Australian Information Security Manual
Evidence request list. 1081 controls, 1081 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Guidelines for communications infrastructure
Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.
- Evidence demonstrating: Cabling infrastructure is installed in accordance with relevant Australian Stand
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
- Evidence demonstrating: SECRET cables, when bundled together or run in conduit, are run exclusively in t
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit joints and TOP SECRET conduits connected by threaded lock nuts.
- Evidence demonstrating: In shared facilities, a visible smear of conduit glue is used to seal all plasti
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to seal all removable covers on TOP SECRET cable reticulation systems.
- Evidence demonstrating: In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals a
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Organisation is consulted and all directions provided are complied with.
- Evidence demonstrating: When penetrating a TOP SECRET audio secure room, the Australian Security Intelli
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre intervals and marked as 'TS RUN'.
- Evidence demonstrating: Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.
- Evidence demonstrating: Cable labelling processes, and supporting cable labelling procedures, are develo
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
A cable register contains the following for each cable: - cable identifier - cable colour - sensitivity/classification - source - destination - location - seal numbers (if applicable).
- Evidence demonstrating: A cable register contains the following for each cable: - cable identifier - cab
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
A cable register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A cable register is developed, implemented, maintained and verified on a regular
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET and TOP SECRET cables are terminated on their own individual patch panels.
- Evidence demonstrating: SECRET and TOP SECRET cables are terminated on their own individual patch panels
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
TOP SECRET patch panels are installed in individual TOP SECRET cabinets.
- Evidence demonstrating: TOP SECRET patch panels are installed in individual TOP SECRET cabinets.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabinet as a TOP SECRET patch panel: - a physical barrier in the cabinet is provided to separate patch panels - only personnel holding a Positive Vetting security clearance have access to the cabinet - approval from the TOP SECRET system's authorising officer is obtained prior to installation.
- Evidence demonstrating: Where spatial constraints demand non-TOP SECRET patch panels be installed in the
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wall outlet boxes to IT equipment, they are run in a protective and easily inspected pathway that is clearly labelled at the IT equipment end with the wall outlet box's identifier.
- Evidence demonstrating: If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
When an emanation security risk assessment is required, it is sought as early as possible in a system's life cycle.
- Evidence demonstrating: When an emanation security risk assessment is required, it is sought as early as
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployable capability, contact ASD for an emanation security risk assessment.
- Evidence demonstrating: System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.
- Evidence demonstrating: IT equipment meets industry and government standards relating to electromagnetic
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.
- Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither sa
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.
- Evidence demonstrating: Wall outlet boxes denote the systems, cable identifiers and wall outlet box iden
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.
- Evidence demonstrating: Cables are labelled at each end with sufficient source and destination details t
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet with a division plate between any SECRET cables and non-SECRET cables.
- Evidence demonstrating: SECRET cables are terminated in an individual cabinet; or for small systems, a c
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
TOP SECRET cables are terminated in an individual TOP SECRET cabinet.
- Evidence demonstrating: TOP SECRET cables are terminated in an individual TOP SECRET cabinet.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.
- Evidence demonstrating: In TOP SECRET areas, cable reticulation systems leading into cabinets in server
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.
- Evidence demonstrating: Cable reticulation systems leading into cabinets are terminated as close as poss
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.
- Evidence demonstrating: In TOP SECRET areas, cable reticulation systems leading into cabinets not in ser
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.
- Evidence demonstrating: SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.
- Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Wall outlet box covers are clear plastic.
- Evidence demonstrating: Wall outlet box covers are clear plastic.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Fibre-optic cables are used for cabling infrastructure instead of copper cables.
- Evidence demonstrating: Fibre-optic cables are used for cabling infrastructure instead of copper cables.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables in non-TOP SECRET areas are inspectable every five metres or less.
- Evidence demonstrating: Cables in non-TOP SECRET areas are inspectable every five metres or less.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.
- Evidence demonstrating: Cable bundles or conduits sharing a common cable reticulation system have a divi
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.
- Evidence demonstrating: Cables from cable trays to wall outlet boxes are run in flexible or plastic cond
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
- Evidence demonstrating: A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables in TOP SECRET areas are fully inspectable for their entire length.
