Data Portability in Service Contracts
  • ISM-1575Partially meets
    One-Month Notice for Service Termination
  • ISM-1576Partially overlaps
    Notify Organisation of Unauthorised System Access
  • ISM-1577Supports
    Ensure Network Segregation from Service Providers
  • ISM-1631Supports
    Identify Suppliers in Cyber Supply Chain
  • ISM-1632Partially meets
    Ensure Secure Procurement from Reliable Suppliers
  • ISM-1637Supports
    Maintain an Outsourced Cloud Service Register
  • ISM-1638Supports
    Maintain a Comprehensive Outsourced Cloud Service Register
  • ISM-1736Supports
    Maintain and Verify Managed Service Register
  • ISM-1737Supports
    Maintain a Comprehensive Managed Service Register
  • ISM-1738Partially overlaps
    Verify Compliance with Security Requirements
  • ISM-1756Supports
    Develop and Maintain Vulnerability Disclosure Processes
  • ISM-1785Partially overlaps
    Develop and Maintain Supplier Management Policy
  • ISM-1786Partially meets
    Maintain an Approved Supplier List
  • ISM-1787Partially meets
    Ensure Suppliers are Approved for IT and OT Sourcing
  • ISM-1788Partially meets
    Identify Multiple Suppliers for Critical IT Sourcing
  • ISM-1789Broader than
    Maintain Reserve Spares of Critical IT and OT Equipment
  • ISM-1790Partially meets
    Ensure Integrity in IT and OT Deliveries
  • ISM-1791Partially meets
    Assess Integrity of Delivered IT and OT Products
  • ISM-1793Supports
    Regular Assessment of Managed Service Providers
  • ISM-1794Partially meets
    Notify Significant Changes to Service Provider Agreements
  • ISM-1797Supports
    Ensure Software Updates are Securely Signed
  • ISM-1800Partially meets
    Ensure Network Devices Have Trusted Firmware
  • ISM-1804Partially meets
    Include Break Clauses in Cloud Service Contracts
  • ISM-1826Broader than
    Select Vendors Committed to Secure Design for Servers
  • ISM-1882Partially meets
    Procurement from Transparent Suppliers
  • ISM-1972Partially overlaps
    Security Assessments for Top Secret Cloud Services
  • ISM-2008Partially meets
    Criteria for Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2027Supports
    Verify Software Artefacts with Digital Signatures
  • ISM-2082Partially meets
    Using Cryptographic BOM in Software Development
  • ISM-2088Supports
    Ensure Accuracy of AI Model Training Data
Annex A 5.20
Integrating security clauses in supplier agreements
Organisational controls
  • ISM-0072Equivalent
    Document Security Requirements in Contractual Arrangements
  • ISM-0141Partially meets
    Report Cyber Incidents Promptly to Designated Contacts
  • ISM-0731Broader than
    CISO Oversight of Cyber Supply Chain Risks
  • ISM-1178Partially overlaps
    Limit Network Documentation for Third Parties
  • ISM-1395Depends on
    Ensuring Data Protection by Service Providers
  • ISM-1451Broader than
    Document Data Ownership in Service Contracts
  • ISM-1568Partially overlaps
    Ensure Security Commitment from Suppliers
  • ISM-1569Partially overlaps
    Document and Share a Supplier Customer Shared Responsibility Model
  • ISM-1571Broader than
    Verify Security Compliance in Service Contracts
  • ISM-1572Partially meets
    Document Service Provider Data Handling and Change Notifications
  • ISM-1575Partially meets
    One-Month Notice for Service Termination
  • ISM-1576Supports
    Treating Unauthorised Service Provider Access as a Reportable Incident
  • ISM-1631Depends on
    Identify Suppliers in Cyber Supply Chain
  • ISM-1737Supports
    Maintain a Comprehensive Managed Service Register
  • ISM-1738Partially meets
    Verify Compliance with Security Requirements
  • ISM-1785Supports
    Develop and Maintain Supplier Management Policy
  • ISM-1786Partially meets
    Maintain an Approved Supplier List
  • ISM-1788Depends on
    Identify Multiple Suppliers for Critical IT Sourcing
  • ISM-1793Depends on
    Regular Assessment of Managed Service Providers
  • ISM-1794Partially meets
    Notify Significant Changes to Service Provider Agreements
  • ISM-1804Partially meets
    Include Break Clauses in Cloud Service Contracts
  • ISM-1882Partially overlaps
    Procurement from Transparent Suppliers
  • ISM-2033Partially overlaps
    Document and Maintain Software Security Requirements
  • ISM-2088Supports
    Ensure Accuracy of AI Model Training Data
Annex A 5.21
Managing Information Security in the ICT Supply Chain
Organisational controls
  • ISM-0039Partially overlaps
    Develop and Maintain a Cyber Security Strategy
  • ISM-0072Partially meets
    Document Security Requirements in Contractual Arrangements
  • ISM-0280Broader than
    Choose PP-evaluated Products Over EAL-based Ones
  • ISM-0285Broader than
    Ensuring Evaluated Products Follow Delivery Procedures
  • ISM-0286Partially overlaps
    Consult ASD for High Assurance IT Delivery Procedures
  • ISM-0305Partially overlaps
    On-Site IT Equipment Maintenance by Cleared Technicians
  • ISM-0310Depends on
    Off-Site IT Equipment Handling Approvals
  • ISM-0629Depends on
    Manage Gateways Between Different Security Domains
  • ISM-0731Broader than
    CISO Oversight of Cyber Supply Chain Risks
  • ISM-0840Broader than
    Certified Services for Outsourced Media Destruction
  • ISM-0938Broader than
    Select Secure-by-Design Committed Vendors
  • ISM-1073Partially overlaps
    Ensure Provider Contracts for System Access
  • ISM-1195Depends on
    Enforce Policy with Evaluated Mobile Device Management
  • ISM-1203Depends on
    Risk Assessment for System Security
  • ISM-1395Broader than
    Ensuring Data Protection by Service Providers
  • ISM-1452Equivalent
    Perform Supply Chain Risk Assessments for System Suppliers
  • ISM-1535Depends on
    Prevent Unsuitable Foreign Data Exports
  • ISM-1567Broader than
    Avoid High-Risk Suppliers in Cyber Supply Chain
  • ISM-1568Broader than
    Ensure Security Commitment from Suppliers
  • ISM-1570Partially overlaps
    Regular IRAP Assessment of Cloud Service Providers
  • ISM-1631Supports
    Identify Suppliers in Cyber Supply Chain
  • ISM-1632Broader than
    Ensure Secure Procurement from Reliable Suppliers
  • ISM-1638Depends on
    Outsourced Cloud Service Register Recording Eight Required Details
  • ISM-1736Depends on
    Maintain and Verify Managed Service Register
  • ISM-1737Broader than
    Maintain a Comprehensive Managed Service Register
  • ISM-1738Partially overlaps
    Verify Compliance with Security Requirements
  • ISM-1743Broader than
    Choose Secure Operating System Vendors
  • ISM-1786Broader than
    Maintain an Approved Supplier List
  • ISM-1787Broader than
    Ensure Suppliers are Approved for IT and OT Sourcing
  • ISM-1788Broader than
    Identify Multiple Suppliers for Critical IT Sourcing
  • ISM-1789Partially meets
    Maintain Reserve Spares of Critical IT and OT Equipment
  • ISM-1790Broader than
    Ensure Integrity in IT and OT Deliveries
  • ISM-1791Broader than
    Assess Integrity of Delivered IT and OT Products
  • ISM-1792Broader than
    Assess Authenticity of IT and OT Deliveries
  • ISM-1797Depends on
    Ensure Software Updates are Securely Signed
  • ISM-1800Broader than
    Ensure Network Devices Have Trusted Firmware
  • ISM-1804Partially meets
    Include Break Clauses in Cloud Service Contracts
  • ISM-1826Broader than
    Select Vendors Committed to Secure Design for Servers
  • ISM-1882Broader than
    Procurement from Transparent Suppliers
  • ISM-1972Partially overlaps
    Security Assessments for Top Secret Cloud Services
  • ISM-2023Broader than
    Maintain a Reliable Source for Software
  • ISM-2026Depends on
    Scan Software Artefacts for Malicious Content
  • ISM-2027Depends on
    Verify Software Artefacts with Digital Signatures
  • ISM-2073Depends on
    Develop a Post-Quantum Cryptography Transition Plan
  • ISM-2082Broader than
    Using Cryptographic BOM in Software Development
  • ISM-2083Depends on
    Provide a Cryptographic Bill of Materials to Software Users
  • ISM-2086Broader than
    Verify Integrity of AI Models, Structures, and Weights
  • ISM-2087Partially overlaps
    Verify the Source and Integrity of AI Training Data
  • ISM-2088Depends on
    Ensure Accuracy of AI Model Training Data
  • ISM-2124Depends on
    Restricting Service Provider Access to Approved Tools, Addresses and Time Windows
  • ISM-2125Depends on
    Independently Log and Analyse All Service Provider System Access
  • ISM-2154Broader than
    Pinning Software Artefact Dependencies to Approved Versions in Source Code
  • ISM-2155Depends on
    Reproducible Builds Enabling Independent Verification of Release Artefacts
Annex A 5.22
Monitoring and Managing Supplier Services
Organisational controls
  • ISM-0009Depends on
    System Owners Identify Supplementary Controls With Authorising Officer
  • ISM-0072Depends on
    Document Security Requirements in Contractual Arrangements
  • ISM-0280Supports
    Choose PP-evaluated Products Over EAL-based Ones
  • ISM-0310Supports
    Off-Site IT Equipment Handling Approvals
  • ISM-0629Supports
    Manage Gateways Between Different Security Domains
  • ISM-0731Partially meets
    CISO Oversight of Cyber Supply Chain Risks
  • ISM-1073Partially overlaps
    Ensure Provider Contracts for System Access
  • ISM-1395Partially overlaps
    Ensuring Data Protection by Service Providers
  • ISM-1452Partially overlaps
    Perform Supply Chain Risk Assessments for System Suppliers
  • ISM-1567Supports
    Avoid High-Risk Suppliers in Cyber Supply Chain
  • ISM-1570Partially overlaps
    Regular IRAP Assessment of Cloud Service Providers
  • ISM-1571Supports
    Verify Security Compliance in Service Contracts
  • ISM-1631Depends on
    Identify Suppliers in Cyber Supply Chain
  • ISM-1637Supports
    Maintain an Outsourced Cloud Service Register
  • ISM-1638Supports
    Maintain a Comprehensive Outsourced Cloud Service Register
  • ISM-1736Supports
    Maintain and Verify Managed Service Register
  • ISM-1737Supports
    Maintain a Comprehensive Managed Service Register
  • ISM-1738Partially overlaps
    Verify Compliance with Security Requirements
  • ISM-1743Partially meets
    Choose Secure Operating System Vendors
  • ISM-1786Partially meets
    Maintain an Approved Supplier List
  • ISM-1787Supports
    Ensure Suppliers are Approved for IT and OT Sourcing
  • ISM-1790Supports
    Ensure Integrity in IT and OT Deliveries
  • ISM-1793Supports
    Regular Assessment of Managed Service Providers
  • ISM-1794Partially meets
    Notify Significant Changes to Service Provider Agreements
  • ISM-1826Broader than
    Select Vendors Committed to Secure Design for Servers
  • ISM-1882Partially overlaps
    Procurement from Transparent Suppliers
  • ISM-1893Supports
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1972Partially overlaps
    ASD Security Control Assessment of TOP SECRET Cloud Services Every 24 Months
  • ISM-2029Supports
    Restrict Third-Party Libraries to Trustworthy Sources
  • ISM-2124Depends on
    Restricting Service Provider Access to Approved Tools, Addresses and Time Windows
  • ISM-2125Depends on
    Independently Log and Analyse All Service Provider System Access
  • ISM-2155Depends on
    Reproducible Builds Enabling Independent Verification of Release Artefacts
Annex A 5.23
Cloud Service Security Management
Organisational controls
  • ISM-0043Depends on
    Cyber Security Incident Response Plan Requirements
  • ISM-0576Supports
    Develop and Maintain Cyber Security Incident Plans
  • ISM-1529Partially overlaps
    Limit Cloud Services to Community or Private for SECRETS
  • ISM-1638Supports
    Maintain a Comprehensive Outsourced Cloud Service Register
  • ISM-1909Partially overlaps
    Perform Root Cause Analysis for Vulnerabilities
Annex A 5.24
Information security incident management planning and preparation
Organisational controls
  • ISM-0039Partially overlaps
    Develop and Maintain a Cyber Security Strategy
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Partially meets
    Report Cyber Security Incidents Promptly
  • ISM-0125Broader than
    Maintaining a Cyber Security Incident Register
  • ISM-0137Supports
    Seek Legal Advice for Intrusion Evidence Collection
  • ISM-0714Partially overlaps
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-0726Supports
    Coordinate Security Risk Management Activities
  • ISM-0733Partially overlaps
    Ensure CISO Awareness of Cyber Incidents
  • ISM-1019Broader than
    Develop a Denial of Service Response Plan
  • ISM-1088Partially meets
    Report Potential Compromises of Mobile Devices Overseas
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1556Depends on
    Security Measures After Overseas Travel with Mobile Devices
  • ISM-1576Partially overlaps
    Notify Organisation of Unauthorised System Access
  • ISM-1618Partially overlaps
    CISO's Role in Cyber Security Incident Response
  • ISM-1625Partially overlaps
    Develop Insider Threat Mitigation Programs
  • ISM-1717Depends on
    Implement Security.txt for Vulnerability Disclosure
  • ISM-1731Broader than
    Plan and Coordinate Intrusion Remediation From Trusted Separate Systems
  • ISM-1756Partially overlaps
    Develop and Maintain Vulnerability Disclosure Processes
  • ISM-1784Partially overlaps
    Annual Testing of Cyber Incident Response Plan
  • ISM-1819Broader than
    Enact Cyber Security Incident Response Plans
  • ISM-1881Supports
    Timely Reporting of Cyber Incidents Without Data Breach
  • ISM-1908Depends on
    Responsible Disclosure of Software Vulnerabilities
  • ISM-1997Partially overlaps
    Define Cyber Security Roles for Leadership
  • ISM-2006Partially overlaps
    Board Plans for Major Cyber Security Incidents
Annex A 5.25
Assessment and decision on information security events
Organisational controls
  • ISM-0043Supports
    Cyber Security Incident Response Plan Requirements
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Equivalent
    Analyse Cyber Security Events Promptly
  • ISM-1784Supports
    Annual Testing of Cyber Incident Response Plan
  • ISM-2116Depends on
    Use Cyber Threat Intelligence for Event Detection
  • ISM-2125Depends on
    Independently Log and Analyse All Service Provider System Access
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2148Partially overlaps
    Revoke Sessions and Tokens on Reset, Compromise, Non-Compliance or Risky Sign-In
Annex A 5.26
Response to Information Security Incidents
Organisational controls
  • ISM-0043Supports
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Supports
    Report Cyber Security Incidents Promptly
  • ISM-0137Supports
    Seek Legal Advice for Intrusion Evidence Collection
  • ISM-0138Depends on
    Maintaining Integrity of Evidence in Investigations
  • ISM-0576Supports
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0917Partially meets
    Procedures for Handling Malicious Code Infections
  • ISM-1213Supports
    Analyse Network Traffic Post-Intrusion Remediation
  • ISM-1300Partially meets
    Mobile Device Security After Overseas Travel
  • ISM-1591Supports
    Suspend User Access for Malicious Activity
  • ISM-1609Broader than
    Consult System Owners Before Continuing Intrusions
  • ISM-1618Supports
    CISO's Role in Cyber Security Incident Response
  • ISM-1731Broader than
    Plan and Coordinate Intrusion Remediation From Trusted Separate Systems
  • ISM-1732Partially overlaps
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-1784Supports
    Annual Testing of Cyber Incident Response Plan
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
  • ISM-1880Depends on
    Timely Reporting of Cyber Incidents Involving Customer Data
  • ISM-1955Supports
    Regularly Change Compromised Credentials
  • ISM-1956Partially overlaps
    Regularly Update AD FS Certificates to Prevent Risks
  • ISM-2006Depends on
    Board Plans for Major Cyber Security Incidents
  • ISM-2104Depends on
    Do Not Post Security Clearance and Briefing Details Online
  • ISM-2106Partially overlaps
    Advise Staff to Limit Posting Work Skills Online
Annex A 5.27
Learning from information security incidents
Organisational controls
  • ISM-0043Supports
    Cyber Security Incident Response Plan Requirements
  • ISM-0125Supports
    Maintaining a Cyber Security Incident Register
  • ISM-0576Supports
    Develop and Maintain Cyber Security Incident Plans
Annex A 5.28
Procedures for Collecting and Preserving Evidence
Organisational controls
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0137Partially overlaps
    Seek Legal Advice for Intrusion Evidence Collection
  • ISM-0138Partially overlaps
    Maintaining Integrity of Evidence in Investigations
  • ISM-0580Partially overlaps
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0585Supports
    Capture Detailed Information in Event Logs
  • ISM-0660Supports
    Monthly Verification of Data Transfer Logs for SECRET Systems
  • ISM-0917Supports
    Procedures for Handling Malicious Code Infections
  • ISM-0988Supports
    Ensure Accurate Time Source for Event Logs
  • ISM-1019Supports
    Develop a Denial of Service Response Plan
  • ISM-1213Depends on
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1537Depends on
    Log Security-Relevant Database Events Centrally
  • ISM-1566Supports
    Central Logging of Unprivileged System Access
  • ISM-1609Partially overlaps
    Consult System Owners Before Continuing Intrusions
  • ISM-1618Depends on
    CISO's Role in Cyber Security Incident Response
  • ISM-1623Supports
    Centralised Logging of PowerShell Activities
  • ISM-1624Supports
    Protect PowerShell Script Block Logs
  • ISM-1625Supports
    Develop Insider Threat Mitigation Programs
  • ISM-1683Supports
    Central Logging of Multi-factor Authentication Events
  • ISM-1731Supports
    Coordinate Intrusion Remediation on Separate Systems
  • ISM-1732Depends on
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-1784Supports
    Annual Testing of Cyber Incident Response Plan
  • ISM-1805Supports
    Develop a Denial of Service Response Plan
  • ISM-1819Depends on
    Enact Cyber Security Incident Response Plans
  • ISM-1855Supports
    Central Logging of Multifunction Device Use
  • ISM-1964Supports
    Central Logging for Network Device Events
  • ISM-1976Supports
    Central Logging of Security Events on macOS
  • ISM-1984Supports
    Encrypt Event Logs in Transit Using ASD Cryptography
  • ISM-1988Supports
    Ensure Event Logs Are Retained for 12 Months
  • ISM-2051Partially overlaps
    Ensure Event Logs for Cybersecurity Event Detection
  • ISM-2089Supports
    Monitor AI Model Performance and Investigate Anomalies
  • ISM-2125Depends on
    Independently Log and Analyse All Service Provider System Access
  • ISM-2159Depends on
    Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
Annex A 5.29
Maintain information security during disruptions
Organisational controls
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0570Depends on
    Maintain Backup Email Gateways to Primary Standards
  • ISM-0576Partially overlaps
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0734Partially overlaps
    CISO Role in Disaster Recovery Planning
  • ISM-1123Depends on
    Ensure UPS Powers All Top Secret IT Equipment
  • ISM-1732Depends on
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-2006Depends on
    Board Plans for Major Cyber Security Incidents
Annex A 5.30
ICT Readiness for Business Continuity
Organisational controls
  • ISM-0570Depends on
    Maintain Backup Email Gateways to Primary Standards
  • ISM-0734Broader than
    CISO Role in Disaster Recovery Planning
  • ISM-1019Partially meets
    Develop a Denial of Service Response Plan
  • ISM-1123Supports
    Ensure UPS Powers All Top Secret IT Equipment
  • ISM-1431Partially overlaps
    Strategies for Mitigating Denial-of-Service Attacks
  • ISM-1437Supports
    Utilising Cloud Providers for Hosting Online Services
  • ISM-1438Broader than
    Ensure High Availability by Using CDNs
  • ISM-1511Partially overlaps
    Conduct and Maintain Regular Data Backups
  • ISM-1547Partially overlaps
    Develop and Maintain Data Backup Procedures
  • ISM-1548Depends on
    Develop and Maintain Data Restoration Processes
  • ISM-1580Partially overlaps
    Ensure High Availability for Online Services
  • ISM-1610Broader than
    Document and Test Emergency System Access Procedures
  • ISM-1615Depends on
    Testing Break Glass Accounts Post Credential Change
  • ISM-1633Supports
    Determine System Boundary, Criticality and Security Objectives
  • ISM-1732Supports
    Coordinated Intrusion Remediation During Planned Outages
  • ISM-1805Partially overlaps
    Develop a Denial of Service Response Plan
Annex A 5.31
Compliance with Information Security Legal Requirements
Organisational controls
  • ISM-0009Depends on
    System Owners Identify Supplementary Controls With Authorising Officer
  • ISM-0041Supports
    Develop a Detailed System Security Plan
  • ISM-0047Depends on
    Approval Process for Cyber Security Documentation
  • ISM-0137Supports
    Seek Legal Advice for Intrusion Evidence Collection
  • ISM-0181Depends on
    Ensure Cabling Meets Australian Standards
  • ISM-0499Depends on
    Ensure Compliance with ASD Communication Security Policies
  • ISM-1478Supports
    CISO Management of Cyber Security Compliance
  • ISM-1571Depends on
    Verify Security Compliance in Service Contracts
  • ISM-1626Depends on
    Seek Legal Advice for Insider Threat Plans
  • ISM-1880Depends on
    Timely Reporting of Cyber Incidents Involving Customer Data
  • ISM-2002Supports
    Ensure Board Cyber Security Literacy for Compliance
  • ISM-2008Supports
    Criteria for Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2033Supports
    Document and Maintain Software Security Requirements
Annex A 5.32
Intellectual Property Rights Protection
Organisational controls
  • ISM-0072Depends on
    Document Security Requirements in Contractual Arrangements
  • ISM-1625Supports
    Develop Insider Threat Mitigation Programs
  • ISM-1730Supports
    Provide a Software Bill of Materials to Consumers
Annex A 5.33
Protection of Records
Organisational controls
  • ISM-0316Supports
    Formal Decision on IT Equipment Disposal
  • ISM-0371Depends on
    Ensure Proper Supervision of Media Destruction
  • ISM-0373Supports
    Supervise and Certify Accountable Material Destruction
  • ISM-0407Partially overlaps
    Maintain Secure User Access Records
  • ISM-1059Depends on
    Encrypt All Data Stored on Media Using ASD-Approved Cryptography
  • ISM-1080Supports
    Use AACA or High Assurance Algorithms for Data Encryption
  • ISM-1505Depends on
    Multi-factor Authentication for Human Users of Data Repositories
  • ISM-1586Partially overlaps
    Record All Data Imports and Exports
  • ISM-1737Depends on
    Recording Required Details for Each Managed Service in the Register
  • ISM-1814Supports
    Prevent Backup Modifications by Unprivileged Users
  • ISM-1815Partially meets
    Protect Event Logs from Unauthorised Access
  • ISM-1866Depends on
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1985Partially meets
    Protect Event Logs from Unauthorised Access
  • ISM-1989Depends on
    Ensure Event Logs Meet Retention Requirements
Annex A 5.34
Privacy and Protection of Personally Identifiable Information
Organisational controls
  • ISM-0821Supports
    Advise on Risks of Posting Personal Information Online
  • ISM-1268Supports
    Enforce Need-to-Know Access in Databases
  • ISM-1395Partially overlaps
    Ensuring Data Protection by Service Providers
  • ISM-1478Supports
    CISO Management of Cyber Security Compliance
  • ISM-1626Supports
    Seek Legal Advice for Insider Threat Plans
  • ISM-1880Partially overlaps
    Timely Reporting of Cyber Incidents Involving Customer Data
  • ISM-2002Supports
    Ensure Board Cyber Security Literacy for Compliance
  • ISM-2021Partially overlaps
    Implement and Maintain Data Minimisation Practices
  • ISM-2046Supports
    Ensure Secure Impersonation Logging Practices
  • ISM-2103Partially overlaps
    AI Data Use Requires Explicit Owner Consent
  • ISM-2107Depends on
    Restrict Personal Information Viewing Online
Annex A 5.35
Independent review of information security
Organisational controls
  • ISM-0009Supports
    Identify Supplementary Controls for System Security
  • ISM-0027Depends on
    Mandatory Authorisation for System Operation
  • ISM-0718Partially overlaps
    CISO Reporting to Board on Cyber Security
  • ISM-0724Depends on
    Implement Cyber Security Metrics and KPIs
  • ISM-0725Supports
    Cyber Security Steering Committee Coordination
  • ISM-0726Supports
    Coordinate Security Risk Management Activities
  • ISM-0732Depends on
    Manage and Allocate Cyber Security Budget
  • ISM-1037Partially overlaps
    Regular Testing of Gateway Security Configurations
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1523Depends on
    Regular Assessment of Security Events in CDS
  • ISM-1563Partially overlaps
    Assessor Produces Security Assessment Report Covering Required Content
  • ISM-1570Partially meets
    Regular IRAP Assessment of Cloud Service Providers
  • ISM-1587Partially overlaps
    Annual Security Status Reporting for Systems
  • ISM-1617Partially overlaps
    Regular Review of Cyber Security Program
  • ISM-1636Partially overlaps
    Security Control Assessment of Systems by Own or IRAP Assessors
  • ISM-1793Broader than
    Regular Assessment of Managed Service Providers
  • ISM-1918Partially overlaps
    Regular Cyber Security Reporting to Audit Committee
  • ISM-1967Partially overlaps
    Ensure Security Assessment of TOP SECRET Systems
  • ISM-1971Depends on
    ASD-Led Security Assessment of TOP SECRET Managed Services Every 24 Months
  • ISM-1972Broader than
    ASD Security Control Assessment of TOP SECRET Cloud Services Every 24 Months
  • ISM-1998Supports
    Integrate Cyber Security Across Business Functions
  • ISM-1999Supports
    Align Cyber Security with Business Strategy
  • ISM-2000Supports
    Regular Cyber Security Briefings for Executives
  • ISM-2002Depends on
    Ensure Board Cyber Security Literacy for Compliance
  • ISM-2005Supports
    Understanding Business Criticality of Organisation Systems
  • ISM-2019Broader than
    ASD Assessment of TOP SECRET Gateways Every 24 Months
Annex A 5.36
Review compliance with information security policies
Organisational controls
  • ISM-0039Depends on
    Develop and Maintain a Cyber Security Strategy
  • ISM-0041Depends on
    Maintain a System Security Plan With Overview and Controls Annex
  • ISM-0072Partially overlaps
    Document Security Requirements in Contractual Arrangements
  • ISM-0264Depends on
    Develop and Maintain an Email Usage Policy
  • ISM-0499Partially meets
    Ensure Compliance with ASD Communication Security Policies
  • ISM-0588Supports
    Develop and Maintain MFD Usage Policy
  • ISM-0718Partially overlaps
    CISO Reporting to Board on Cyber Security
  • ISM-0724Depends on
    Implement Cyber Security Metrics and KPIs
  • ISM-1037Broader than
    Regular Testing of Gateway Security Configurations
  • ISM-1078Supports
    Develop and Maintain Telephone System Usage Policy
  • ISM-1359Depends on
    Establish and Maintain Removable Media Policy
  • ISM-1478Partially overlaps
    CISO Management of Cyber Security Compliance
  • ISM-1523Broader than
    Regular Assessment of Security Events in CDS
  • ISM-1533Depends on
    Establish Mobile Device Management Policies
  • ISM-1549Depends on
    Develop and Maintain Media Management Policy
  • ISM-1551Depends on
    Develop and Maintain IT Equipment Management Policy
  • ISM-1617Depends on
    Regular Review of Cyber Security Program
  • ISM-1738Partially overlaps
    Verify Compliance with Security Requirements
  • ISM-1755Depends on
    Develop and Maintain a Vulnerability Disclosure Policy
  • ISM-1763Depends on
    Use NIST P-384 Curve for ECDSA Signatures
  • ISM-1864Depends on
    Develop and Enforce a System Usage Policy
  • ISM-1884Depends on
    Ensure Compliance with Emanation Security Doctrine
  • ISM-1956Depends on
    Regularly Update AD FS Certificates to Prevent Risks
  • ISM-1971Partially overlaps
    ASD-Led Security Assessment of TOP SECRET Managed Services Every 24 Months
  • ISM-1997Depends on
    Define Cyber Security Roles for Leadership
  • ISM-1998Supports
    Integrate Cyber Security Across Business Functions
  • ISM-2074Supports
    Develop and Maintain AI Usage Policy
  • ISM-2120Depends on
    Develop and Maintain Secure Software Policy
Annex A 5.37
Documented Operating Procedures for Information Processing
Organisational controls
  • ISM-0041Supports
    Develop a Detailed System Security Plan
  • ISM-0042Supports
    Maintain Effective System Administration Practices
  • ISM-0206Partially meets
    Develop and Maintain Cable Labelling Processes
  • ISM-0348Broader than
    Develop and Maintain Media Sanitisation Procedures
  • ISM-0362Supports
    Follow Manufacturer's Directions for Degaussing
  • ISM-0372Broader than
    Supervision of Media Destruction Procedures
  • ISM-0499Supports
    Ensure Compliance with ASD Communication Security Policies
  • ISM-0576Partially overlaps
    Develop and Maintain Cyber Security Incident Plans
  • ISM-0888Supports
    Annual Review of Cyber Security Documentation
  • ISM-0912Partially overlaps
    Establish and Manage System Configuration Changes
  • ISM-1359Supports
    Establish and Maintain Removable Media Policy
  • ISM-1478Depends on
    CISO Management of Cyber Security Compliance
  • ISM-1549Supports
    Develop and Maintain Media Management Policy
  • ISM-1551Supports
    Develop and Maintain IT Equipment Management Policy
  • ISM-1602Partially overlaps
    Ensure Cyber Security Docs Are Communicated
  • ISM-1802Supports
    Operate Approved High Assurance Cryptographic Equipment
Annex A 6.1
Personnel Background Verification
People controls
  • ISM-0269Depends on
    Restrict Sensitive Emails to Verified Recipients
  • ISM-0434Partially overlaps
    Ensure Personnel Employment Screening and Security Clearance
  • ISM-0613Partially meets
    Requirement for Gateway System Administrators Nationality
  • ISM-1520Broader than
    Employment Screening for Gateway Administrators
  • ISM-1773Depends on
    Eligibility Criteria for Gateway System Administrators
Annex A 6.2
Terms and conditions of employment for security
People controls
  • ISM-0661Depends on
    Holding Human Users Accountable for Data Transfers They Perform
  • ISM-0714Supports
    Appoint a CISO to Lead Cyber Security Across IT and OT
  • ISM-1773Supports
    Eligibility Criteria for Gateway System Administrators
  • ISM-2020Partially overlaps
    Ensure Adequate Cyber Security Personnel Are Acquired
  • ISM-2035Partially overlaps
    Document Security Roles for Software Development
  • ISM-2036Partially overlaps
    Document Security Duties for Software Developers
Annex A 6.3
Information security awareness, education and training program
People controls
  • ISM-0229Partially meets
    Guidelines for Discussing Sensitive Information Over Phones
  • ISM-0230Partially meets
    Advising on Risks of Non-Secure Telephone Systems
  • ISM-0252Partially overlaps
    Annual Cyber Security Awareness for Personnel
  • ISM-0370Supports
    Supervise Media Destruction with Cleared Personnel
  • ISM-0435Partially meets
    Pre-Access Briefings for System Resources
  • ISM-0610Partially meets
    Train Users on Secure Use of CDSs
  • ISM-0612Broader than
    Training for Gateway System Administrators
  • ISM-0661Depends on
    Holding Human Users Accountable for Data Transfers They Perform
  • ISM-0701Supports
    Establish Mobile Device Emergency Sanitisation Processes and Procedures
  • ISM-0817Broader than
    Reporting Suspicious Online Contact Awareness
  • ISM-0821Broader than
    Advise on Risks of Posting Personal Information Online
  • ISM-0824Supports
    Avoid Using Unauthorised Online File Services
  • ISM-1083Broader than
    Advise Personnel on Mobile Communication Sensitivity
  • ISM-1146Supports
    Separate Personal and Work Accounts for Online Services
  • ISM-1298Broader than
    Advise Personnel on Overseas Mobile Device Security
  • ISM-1554Supports
    Guidelines for Using Mobile Devices Abroad
  • ISM-1565Broader than
    Annual Tailored Training for All Privileged Access Holders
  • ISM-1602Partially overlaps
    Ensure Cyber Security Docs Are Communicated
  • ISM-1644Partially meets
    Secure Communication Practices in Public Areas
  • ISM-1740Broader than
    Manage and Report Business Email Compromise
  • ISM-1864Supports
    Develop and Enforce a System Usage Policy
  • ISM-1998Supports
    Integrate Cyber Security Across Business Functions
  • ISM-2001Supports
    Championing Cyber Security at an Executive Level
  • ISM-2003Supports
    Monitor Cyber Security Workforce and Skill Gaps
  • ISM-2004Supports
    Enhancing Cyber Security Skills and Experience
  • ISM-2022Partially meets
    Develop and Maintain Cyber Security Training Register
  • ISM-2035Partially overlaps
    Document Security Roles for Software Development
  • ISM-2037Partially meets
    Train Software Developers Lacking Cyber Security Skills
  • ISM-2038Supports
    Maintain Developer Cyber Security Skills Register
  • ISM-2071Broader than
    Training on Managing Social Engineering Threats
  • ISM-2104Broader than
    Do Not Post Security Clearance and Briefing Details Online
  • ISM-2105Broader than
    Advise Staff to Limit Posting Work Information on Unauthorised Online Services
  • ISM-2106Broader than
    Advise Staff to Limit Posting Work Skills Online
  • ISM-2107Broader than
    Restrict Personal Information Viewing Online
  • ISM-2121Partially overlaps
    Prevent Using Developers Without Cyber Security Skills
Annex A 6.4
Disciplinary Process for Information Security Violations
People controls
  • ISM-0661Depends on
    Holding Human Users Accountable for Data Transfers They Perform
  • ISM-0820Supports
    Avoid Posting Work Data on Unauthorised Online Services
  • ISM-1864Supports
    Develop and Enforce a System Usage Policy
  • ISM-1865Depends on
    Compliance with System Usage Policies for Access
Annex A 6.5
Responsibilities after employment termination or role change
People controls
  • ISM-0430Partially overlaps
    Immediate Suspension of Unneeded System Access
  • ISM-1569Partially overlaps
    Document and Share a Supplier Customer Shared Responsibility Model
  • ISM-1997Depends on
    Define Cyber Security Roles for Leadership
  • ISM-2036Depends on
    Document Security Duties for Software Developers
Annex A 6.6
Confidentiality and Non-disclosure Agreements
People controls
  • ISM-0072Partially overlaps
    Document Security Requirements in Contractual Arrangements
  • ISM-0820Supports
    Avoid Posting Work Data on Unauthorised Online Services
Annex A 6.7
Remote Working Security Measures
People controls
  • ISM-0467Depends on
    Using HACE for Secure Communication of Data
  • ISM-0487Depends on
    Disable Certain Features for Passwordless SSH Logins
  • ISM-0488Partially meets
    Use Forced Commands for SSH Without Passwords
  • ISM-0694Broader than
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0705Broader than
    Disable Split Tunnelling for VPN Connections
  • ISM-0824Partially meets
    Avoid Using Unauthorised Online File Services
  • ISM-0871Supports
    Supervise Mobile Devices During Active Use
  • ISM-1006Partially overlaps
    Prevent Unauthorised Access to Network Traffic
  • ISM-1084Supports
    Transporting Mobile Devices Securely
  • ISM-1146Broader than
    Separate Personal and Work Accounts for Online Services
  • ISM-1400Partially overlaps
    Enforce Data Separation on Personal Devices
  • ISM-1482Partially overlaps
    Ensure Separation of Classified and Personal Data on Devices
  • ISM-1504Partially meets
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1554Partially meets
    Guidelines for Using Mobile Devices Abroad
  • ISM-1866Partially overlaps
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1887Broader than
    Implement Remote Locate and Wipe for Mobile Security
  • ISM-1990Depends on
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
  • ISM-2096Depends on
    Separate Organisational and Personal Mobile Data
  • ISM-2098Depends on
    Prevent Data Transfer Over USB on Mobile Devices
  • ISM-2101Depends on
    Restrict Sensitive Conversations Near Vehicles
  • ISM-2149Depends on
    Develop, Enforce and Maintain an Authorised RMM and Remote Access Tool List
Annex A 6.8
Mechanisms for Reporting Security Events
People controls
  • ISM-0043Partially overlaps
    Cyber Security Incident Response Plan Requirements
  • ISM-0123Partially overlaps
    Report Cyber Security Incidents Promptly
  • ISM-0125Partially overlaps
    Maintaining a Cyber Security Incident Register
  • ISM-0142Broader than
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0252Supports
    Annual Cyber Security Awareness for Personnel
  • ISM-0820Broader than
    Avoid Posting Work Data on Unauthorised Online Services
  • ISM-1088Partially overlaps
    Report Potential Compromises of Mobile Devices Overseas
  • ISM-1523Supports
    Regular Assessment of Security Events in CDS
  • ISM-1556Supports
    Security Measures After Overseas Travel with Mobile Devices
  • ISM-1740Depends on
    Manage and Report Business Email Compromise
  • ISM-1803Partially overlaps
    Document and Report Cyber Security Incidents
  • ISM-1880Partially overlaps
    Timely Reporting of Cyber Incidents Involving Customer Data
  • ISM-1881Partially overlaps
    Timely Reporting of Cyber Incidents Without Data Breach
  • ISM-2001Depends on
    Championing Cyber Security at an Executive Level
  • ISM-2071Partially overlaps
    Training on Managing Social Engineering Threats
  • ISM-2105Partially overlaps
    Advise Staff to Limit Posting Work Information on Unauthorised Online Services
Annex A 7.1
Physical Security Perimeters
Physical controls
  • ISM-0161Supports
    Ensure Security of Unused IT Equipment and Media
  • ISM-0164Supports
    Prevent Unauthorised Viewing of System Displays
  • ISM-0217Supports
    Secure Separation of Non-TOP SECRET and TOP SECRET Panels
  • ISM-0225Broader than
    Prevent Unauthorised RF and IR Device Entry
  • ISM-0235Partially meets
    Use of Speakerphones in TOP SECRET Areas
  • ISM-0559Supports
    Restrict Microphone and Webcam Use in SECRET Areas
  • ISM-0735Partially overlaps
    CISO Oversees the Cyber Security Awareness Training Program
  • ISM-0810Partially meets
    Secure Facilities Based on System Classification
  • ISM-0813Supports
    Ensure Secure Access to Critical Infrastructure
  • ISM-0829Broader than
    Detect Unauthorised RF Devices in Secure Areas
  • ISM-1053Broader than
    Secure Physical Access for Classified Equipment
  • ISM-1074Partially meets
    Controlling Access to Critical IT Infrastructure
  • ISM-1098Broader than
    Terminate Cable Systems at Cabinet Boundaries
  • ISM-1103Depends on
    Terminate Cables Outside Cabinets in Secure Areas
  • ISM-1137Partially overlaps
    Request Risk Assessment for Emanation Security
  • ISM-1296Partially overlaps
    Protect Network Devices in Public Areas
  • ISM-1633Supports
    Determine System Boundary, Criticality and Security Objectives
  • ISM-1974Broader than
    Securing Non-Classified IT Equipment in Secure Rooms
  • ISM-1975Supports
    Secure Non-Classified Equipment in Safe Containers
  • ISM-2070Supports
    Control Access to Recording Devices in Secure Areas
Annex A 7.2
Physical access controls for secure areas
Physical controls
  • ISM-0161Depends on
    Ensure Security of Unused IT Equipment and Media
  • ISM-0164Partially meets
    Prevent Unauthorised Viewing of System Displays
  • ISM-0225Broader than
    Prevent Unauthorised RF and IR Device Entry
  • ISM-0306Partially overlaps
    Escort Uncleared Technicians During IT Equipment Maintenance or Repairs
  • ISM-0345Depends on
    Disable External Interfaces for Direct Memory Access
  • ISM-0418Supports
    Keep Physical Credentials Separate from Systems
  • ISM-0810Broader than
    Secure Facilities Based on System Classification
  • ISM-0813Partially overlaps
    Ensure Secure Access to Critical Infrastructure
  • ISM-1053Partially overlaps
    Secure Physical Access for Classified Equipment
  • ISM-1074Partially overlaps
    Controlling Access to Critical IT Infrastructure
  • ISM-1105Partially meets
    Ensure Wall Outlets Have Appropriate Cable Security
  • ISM-1296Partially overlaps
    Protect Network Devices in Public Areas
  • ISM-1327Partially overlaps
    Secure Certificates for Network Authentication
  • ISM-1957Supports
    Ensure CA Servers Use Hardware Security Modules
  • ISM-1973Supports
    Secure Facilities for Non-Classified Systems
  • ISM-1974Supports
    Securing Non-Classified IT Equipment in Secure Rooms
  • ISM-1975Partially overlaps
    Secure Non-Classified Equipment in Safe Containers
  • ISM-2007Supports
    Authorised Medical Device Register for SECRET and TOP SECRET Areas
  • ISM-2070Broader than
    Control Access to Recording Devices in Secure Areas
Annex A 7.3
Physical Security for Offices and Facilities
Physical controls
  • ISM-0161Supports
    Ensure Security of Unused IT Equipment and Media
  • ISM-0164Broader than
    Prevent Unauthorised Viewing of System Displays
  • ISM-0194Partially meets
    Sealing Conduit Joints in Shared Facilities
  • ISM-0198Partially meets
    Consultation for Penetrating Audio Secure Rooms
  • ISM-0216Partially meets
    Ensure Separate Cabinets for TOP SECRET Patch Panels
  • ISM-0225Partially meets
    Prevent Unauthorised RF and IR Device Entry
  • ISM-0735Partially meets
    CISO Oversees the Cyber Security Awareness Training Program
  • ISM-0810Partially meets
    Secure Facilities Based on System Classification
  • ISM-0813Partially meets
    Ensure Secure Access to Critical Infrastructure
  • ISM-1036Partially meets