- Evidence demonstrating: Cables in TOP SECRET areas are fully inspectable for their entire length.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET cables are encased in conduit with all gaps between the TOP SECRET conduit and the wall filled with an appropriate sealing compound.
- Evidence demonstrating: Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
A power distribution board with a feed from an Uninterruptible Power Supply is used to power all TOP SECRET IT equipment.
- Evidence demonstrating: A power distribution board with a feed from an Uninterruptible Power Supply is u
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In shared facilities, cables are run in an enclosed cable reticulation system.
- Evidence demonstrating: In shared facilities, cables are run in an enclosed cable reticulation system.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In shared facilities, TOP SECRET cables are not run in party walls.
- Evidence demonstrating: In shared facilities, TOP SECRET cables are not run in party walls.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security risk assessment.
- Evidence demonstrating: System owners deploying SECRET or TOP SECRET systems within fixed facilities con
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.
- Evidence demonstrating: In shared facilities, conduits or the front covers of ducts, cable trays in floo
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appropriate colour and labelled at inspection points.
- Evidence demonstrating: SECRET and TOP SECRET cables with non-conformant cable colouring are banded with
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.
- Evidence demonstrating: Building management cables are labelled with their purpose in black writing on a
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables for foreign systems installed in Australian facilities are labelled at inspection points.
- Evidence demonstrating: Cables for foreign systems installed in Australian facilities are labelled at in
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Floor plan diagrams are developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: Floor plan diagrams are developed, implemented, maintained and verified on a reg
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Floor plan diagrams contain the following: - cable paths (including ingress and egress points between floors) - cable reticulation system and conduit paths - floor concentration boxes - wall outlet boxes - network cabinets.
- Evidence demonstrating: Floor plan diagrams contain the following: - cable paths (including ingress and
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET cables are coloured salmon pink.
- Evidence demonstrating: SECRET cables are coloured salmon pink.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
TOP SECRET cables are coloured red.
- Evidence demonstrating: TOP SECRET cables are coloured red.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
SECRET wall outlet boxes are coloured salmon pink.
- Evidence demonstrating: SECRET wall outlet boxes are coloured salmon pink.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
TOP SECRET wall outlet boxes are coloured red.
- Evidence demonstrating: TOP SECRET wall outlet boxes are coloured red.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Cables for individual systems use a consistent colour.
- Evidence demonstrating: Cables for individual systems use a consistent colour.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.
- Evidence demonstrating: TOP SECRET cables, when bundled together or run in conduit, are run exclusively
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Wall outlet boxes for individual systems use a consistent colour.
- Evidence demonstrating: Wall outlet boxes for individual systems use a consistent colour.
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.
- Evidence demonstrating: Emanation security doctrine produced by ASD for the management of emanation secu
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Recommended actions contained within emanation security mitigation advice issued for systems are implemented by system owners.
- Evidence demonstrating: Recommended actions contained within emanation security mitigation advice issued
- Cabling records and standards compliance
- Emanation security assessments
- Cable labelling/inspection records
- Cabling not installed to standard
- No emanation security consideration
Guidelines for communications systems
Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.
- Evidence demonstrating: Personnel are advised of the permitted sensitivity or classification of informat
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.
- Evidence demonstrating: Personnel are advised of security risks posed by non-secure telephone systems in
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.
- Evidence demonstrating: When using cryptographic equipment to permit different levels of conversation fo
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.
- Evidence demonstrating: Telephone systems used for sensitive or classified conversations encrypt all tra
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted.
- Evidence demonstrating: Cordless telephone handsets and headsets are not used for sensitive or classifie
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.
- Evidence demonstrating: Speakerphones are not used on telephone systems in TOP SECRET areas unless the t
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.
- Evidence demonstrating: Off-hook audio protection features are used on telephone systems in areas where
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
MFDs are not connected to digital telephone systems.
- Evidence demonstrating: MFDs are not connected to digital telephone systems.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.
- Evidence demonstrating: When video conferencing or IP telephony traffic passes through a gateway contain
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.
- Evidence demonstrating: Video conferencing and IP telephony calls are conducted using a secure real-time
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Video conferencing and IP telephony calls are established using a secure session initiation protocol.