    Place Multifunction Devices Where Their Use Can Be Observed
  • ISM-1053Partially meets
    Secure Physical Access for Classified Equipment
  • ISM-1107Broader than
    Colour Restrictions for Wall Outlet Boxes
  • ISM-1116Partially meets
    Ensure Separation Between Top Secret and Other Cabinets
  • ISM-1130Partially meets
    Use Enclosed Systems for Shared Facility Cables
  • ISM-1164Partially meets
    Use Clear Plastic for Shared Facility Cabling Covers
  • ISM-1296Broader than
    Protect Network Devices in Public Areas
  • ISM-1327Partially overlaps
    Secure Certificates for Network Authentication
  • ISM-1645Partially meets
    Maintain and Verify Floor Plan Diagrams
  • ISM-1720Partially meets
    Colour Coding for Secret Wall Outlet Boxes
  • ISM-1973Partially meets
    Secure Facilities for Non-Classified Systems
  • ISM-1974Partially meets
    Securing Non-Classified IT Equipment in Secure Rooms
  • ISM-1975Partially meets
    Secure Non-Classified Equipment in Safe Containers
Annex A 7.4
Continuous monitoring of physical access to premises
Physical controls
  • ISM-1053Partially overlaps
    Secure Physical Access for Classified Equipment
  • ISM-1296Depends on
    Protect Network Devices in Public Areas
  • ISM-1973Supports
    Secure Facilities for Non-Classified Systems
  • ISM-1974Supports
    Securing Non-Classified IT Equipment in Secure Rooms
Annex A 7.5
Protecting against physical and environmental threats
Physical controls
  • ISM-0164Partially meets
    Prevent Unauthorised Viewing of System Displays
  • ISM-0194Broader than
    Sealing Conduit Joints in Shared Facilities
  • ISM-0195Broader than
    Seal Removable Covers on TOP SECRET Cables
  • ISM-0216Broader than
    Ensure Separate Cabinets for TOP SECRET Patch Panels
  • ISM-0734Partially overlaps
    CISO Role in Disaster Recovery Planning
  • ISM-0735Partially overlaps
    CISO Oversees the Cyber Security Awareness Training Program
  • ISM-0810Supports
    Secure Facilities Based on System Classification
  • ISM-0813Broader than
    Ensure Secure Access to Critical Infrastructure
  • ISM-0829Partially meets
    Detect Unauthorised RF Devices in Secure Areas
  • ISM-1053Supports
    Secure Physical Access for Classified Equipment
  • ISM-1074Broader than
    Controlling Access to Critical IT Infrastructure
  • ISM-1116Broader than
    Ensure Separation Between Top Secret and Other Cabinets
  • ISM-1119Partially overlaps
    Ensure Cables in TOP SECRET Areas are Inspectable
  • ISM-1164Broader than
    Use Clear Plastic for Shared Facility Cabling Covers
  • ISM-1296Partially overlaps
    Protect Network Devices in Public Areas
  • ISM-1645Broader than
    Maintain and Verify Floor Plan Diagrams
  • ISM-1973Broader than
    Secure Facilities for Non-Classified Systems
  • ISM-1975Partially meets
    Secure Non-Classified Equipment in Safe Containers
Annex A 7.6
Security Measures for Working in Secure Areas
Physical controls
  • ISM-0164Broader than
    Prevent Unauthorised Viewing of System Displays
  • ISM-0218Partially meets
    Label and Protect Long TS Fibre-Optic Leads
  • ISM-0225Broader than
    Prevent Unauthorised RF and IR Device Entry
  • ISM-0236Broader than
    Implement Off-hook Audio Protection on Telephones
  • ISM-0559Broader than
    Restrict Microphone and Webcam Use in SECRET Areas
  • ISM-0735Partially overlaps
    CISO Oversees the Cyber Security Awareness Training Program
  • ISM-0810Partially overlaps
    Secure Facilities Based on System Classification
  • ISM-0829Broader than
    Detect Unauthorised RF Devices in Secure Areas
  • ISM-0931Partially meets
    Off-hook Audio Protection Using Push-to-Talk Devices
  • ISM-1013Broader than
    Limit Wireless Range with RF Shielding
  • ISM-1101Broader than
    Terminate Cabling Closely in Top Secret Areas
  • ISM-1103Broader than
    Terminate Cables Outside Cabinets in Secure Areas
  • ISM-1137Partially overlaps
    Request Risk Assessment for Emanation Security
  • ISM-1296Partially overlaps
    Protect Network Devices in Public Areas
  • ISM-1450Broader than
    Restricting Devices in Top Secret Areas
  • ISM-1635Partially meets
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1720Partially meets
    Colour Coding for Secret Wall Outlet Boxes
  • ISM-1721Supports
    Red Colour Coding for TOP SECRET Outlet Boxes
  • ISM-1821Supports
    Ensuring Exclusive Bundling for TOP SECRET Cables
  • ISM-1885Supports
    Implement Emanation Security Measures for Systems
  • ISM-1973Partially overlaps
    Secure Facilities for Non-Classified Systems
  • ISM-2008Broader than
    Criteria for Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2069Broader than
    Maintain Register of Authorised Recording Devices in SECRET and TOP SECRET Areas
  • ISM-2070Broader than
    Control Access to Recording Devices in Secure Areas
Annex A 7.7
Clear desk and clear screen policies
Physical controls
  • ISM-0161Partially overlaps
    Ensure Security of Unused IT Equipment and Media
  • ISM-0164Partially overlaps
    Prevent Unauthorised Viewing of System Displays
  • ISM-0831Partially overlaps
    Ensure Proper Handling of Sensitive Media
  • ISM-0853Partially overlaps
    Terminate User Sessions and Restart Workstations Daily
  • ISM-0866Partially overlaps
    Ensure Privacy While Viewing Data in Public
  • ISM-0870Partially overlaps
    Secure Storage and Handling of Mobile Devices
  • ISM-1076Partially overlaps
    Sanitise Screen Burn-In With a Solid White Image
  • ISM-1145Partially overlaps
    Apply Privacy Filters to Protect Device Screens
  • ISM-1299Supports
    Personnel Awareness for Secure Mobile Device Usage
  • ISM-1359Partially overlaps
    Establish and Maintain Removable Media Policy
  • ISM-1888Supports
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-2012Partially overlaps
    Ensure Secure Screen Locking on Systems
Annex A 7.8
Equipment Siting and Protection
Physical controls
  • ISM-0161Partially overlaps
    Ensure Security of Unused IT Equipment and Media
  • ISM-0164Partially overlaps
    Prevent Unauthorised Viewing of System Displays
  • ISM-0194Partially meets
    Sealing Conduit Joints in Shared Facilities
  • ISM-0216Partially overlaps
    Ensure Separate Cabinets for TOP SECRET Patch Panels
  • ISM-0345Supports
    Disable External Interfaces for Direct Memory Access
  • ISM-0735Partially overlaps
    CISO Oversees the Cyber Security Awareness Training Program
  • ISM-0810Partially overlaps
    Secure Facilities Based on System Classification
  • ISM-0813Partially overlaps
    Ensure Secure Access to Critical Infrastructure
  • ISM-0870Partially overlaps
    Secure Storage and Handling of Mobile Devices
  • ISM-0871Partially overlaps
    Supervise Mobile Devices During Active Use
  • ISM-1036Partially meets
    Place Multifunction Devices Where Their Use Can Be Observed
  • ISM-1053Partially overlaps
    Secure Physical Access for Classified Equipment
  • ISM-1074Partially overlaps
    Controlling Access to Critical IT Infrastructure
  • ISM-1109Broader than
    Ensure Clear Plastic Covers for Wall Outlets
  • ISM-1116Partially meets
    Ensure Separation Between Top Secret and Other Cabinets
  • ISM-1119Partially overlaps
    Ensure Cables in TOP SECRET Areas are Inspectable
  • ISM-1296Broader than
    Protect Network Devices in Public Areas
  • ISM-1599Depends on
    Proper Handling of Sensitive IT Equipment
  • ISM-1721Supports
    Red Colour Coding for TOP SECRET Outlet Boxes
  • ISM-1973Partially overlaps
    Secure Facilities for Non-Classified Systems
  • ISM-1974Partially overlaps
    Securing Non-Classified IT Equipment in Secure Rooms
  • ISM-1975Partially overlaps
    Secure Non-Classified Equipment in Safe Containers
Annex A 7.9
Security of Off-Site Assets
Physical controls
  • ISM-0161Supports
    Ensure Security of Unused IT Equipment and Media
  • ISM-0457Partially overlaps
    Use Evaluated Crypto for Sensitive Data Encryption
  • ISM-0465Partially overlaps
    Use Evaluated Cryptographic Tools for Sensitive Data
  • ISM-1314Supports
    Ensure Wireless Devices are Wi-Fi Alliance Certified
  • ISM-1400Partially meets
    Enforce Data Separation on Personal Devices
  • ISM-1554Partially meets
    Guidelines for Using Mobile Devices Abroad
Annex A 7.10
Secure Management of Storage Media
Physical controls
  • ISM-0307Partially meets
    Sanitise Equipment When Not Using Cleared Technician
  • ISM-0311Partially overlaps
    Ensuring Sanitisation of IT Equipment Media
  • ISM-0312Partially meets
    Return Overseas Equipment for Destruction
  • ISM-0313Partially overlaps
    Develop and Maintain IT Equipment Sanitisation Procedures
  • ISM-0315Partially overlaps
    Ensure Destruction of High Assurance IT Equipment
  • ISM-0316Partially meets
    Formal Decision on IT Equipment Disposal
  • ISM-0317Partially meets
    Ensuring Data Erasure on Printer Cartridges and Drums
  • ISM-0318Partially meets
    Safely Disposing of Unsanitised Printer Components
  • ISM-0321Partially meets
    Contact ASD for Guidance on Secure IT Disposal
  • ISM-0323Supports
    Classifying Media by Data Sensitivity
  • ISM-0325Broader than
    Reclassify Media to Higher Sensitivity
  • ISM-0330Partially meets
    Proper Sanitisation and Reclassification of Media
  • ISM-0337Broader than
    Ensure Media is Used with Authorised Systems
  • ISM-0343Partially overlaps
    Disabling Unnecessary Access to Removable Media
  • ISM-0348Partially overlaps
    Develop and Maintain Media Sanitisation Procedures
  • ISM-0350Partially meets
    Destroy Unsanitizable Media Before Disposal
  • ISM-0351Partially meets
    Proper Method for Volatile Media Sanitisation
  • ISM-0352Partially meets
    Secure Volatile Media by Overwriting with Random Data
  • ISM-0354Partially meets
    Ensuring Proper Sanitisation of Magnetic Media
  • ISM-0356Partially meets
    Classify Magnetic Media After Sanitisation
  • ISM-0357Partially meets
    Sanitising Non-volatile EPROM Media
  • ISM-0358Partially meets
    Classification Retention for Sanitised EPROM and EEPROM
  • ISM-0359Partially meets
    Proper Sanitisation of Non-Volatile Flash Memory
  • ISM-0360Partially overlaps
    Classification Retention After Flash Memory Sanitisation
  • ISM-0361Partially meets
    Using Degaussers for Magnetic Media Destruction
  • ISM-0362Partially meets
    Follow Manufacturer's Directions for Degaussing
  • ISM-0363Partially meets
    Develop and Maintain Media Destruction Processes
  • ISM-0368Partially meets
    Ensuring Media Particles Are No Larger Than 9 mm
  • ISM-0371Partially meets
    Ensure Proper Supervision of Media Destruction
  • ISM-0374Partially meets
    Develop and Maintain Media Disposal Procedures
  • ISM-0375Partially meets
    Decide on Public Release of Data Storage Media
  • ISM-0378Partially meets
    Remove Labels from Media Before Disposal
  • ISM-0462Partially overlaps
    Managing Encryption Access for IT Equipment and Media
  • ISM-0831Equivalent
    Ensure Proper Handling of Sensitive Media
  • ISM-0835Partially overlaps
    TOP SECRET Volatile Media Retains Classification After Sanitisation
  • ISM-0836Partially meets
    Overwriting EEPROM for Complete Data Sanitisation
  • ISM-0839Partially meets
    Prohibit Outsourcing of Media Destruction
  • ISM-0840Partially overlaps
    Certified Services for Outsourced Media Destruction
  • ISM-0947Partially meets
    Sanitise Media After Data Transfers Between Domains
  • ISM-1059Partially meets
    Encrypt All Data Stored on Media Using ASD-Approved Cryptography
  • ISM-1065Partially meets
    Reset Device Settings Before Media Sanitisation
  • ISM-1067Supports
    Secure Erase for Non-Volatile Magnetic Media
  • ISM-1084Partially meets
    Transporting Mobile Devices Securely
  • ISM-1157Partially meets
    Use Evaluated Diodes to Control Unidirectional Gateway Data Flow
  • ISM-1160Partially meets
    Use NSA-evaluated Degaussers for Media Destruction
  • ISM-1217Partially overlaps
    Remove Identifying Labels from IT Equipment Before Disposal
  • ISM-1222Partially meets
    Destroy Unsanitised Televisions and Monitors
  • ISM-1299Supports
    Personnel Awareness for Secure Mobile Device Usage
  • ISM-1300Partially overlaps
    Mobile Device Security After Overseas Travel
  • ISM-1361Partially meets
    Use Approved Equipment for Media Destruction
  • ISM-1418Partially overlaps
    Disable Unnecessary Removable Media Access
  • ISM-1550Partially meets
    Develop and Maintain IT Equipment Disposal Procedures
  • ISM-1600Partially meets
    Ensure Media is Sanitised Before Initial Use
  • ISM-1641Partially meets
    Ensure Degaussed Media is Physically Damaged
  • ISM-1722Partially meets
    Methods for Destroying Electrostatic Memory Devices
  • ISM-1723Partially meets
    Methods for Destroying Magnetic Floppy Disks
  • ISM-1724Partially meets
    Methods for Destroying Magnetic Hard Disks
  • ISM-1725Partially meets
    Methods for Destroying Magnetic Tapes
  • ISM-1726Partially meets
    Methods for Destructing Optical Disks
  • ISM-1727Broader than
    Methods for Destroying Semiconductor Memory
  • ISM-1728Partially meets
    Handling Media Waste Based on Particle Size
  • ISM-1729Broader than
    Storage Classification of Media Waste Particles
  • ISM-1735Partially meets
    Destroy Unsanitised Media Before Disposal
  • ISM-1866Broader than
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-2072Partially meets
    Store AI Models In A Non-Executable File Format
  • ISM-2098Broader than
    Prevent Data Transfer Over USB on Mobile Devices
Annex A 7.11
Protection from Utility Failures
Physical controls
  • ISM-1123Supports
    Ensure UPS Powers All Top Secret IT Equipment
  • ISM-1438Partially overlaps
    Ensure High Availability by Using CDNs
  • ISM-1580Partially overlaps
    Ensure High Availability for Online Services
Annex A 7.12
Secure Cabling for Power and Data
Physical controls
  • ISM-0181Supports
    Ensure Cabling Meets Australian Standards
  • ISM-0187Broader than
    Exclusive Secret Cable Bundling in Infrastructure
  • ISM-0195Broader than
    Seal Removable Covers on TOP SECRET Cables
  • ISM-0206Supports
    Develop and Maintain Cable Labelling Processes
  • ISM-0213Partially overlaps
    Segregate Patch Panels for Secret-Level Cables
  • ISM-0250Partially overlaps
    Ensure IT Equipment Meets EMI/EMC Standards
  • ISM-0926Partially meets
    Ensure Cables Are Not Salmon Pink or Red
  • ISM-1095Supports
    Proper Labelling of Wall Outlet Boxes
  • ISM-1096Partially meets
    Ensure Proper Labelling of Cables for Identification
  • ISM-1100Broader than
    Terminating TOP SECRET Cables in Cabinets
  • ISM-1101Broader than
    Terminate Cabling Closely in Top Secret Areas
  • ISM-1102Broader than
    Terminate Cable Reticulation Close to Cabinet
  • ISM-1103Broader than
    Terminate Cables Outside Cabinets in Secure Areas
  • ISM-1111Broader than
    Ensure Fibre-Optic Cables Replace Copper Cables
  • ISM-1112Broader than
    Ensure Cables Are Inspectable Every Five Metres
  • ISM-1114Broader than
    Ensure Separation in Cable Reticulation Systems
  • ISM-1115Partially meets
    Ensure Cables Use Conduits in Walls
  • ISM-1119Broader than
    Ensure Cables in TOP SECRET Areas are Inspectable
  • ISM-1122Broader than
    Secure TOP SECRET Cable Wall Exits
  • ISM-1130Partially meets
    Use Enclosed Systems for Shared Facility Cables
  • ISM-1133Partially meets
    Prevent Installation of TOP SECRET Cables in Shared Walls
  • ISM-1164Partially meets
    Use Clear Plastic for Shared Facility Cabling Covers
  • ISM-1296Depends on
    Protect Network Devices in Public Areas
  • ISM-1639Partially overlaps
    Label Building Management Cables Clearly
  • ISM-1640Supports
    Label Cables for Foreign Systems in Australia
  • ISM-1718Partially meets
    Colour Code for SECRET Cables
  • ISM-1719Depends on
    Colour Code for TOP SECRET Cables
  • ISM-1821Partially meets
    Ensuring Exclusive Bundling for TOP SECRET Cables
Annex A 7.13
Proper Maintenance of Equipment
Physical controls
  • ISM-0206Supports
    Develop and Maintain Cable Labelling Processes
  • ISM-0211Partially overlaps
    Develop and Verify a Cable Register
  • ISM-0290Supports
    Secure Configuration of High Assurance IT Equipment
  • ISM-0298Partially overlaps
    Centralised System Patch and Update Management
  • ISM-0305Partially meets
    On-Site IT Equipment Maintenance by Cleared Technicians
  • ISM-0306Supports
    Escort Uncleared Technicians During IT Equipment Maintenance or Repairs
  • ISM-0307Partially overlaps
    Sanitise Equipment When Not Using Cleared Technician
  • ISM-0310Partially overlaps
    Off-Site IT Equipment Handling Approvals
  • ISM-1079Supports
    Seek Approval for High Assurance IT Repairs
  • ISM-1598Partially overlaps
    Inspect IT Equipment Post-Maintenance for Unauthorised Changes
  • ISM-1801Partially meets
    Monthly Restart of Network Devices
  • ISM-1913Supports
    Develop and Maintain Approved IT Configurations
  • ISM-1982Supports
    Replace Unsupported Networked IT Equipment
Annex A 7.14
Secure disposal or re-use of equipment
Physical controls
  • ISM-0161Partially overlaps
    Ensure Security of Unused IT Equipment and Media
  • ISM-0307Partially overlaps
    Sanitise Equipment When Not Using Cleared Technician
  • ISM-0311Equivalent
    Ensuring Sanitisation of IT Equipment Media
  • ISM-0312Partially meets
    Return Overseas Equipment for Destruction
  • ISM-0313Partially overlaps
    Develop and Maintain IT Equipment Sanitisation Procedures
  • ISM-0315Partially overlaps
    Ensure Destruction of High Assurance IT Equipment
  • ISM-0316Partially overlaps
    Formal Decision on IT Equipment Disposal
  • ISM-0317Partially meets
    Ensuring Data Erasure on Printer Cartridges and Drums
  • ISM-0318Partially meets
    Safely Disposing of Unsanitised Printer Components
  • ISM-0321Partially overlaps
    Contact ASD for Guidance on Secure IT Disposal
  • ISM-0330Partially overlaps
    Proper Sanitisation and Reclassification of Media
  • ISM-0350Partially overlaps
    Destroy Unsanitizable Media Before Disposal
  • ISM-0351Partially meets
    Proper Method for Volatile Media Sanitisation
  • ISM-0352Partially meets
    Secure Volatile Media by Overwriting with Random Data
  • ISM-0354Partially meets
    Ensuring Proper Sanitisation of Magnetic Media
  • ISM-0357Partially meets
    Sanitising Non-volatile EPROM Media
  • ISM-0359Supports
    Proper Sanitisation of Non-Volatile Flash Memory
  • ISM-0360Partially overlaps
    Classification Retention After Flash Memory Sanitisation
  • ISM-0361Supports
    Using Degaussers for Magnetic Media Destruction
  • ISM-0362Supports
    Follow Manufacturer's Directions for Degaussing
  • ISM-0363Partially overlaps
    Develop and Maintain Media Destruction Processes
  • ISM-0368Broader than
    Ensuring Media Particles Are No Larger Than 9 mm
  • ISM-0371Partially overlaps
    Ensure Proper Supervision of Media Destruction
  • ISM-0373Partially meets
    Supervise and Certify Accountable Material Destruction
  • ISM-0374Partially overlaps
    Develop and Maintain Media Disposal Procedures
  • ISM-0375Partially overlaps
    Decide on Public Release of Data Storage Media
  • ISM-0378Partially overlaps
    Remove Labels from Media Before Disposal
  • ISM-0835Partially overlaps
    TOP SECRET Volatile Media Retains Classification After Sanitisation
  • ISM-0836Partially meets
    Overwriting EEPROM for Complete Data Sanitisation
  • ISM-0839Partially overlaps
    Prohibit Outsourcing of Media Destruction
  • ISM-0947Partially overlaps
    Sanitise Media After Data Transfers Between Domains
  • ISM-1065Supports
    Reset Device Settings Before Media Sanitisation
  • ISM-1067Partially meets
    Secure Erase for Non-Volatile Magnetic Media
  • ISM-1157Partially meets
    Use Evaluated Diodes to Control Unidirectional Gateway Data Flow
  • ISM-1160Partially meets
    Use NSA-evaluated Degaussers for Media Destruction
  • ISM-1217Partially overlaps
    Remove Identifying Labels from IT Equipment Before Disposal
  • ISM-1218Partially meets
    Sanitise Overseas IT Equipment Handling Sensitive Data
  • ISM-1219Partially meets
    Inspect and Destroy MFD Print Drums and Image Transfer Rollers
  • ISM-1220Partially meets
    Inspect and Destroy Retained Images on Printer Platens
  • ISM-1221Supports
    Check Printers and MFDs for Trapped Pages
  • ISM-1222Partially meets
    Destroy Unsanitised Televisions and Monitors
  • ISM-1223Partially meets
    Methods for Sanitising Network Device Memory
  • ISM-1361Partially overlaps
    Use Approved Equipment for Media Destruction
  • ISM-1517Partially meets
    Microform Destruction Using Fine Powder Method
  • ISM-1550Partially overlaps
    Develop and Maintain IT Equipment Disposal Procedures
  • ISM-1599Partially overlaps
    Proper Handling of Sensitive IT Equipment
  • ISM-1641Partially meets
    Ensure Degaussed Media is Physically Damaged
  • ISM-1642Partially overlaps
    Ensure Media is Sanitised Before Reuse
  • ISM-1724Partially overlaps
    Methods for Destroying Magnetic Hard Disks
  • ISM-1726Partially meets
    Methods for Destructing Optical Disks
  • ISM-1727Broader than
    Methods for Destroying Semiconductor Memory
  • ISM-1729Partially overlaps
    Storage Classification of Media Waste Particles
  • ISM-1735Partially overlaps
    Destroy Unsanitised Media Before Disposal
  • ISM-1741Partially overlaps
    Implement IT Equipment Destruction Procedures
  • ISM-1742Partially overlaps
    Destroy Un-sanitizable IT Equipment Safely
  • ISM-2021Partially overlaps
    Implement and Maintain Data Minimisation Practices
  • ISM-2053Supports
    End of Life Procedures for Software
Annex A 8.1
Protection of User Endpoint Devices
Technological controls
  • ISM-0161Partially overlaps
    Ensure Security of Unused IT Equipment and Media
  • ISM-0345Partially meets
    Disable External Interfaces for Direct Memory Access
  • ISM-0489Broader than
    Four-Hour Cached SSH Private Key Lifetime and Screen Locks
  • ISM-0591Partially meets
    Use Evaluated Peripheral Switches Securely
  • ISM-0682Partially meets
    Disable Bluetooth on SECRET/TS Mobile Devices
  • ISM-0687Partially meets
    Use Approved Platforms for Secure Mobile Access
  • ISM-0853Broader than
    Terminate Interactive User Sessions and Restart Workstations at Least Daily
  • ISM-0864Partially meets
    Prevent Modifications to Security Settings on Mobile Devices
  • ISM-0866Partially meets
    Ensure Privacy While Viewing Data in Public
  • ISM-0869Broader than
    Encrypt Storage on Mobile Devices
  • ISM-0870Broader than
    Secure Storage and Handling of Mobile Devices
  • ISM-0871Partially meets
    Supervise Mobile Devices During Active Use
  • ISM-0874Broader than
    Ensure Internet Access via Organisation's Gateway
  • ISM-1059Broader than
    Encrypt All Data Stored on Media Using ASD-Approved Cryptography
  • ISM-1080Supports
    Use AACA or High Assurance Algorithms for Data Encryption
  • ISM-1082Partially meets
    Develop and Maintain Mobile Device Usage Policy
  • ISM-1084Partially meets
    Transporting Mobile Devices Securely
  • ISM-1195Broader than
    Enforce Policy with Evaluated Mobile Device Management
  • ISM-1196Broader than
    Keep Mobile Devices Undiscoverable via Bluetooth
  • ISM-1198Partially meets
    Secure Bluetooth Pairing for Mobile Devices
  • ISM-1199Partially meets
    Remove Unnecessary Bluetooth Pairings on Devices
  • ISM-1200Broader than
    Secure Bluetooth Pairing for Mobile Devices
  • ISM-1341Broader than
    Implement HIPS or EDR on Workstations
  • ISM-1400Partially meets
    Enforce Data Separation on Personal Devices
  • ISM-1450Supports
    Restricting Devices in Top Secret Areas
  • ISM-1482Partially meets
    Ensure Separation of Classified and Personal Data on Devices
  • ISM-1533Partially meets
    Establish Mobile Device Management Policies
  • ISM-1554Partially meets
    Guidelines for Using Mobile Devices Abroad
  • ISM-1585Depends on
    Lock Web Browser Security Settings Against Human User Changes
  • ISM-1686Partially meets
    Enable Credential Guard for Credential Protection
  • ISM-1809Depends on
    Compensating Controls for Unsupported Systems Pending Removal or Replacement
  • ISM-1866Partially meets
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1867Broader than
    Use Approved Mobile Platforms for Sensitive Access
  • ISM-1868Partially meets
    Restrictions on Mobile Device Removable Media
  • ISM-1886Partially meets
    Ensure Mobile Devices Operate in Supervised Mode
  • ISM-1887Broader than
    Implement Remote Locate and Wipe for Mobile Security
  • ISM-1888Partially meets
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-1896Partially meets
    Enable Memory Integrity for Credential Protection
  • ISM-1898Partially meets
    Use Secure Admin Workstations for Administration
  • ISM-2097Depends on
    Configure Mobile Devices with Always On VPN
Annex A 8.2
Management of Privileged Access Rights
Technological controls
  • ISM-0078Supports
    Australian Supervision of AUSTEO/AGAO Data Systems
  • ISM-0407Depends on
    Maintaining a Secure Lifetime Access Record for Each Human User
  • ISM-0415Partially overlaps
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0432Depends on
    Document System Access Requirements in Security Plans
  • ISM-0443Broader than
    Restrict Temporary Access to Secure Systems
  • ISM-0445Broader than
    Dedicated Privileged Accounts Used Solely for Privileged Duties
  • ISM-0446Partially overlaps
    Restrict Privileged Access for Foreign Nationals
  • ISM-0447Broader than
    Restrict Privileged Access for Foreign Nationals
  • ISM-0611Broader than
    Restrict Privileges for Gateway Administrators
  • ISM-0629Depends on
    Manage Gateways Between Different Security Domains
  • ISM-0665Depends on
    CISO Verifies and Authorises Trustworthy Sources for SECRET and TOP SECRET Systems
  • ISM-1175Broader than
    Restrict Privileged Users from Internet Access
  • ISM-1249Broader than
    Limit Server Application User Privileges
  • ISM-1250Partially overlaps
    Limit Server Application User Account Privileges
  • ISM-1263Broader than
    Enforce Unique Accounts for Server Administration
  • ISM-1297Depends on
    Seek Legal Advice for Personal Device Access
  • ISM-1392Depends on
    Restrict File Modifications via Path Rules
  • ISM-1422Depends on
    Prevent Unauthorised Access to Software Source
  • ISM-1487Partially overlaps
    Restrict Macro Editing to Privileged Users
  • ISM-1507Broader than
    Ensure Requests for Privileged Access are Verified
  • ISM-1508Partially overlaps
    Limit Privileged Access to Essential Duties Only
  • ISM-1565Depends on
    Annual Tailored Training for All Privileged Access Holders
  • ISM-1583Depends on
    Ensure Contractors are Identified as Users
  • ISM-1591Partially overlaps
    Remove or Suspend Access When Users Are Detected Acting Maliciously
  • ISM-1593Depends on
    Verify User Identity Before Issuing, Resetting, Disabling or Enrolling Credentials
  • ISM-1604Depends on
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1612Broader than
    Restricted Use of Break Glass Accounts for Emergencies
  • ISM-1614Partially overlaps
    Manage Emergency Account Access Changes
  • ISM-1619Depends on
    Configure Service Accounts as Managed Service Accounts
  • ISM-1620Broader than
    Ensure Privileged Accounts are Secured in AD
  • ISM-1647Broader than
    Disable Privileged Access After 12 Months
  • ISM-1648Broader than
    Disabling Inactive Privileged Access to Systems
  • ISM-1649Broader than
    Implement Just-in-Time Administration for System Access
  • ISM-1650Partially meets
    Log Management of Privileged User Activities
  • ISM-1685Depends on
    Strengthening Passwords for Critical Accounts
  • ISM-1688Broader than
    Block Unprivileged Account Logons to Privileged Operating Environments
  • ISM-1689Broader than
    Block Privileged Account Logons to Unprivileged Operating Environments
  • ISM-1706Partially overlaps
    Prevent Backup Access by Privileged Users
  • ISM-1827Broader than
    Use Dedicated Admin Accounts for Domain Controllers
  • ISM-1834Supports
    Ensure No Duplicate SPNs in Active Directory
  • ISM-1835Broader than
    Restrict Delegation of Privileged Active Directory Accounts
  • ISM-1842Broader than
    Use Privileged Accounts for Domain Machine Addition
  • ISM-1846Broader than
    Restrict Pre-Windows 2000 Access Group Membership
  • ISM-1883Broader than
    Limit Authorised Privileged Account Online Service Access to Duties
  • ISM-1898Depends on
    Use Secure Admin Workstations for Administration
  • ISM-1927Broader than
    Limit Identity Server Access to Privileged Users Requiring It
  • ISM-1932Partially overlaps
    Limit Service Accounts with SPNs in Active Directory
  • ISM-1934Broader than
    Six-Monthly Review and Removal of DCSync User Permissions
  • ISM-1936Partially meets
    Prevent Usage of sIDHistory in User Accounts
  • ISM-1939Broader than
    Minimise Members in Privileged Security Groups
  • ISM-1940Broader than
    Restrict Service Accounts from Privileged Groups
  • ISM-1942Broader than
    Domain Computers Group Privilege Restriction
  • ISM-1946Broader than
    Restrict Write Access to Certificate Templates
  • ISM-1948Depends on
    Certificate Manager Approval for Templates Allowing Supplied SANs
  • ISM-1949Broader than
    Use Dedicated Accounts for AD FS Administration
  • ISM-1950Depends on
    Disable Soft Matching After Synchronisation
  • ISM-1952Broader than
    Prevent Synchronisation of Privileged Accounts
  • ISM-1958Broader than
    Prevent Unauthorised Access for DCSync Accounts
  • ISM-2005Depends on
    Understanding Business Criticality of Organisation Systems
  • ISM-2048Broader than
    Restrict Non-Admins from Changing Permissions
  • ISM-2113Depends on
    Configuring AI Applications to Require Human Approval Before High-Impact Actions
  • ISM-2128Broader than
    Limit Kernel-Mode Code Installation to Privileged Users Who Need It
Annex A 8.3
Restrict access to information and assets
Technological controls
  • ISM-0133Partially overlaps
    Responding to Data Spills by Restricting Access
  • ISM-0217Partially meets
    Secure Separation of Non-TOP SECRET and TOP SECRET Panels
  • ISM-0267Partially meets
    Blocking Access to Unapproved Webmail Services
  • ISM-0343Partially meets
    Disabling Unnecessary Access to Removable Media
  • ISM-0382Partially meets
    Restrict Unprivileged User Actions on Applications
  • ISM-0409Partially meets
    Restrict Foreign Nationals' Access to Sensitive Data
  • ISM-0411Partially meets
    Restrict System Access for Foreign Nationals
  • ISM-0428Supports
    Enforcement of Secure Session Locking Measures
  • ISM-0441Broader than
    Restricting Temporary System Access to Data Required for Duties
  • ISM-0443Partially meets
    Restrict Temporary Access to Secure Systems
  • ISM-0462Partially overlaps
    Managing Encryption Access for IT Equipment and Media
  • ISM-0485Supports
    Use Public Key Authentication for SSH Access
  • ISM-0488Partially meets
    Use Forced Commands for SSH Without Passwords
  • ISM-0520Broader than
    Prevent Unauthorised Network Device Connections
  • ISM-0530Partially meets
    Administer VLANs from Trusted Security Domains
  • ISM-0551Broader than
    Ensure Secure IP Telephony Device Authentication
  • ISM-0555Broader than
    Ensure Authentication for IP Telephony Actions
  • ISM-0558Partially meets
    Restrict IP Phone Network Access in Public Areas
  • ISM-0611Partially meets
    Restrict Privileges for Gateway Administrators
  • ISM-0622Partially meets
    Ensuring Network Authentication via Gateways
  • ISM-0694Partially meets
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0854Partially meets
    Access Restrictions for AUSTEO and AGAO Data
  • ISM-0870Depends on
    Secure Storage and Handling of Mobile Devices
  • ISM-1006Partially meets
    Prevent Unauthorised Access to Network Traffic
  • ISM-1175Broader than
    Restrict Privileged Users from Internet Access
  • ISM-1249Partially meets
    Limit Server Application User Privileges
  • ISM-1250Partially meets
    Limit Server Application User Account Privileges
  • ISM-1255Broader than
    Restrict Database User Access Based on Duties
  • ISM-1256Partially meets
    Implement File-Based Access Controls for Databases
  • ISM-1268Broader than
    Enforce Need-to-Know Access in Databases
  • ISM-1323Partially meets
    Requiring Certificates for Wireless Network Access
  • ISM-1327Broader than
    Secure Certificates for Network Authentication
  • ISM-1386Partially meets
    Restrict Network Management Traffic Origin
  • ISM-1392Partially meets
    Restrict File Modifications via Path Rules
  • ISM-1403Partially meets
    Lock Accounts After Five Failed Logon Attempts
  • ISM-1422Broader than
    Prevent Unauthorised Access to Software Source
  • ISM-1439Broader than
    Restrict IP Disclosure in CDNs
  • ISM-1449Supports
    Protect SSH Private Keys with Passwords or Encryption
  • ISM-1487Broader than
    Restrict Write Access to Trusted Locations to Macro Vetting Users
  • ISM-1508Broader than
    Restricting Privileged Access to What Duties Require
  • ISM-1604Partially meets
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1611Partially meets
    Use Break Glass Accounts Only in Emergencies
  • ISM-1612Partially meets
    Restricted Use of Break Glass Accounts for Emergencies
  • ISM-1649Partially meets
    Implement Just-in-Time Administration for System Access
  • ISM-1705Partially meets
    Restrict Access to User Account Backups
  • ISM-1812Partially meets
    Restrict Backup Access to Unprivileged Users
  • ISM-1813Partially meets
    Prevent Unauthorised User Access to Backup Data
  • ISM-1814Partially meets
    Prevent Backup Modifications by Unprivileged Users
  • ISM-1815Partially meets
    Protect Event Logs from Unauthorised Access
  • ISM-1816Supports
    Prevent Unauthorised Changes to Software Sources
  • ISM-1817Partially meets
    Secure API Access with Authentication and Authorisation
  • ISM-1833Partially overlaps
    Limit Privileges for User Accounts in Active Directory
  • ISM-1838Supports
    Restrict UserPassword Attribute in AD Accounts
  • ISM-1839Partially meets
    Secure Account Properties in Active Directory
  • ISM-1841Partially meets
    Restrict Domain Joining to Admin Users Only
  • ISM-1846Partially meets
    Restrict Pre-Windows 2000 Access Group Membership
  • ISM-1852Broader than
    Limit Unprivileged Access to What Duties Require
  • ISM-1854Broader than
    Human Users Authenticate to MFDs Before Printing, Scanning or Copying
  • ISM-1862Broader than
    Restrict Access and Conceal Web Server IP Addresses
  • ISM-1866Partially overlaps
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1888Supports
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-1927Partially meets
    Restrict Access to Microsoft Active Directory Servers
  • ISM-1933Partially meets
    Restrict DCSync Permissions on Service Accounts
  • ISM-1936Partially meets
    Prevent Usage of sIDHistory in User Accounts
  • ISM-1985Partially meets
    Protect Event Logs from Unauthorised Access
  • ISM-2009Partially meets
    Restrict Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2014Partially meets
    Ensure API Client Authentication and Authorisation
  • ISM-2046Supports
    Ensure Secure Impersonation Logging Practices
  • ISM-2048Partially meets
    Restrict Non-Admins from Changing Permissions
  • ISM-2092Partially meets
    Enforce Fine-Grained Permissions for AI Applications
  • ISM-2093Broader than
    Role-Based Access Controls in AI Applications
  • ISM-2095Broader than
    Block Personal Devices Granting AI Agents Access to Sensitive Systems
  • ISM-2124Broader than
    Restricting Service Provider Access to Approved Tools, Addresses and Time Windows
  • ISM-2136Depends on
    Enforcing Risk-Based Access Decisions Informed by Contextual Signals
  • ISM-2137Broader than
    Block User OAuth Consent, Reserve It for Authorised Administrators
  • ISM-2156Broader than
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
  • ISM-2157Broader than
    Agentic AI Tool Calls Limited by User Access and Task-Scoped Authorisation
Annex A 8.4
Access management for source code and tools
Technological controls
  • ISM-0405Supports
    Validation for Unprivileged System Access Requests
  • ISM-0414Depends on
    Uniquely Identifying Every User Granted System Access
  • ISM-0415Depends on
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0430Supports
    Immediate Suspension of Unneeded System Access
  • ISM-0441Partially overlaps
    Restricting Temporary System Access to Data Required for Duties
  • ISM-1419Supports
    Software Development in Development Environments
  • ISM-1422Broader than
    Prevent Unauthorised Access to Software Source
  • ISM-1746Partially overlaps
    Restrict File System Permission Changes
  • ISM-1780Depends on
    Apply SecDevOps for Secure Software Development
  • ISM-1845Supports
    Disable User Security Group Access in Active Directory
  • ISM-2024Supports
    Utilise Authoritative Sources in Software Development
  • ISM-2033Supports
    Document and Maintain Software Security Requirements
  • ISM-2048Supports
    Restrict Non-Admins from Changing Permissions
Annex A 8.5
Secure authentication technologies and procedures
Technological controls
  • ISM-0417Partially meets
    Use Passwords When Multi-Factor Authentication Isn't Supported
  • ISM-0418Partially overlaps
    Keep Physical Credentials Separate from Systems
  • ISM-0421Broader than
    Require Minimum 15-Character Passwords for Security
  • ISM-0428Supports
    Enforcement of Secure Session Locking Measures
  • ISM-0484Partially meets
    Configure SSH for Secure Server Access
  • ISM-0485Broader than
    Use Public Key Authentication for SSH Access
  • ISM-0488Partially meets
    Use Forced Commands for SSH Without Passwords
  • ISM-0520Depends on
    Prevent Unauthorised Network Device Connections
  • ISM-0551Broader than
    Ensure Secure IP Telephony Device Authentication
  • ISM-0554Partially meets
    Secure Two-Way Authentication for Video Calls
  • ISM-0590Broader than
    Ensure Strong Authentication for Multi-Function Devices
  • ISM-0619Partially meets
    User Authentication for Network Gateway Access
  • ISM-0622Broader than
    Ensuring Network Authentication via Gateways
  • ISM-0974Partially meets
    Implement Multi-factor Authentication for User Access
  • ISM-1014Broader than
    Implement Individual Logins for Secure IP Phone Use
  • ISM-1034Partially meets
    Deploy HIPS or EDR on Critical and High-Value Servers
  • ISM-1055Broader than
    Disable Insecure LAN Manager Authentication
  • ISM-1151Broader than
    Verify Email Authenticity Using SPF
  • ISM-1173Partially meets
    Use Multi-Factor Authentication for Privileged Users
  • ISM-1200Partially overlaps
    Secure Bluetooth Pairing for Mobile Devices
  • ISM-1321Partially meets
    Implement EAP-TLS for Secure Wireless Authentication
  • ISM-1322Partially meets
    Assessing 802.1X Components in Wireless Networks
  • ISM-1323Broader than
    Requiring X.509 Certificates for 802.1X Network Authentication
  • ISM-1324Depends on
    Generating X.509 Certificates With Evaluated CA or HSM
  • ISM-1327Partially overlaps
    Secure Certificates for Network Authentication
  • ISM-1330Broader than
    Limit PMK Caching Duration on Wireless Networks
  • ISM-1504Broader than
    Multi-Factor Authentication for Human Users of Sensitive Data Online Services
  • ISM-1505Partially meets
    Implement Multi-factor Authentication for Data Repositories
  • ISM-1546Broader than
    Ensure User Authentication Before System Access
  • ISM-1558Broader than
    Ensure Secure Construction of Passwords
  • ISM-1559Broader than
    Minimum Password Length for Secure Systems
  • ISM-1560Broader than
    Ensure Strong Passwords for SECRET System Authentication
  • ISM-1603Broader than
    Disabling Vulnerable Authentication Methods
  • ISM-1679Broader than
    Multi-factor Authentication for Third-party Services Handling Sensitive Data
  • ISM-1680Partially meets
    Use Multi-Factor Authentication for Online Services
  • ISM-1681Broader than
    Mandating Multi-Factor Authentication for Customer Services
  • ISM-1682Broader than
    Phishing-resistant multi-factor authentication for human users of systems
  • ISM-1711Broader than
    Ensure User Identity Confidentiality in EAP-TLS
  • ISM-1817Broader than
    Secure API Access with Authentication and Authorisation
  • ISM-1818Broader than
    Client Authentication for Network API Access
  • ISM-1836Partially meets
    Require Kerberos Pre-Authentication for User Accounts
  • ISM-1854Partially meets
    Require User Authentication for Multifunction Devices
  • ISM-1872Broader than
    Ensuring Phishing-Resistant Multi-Factor Authentication
  • ISM-1874Partially meets
    Phishing-Resistant Multi-Factor Authentication for Customers
  • ISM-1892Broader than
    Multi-Factor Authentication for Organisation Users of Online Customer Services
  • ISM-1893Partially meets
    Enforcing Multi-Factor Authentication for User Security
  • ISM-1894Partially meets
    Ensuring Phishing-Resistant Multi-factor Authentication
  • ISM-1919Broader than
    Disable Authentication Protocols That Cannot Support Multi-Factor Authentication
  • ISM-1920Partially meets
    Prevent Self-enrollment on Untrusted Devices
  • ISM-1929Partially meets
    Ensure LDAP Signing on AD DS Domain Controllers
  • ISM-1943Broader than
    Enforce Certificate and User Mapping in AD Services
  • ISM-1947Broader than
    Remove User Authentication from Extended Key Usages
  • ISM-2009Partially meets
    Restrict Medical Devices in SECRET and TOP SECRET Areas
  • ISM-2011Broader than
    Disabling Weaker MFA Options When Phishing-Resistant MFA Is Used
  • ISM-2012Partially overlaps
    Enforced Screen Lock With Full Re-Authentication After Inactivity
  • ISM-2013Broader than
    Ensure Client Authentication for Internal Network APIs
  • ISM-2014Broader than
    Ensure API Client Authentication and Authorisation
  • ISM-2047Broader than
    Notify Users of Authentication Resets via Secondary Channel
  • ISM-2049Partially overlaps
    Enforcing Re-authentication After Permission Changes
  • ISM-2076Broader than
    Eliminating Security Questions for Authentication
  • ISM-2077Broader than
    Avoid Email for Out-of-Band Authentication
  • ISM-2081Broader than
    Enforce Use of All ASCII Characters in Passwords
  • ISM-2092Depends on
    Enforce Fine-Grained Permissions for AI Applications
  • ISM-2109Broader than
    Pre-Boot Authentication for Encrypted System Volume Media
  • ISM-2126Depends on
    Positively Identify Requestors Before Actioning Account, Banking or Payment Requests
  • ISM-2140Broader than
    Disable OAuth Device Code Flow Unless Required and Restrict Its Use
  • ISM-2147Broader than
    Cryptographically Bind Tokens and Session Cookies to Issuing Device
  • ISM-2165Broader than
    Fresh EAP-TLS Authentication for Each New Connectivity Association Key
  • ISM-2167Broader than
    Disabling Pre-Shared Key Fallback Authentication for MACsec
Annex A 8.6
Capacity Management for Resource Use
Technological controls
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-0518Supports
    Maintain Comprehensive Network Documentation
  • ISM-1431Partially overlaps
    Strategies for Mitigating Denial-of-Service Attacks
  • ISM-1579Partially overlaps
    Dynamic Resource Scaling for Demand Spikes
  • ISM-1581Partially overlaps
    Monitor Capacity and Availability of Online Services
  • ISM-2090Supports
    Rate Limiting for AI Inference Queries
  • ISM-2091Broader than
    Enforce Resource Limits for AI Models
  • ISM-2114Partially overlaps
    Monitor Baselines for AI Application Performance
Annex A 8.7
Protection against malware
Technological controls
  • ISM-0263Depends on
    Inspect and Decrypt TLS Traffic through Gateways
  • ISM-0651Broader than
    Block Malicious or Uninspectable Files
  • ISM-0652Broader than
    Quarantine Suspicious Files for Review
  • ISM-0657Broader than
    Scanning Data for Threats Before Manual Import
  • ISM-0917Partially overlaps
    Procedures for Handling Malicious Code Infections
  • ISM-1234Broader than
    Protect Email Systems with Content Filtering
  • ISM-1287Depends on
    Ensure Gateway and CDS File Content Sanitisation
  • ISM-1288Broader than
    Antivirus Scanning of Gateway Files
  • ISM-1289Broader than
    Unpack Archive Files for Content Filtering at Gateways
  • ISM-1290Supports
    Controlled Unpacking of Archive Files for Filtering
  • ISM-1299Depends on
    Personnel Awareness for Secure Mobile Device Usage
  • ISM-1341Broader than
    Implement HIPS or EDR on Workstations
  • ISM-1389Broader than
    Analyse Executable Files in Sandboxes
  • ISM-1417Partially meets
    Ensure Antivirus Protection on Workstations and Servers
  • ISM-1486Broader than
    Restrict Java Processing in Web Browsers
  • ISM-1565Depends on
    Annual Tailored Training for All Privileged Access Holders
  • ISM-1608Broader than
    Scan Third-Party SOEs for Malicious Code
  • ISM-1659Supports
    Implement Microsoft's Vulnerable Driver Blocklist
  • ISM-1672Broader than
    Enable Antivirus Scanning for Office Macros
  • ISM-1745Partially overlaps
    Enable Security Features for System Protection
  • ISM-1782Depends on
    Use Protective DNS to Block Malicious Domains
  • ISM-1890Broader than
    Ensure Macros Are Free of Malicious Code
  • ISM-1969Broader than
    Preventing Accidental Execution of Malicious Code
  • ISM-2026Broader than
    Scan Software Artefacts for Malicious Content
Annex A 8.8
Management of Technical Vulnerabilities
Technological controls
  • ISM-0290Depends on
    Secure Configuration of High Assurance IT Equipment
  • ISM-0298Broader than
    Centralised System Patch and Update Management
  • ISM-0300Broader than
    Apply System Security Patches with Approval
  • ISM-0912Partially overlaps
    Establish and Manage System Configuration Changes
  • ISM-1143Depends on
    Develop and Maintain Patch Management Procedures
  • ISM-1163Partially overlaps
    Continuous Monitoring Plan to Find and Fix Vulnerabilities
  • ISM-1211Depends on
    System Administration Performed Under Change and Configuration Management Plan
  • ISM-1246Depends on
    Apply Strict Server Application Hardening Guidelines
  • ISM-1316Broader than
    Ensure Default Wireless SSIDs Are Changed
  • ISM-1366Broader than
    Ensure Timely Security Updates for Mobile Devices
  • ISM-1424Depends on
    Ensure Web Security Through Response Headers
  • ISM-1483Depends on
    Use Latest Release of Internet-Facing Server Applications
  • ISM-1501Broader than
    Replace Unsupported Operating Systems
  • ISM-1526Partially overlaps
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1585Depends on
    Lock Web Browser Security Settings Against Human User Changes
  • ISM-1605Depends on
    Harden the Operating System Beneath Software Isolation Mechanisms
  • ISM-1606Broader than
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1616Partially overlaps
    Implementing a Vulnerability Disclosure Program
  • ISM-1622Broader than
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1635Partially meets
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1643Depends on
    Maintain Detailed Software Version and Patch Records
  • ISM-1659Supports
    Implement Microsoft's Vulnerable Driver Blocklist
  • ISM-1690Broader than
    Timely Application of Non-Critical Vulnerability Patches
  • ISM-1691Broader than
    Timely Vulnerability Patching in Software Tools
  • ISM-1692Broader than
    Quick Apply Critical Patches for Vulnerabilities
  • ISM-1693Broader than
    Timely Application of Patches to Mitigate Vulnerabilities
  • ISM-1694Broader than
    Timely Application of Non-Critical Security Patches
  • ISM-1695Broader than
    Timely Application of System Security Patches
  • ISM-1696Broader than
    Apply Critical Patches Within 48 Hours
  • ISM-1697Broader than
    Apply Non-Critical Patches Within One Month
  • ISM-1698Broader than
    Daily Vulnerability Scanning for Missing Updates
  • ISM-1701Broader than
    Daily Vulnerability Scanning for Internet-Facing Systems
  • ISM-1702Broader than
    Regularly Scan for Missing Security Patches
  • ISM-1703Partially meets
    Regular Vulnerability Scanning for Missing Patches
  • ISM-1704Depends on
    Remove Unsupported Software to Ensure Security
  • ISM-1717Partially overlaps
    Implement Security.txt for Vulnerability Disclosure
  • ISM-1745Depends on
    Enable Security Features for System Protection
  • ISM-1751Broader than
    Timely Application of Vendor Patches for Non-Critical OS Vulnerabilities
  • ISM-1752Broader than
    Fortnightly Vulnerability Scanning for Non-Workstations
  • ISM-1754Broader than
    Timely Resolution of Identified Software Vulnerabilities
  • ISM-1755Depends on
    Develop and Maintain a Vulnerability Disclosure Policy
  • ISM-1756Partially overlaps
    Develop and Maintain Vulnerability Disclosure Processes
  • ISM-1808Broader than
    Vulnerability Scanning with Updated Tools
  • ISM-1809Partially overlaps
    Implement Compensating Controls for Unsupported Systems
  • ISM-1829Broader than
    Prevent Password Storage in Group Policy Preferences
  • ISM-1848Depends on
    Replace Unsupported Software-Based Isolation Mechanisms Sharing Physical Resources
  • ISM-1876Partially meets
    Apply Critical Patches Within 48 Hours
  • ISM-1877Broader than
    Timely Application of Critical Security Patches
  • ISM-1878Broader than
    Apply Critical Patches Within 48 Hours
  • ISM-1879Broader than
    Timely Patching of Critical Driver Vulnerabilities
  • ISM-1900Broader than
    Fortnightly System Vulnerability Scanning
  • ISM-1901Broader than
    Timely Application of Non-Critical Security Patches
  • ISM-1903Broader than
    Rapid Application of Critical Firmware Patches
  • ISM-1904Broader than
    Apply Firmware Patches for Non-Critical Vulnerabilities
  • ISM-1905Partially meets
    Remove Online Services No Longer Supported by Vendors
  • ISM-1913Partially overlaps
    Develop and Maintain Approved IT Configurations
  • ISM-1914Partially meets
    Ensure Operating Systems Have Approved Configurations
  • ISM-1915Partially meets
    Ensure User Application Configurations are Approved
  • ISM-1916Partially meets
    Ensure Server Application Configurations Are Approved
  • ISM-1931Supports
    Ensure SID Filtering for Domain and Forest Trusts
  • ISM-1956Depends on
    Regularly Update AD FS Certificates to Prevent Risks
  • ISM-2054Partially meets
    Ensure No Vulnerabilities in Third-Party Software Components
  • ISM-2118Broader than
    Conduct Vulnerability Assessments and Penetration Tests
  • ISM-2119Depends on
    Utilise AI Models in Vulnerability Assessments and Penetration Tests
  • ISM-2131Partially overlaps
    Quarterly Certificate Template Reviews to Remediate Misconfigurations
  • ISM-2161Depends on
    Verify Network Device Firmware and Configuration Against Known-Good Baseline
Annex A 8.9
Configuration Management for Secure IT Systems
Technological controls
  • ISM-0042Partially overlaps
    Maintain Effective System Administration Practices
  • ISM-0211Supports
    Develop and Verify a Cable Register
  • ISM-0272Broader than
    Restrict Protective Marking Tools to Authorised System Markings
  • ISM-0289Partially overlaps
    Implement and Manage Evaluated Products Correctly
  • ISM-0290Partially overlaps
    Secure Configuration of High Assurance IT Equipment
  • ISM-0341Partially meets
    Disable Automatic Execution for Removable Media
  • ISM-0380Partially meets
    Disable Unneeded OS Accounts and Services
  • ISM-0383Partially meets
    Change Default OS User Accounts During Setup
  • ISM-0481Supports
    Ensure Use of High Assurance Cryptographic Protocols
  • ISM-0484Partially meets
    Configure SSH for Secure Server Access
  • ISM-0487Partially meets
    Disable Certain Features for Passwordless SSH Logins
  • ISM-0498Broader than
    Ensure Short Lifetimes for IPsec Associations
  • ISM-0516Supports
    Comprehensive Network Diagrams for Critical Components
  • ISM-0518Supports
    Maintain Comprehensive Network Documentation
  • ISM-0530Supports
    Administer VLANs from Trusted Security Domains
  • ISM-0567Partially meets
    Restrict Email Relay to Specific Domains
  • ISM-0570Partially meets
    Maintain Backup Email Gateways to Primary Standards
  • ISM-0574Partially meets
    Use SPF to Authorise Email Servers
  • ISM-0589Partially overlaps
    Limit Document Sensitivity on MFDs Based on Network Classification
  • ISM-0591Supports
    Use Evaluated Peripheral Switches Securely
  • ISM-0864Partially meets
    Prevent Modifications to Security Settings on Mobile Devices
  • ISM-0912Partially overlaps
    Establish and Manage System Configuration Changes
  • ISM-1027Partially meets
    Configure Email Distribution Lists to Preserve DKIM Signatures
  • ISM-1034Partially meets
    Deploy HIPS or EDR on Critical and High-Value Servers
  • ISM-1037Partially meets
    Regular Testing of Gateway Security Configurations
  • ISM-1055Partially meets
    Disable Insecure LAN Manager Authentication
  • ISM-1183Partially meets
    Implement Hard Fail SPF Records for Email Security
  • ISM-1196Partially meets
    Keep Mobile Devices Undiscoverable via Bluetooth
  • ISM-1211Partially meets
    System Admin Activities Follow Change Management Plan
  • ISM-1260Partially meets
    Secure Server Applications by Changing Default Credentials
  • ISM-1272Partially meets
    Disable Database Networking for Local Access
  • ISM-1277Depends on
    Encrypt Database and Web Server Communications
  • ISM-1304Partially meets
    Secure Network Devices by Changing Default Credentials
  • ISM-1311Partially meets
    Prevent Use of Insecure SNMP Versions on Networks
  • ISM-1312Partially meets
    Changing Default SNMP Community Strings on Devices
  • ISM-1316Partially meets
    Ensure Default Wireless SSIDs Are Changed
  • ISM-1319Partially meets
    Avoid Static IP Addressing on Wireless Networks
  • ISM-1369Partially meets
    Ensure TLS Connections Use AES-GCM Encryption
  • ISM-1406Broader than
    Use SOEs for Workstations and Servers
  • ISM-1408Broader than
    Use 64-bit Operating Systems
  • ISM-1409Partially meets
    Implement Restrictive OS Hardening Guidelines
  • ISM-1419Supports
    Software Development in Development Environments
  • ISM-1428Partially meets
    Disable IPv6 Tunnelling Unless Necessary
  • ISM-1439Depends on
    Restrict IP Disclosure in CDNs
  • ISM-1450Supports
    Restricting Devices in Top Secret Areas
  • ISM-1489Depends on
    Lock Microsoft Office Macro Security Settings Against User Changes
  • ISM-1493Supports
    Maintain and Verify Software Registers
  • ISM-1536Partially meets
    Centrally Log User-Initiated Database Queries and Errors
  • ISM-1540Partially meets
    Configuring DMARC for Email Security
  • ISM-1552Depends on
    Secure Web Content with HTTPS Only
  • ISM-1562Partially meets
    Secure Video Conferencing and Telephony Systems
  • ISM-1585Broader than
    Lock Web Browser Security Settings Against Human User Changes
  • ISM-1588Partially meets
    Annual Review of Standard Operating Environments
  • ISM-1598Partially meets
    Inspect IT Equipment Post-Maintenance for Unauthorised Changes
  • ISM-1604Partially meets
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1605Depends on
    Harden the Operating System Beneath Software Isolation Mechanisms
  • ISM-1608Partially overlaps
    Scan Third-Party SOEs for Malicious Code
  • ISM-1619Supports
    Configure Service Accounts as Managed Service Accounts
  • ISM-1622Partially meets
    Ensure PowerShell Uses Constrained Language Mode
  • ISM-1627Depends on
    Block Inbound Traffic from Anonymity Networks
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1635Broader than
    Ensure Security Controls for System Environments
  • ISM-1646Supports
    Detail Cabling Paths and Points on Floor Plans
  • ISM-1669Partially meets
    Prevent Microsoft Office from Injecting Code
  • ISM-1673Partially meets
    Prevent Win32 API Calls by Office Macros
  • ISM-1696Supports
    Apply Critical Patches Within 48 Hours
  • ISM-1710Partially meets
    Secure Default Settings for Wireless Access Points
  • ISM-1730Supports
    Provide a Software Bill of Materials to Consumers
  • ISM-1798Supports
    Develop Secure Configuration Guidelines for Software
  • ISM-1806Partially meets
    Change Default User Credentials During Setup
  • ISM-1809Depends on
    Compensating Controls for Unsupported Systems Pending Removal or Replacement
  • ISM-1823Partially meets
    Prevent Users from Changing Security Settings in Apps
  • ISM-1824Partially meets
    Prevent Changes to PDF Application Security Settings
  • ISM-1825Partially meets
    Ensure Security Configuration Is Immutable by Users
  • ISM-1828Partially meets
    Disable Print Spooler on AD DS Domain Controllers
  • ISM-1832Partially meets
    SPN Configuration for Active Directory Accounts
  • ISM-1834Partially meets
    Ensure No Duplicate SPNs in Active Directory
  • ISM-1838Partially meets
    Restrict UserPassword Attribute in AD Accounts
  • ISM-1860Partially meets
    Harden PDF Applications Using ASD Guidance
  • ISM-1887Partially meets
    Implement Remote Locate and Wipe for Mobile Security
  • ISM-1888Supports
    Ensure Mobile Devices Have Secure Lock Screens
  • ISM-1912Partially overlaps
    Document Device Settings for Critical and High-Value Servers
  • ISM-1913Equivalent
    Develop and Maintain Approved IT Configurations
  • ISM-1914Broader than
    Ensure Operating Systems Have Approved Configurations
  • ISM-1915Partially meets
    Ensure User Application Configurations are Approved
  • ISM-1916Broader than
    Ensure Server Application Configurations Are Approved
  • ISM-1926Partially meets
    Ensure Exclusive Usage of Microsoft AD Servers
  • ISM-1931Partially meets
    Ensure SID Filtering for Domain and Forest Trusts
  • ISM-1935Partially meets
    Prevent Unconstrained Delegation in Domain Services
  • ISM-1944Broader than
    Remove EDITF_ATTRIBUTESUBJECTALTNAME2 Flag From AD CS Certification Authorities
  • ISM-1951Partially meets
    Disable Hard Match Takeover in Microsoft Entra Connect
  • ISM-1956Partially meets
    Regularly Update AD FS Certificates to Prevent Risks
  • ISM-1981Supports
    Replace Unsupportable Non-Internet Network Devices
  • ISM-2025Supports
    Using Issue Tracking for Software Development Tasks
  • ISM-2031Supports
    Secure System Build Tools Implementation
  • ISM-2033Supports
    Document and Maintain Software Security Requirements
  • ISM-2045Supports
    Ensure Backwards Compatibility Doesn't Weaken Security
  • ISM-2084Supports
    Document AI Model and System Characteristics
  • ISM-2113Depends on
    Configuring AI Applications to Require Human Approval Before High-Impact Actions
  • ISM-2127Broader than
    Enforce Driver Digital Signature Verification Before Loading
  • ISM-2130Broader than
    Disabling or Hardening AD CS Web Enrolment Interfaces
  • ISM-2131Broader than
    Quarterly Certificate Template Reviews to Remediate Misconfigurations
  • ISM-2161Depends on
    Verify Network Device Firmware and Configuration Against Known-Good Baseline
  • ISM-2162Broader than
    Disabling or Removing Unneeded Network Device Components and Services
  • ISM-2167Broader than
    Disabling Pre-Shared Key Fallback Authentication for MACsec
Annex A 8.10
Secure deletion of information when no longer needed
Technological controls
  • ISM-0307Partially overlaps
    Sanitise Equipment When Not Using Cleared Technician
  • ISM-0311Partially overlaps
    Ensuring Sanitisation of IT Equipment Media
  • ISM-0317Broader than
    Ensuring Data Erasure on Printer Cartridges and Drums
  • ISM-0330Partially overlaps
    Proper Sanitisation and Reclassification of Media
  • ISM-0348Supports
    Develop and Maintain Media Sanitisation Procedures
  • ISM-0351Broader than
    Proper Method for Volatile Media Sanitisation
  • ISM-0357Partially meets
    Sanitising Non-volatile EPROM Media
  • ISM-0359Partially meets
    Proper Sanitisation of Non-Volatile Flash Memory
  • ISM-0361Supports
    Using Degaussers for Magnetic Media Destruction
  • ISM-0362Supports
    Follow Manufacturer's Directions for Degaussing
  • ISM-0363Depends on
    Develop and Maintain Media Destruction Processes
  • ISM-0371Partially overlaps
    Ensure Proper Supervision of Media Destruction
  • ISM-0375Partially overlaps
    Decide on Public Release of Data Storage Media
  • ISM-0835Partially overlaps
    TOP SECRET Volatile Media Retains Classification After Sanitisation
  • ISM-0947Broader than
    Sanitise Media After Data Transfers Between Domains
  • ISM-1065Supports
    Reset Device Settings Before Media Sanitisation
  • ISM-1160Broader than
    Use NSA-evaluated Degaussers for Media Destruction
  • ISM-1221Partially meets
    Check Printers and MFDs for Trapped Pages
  • ISM-1223Broader than
    Methods for Sanitising Network Device Memory
  • ISM-1574Partially overlaps
    Data Portability in Service Contracts
  • ISM-1600Partially overlaps
    Ensure Media is Sanitised Before Initial Use
  • ISM-1722Partially meets
    Methods for Destroying Electrostatic Memory Devices
  • ISM-1723Partially meets
    Methods for Destroying Magnetic Floppy Disks
  • ISM-2021Broader than
    Implement and Maintain Data Minimisation Practices
  • ISM-2053Partially overlaps
    End of Life Procedures for Software
  • ISM-2111Broader than
    Remove Temporary Installation Files Post-Installation
  • ISM-2123Broader than
    Delete AI Chat Session Prompts and Outputs
Annex A 8.11
Data Masking for Sensitive Information
Technological controls
  • ISM-1268Partially overlaps
    Enforce Need-to-Know Access in Databases
Annex A 8.12
Data Leakage Prevention Measures
Technological controls
  • ISM-0240Broader than
    Prevent Sensitive Data in Messaging Services
  • ISM-0267Supports
    Blocking Access to Unapproved Webmail Services
  • ISM-0325Depends on
    Reclassify Media to Higher Sensitivity
  • ISM-0565Broader than
    Email Security for Protective Markings
  • ISM-0589Partially meets
    Limit Document Sensitivity on MFDs Based on Network Classification
  • ISM-0591Depends on
    Use Evaluated Peripheral Switches Securely
  • ISM-0639Depends on
    Use Evaluated Firewalls Between Security Domains
  • ISM-0659Partially overlaps
    Filtering Content of Gateway and CDS Files
  • ISM-0661Partially overlaps
    User Accountability for Data Transfers
  • ISM-0664Partially overlaps
    Authorisation of Secret Data Exports
  • ISM-0669Partially overlaps
    Security Measures for Manual Data Export
  • ISM-0682Broader than
    Disable Bluetooth on SECRET/TS Mobile Devices
  • ISM-1024Supports
    Verify Senders for Email Failure Notifications
  • ISM-1085Supports
    Encrypt Sensitive Data Over Public Networks
  • ISM-1089Depends on
    Block Downgrading Protective Markings on Email Replies and Forwards
  • ISM-1187Partially overlaps
    Check Data for Improper Markings Before Export
  • ISM-1192Partially overlaps
    Inspecting and Filtering Data with Gateways
  • ISM-1293Supports
    Decrypt Encrypted Files for Content Filtering
  • ISM-1299Supports
    Personnel Awareness for Secure Mobile Device Usage
  • ISM-1400Depends on
    Enforce Data Separation on Personal Devices
  • ISM-1429Depends on
    Block IPv6 Tunnelling at Externally Connected Network Boundaries
  • ISM-1482Supports
    Ensure Separation of Classified and Personal Data on Devices
  • ISM-1534Broader than
    Remove and Destroy Printer and MFD Ribbons
  • ISM-1535Partially overlaps
    Prevent Unsuitable Foreign Data Exports
  • ISM-1565Depends on
    Annual Tailored Training for All Privileged Access Holders
  • ISM-1778Depends on
    Quarantine Security-Noncompliant Data for Review
  • ISM-1866Broader than
    Prevent Storing Classified Data on Privately Owned Devices
  • ISM-1868Depends on
    Restrictions on Mobile Device Removable Media
  • ISM-1875Broader than
    Monthly System Scans to Detect Credentials Stored in the Clear
  • ISM-1885Partially overlaps
    Implement Emanation Security Measures for Systems
  • ISM-1924Supports
    Detect and Mitigate Adversarial Prompts in Generative AI Applications
  • ISM-1930Depends on
    Prevent Storing Passwords in Group Policy Preferences
  • ISM-1965Supports
    Content Checking for Imported or Exported Files
  • ISM-2052Partially overlaps
    Ensure Event Logs Protect Sensitive Data
  • ISM-2094Broader than
    AI Content Filtering to Block Sensitive Data Exposure
Annex A 8.13
Backup and Recovery Procedures for Data
Technological controls
  • ISM-0042Partially meets
    Maintain Effective System Administration Practices
  • ISM-0917Partially overlaps
    Procedures for Handling Malicious Code Infections
  • ISM-1511Partially overlaps
    Conduct and Maintain Regular Data Backups
  • ISM-1515Broader than
    Test Backup Restoration During Disaster Recovery
  • ISM-1547Partially overlaps
    Develop and Maintain Data Backup Procedures
  • ISM-1548Partially overlaps
    Develop and Maintain Data Restoration Processes
  • ISM-1555Partially meets
    Prepare Mobile Devices Before Overseas Travel
  • ISM-1574Depends on
    Data Portability in Service Contracts
  • ISM-1705Supports
    Restrict Access to User Account Backups
  • ISM-1732Depends on
    Coordinating and Sequencing Intrusion Remediation to Prevent Re-Compromise
  • ISM-1810Broader than
    Ensuring Data Backup Synchronisation
  • ISM-1928Broader than
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-2151Broader than
    Technically Enforced Immutability Protecting Backups Through Their Retention Period
Annex A 8.14
Redundancy of Information Processing Facilities
Technological controls
  • ISM-1405Depends on
    Implement a Centralised Event Logging Facility
Annex A 8.15
Logging of Activities and Events
Technological controls
  • ISM-0138Depends on
    Maintaining Integrity of Evidence in Investigations
  • ISM-0261Broader than
    Log Web Proxy Activity for Security Analysis
  • ISM-0415Depends on
    Strictly Controlling Shared Accounts and Identifying Their Users
  • ISM-0565Broader than
    Email Security for Protective Markings
  • ISM-0580Partially overlaps
    Develop, Implement and Maintain a Security Monitoring Policy
  • ISM-0582Broader than
    Central Logging of Windows Security Events
  • ISM-0585Broader than
    Capture Detailed Information in Event Logs
  • ISM-0634Broader than
    Central Logging for Gateway Security Events
  • ISM-0661Supports
    Holding Human Users Accountable for Data Transfers They Perform
  • ISM-0670Broader than
    Central Logging of CDS Security Events
  • ISM-0988Supports
    Ensure Accurate Time Source for Event Logs
  • ISM-1030Broader than
    Deploy NIDS/NIPS for Gateway Traffic Monitoring
  • ISM-1213Broader than
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1228Supports
    Analyse Cyber Security Events Promptly
  • ISM-1341Depends on
    Implement HIPS or EDR on Workstations
  • ISM-1405Partially overlaps
    Implement a Centralised Event Logging Facility
  • ISM-1509Broader than
    Log Privileged Access Events Centrally for Monitoring
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1536Broader than
    Central Logging of Software Database Queries and Errors
  • ISM-1537Broader than
    Log Security-Relevant Database Events Centrally
  • ISM-1566Broader than
    Central Logging of Unprivileged System Access
  • ISM-1586Broader than
    Record All Data Imports and Exports
  • ISM-1611Depends on
    Use Break Glass Accounts Only in Emergencies
  • ISM-1613Partially meets
    Central Logging of Break Glass Account Usage
  • ISM-1623Broader than
    Centralised Logging of PowerShell Activities
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1650Broader than
    Log Management of Privileged User Activities
  • ISM-1683Broader than
    Central Logging of Multi-factor Authentication Events
  • ISM-1805Depends on
    Develop a Denial of Service Response Plan
  • ISM-1830Broader than
    Central Logging of Security Events for Microsoft AD Infrastructure Servers
  • ISM-1855Partially meets
    Central Logging of Multifunction Device Use
  • ISM-1889Broader than
    Central Logging of Command Line Events
  • ISM-1895Broader than
    Log Single-factor Authentication Events
  • ISM-1906Broader than
    Timely Analysis of Internet-Facing Server Logs
  • ISM-1911Broader than
    Centralised Logging of Software Errors and Usage
  • ISM-1937Broader than
    Weekly Audit of sIDHistory in User Accounts
  • ISM-1941Supports
    Restrict Computer Accounts in Privileged Security Groups
  • ISM-1959Broader than
    Ensure Consistent Formatting for Event Logs
  • ISM-1963Broader than
    Central Logging of Events on Internet-Facing Devices
  • ISM-1964Broader than
    Central Logging for Network Device Events
  • ISM-1978Partially meets
    Centralised Logging for Server Application Events
  • ISM-1979Broader than
    Central Logging for Security Events on Servers
  • ISM-1983Broader than
    Log Events Sent to Centralised Facility Quickly
  • ISM-1984Depends on
    Encrypt Event Logs in Transit Using ASD Cryptography
  • ISM-1985Broader than
    Protect Event Logs from Unauthorised Access
  • ISM-1986Broader than
    Timely Analysis of Critical Server Event Logs
  • ISM-1987Broader than
    Timely Analysis of Security Event Logs
  • ISM-1988Broader than
    Ensure Event Logs Are Retained for 12 Months
  • ISM-1989Partially overlaps
    Ensure Event Logs Meet Retention Requirements
  • ISM-2015Broader than
    Central Logging of Non-Internet Network API Data Access
  • ISM-2046Partially overlaps
    Ensure Secure Impersonation Logging Practices
  • ISM-2051Partially meets
    Ensure Event Logs for Cyber security Event Detection
  • ISM-2052Broader than
    Ensure Event Logs Protect Sensitive Data
  • ISM-2089Broader than
    Monitor AI Model Performance and Investigate Anomalies
  • ISM-2094Depends on
    AI Content Filtering to Block Sensitive Data Exposure
  • ISM-2116Depends on
    Use Cyber Threat Intelligence for Event Detection
  • ISM-2117Supports
    AI Models Augment Cyber Security Event Detection
  • ISM-2125Broader than
    Independently Log and Analyse All Service Provider System Access
  • ISM-2129Broader than
    Centrally Log WMI Activity and Event Subscriptions
  • ISM-2132Broader than
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2139Broader than
    Central Logging of Third-Party OAuth Consent, Token Issuance and Use
  • ISM-2153Depends on
    Quarterly Threat Hunting Informed by Current Threat Intelligence
  • ISM-2159Broader than
    Centrally Log Agentic AI Tool Invocations, External Requests and Outputs
Annex A 8.16
Monitoring Networks and Systems for Anomalous Behaviour
Technological controls
  • ISM-0120Supports
    Access to Tools for Detecting Security Events
  • ISM-0261Depends on
    Log Web Proxy Activity for Security Analysis
  • ISM-0263Depends on
    Inspect and Decrypt TLS Traffic through Gateways
  • ISM-0582Partially meets
    Central Logging of Windows Security Events
  • ISM-0585Depends on
    Capture Detailed Information in Event Logs
  • ISM-0634Depends on
    Central Logging for Gateway Security Events
  • ISM-0652Partially overlaps
    Quarantine Suspicious Files for Review
  • ISM-1028Depends on
    Use NIDS/NIPS for Gateway Network Security
  • ISM-1030Broader than
    Deploy NIDS/NIPS for Gateway Traffic Monitoring
  • ISM-1213Broader than
    Enhanced Monitoring After Intrusion Remediation Until Eradication Is Confirmed
  • ISM-1341Depends on
    Implement HIPS or EDR on Workstations
  • ISM-1430Depends on
    Configure IPv6 Addresses with DHCPv6 in Stateful Mode
  • ISM-1431Partially overlaps
    Strategies for Mitigating Denial-of-Service Attacks
  • ISM-1526Depends on
    System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
  • ISM-1537Depends on
    Log Security-Relevant Database Events Centrally
  • ISM-1556Depends on
    Security Measures After Overseas Travel with Mobile Devices
  • ISM-1566Depends on
    Central Logging of Unprivileged System Access
  • ISM-1607Broader than
    Integrity Monitoring and Logging for Isolation Mechanism
  • ISM-1650Depends on
    Log Management of Privileged User Activities
  • ISM-1830Depends on
    Central Logging of Security Events for Microsoft AD Infrastructure Servers
  • ISM-1889Depends on
    Central Logging of Command Line Events
  • ISM-1911Depends on
    Centralised Logging of Software Errors and Usage
  • ISM-1924Depends on
    Detect and Mitigate Adversarial Prompts in Generative AI Applications
  • ISM-1963Depends on
    Central Logging of Events on Internet-Facing Devices
  • ISM-1970Depends on
    Segregated Environment for Malicious Code Analysis
  • ISM-1976Broader than
    Central Logging of Security Events on macOS
  • ISM-1978Partially meets
    Centralised Logging for Server Application Events
  • ISM-1979Partially meets
    Central Logging for Security Events on Servers
  • ISM-1987Partially overlaps
    Timely Analysis of Security Event Logs
  • ISM-2015Depends on
    Central Logging of Non-Internet Network API Data Access
  • ISM-2051Depends on
    Ensure Event Logs for Cyber security Event Detection
  • ISM-2089Broader than
    Monitor AI Model Performance and Investigate Anomalies
  • ISM-2114Broader than
    Monitor Baselines for AI Application Performance
  • ISM-2116Depends on
    Use Cyber Threat Intelligence for Event Detection
  • ISM-2117Depends on
    AI Models Augment Cyber Security Event Detection
  • ISM-2153Depends on
    Quarterly Threat Hunting Informed by Current Threat Intelligence
Annex A 8.17
Clock synchronisation for information systems
Technological controls
  • ISM-0585Supports
    Capture Detailed Information in Event Logs
  • ISM-0988Partially overlaps
    Ensure Accurate Time Source for Event Logs
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2139Depends on
    Central Logging of Third-Party OAuth Consent, Token Issuance and Use
Annex A 8.18
Use of Privileged Utility Programs
Technological controls
  • ISM-0382Supports
    Restrict Unprivileged User Actions on Applications
  • ISM-0846Supports
    Prevent Users Disabling, Bypassing or Exempting Application Control
  • ISM-1491Partially overlaps
    Prevent Script Execution by Unprivileged Users
  • ISM-1584Depends on
    Prevent Unauthorised Changes to Security Settings
  • ISM-1592Partially overlaps
    Prevent Unauthorised Application Installations by Users
  • ISM-1657Partially overlaps
    Restrict Application Execution to Approved Set
  • ISM-1658Partially overlaps
    Restrict Execution of Drivers via Application Control
  • ISM-1746Depends on
    Restrict File System Permission Changes
  • ISM-1748Depends on
    Lock Email Client Security Settings Against User Changes
  • ISM-2023Supports
    Maintain a Reliable Source for Software
Annex A 8.19
Secure Software Installation Procedures
Technological controls
  • ISM-0042Partially meets
    Maintain Effective System Administration Practices
  • ISM-0289Partially overlaps
    Implement and Manage Evaluated Products Correctly
  • ISM-0290Supports
    Secure Configuration of High Assurance IT Equipment
  • ISM-0382Broader than
    Prevent Unprivileged Human Users Uninstalling or Disabling Approved Applications
  • ISM-0912Partially overlaps
    Establish and Manage System Configuration Changes
  • ISM-1143Partially overlaps
    Develop and Maintain Patch Management Procedures
  • ISM-1211Depends on
    System Administration Performed Under Change and Configuration Management Plan
  • ISM-1245Partially meets
    Remove Temporary Files After Server Installation
  • ISM-1406Partially overlaps
    Use SOEs for Workstations and Servers
  • ISM-1409Partially overlaps
    Implement Restrictive OS Hardening Guidelines
  • ISM-1419Partially overlaps
    Software Development in Development Environments
  • ISM-1493Partially overlaps
    Maintain and Verify Software Registers
  • ISM-1592Partially overlaps
    Prevent Unauthorised Application Installations by Users
  • ISM-1598Depends on
    Inspect IT Equipment Post-Maintenance for Unauthorised Changes
  • ISM-1606Supports
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1608Supports
    Scan Third-Party SOEs for Malicious Code
  • ISM-1635Partially meets
    System Owners Implement Security Controls for Each System and Environment
  • ISM-1655Partially meets
    Ensure .NET Framework 3.5 is Disabled or Removed
  • ISM-1796Supports
    Digitally Sign Executable Software for Security
  • ISM-1797Partially meets
    Ensure Software Updates are Securely Signed
  • ISM-1798Supports
    Develop Secure Configuration Guidelines for Software
  • ISM-1800Partially overlaps
    Ensure Network Devices Have Trusted Firmware
  • ISM-1871Depends on
    Implement Application Control Exclusions for System Areas
  • ISM-1915Partially overlaps
    Ensure User Application Configurations are Approved
  • ISM-1916Supports
    Ensure Server Application Configurations Are Approved
  • ISM-1926Partially meets
    Ensure Exclusive Usage of Microsoft AD Servers
  • ISM-2023Partially overlaps
    Maintain a Reliable Source for Software
  • ISM-2027Supports
    Verify Software Artefacts with Digital Signatures
  • ISM-2044Supports
    Prevent Default Credentials in Software Installations
  • ISM-2045Supports
    Ensure Backwards Compatibility Doesn't Weaken Security
  • ISM-2111Broader than
    Remove Temporary Installation Files Post-Installation
Annex A 8.20
Network and Network Devices Security
Technological controls
  • ISM-0245Broader than
    Prevent MFD Connections to Digital Phone Systems
  • ISM-0263Broader than
    Inspect and Decrypt TLS Traffic through Gateways
  • ISM-0267Partially meets
    Blocking Access to Unapproved Webmail Services
  • ISM-0467Depends on
    Using HACE for Secure Communication of Data
  • ISM-0469Partially meets
    Use Approved Cryptographic Protocols When Encrypting Data In Transit
  • ISM-0484Broader than
    Configure SSH for Secure Server Access
  • ISM-0494Broader than
    Use of IPsec Tunnel and Transport Modes
  • ISM-0516Supports
    Comprehensive Network Diagrams for Critical Components
  • ISM-0518Supports
    Maintain Comprehensive Network Documentation
  • ISM-0520Broader than
    Prevent Unauthorised Network Device Connections
  • ISM-0529Depends on
    Avoid Using VLANs for Different Security Domains
  • ISM-0530Broader than
    Administer VLANs from Trusted Security Domains
  • ISM-0534Broader than
    Disable Unused Network Device Ports
  • ISM-0548Depends on
    Ensure Secure Protocols for Video and IP Calls
  • ISM-0551Broader than
    Ensure Secure IP Telephony Device Authentication
  • ISM-0558Broader than
    Restrict IP Phone Network Access in Public Areas
  • ISM-0569Broader than
    Centralise Email Routing via Gateways
  • ISM-0572Broader than
    Enable Opportunistic TLS for Email Server Encryption
  • ISM-0622Broader than
    Ensuring Network Authentication via Gateways
  • ISM-0628Broader than
    Implementing Secure Network Gateways
  • ISM-0629Depends on
    Manage Gateways Between Different Security Domains
  • ISM-0631Broader than
    Restrict Data Flows with Authorised Gateways
  • ISM-0639Depends on
    Use Evaluated Firewalls Between Security Domains
  • ISM-0643Broader than
    Use of Diodes for Unidirectional Gateway Security
  • ISM-0694Supports
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0874Broader than
    Ensure Internet Access via Organisation's Gateway
  • ISM-1006Broader than
    Prevent Unauthorised Access to Network Traffic
  • ISM-1028Broader than
    Use NIDS/NIPS for Gateway Network Security
  • ISM-1030Broader than
    Deploy NIDS/NIPS for Gateway Traffic Monitoring
  • ISM-1085Supports
    Encrypt Sensitive Data Over Public Networks
  • ISM-1158Partially meets
    High Assurance Evaluation for Network Diodes
  • ISM-1182Partially meets
    Implement Network Traffic Control Measures
  • ISM-1192Broader than
    Inspecting and Filtering Data with Gateways
  • ISM-1270Partially meets
    Separate Network Segments for Database Servers
  • ISM-1271Broader than
    Restrict Network Access to Database Servers
  • ISM-1272Partially meets
    Disable Database Networking for Local Access
  • ISM-1284Depends on
    Ensure Content Validation for Gateway Files
  • ISM-1286Supports
    Ensure Content Conversion at Gateways
  • ISM-1289Supports
    Unpack Archive Files for Content Filtering at Gateways
  • ISM-1296Partially overlaps
    Protect Network Devices in Public Areas
  • ISM-1297Partially meets
    Seek Legal Advice for Personal Device Access
  • ISM-1304Partially meets
    Secure Network Devices by Changing Default Credentials
  • ISM-1311Broader than
    Prevent Use of Insecure SNMP Versions on Networks
  • ISM-1312Broader than
    Changing Default SNMP Community Strings on Devices
  • ISM-1314Broader than
    Ensure Wireless Devices are Wi-Fi Alliance Certified
  • ISM-1315Partially meets
    Disable Wireless Network Administrative Interfaces
  • ISM-1316Broader than
    Ensure Default Wireless SSIDs Are Changed
  • ISM-1317Partially meets
    Secure Naming of Non-Public Wireless Networks
  • ISM-1318Partially meets
    Keep SSID Broadcasting Enabled on Wireless Access Points
  • ISM-1319Partially meets
    Avoid Static IP Addressing on Wireless Networks
  • ISM-1320Broader than
    Avoid Using MAC Filtering for Wireless Access Control
  • ISM-1321Partially meets
    Implement EAP-TLS for Secure Wireless Authentication
  • ISM-1322Partially meets
    Assessing 802.1X Components in Wireless Networks
  • ISM-1323Depends on
    Requiring X.509 Certificates for 802.1X Network Authentication
  • ISM-1330Broader than
    Limit PMK Caching Duration on Wireless Networks
  • ISM-1332Broader than
    Ensure Wireless Traffic is Secure with WPA3-Enterprise
  • ISM-1334Broader than
    Ensure Frequency Separation in Wireless Networks
  • ISM-1335Broader than
    Enabling 802.11w to Protect Wireless Management Frames
  • ISM-1338Partially meets
    Use Lower-Powered Wireless Access Points for Coverage
  • ISM-1364Partially meets
    Separate VLANs by Security Domains
  • ISM-1386Partially meets
    Restrict Network Management Traffic Origin
  • ISM-1416Partially meets
    Implement Firewalls to Control Network Connections
  • ISM-1427Broader than
    Prevent IP Source Address Spoofing in Gateways
  • ISM-1428Broader than
    Disable IPv6 Tunnelling Unless Necessary
  • ISM-1430Broader than
    Configure IPv6 Addresses with DHCPv6 in Stateful Mode
  • ISM-1439Broader than
    Restrict IP Disclosure in CDNs
  • ISM-1506Broader than
    Disable SSH Version 1 for Security
  • ISM-1521Partially meets
    Use Protocol Breaks to Separate Network Layers
  • ISM-1522Depends on
    Ensure CDSs Separate Upward and Downward Data Paths
  • ISM-1532Broader than
    Avoid Using VLANs for Network Separation
  • ISM-1553Partially meets
    Disable TLS Compression for Security
  • ISM-1562Broader than
    Secure Video Conferencing and Telephony Systems
  • ISM-1604Depends on
    Harden Software Isolation Mechanisms Sharing Physical Computing Resources
  • ISM-1628Broader than
    Prevent Anonymity Network Traffic in Outbound Connections
  • ISM-1646Depends on
    Detail Cabling Paths and Points on Floor Plans
  • ISM-1710Broader than
    Secure Default Settings for Wireless Access Points
  • ISM-1753Broader than
    Replace Unsupported Internet-Facing Devices
  • ISM-1772Broader than
    Use Secure Pseudorandom Functions for IPsec Connections
  • ISM-1774Broader than
    Secure Management Paths for Network Gateways
  • ISM-1781Broader than
    Encrypt Network Data with ASD-Approved Cryptography
  • ISM-1782Partially meets
    Use Protective DNS to Block Malicious Domains
  • ISM-1783Broader than
    Secure BGP with Valid ROA for IP Addresses
  • ISM-1800Partially meets
    Ensure Network Devices Have Trusted Firmware
  • ISM-1809Supports
    Implement Compensating Controls for Unsupported Systems
  • ISM-1862Partially meets
    Restrict Access and Conceal Web Server IP Addresses
  • ISM-1863Partially meets
    Restrict Exposure of Network Management Interfaces
  • ISM-1899Broader than
    Restrict Unauthorised Network Connections
  • ISM-1912Depends on
    Document Device Settings for Critical and High-Value Servers
  • ISM-1929Partially meets
    Ensure LDAP Signing on AD DS Domain Controllers
  • ISM-1962Broader than
    Disable SMBv1 Protocol on Networks
  • ISM-1963Depends on
    Central Logging of Events on Internet-Facing Devices
  • ISM-1964Partially meets
    Central Logging for Network Device Events
  • ISM-1970Supports
    Segregated Environment for Malicious Code Analysis
  • ISM-1981Broader than
    Replace Unsupportable Non-Internet Network Devices
  • ISM-1982Supports
    Replace Unsupported Networked IT Equipment
  • ISM-1984Supports
    Encrypt Event Logs in Transit Using ASD Cryptography
  • ISM-2017Partially meets
    Encrypt DNS Traffic Between Clients and Servers
  • ISM-2018Broader than
    Secure BGP Routing with RPKI-Registered IP Addresses
  • ISM-2097Depends on
    Configure Mobile Devices with Always On VPN
  • ISM-2130Broader than
    Disabling or Hardening AD CS Web Enrolment Interfaces
  • ISM-2150Broader than
    Gateways Block Connections for Unauthorised RMM and Remote Access Tools
  • ISM-2161Broader than
    Verify Network Device Firmware and Configuration Against Known-Good Baseline
  • ISM-2162Broader than
    Disabling or Removing Unneeded Network Device Components and Services
  • ISM-2163Broader than
    Enable MACsec Confidentiality Mode Using GCM-AES Cipher Suites
  • ISM-2164Broader than
    Set MACsec Connectivity Association Lifetime Below 24 Hours
  • ISM-2166Broader than
    MACsec Secure Association Lifetime Limited To Under Four Hours
  • ISM-2167Broader than
    Disabling Pre-Shared Key Fallback Authentication for MACsec
Annex A 8.21
Security of Network Services
Technological controls
  • ISM-0530Depends on
    Administer VLANs from Trusted Security Domains
  • ISM-0558Broader than
    Restrict IP Phone Network Access in Public Areas
  • ISM-1037Depends on
    Regular Testing of Gateway Security Configurations
  • ISM-1182Partially overlaps
    Implement Network Traffic Control Measures
  • ISM-1186Partially meets
    Ensure IPv6 Network Security Appliances Are Used
  • ISM-1271Depends on
    Restrict Network Access to Database Servers
  • ISM-1284Depends on
    Ensure Content Validation for Gateway Files
  • ISM-1297Depends on
    Seek Legal Advice for Personal Device Access
  • ISM-1314Broader than
    Ensure Wireless Devices are Wi-Fi Alliance Certified
  • ISM-1323Depends on
    Requiring X.509 Certificates for 802.1X Network Authentication
  • ISM-1335Broader than
    Enabling 802.11w to Protect Wireless Management Frames
  • ISM-1364Supports
    Separate VLANs by Security Domains
  • ISM-1428Supports
    Disable IPv6 Tunnelling Unless Necessary
  • ISM-1479Partially overlaps
    Minimise Server-to-Server Communication
  • ISM-1572Supports
    Document Service Provider Data Handling and Change Notifications
  • ISM-1577Partially overlaps
    Ensure Network Segregation from Service Providers
  • ISM-1579Partially overlaps
    Dynamic Resource Scaling for Demand Spikes
  • ISM-1581Partially overlaps
    Monitor Capacity and Availability of Online Services
  • ISM-1628Broader than
    Prevent Anonymity Network Traffic in Outbound Connections
  • ISM-1738Supports
    Verify Compliance with Security Requirements
  • ISM-1912Depends on
    Document Device Settings for Critical and High-Value Servers
  • ISM-1960Depends on
    Timely Analysis of Event Logs for Cyber security
  • ISM-1962Broader than
    Disable SMBv1 Protocol on Networks
  • ISM-2068Supports
    Restrict Internet Access for Networked Devices
Annex A 8.22
Network Segregation for Security
Technological controls
  • ISM-0213Broader than
    Segregate Patch Panels for Secret-Level Cables
  • ISM-0385Depends on
    Maintain Effective Functional Separation Between Servers
  • ISM-0409Depends on
    Restricting Foreign National Access to AUSTEO and REL Systems
  • ISM-0411Depends on
    Restricting Foreign National Access to Systems Handling AGAO Data
  • ISM-0441Supports
    Ensuring Limited Access for Temporary System Use
  • ISM-0516Supports
    Comprehensive Network Diagrams for Critical Components
  • ISM-0529Partially meets
    Avoid Using VLANs for Different Security Domains
  • ISM-0530Supports
    Administer VLANs from Trusted Security Domains
  • ISM-0535Broader than
    Prevent VLAN Trunk Sharing Across Security Domains
  • ISM-0536Broader than
    Segregate Public Wireless Networks from Organisation Networks
  • ISM-0549Partially meets
    Separate Video Conferencing and IP Telephony Traffic From Other Data
  • ISM-0556Partially meets
    Ensure Traffic Separation for Video Conferencing and Telephony
  • ISM-0558Partially meets
    Restrict IP Phone Network Access in Public Areas
  • ISM-0591Depends on
    Use Evaluated Peripheral Switches Securely
  • ISM-0626Broader than
    Implementing CDS for Secure Network Segmentation
  • ISM-0628Broader than
    Implementing Secure Network Gateways
  • ISM-0629Supports
    Manage Gateways Between Different Security Domains
  • ISM-0631Depends on
    Restrict Data Flows with Authorised Gateways
  • ISM-0635Partially meets
    Ensure Network Paths are Isolated in CDSs
  • ISM-0637Broader than
    Implementing Demilitarised Zones in Gateways
  • ISM-0639Depends on
    Use Evaluated Firewalls Between Security Domains
  • ISM-0643Supports
    Use of Diodes for Unidirectional Gateway Security
  • ISM-0645Partially meets
    High Assurance Evaluation of Unidirectional Gateways
  • ISM-0694Supports
    Block Privately Owned Devices From SECRET and TOP SECRET Systems
  • ISM-0874Depends on
    Ensure Internet Access via Organisation's Gateway
  • ISM-1158Supports
    High Assurance Evaluation for Network Diodes
  • ISM-1181Equivalent
    Segregate Networks by Server Criticality
  • ISM-1182Partially overlaps
    Implement Network Traffic Control Measures
  • ISM-1269Partially overlaps
    Ensure Databases and Web Servers are Separated
  • ISM-1270Partially meets
    Separate Network Segments for Database Servers
  • ISM-1271Partially overlaps
    Restrict Network Access to Database Servers
  • ISM-1277Depends on
    Encrypt Database and Web Server Communications
  • ISM-1315Supports
    Disable Wireless Network Administrative Interfaces
  • ISM-1364Partially meets
    Separate VLANs by Security Domains
  • ISM-1385Partially overlaps
    Segregation of Administrative Infrastructure from Networks
  • ISM-1386Partially overlaps
    Restrict Network Management Traffic Origin
  • ISM-1436Partially meets
    Segregate Critical Services to Prevent DoS Attacks
  • ISM-1439Broader than
    Restrict IP Disclosure in CDNs
  • ISM-1479Partially overlaps
    Minimise Server-to-Server Communication
  • ISM-1521Supports
    Use Protocol Breaks to Separate Network Layers
  • ISM-1522Supports
    Ensure CDSs Separate Upward and Downward Data Paths
  • ISM-1528Supports
    Utilising Evaluated Firewalls for Network Security
  • ISM-1532Partially meets
    Avoid Using VLANs for Network Separation
  • ISM-1562Partially overlaps
    Secure Video Conferencing and Telephony Systems
  • ISM-1577Partially overlaps
    Ensure Network Segregation from Service Providers
  • ISM-1633Supports
    Determine System Boundary, Criticality and Security Objectives
  • ISM-1750Partially overlaps
    Segregation of Administrative Infrastructure for Server Security
  • ISM-1774Partially overlaps
    Secure Management Paths for Network Gateways
  • ISM-1809Supports
    Implement Compensating Controls for Unsupported Systems
  • ISM-1852Depends on
    Limit Unprivileged Access to What Duties Require
  • ISM-1862Partially overlaps
    Restrict Access and Conceal Web Server IP Addresses
  • ISM-1899Broader than
    Restrict Unauthorised Network Connections
  • ISM-1970Partially meets
    Segregated Environment for Malicious Code Analysis
  • ISM-2068Supports
    Restrict Internet Access for Networked Devices
  • ISM-2152Depends on
    Segregate Backup Infrastructure With Separate Administrative Authentication
  • ISM-2156Depends on
    Restrict Agentic AI Applications to Minimum Tools, Functions and Permissions
  • ISM-2160Broader than
    Restricting Networked Management Interfaces to a Segregated Management Network
Annex A 8.23
Web Filtering to Reduce Malicious Website Exposure
Technological controls
  • ISM-0258Supports
    Establish and Maintain a Web Usage Policy
  • ISM-0260Supports
    Ensure All Web Access Uses Proxies
  • ISM-0267Broader than
    Blocking Access to Unapproved Webmail Services
  • ISM-0659Partially overlaps
    Filtering Content of Gateway and CDS Files
  • ISM-0874Depends on
    Ensure Internet Access via Organisation's Gateway
  • ISM-0958Partially overlaps
    Implement Domain Name Allow and Block Lists
  • ISM-0961Broader than
    Restrict Active Content with Web Filters
  • ISM-0963Equivalent
    Implementing Web Content Filters for Safety
  • ISM-1171Broader than
    Block Direct IP Access to Websites
  • ISM-1236Broader than
    Blocking Malicious and Anonymous Domain Names
  • ISM-1237Partially overlaps
    Implement Web Content Filters for Outbound Traffic
  • ISM-1485Broader than
    Prevent Web Browsers from Processing Ads
  • ISM-1782Broader than
    Use Protective DNS to Block Malicious Domains
  • ISM-2068Partially overlaps
    Restrict Internet Access for Networked Devices
  • ISM-2112Partially overlaps
    Disable AI Applications' Direct Access to External Public Data Sources
Annex A 8.24
Effective Use of Cryptography and Key Management
Technological controls
  • ISM-0142Partially overlaps
    Report Cryptographic Equipment Compromises Promptly
  • ISM-0231Depends on
    Visual Indication for Secure Telephone Connections
  • ISM-0232Broader than
    Encrypt External Traffic for Sensitive Calls
  • ISM-0233Broader than
    Use Encrypted Cordless Systems for Sensitive Conversations
  • ISM-0263Depends on
    Inspect and Decrypt TLS Traffic through Gateways
  • ISM-0455Partially overlaps
    Enable Data Recovery for Encrypted Data
  • ISM-0457Partially meets
    Use Evaluated Crypto for Sensitive Data Encryption
  • ISM-0459Partially meets
    Implement Full or Partial Disk Encryption
  • ISM-0460Partially meets
    Use HACE for Encrypting Sensitive Media
  • ISM-0465Broader than
    Use Evaluated Cryptographic Tools for Sensitive Data
  • ISM-0467Broader than
    Using HACE for Secure Communication of Data
  • ISM-0469Partially overlaps
    Use Approved Cryptographic Protocols When Encrypting Data In Transit
  • ISM-0471Broader than
    Use Only High Assurance Cryptographic Algorithms
  • ISM-0472Broader than
    Using Proper Modulus Size for Diffie-Hellman Keys
  • ISM-0474Broader than
    Using Secure Elliptic Curve Diffie-Hellman Encryption
  • ISM-0475Partially meets
    Use P-384 Curve for Secure Digital Signatures
  • ISM-0476Broader than
    Ensuring Strong RSA Modulus for Digital Security
  • ISM-0477Broader than
    Separate RSA Key Pairs for Different Functions
  • ISM-0479Broader than
    Avoid Using ECB Mode for Symmetric Encryption
  • ISM-0481Broader than
    Ensure Use of High Assurance Cryptographic Protocols
  • ISM-0489Broader than
    Four-Hour Cached SSH Private Key Lifetime and Screen Locks
  • ISM-0490Partially meets
    Ensure S/MIME 3.0 or Later is Used
  • ISM-0496Partially meets
    Use ESP Protocol for Secure IPsec Connections
  • ISM-0507Equivalent
    Develop and Maintain Cryptographic Key Management Processes
  • ISM-0554Supports
    Secure Two-Way Authentication for Video Calls
  • ISM-0571Supports
    Ensure Secure Email Transmission via Gateways
  • ISM-0572Broader than
    Enable Opportunistic TLS for Email Server Encryption
  • ISM-0675Supports
    Ensure Data Exports are Digitally Signed
  • ISM-0677Depends on
    Ensure File Integrity Through Signature Validation
  • ISM-0702Partially overlaps
    Using Cryptographic Sanitisation on Mobile Devices
  • ISM-0869Supports
    Encrypt Storage on Mobile Devices
  • ISM-0994Partially meets
    Use ECDH for Secure Key Exchanges
  • ISM-0998Broader than
    Using Integrity Algorithms for IPsec Connections
  • ISM-0999Partially meets
    Use DH or ECDH for Secure Key Establishment
  • ISM-1000Broader than
    Utilising Perfect Forward Secrecy for IPsec
  • ISM-1059Supports
    Encrypt All Data Stored on Media Using ASD-Approved Cryptography
  • ISM-1080Partially overlaps
    Use AACA or High Assurance Algorithms for Data Encryption
  • ISM-1085Partially meets
    Encrypt Sensitive Data Over Public Networks
  • ISM-1091Broader than
    Change Keying Material When Compromised
  • ISM-1139Partially meets
    Require Latest Version of TLS for Security
  • ISM-1233Partially meets
    Use IKE Version 2 for IPsec Key Exchange
  • ISM-1277Broader than
    Encrypt Database and Web Server Communications
  • ISM-1324Broader than
    Generating X.509 Certificates With Evaluated CA or HSM
  • ISM-1327Broader than
    Access Controls, Encryption and User Authentication for X.509 Certificates
  • ISM-1332Broader than
    Ensure Wireless Traffic is Secure with WPA3-Enterprise
  • ISM-1370Partially meets
    Ensure Only Server-Initiated TLS Renegotiation
  • ISM-1372Broader than
    Ephemeral DH or ECDH Key Establishment for TLS Connections
  • ISM-1373Broader than
    Ensure TLS Connections do not use Anonymous DH
  • ISM-1374Broader than
    Use SHA-2 Certificates for Secure TLS Connections
  • ISM-1375Broader than
    Use SHA-2 for Secure TLS Connections
  • ISM-1402Partially meets
    Protecting Stored Credentials with Security Measures
  • ISM-1446Partially meets
    Use Approved Elliptic Curves for Encryption
  • ISM-1449Broader than
    Protect SSH Private Keys with Passwords or Encryption
  • ISM-1453Broader than
    Ensure PFS is Enabled for TLS Connections
  • ISM-1454Broader than
    Enhancing Security with Encrypted RADIUS Communications
  • ISM-1629Partially meets
    Select Correct Modulus for Diffie-Hellman Encryption
  • ISM-1712Partially meets
    Ensure Secure Authenticator Communication for Wireless FT
  • ISM-1759Partially meets
    Ensure Strong Encryption with Diffie-Hellman
  • ISM-1761Broader than
    Use NIST Curves for ECDH Encryption
  • ISM-1762Broader than
    Use NIST P-384 Curve for ECDH Keys
  • ISM-1763Broader than
    Use NIST P-384 Curve for ECDSA Signatures
  • ISM-1764Broader than
    Use NIST P-384 Curve for ECDSA Signatures
  • ISM-1765Broader than
    Use RSA with 3072-bit Modulus for Security
  • ISM-1766Partially meets
    Ensure Secure Hashing with SHA-2 Algorithm
  • ISM-1767Partially meets
    Use SHA-2 with Minimum 256-bit Output
  • ISM-1768Broader than
    Use Appropriate SHA-2 Output Size for Hashing
  • ISM-1769Broader than
    Using AES Encryption with Strong Key Lengths
  • ISM-1770Broader than
    Utilise Strong AES Encryption Algorithms
  • ISM-1771Broader than
    Use AES Encryption for IPsec Connections
  • ISM-1772Partially meets
    Use Secure Pseudorandom Functions for IPsec Connections
  • ISM-1796Supports
    Digitally Sign Executable Software for Security
  • ISM-1797Partially meets
    Ensure Software Updates are Securely Signed
  • ISM-1802Broader than
    Operate Approved High Assurance Cryptographic Equipment
  • ISM-1917Partially overlaps
    Support Post-Quantum Cryptographic Algorithms by 2030
  • ISM-1928Supports
    Encrypt and Restrict Access to Microsoft AD and Entra Connect Server Backups
  • ISM-1957Broader than
    Ensure CA Servers Use Hardware Security Modules
  • ISM-1984Partially meets
    Encrypt Event Logs in Transit Using ASD Cryptography
  • ISM-1990Broader than
    Prefer FIPS 140-3 Validated ML-DSA and ML-KEM Implementations
  • ISM-1991Broader than
    Implement ML-DSA for Enhanced Digital Signature Security
  • ISM-1992Broader than
    Using Hedged Variant of ML-DSA for Digital Signatures
  • ISM-1993Partially meets
    Use Pre-Hashed ML-DSA Variants Only When Necessary
  • ISM-1994Partially meets
    Use Correct Hashing for ML-DSA Pre-hashed Variants
  • ISM-1995Broader than
    Use ML-KEM for Secure Key Encapsulation
  • ISM-1996Broader than
    Using Hybrid Schemes for Secure Encryption
  • ISM-2010Partially meets
    Ensure SPNs Use Strong Encryption in AD Services
  • ISM-2017Partially meets
    Encrypt DNS Traffic Between Clients and Servers
  • ISM-2027Depends on
    Verify Software Artefacts with Digital Signatures
  • ISM-2050Partially meets
    Validate Digital Signature Certificates Securely
  • ISM-2073Supports
    Develop a Post-Quantum Cryptography Transition Plan
  • ISM-2082Broader than
    Using Cryptographic BOM in Software Development
  • ISM-2083Depends on
    Provide a Cryptographic Bill of Materials to Software Users
  • ISM-2108Broader than
    Mobile Apps Encrypt Sensitive Data Using ASD-Approved Cryptography
  • ISM-2109Partially overlaps
    Pre-Boot Authentication for Encrypted System Volume Media
  • ISM-2163Broader than
    Enable MACsec Confidentiality Mode Using GCM-AES Cipher Suites
  • ISM-2164Broader than
    Set MACsec Connectivity Association Lifetime Below 24 Hours
  • ISM-2166Broader than
    MACsec Secure Association Lifetime Limited To Under Four Hours
Annex A 8.25
Secure Development Lifecycle
Technological controls
  • ISM-0246Partially meets
    Contact ASD for Emanation Security Assessment
  • ISM-0401Partially overlaps
    Implement Secure by Design in Software Development
  • ISM-0402Partially meets
    Software Vulnerability Testing Using SAST, DAST and SCA
  • ISM-0481Supports
    Ensure Use of High Assurance Cryptographic Protocols
  • ISM-0938Broader than
    Select Secure-by-Design Committed Vendors
  • ISM-0971Broader than
    Use OWASP Standards in Web Application Development
  • ISM-1238Broader than
    Incorporate Threat Modelling in Software Development
  • ISM-1239Partially meets
    Ensure Use of Robust Web Application Frameworks
  • ISM-1240Partially meets
    Ensure Input Validation and Sanitisation for Internet Data
  • ISM-1241Partially meets
    Ensuring Secure Web Application Output Encoding
  • ISM-1275Broader than
    Ensure Secure Database Queries in Software
  • ISM-1276Partially meets
    Use Safe Database Query Methods
  • ISM-1278Partially meets
    Minimise Database Error Information in Software
  • ISM-1419Partially meets
    Software Development in Development Environments
  • ISM-1616Supports
    Implementing a Vulnerability Disclosure Program
  • ISM-1730Broader than
    Provide a Software Bill of Materials to Consumers
  • ISM-1780Partially overlaps
    Apply SecDevOps for Secure Software Development
  • ISM-1796Partially meets
    Digitally Sign Executable Software for Security
  • ISM-1797Supports
    Ensure Software Updates are Securely Signed
  • ISM-1798Partially meets
    Develop Secure Configuration Guidelines for Software
  • ISM-1826Depends on
    Select Vendors Committed to Secure Design for Servers
  • ISM-1849Broader than
    Implement OWASP Top 10 in Web Development
  • ISM-1850Broader than
    Mitigate OWASP Top 10 in Web Applications
  • ISM-1851Partially meets
    Secure Development Using OWASP API Security Top 10
  • ISM-1917Partially meets
    Support Post-Quantum Cryptographic Algorithms by 2030
  • ISM-1922Partially meets
    Use OWASP Standards in Mobile App Development
  • ISM-2016Partially meets
    Ensure Input Validation and Sanitisation for Security
  • ISM-2025Depends on
    Using Issue Tracking for Software Development Tasks
  • ISM-2028Broader than
    Test Software Artefacts for Security Weaknesses
  • ISM-2030Broader than
    Commit-Time Scanning Blocks Secrets From Source Repositories
  • ISM-2031Broader than
    Secure System Build Tools Implementation
  • ISM-2033Partially meets
    Document and Maintain Software Security Requirements
  • ISM-2034Broader than
    Document and Review Security Design in Development
  • ISM-2036Broader than
    Document Security Duties for Software Developers
  • ISM-2039Partially meets
    Review Threat Model During Software Development
  • ISM-2040Broader than
    Ensure Secure Programming Practices in Software Development
  • ISM-2041Partially meets
    Ensure Use of Memory-Safe Programming Practices
  • ISM-2042Partially overlaps
    Ensuring Security in Software Development Lifecycle
  • ISM-2043Partially meets
    Ensuring Readable and Maintainable Software Architecture
  • ISM-2055Partially meets
    Ensure Software Components Meet Build Standards
  • ISM-2056Partially meets
    Provide Provenance for Software Builds
  • ISM-2057Partially meets
    Document, Build and Test All Input Validation Rules
  • ISM-2060Partially meets
    Ensure Code Reviews for Secure Software Design
  • ISM-2061Broader than
    Peer Reviews of Critical and Security-Related Software Components
  • ISM-2064Partially meets
    Ensure Secure Cookies with Signed Bearer Tokens
  • ISM-2083Partially overlaps
    Provide a Cryptographic Bill of Materials to Software Users
  • ISM-2121Supports
    Prevent Using Developers Without Cyber Security Skills
  • ISM-2122Broader than
    Use Suitable AI Models to Augment Software Security Testing
  • ISM-2154Broader than
    Pinning Software Artefact Dependencies to Approved Versions in Source Code
  • ISM-2155Broader than
    Reproducible Builds Enabling Independent Verification of Release Artefacts
Annex A 8.26
Defining Security Requirements for Applications
Technological controls
  • ISM-0246Partially meets
    Contact ASD for Emanation Security Assessment
  • ISM-0471Supports
    Use Only High Assurance Cryptographic Algorithms
  • ISM-0481Supports
    Ensure Use of High Assurance Cryptographic Protocols
  • ISM-0971Supports
    Use OWASP Standards in Web Application Development
  • ISM-1238Supports
    Incorporate Threat Modelling in Software Development
  • ISM-1239Partially meets
    Ensure Use of Robust Web Application Frameworks
  • ISM-1424Partially meets
    Ensure Web Security Through Response Headers
  • ISM-1552Partially meets
    Secure Web Content with HTTPS Only
  • ISM-1568Supports
    Ensure Security Commitment from Suppliers
  • ISM-1597Partially meets
    Ensuring Credential Input Obscurity
  • ISM-1739Partially overlaps
    Approve Security Architecture Before System Development
  • ISM-1806Partially meets
    Change Default User Credentials During Setup
  • ISM-1849Supports
    Implement OWASP Top 10 in Web Development
  • ISM-1850Partially meets
    Mitigate OWASP Top 10 in Web Applications
  • ISM-1851Partially meets
    Secure Development Using OWASP API Security Top 10
  • ISM-1917Partially meets
    Support Post-Quantum Cryptographic Algorithms by 2030
  • ISM-1924Depends on
    Detect and Mitigate Adversarial Prompts in Generative AI Applications
  • ISM-2027Supports
    Verify Software Artefacts with Digital Signatures
  • ISM-2028Supports
    Test Software Artefacts for Security Weaknesses
  • ISM-2030Depends on
    Commit-Time Scanning Blocks Secrets From Source Repositories
  • ISM-2033Partially overlaps
    Document and Maintain Software Security Requirements
  • ISM-2039Supports
    Review Threat Model During Software Development
  • ISM-2041Supports
    Ensure Use of Memory-Safe Programming Practices
  • ISM-2045Supports
    Ensure Backwards Compatibility Doesn't Weaken Security
  • ISM-2046Partially meets
    Ensure Secure Impersonation Logging Practices
  • ISM-2055Partially meets
    Ensure Software Components Meet Build Standards
  • ISM-2059Supports
    Restrict and Scan File Uploads for Security
  • ISM-2063Partially meets
    Ensure Web App Cookies Have Security Flags
  • ISM-2064Partially meets
    Ensure Secure Cookies with Signed Bearer Tokens
  • ISM-2065Partially meets
    Ensure Secure Session Cookies with High Entropy Tokens
  • ISM-2067Depends on
    Ensure Single Logout for Single Sign-On Web Applications
  • ISM-2072Partially meets
    Store AI Models In A Non-Executable File Format
  • ISM-2110Partially overlaps
    Hardening User Applications with ASD and Vendor Guidance
  • ISM-2113Broader than
    Configuring AI Applications to Require Human Approval Before High-Impact Actions
Annex A 8.27
Secure system architecture and engineering principles
Technological controls
  • ISM-0246Depends on
    Contact ASD for Emanation Security Assessment
  • ISM-0401Partially meets
    Implement Secure by Design in Software Development
  • ISM-0479Depends on
    Avoid Using ECB Mode for Symmetric Encryption
  • ISM-0548Depends on
    Ensure Secure Protocols for Video and IP Calls
  • ISM-0591Broader than
    Use Evaluated Peripheral Switches Securely
  • ISM-0597Depends on
    Consult ASD Before Changing CDS Connectivity
  • ISM-0938Broader than
    Select Secure-by-Design Committed Vendors
  • ISM-0971Broader than
    Use OWASP Standards in Web Application Development
  • ISM-1238Partially meets
    Incorporate Threat Modelling in Software Development
  • ISM-1457Supports
    Evaluate Peripheral Switches for Security Domains
  • ISM-1460Broader than
    Secure By Design Vendor Isolation Mechanisms
  • ISM-1522Depends on
    Ensure CDSs Separate Upward and Downward Data Paths
  • ISM-1739Partially overlaps
    Approve Security Architecture Before System Development
  • ISM-1780Partially overlaps
    Apply SecDevOps for Secure Software Development
  • ISM-1798Broader than
    Develop Secure Configuration Guidelines for Software
  • ISM-1826Depends on
    Select Vendors Committed to Secure Design for Servers
  • ISM-1850Broader than
    Mitigate OWASP Top 10 in Web Applications
  • ISM-1885Broader than
    Implement Emanation Security Measures for Systems
  • ISM-1917Broader than
    Support Post-Quantum Cryptographic Algorithms by 2030
  • ISM-1996Partially meets
    Using Hybrid Schemes for Secure Encryption
  • ISM-2031Broader than
    Secure System Build Tools Implementation
  • ISM-2033Partially overlaps
    Document and Maintain Software Security Requirements
  • ISM-2034Broader than
    Document and Review Security Design in Development
  • ISM-2039Partially meets
    Review Threat Model During Software Development
  • ISM-2042Partially overlaps
    Ensuring Security in Software Development Lifecycle
  • ISM-2043Broader than
    Ensuring Readable and Maintainable Software Architecture
  • ISM-2060Depends on
    Ensure Code Reviews for Secure Software Design
  • ISM-2082Depends on
    Using Cryptographic BOM in Software Development
  • ISM-2084Partially overlaps
    Document AI Model and System Characteristics
  • ISM-2121Supports
    Prevent Using Developers Without Cyber Security Skills
  • ISM-2122Depends on
    Use Suitable AI Models to Augment Software Security Testing
  • ISM-2154Broader than
    Pinning Software Artefact Dependencies to Approved Versions in Source Code
  • ISM-2158Broader than
    Treat Agentic AI Retrieved External Content as Untrusted Data
Annex A 8.28
Secure Coding Practices in Software Development
Technological controls
  • ISM-0401Partially meets
    Implement Secure by Design in Software Development
  • ISM-0402Supports
    Software Vulnerability Testing Using SAST, DAST and SCA
  • ISM-0938Broader than
    Select Secure-by-Design Committed Vendors
  • ISM-0971Supports
    Use OWASP Standards in Web Application Development
  • ISM-1238Supports
    Incorporate Threat Modelling in Software Development
  • ISM-1239Supports
    Ensure Use of Robust Web Application Frameworks
  • ISM-1241Partially meets
    Ensuring Secure Web Application Output Encoding
  • ISM-1275Partially meets
    Ensure Secure Database Queries in Software
  • ISM-1276Partially meets
    Use Safe Database Query Methods
  • ISM-1278Partially meets
    Minimise Database Error Information in Software
  • ISM-1460Partially overlaps
    Secure By Design Vendor Isolation Mechanisms
  • ISM-1780Partially meets
    Apply SecDevOps for Secure Software Development
  • ISM-1826Depends on
    Select Vendors Committed to Secure Design for Servers
  • ISM-1849Supports
    Implement OWASP Top 10 in Web Development
  • ISM-1850Broader than
    Mitigate OWASP Top 10 in Web Applications
  • ISM-1851Supports
    Secure Development Using OWASP API Security Top 10
  • ISM-1922Supports
    Use OWASP Standards in Mobile App Development
  • ISM-1924Depends on
    Detect and Mitigate Adversarial Prompts in Generative AI Applications
  • ISM-2016Partially meets
    Ensure Input Validation and Sanitisation for Security
  • ISM-2024Supports
    Utilise Authoritative Sources in Software Development
  • ISM-2030Broader than
    Commit-Time Scanning Blocks Secrets From Source Repositories
  • ISM-2031Supports
    Secure System Build Tools Implementation
  • ISM-2033Supports
    Document and Maintain Software Security Requirements
  • ISM-2037Depends on
    Train Software Developers Lacking Cyber Security Skills
  • ISM-2040Equivalent
    Ensure Secure Programming Practices in Software Development
  • ISM-2041Partially overlaps
    Ensure Use of Memory-Safe Programming Practices
  • ISM-2042Partially overlaps
    Ensuring Security in Software Development Lifecycle
  • ISM-2055Partially meets
    Ensure Software Components Meet Build Standards
  • ISM-2057Partially meets
    Document, Build and Test All Input Validation Rules
  • ISM-2058Partially meets
    Ensure Data Validation Before Deserialisation
  • ISM-2059Supports
    Restrict and Scan File Uploads for Security
  • ISM-2060Supports
    Ensure Code Reviews for Secure Software Design
  • ISM-2061Partially meets
    Peer Reviews of Critical and Security-Related Software Components
  • ISM-2062Supports
    Unit and Integration Testing for Code Quality
  • ISM-2064Partially meets
    Ensure Secure Cookies with Signed Bearer Tokens
  • ISM-2066Partially meets
    Centralised Management of Web Application Sessions
  • ISM-2085Partially meets
    Prevent Exposure of AI Model Confidence Scores
  • ISM-2122Depends on
    Use Suitable AI Models to Augment Software Security Testing
  • ISM-2158Broader than
    Treat Agentic AI Retrieved External Content as Untrusted Data
Annex A 8.29
Security testing in development and acceptance
Technological controls
  • ISM-0400Supports
    Segregation of Environments in Software Development
  • ISM-0401Partially meets
    Implement Secure by Design in Software Development
  • ISM-0402Partially meets
    Software Vulnerability Testing Using SAST, DAST and SCA
  • ISM-0971Partially meets
    Use OWASP Standards in Web Application Development
  • ISM-1238Supports
    Incorporate Threat Modelling in Software Development
  • ISM-1239Supports
    Ensure Use of Robust Web Application Frameworks
  • ISM-1240Partially meets
    Ensure Input Validation and Sanitisation for Internet Data
  • ISM-1419Supports
    Software Development in Development Environments
  • ISM-1524Partially meets
    Ensure Rigorous Testing of Content Filters
  • ISM-1597Supports
    Ensuring Credential Input Obscurity
  • ISM-1780Partially meets
    Apply SecDevOps for Secure Software Development
  • ISM-1791Partially overlaps
    Assess Integrity of Delivered IT and OT Products
  • ISM-1850Supports
    Mitigate OWASP Top 10 in Web Applications
  • ISM-1851Partially meets
    Secure Development Using OWASP API Security Top 10
  • ISM-1922Partially overlaps
    Use OWASP Standards in Mobile App Development
  • ISM-2026Partially overlaps
    Scan Software Artefacts for Malicious Content
  • ISM-2028Partially overlaps
    Test Software Artefacts for Security Weaknesses
  • ISM-2029Supports
    Restrict Third-Party Libraries to Trustworthy Sources
  • ISM-2031Partially overlaps
    Secure System Build Tools Implementation
  • ISM-2032Partially meets
    Ensure Automated Tests Are Completed Before Building
  • ISM-2033Supports
    Document and Maintain Software Security Requirements
  • ISM-2039Supports
    Review Threat Model During Software Development
  • ISM-2040Supports
    Ensure Secure Programming Practices in Software Development
  • ISM-2042Partially meets
    Ensuring Security in Software Development Lifecycle
  • ISM-2054Supports
    Ensure No Vulnerabilities in Third-Party Software Components
  • ISM-2055Partially overlaps
    Ensure Software Components Meet Build Standards
  • ISM-2057Partially meets
    Document, Build and Test All Input Validation Rules
  • ISM-2059Supports
    Restrict and Scan File Uploads for Security
  • ISM-2060Partially overlaps
    Ensure Code Reviews for Secure Software Design
  • ISM-2061Partially overlaps
    Peer Reviews of Critical and Security-Related Software Components
  • ISM-2062Partially meets
    Unit and Integration Testing for Code Quality
  • ISM-2102Broader than
    Periodically Test Software Artefacts for Weaknesses
  • ISM-2119Depends on
    Utilise AI Models in Vulnerability Assessments and Penetration Tests
  • ISM-2122Broader than
    Use Suitable AI Models to Augment Software Security Testing
Annex A 8.30
Management of Outsourced System Development
Technological controls
  • ISM-0401Partially overlaps
    Implement Secure by Design in Software Development
  • ISM-0402Supports
    Software Vulnerability Testing Using SAST, DAST and SCA
  • ISM-0731Partially overlaps
    CISO Oversight of Cyber Supply Chain Risks
  • ISM-1239Supports
    Ensure Use of Robust Web Application Frameworks
  • ISM-1395Partially overlaps
    Ensuring Data Protection by Service Providers
  • ISM-1452Partially overlaps
    Perform Supply Chain Risk Assessments for System Suppliers
  • ISM-1634Supports
    Tailoring System Controls for Security and Resilience
  • ISM-1738Supports
    Verify Compliance with Security Requirements
  • ISM-1780Partially overlaps
    Apply SecDevOps for Secure Software Development
  • ISM-1791Supports
    Assess Integrity of Delivered IT and OT Products
  • ISM-1826Partially overlaps
    Select Vendors Committed to Secure Design for Servers
  • ISM-2024Supports
    Utilise Authoritative Sources in Software Development
  • ISM-2028Depends on
    Test Software Artefacts for Security Weaknesses
  • ISM-2029Supports
    Restrict Third-Party Libraries to Trustworthy Sources
  • ISM-2031Partially overlaps
    Secure System Build Tools Implementation
  • ISM-2033Partially overlaps
    Document and Maintain Software Security Requirements
  • ISM-2039Supports
    Review Threat Model During Software Development
  • ISM-2086Supports
    Verify Integrity of AI Models, Structures, and Weights
  • ISM-2087Partially overlaps
    Verify the Source and Integrity of AI Training Data
  • ISM-2102Depends on
    Periodically Test Software Artefacts for Weaknesses
Annex A 8.31
Separation of Development, Test, and Production Environments
Technological controls
  • ISM-0385Partially overlaps
    Maintain Effective Functional Separation Between Servers
  • ISM-0400Equivalent
    Segregation of Environments in Software Development
  • ISM-1211Depends on
    System Administration Performed Under Change and Configuration Management Plan
  • ISM-1273Partially overlaps
    Segregate Environments for Database Servers
  • ISM-1274Supports
    Ensure Non-Production Databases Match Production Security
  • ISM-1419Equivalent
    Software Development in Development Environments
  • ISM-1420Partially overlaps
    Ensure Non-Production Security Matches Production
  • ISM-1689Supports
    Restrict Privileged Accounts Access to Non-Privileged Environments
  • ISM-1816Depends on
    Prevent Unauthorised Changes to Software Sources
  • ISM-1852Depends on
    Limit Unprivileged Access to What Duties Require
  • ISM-1970Partially meets
    Segregated Environment for Malicious Code Analysis
  • ISM-2143Partially overlaps
    Unique Per-Application Credentials Not Shared Across Environments
Annex A 8.32
Change management procedures for information systems
Technological controls
  • ISM-0042Partially meets
    Maintain Effective System Administration Practices
  • ISM-0289Supports
    Implement and Manage Evaluated Products Correctly
  • ISM-0300Partially overlaps
    Apply System Security Patches with Approval
  • ISM-0518Depends on
    Maintain Comprehensive Network Documentation
  • ISM-0597Broader than
    Consult ASD Before Changing CDS Connectivity
  • ISM-0912Partially meets
    Establish and Manage System Configuration Changes
  • ISM-1079Partially overlaps
    Seek Approval for High Assurance IT Repairs
  • ISM-1143Supports
    Develop and Maintain Patch Management Procedures
  • ISM-1211Partially overlaps
    System Admin Activities Follow Change Management Plan
  • ISM-1297Depends on
    Seek Legal Advice for Personal Device Access
  • ISM-1419Broader than
    Software Development in Development Environments
  • ISM-1430Depends on
    Configure IPv6 Addresses with DHCPv6 in Stateful Mode
  • ISM-1564Supports
    System Owner Produces Plan of Action and Milestones After Assessment
  • ISM-1598Partially overlaps
    Inspect IT Equipment Post-Maintenance for Unauthorised Changes
  • ISM-1606Depends on
    Patch Isolation Mechanisms and Underlying Operating Systems Promptly
  • ISM-1610Depends on
    Document and Test Emergency System Access Procedures
  • ISM-1615Depends on
    Testing Break Glass Accounts Post Credential Change
  • ISM-1634Depends on
    System Owners Select and Tailor Controls in Consultation with Authorising Officer
  • ISM-1732Supports
    Coordinated Intrusion Remediation During Planned Outages
  • ISM-1816Depends on
    Prevent Unauthorised Changes to Software Sources
  • ISM-1824Broader than
    Lock PDF Application Security Settings Against User Changes
  • ISM-1944Broader than
    Remove EDITF_ATTRIBUTESUBJECTALTNAME2 Flag From AD CS Certification Authorities
  • ISM-1948Broader than
    Certificate Manager Approval for Templates Allowing Supplied SANs
  • ISM-2025Depends on
    Using Issue Tracking for Software Development Tasks
  • ISM-2073Supports
    Develop a Post-Quantum Cryptography Transition Plan
  • ISM-2113Supports
    Configuring AI Applications to Require Human Approval Before High-Impact Actions
  • ISM-2132Depends on
    Central Logging of Certificate Enrolment Requests, Template and AD CS Configuration Changes
  • ISM-2161Depends on
    Verify Network Device Firmware and Configuration Against Known-Good Baseline
Annex A 8.33
Test Information Selection and Protection
Technological controls
  • ISM-0457Supports
    Use Evaluated Crypto for Sensitive Data Encryption
  • ISM-0465Supports
    Use Evaluated Cryptographic Tools for Sensitive Data
  • ISM-0631Supports
    Restrict Data Flows with Authorised Gateways
  • ISM-0831Partially overlaps
    Ensure Proper Handling of Sensitive Media
  • ISM-1273Supports
    Segregate Environments for Database Servers
  • ISM-2021Partially overlaps
    Implement and Maintain Data Minimisation Practices
  • ISM-2094Supports
    AI Content Filtering to Block Sensitive Data Exposure
Annex A 8.34
Protection of information systems during audits
Technological controls
  • ISM-1524Partially overlaps
    Ensure Rigorous Testing of Content Filters
  • ISM-1563Partially overlaps
    Generate Comprehensive Security Assessment Reports
  • ISM-1564Depends on
    System Owner Produces Plan of Action and Milestones After Assessment
  • ISM-1636Partially overlaps
    Security Control Assessment of Systems by Own or IRAP Assessors
  • ISM-1967Partially overlaps
    ASD Assessor Security Control Assessment of TOP SECRET Systems

How to use this mapping

Read it in whichever direction you are being assessed. If ISO 27001 is your primary framework, use the table to find the ASD ISM controls that cover the same ground, so evidence you already hold can be reused instead of rebuilt. If ASD ISM is what you are being held to, work back from the counterpart column to see which ISO 27001 controls contribute. A mapping means the two controls address related risk, not that satisfying one satisfies the other, so always read the relationship label before relying on it.

Frequently asked questions

Does meeting ISO 27001 mean I meet the ASD ISM?

No. The mapping shows where the two frameworks address related risk, not that one satisfies the other. ISO/IEC 27001:2022 Annex A controls are broad outcome statements, while ISM controls are specific and often technical, so a single Annex A control typically corresponds to many ISM controls and rarely covers all of them. Use the mapping to reuse evidence, then check each ISM control on its own terms.

Why does one ISO 27001 control map to so many ISM controls?

Because the two are written at different levels of detail. An Annex A control such as access control states an outcome in a sentence or two. The ISM breaks the same ground into many separate, testable requirements covering privileged access, authentication, session handling and logging. A one-to-many relationship is the normal shape of this mapping rather than a sign of duplication.

What do the relationship labels mean?

Each pairing carries a label describing how the two controls relate. Partially meets means the mapped control covers part of the requirement. Partially overlaps means they share ground without either containing the other. Supports means one helps achieve the other. Depends on means one relies on the other being in place. Equivalent is reserved for genuinely matching requirements and is rare.

Is this mapping official?

No. Neither ISO nor the Australian Signals Directorate publishes an official crosswalk between these two frameworks. This mapping is produced by Control Stack from the control text of both frameworks and reviewed for topic fidelity. Treat it as a working aid for planning and evidence reuse, not as an authoritative statement from either body.