- Evidence demonstrating: Video conferencing and IP telephony calls are established using a secure session
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Video conferencing and IP telephony traffic is separated physically or logically from other data traffic.
- Evidence demonstrating: Video conferencing and IP telephony traffic is separated physically or logically
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
IP telephony is configured such that: - IP phones authenticate themselves to the call controller upon registration - auto-registration is disabled and only authorised devices are allowed to access the network - unauthorised devices are blocked by default - all unused and prohibited functionality is disabled.
- Evidence demonstrating: IP telephony is configured such that: - IP phones authenticate themselves to the
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.
- Evidence demonstrating: Authentication and authorisation is used for all actions on a video conferencing
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.
- Evidence demonstrating: An encrypted and non-replayable two-way authentication scheme is used for call a
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.
- Evidence demonstrating: Authentication and authorisation is used for all actions on an IP telephony netw
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses Virtual Local Area Networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.
- Evidence demonstrating: Workstations are not connected to video conferencing units or IP phones unless t
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.
- Evidence demonstrating: IP phones used in public areas do not have the ability to access data networks,
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.
- Evidence demonstrating: Microphones (including headsets and USB handsets) and webcams are not used with
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
An MFD usage policy is developed, implemented and maintained.
- Evidence demonstrating: An MFD usage policy is developed, implemented and maintained.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.
- Evidence demonstrating: MFDs are not used to scan or copy documents above the sensitivity or classificat
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.
- Evidence demonstrating: Authentication measures for MFDs are the same strength as those used for worksta
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements.
- Evidence demonstrating: In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets a
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversations.
- Evidence demonstrating: Individual logins are implemented for IP phones used for SECRET or TOP SECRET co
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.
- Evidence demonstrating: A denial of service response plan for video conferencing and IP telephony servic
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
MFDs are located in areas where their use can be observed.
- Evidence demonstrating: MFDs are located in areas where their use can be observed.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
A telephone system usage policy is developed, implemented and maintained.
- Evidence demonstrating: A telephone system usage policy is developed, implemented and maintained.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.
- Evidence demonstrating: Microphones (including headsets and USB handsets) and webcams are not used with
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Video conferencing and IP telephony infrastructure is hardened.
- Evidence demonstrating: Video conferencing and IP telephony infrastructure is hardened.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
A denial of service response plan for video conferencing and IP telephony services contains the following: - how to identify signs of a denial-of-service attack - how to identify the source of a denial-of-service attack - how capabilities can be maintained during a denial-of-service attack - what actions can be taken to respond to a denial-of-service attack.
- Evidence demonstrating: A denial of service response plan for video conferencing and IP telephony servic
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Users authenticate to MFDs before they can print, scan or copy documents.
- Evidence demonstrating: Users authenticate to MFDs before they can print, scan or copy documents.
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.
- Evidence demonstrating: Use of MFDs for printing, scanning and copying purposes, including the capture o
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Fax machines, and online fax services, are not used for sending or receiving fax messages.
- Evidence demonstrating: Fax machines, and online fax services, are not used for sending or receiving fax
- Telephone/video/fax usage policies
- Classification/marking of communications
- Configuration records
- No usage policy
- Classification not enforced on communications
Guidelines for cryptography
The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.
- Evidence demonstrating: The compromise or suspected compromise of cryptographic equipment or associated
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.
- Evidence demonstrating: Where practical, cryptographic equipment, applications and libraries provide a m
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.
- Evidence demonstrating: Cryptographic equipment, applications or libraries that have completed a Common
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Full disk encryption, or partial encryption where access controls will only allow writing to the encrypted partition, is implemented when encrypting data at rest.
- Evidence demonstrating: Full disk encryption, or partial encryption where access controls will only allo
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
HACE is used when encrypting media that contains SECRET or TOP SECRET data.
- Evidence demonstrating: HACE is used when encrypting media that contains SECRET or TOP SECRET data.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.
- Evidence demonstrating: When a user authenticates to the encryption functionality of IT equipment or med
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.
- Evidence demonstrating: Cryptographic equipment, applications or libraries that have completed a Common
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.
- Evidence demonstrating: HACE is used to protect SECRET and TOP SECRET data when communicated over insuff
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is used to protect data when communicated over network infrastructure.
- Evidence demonstrating: An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic pr
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.
- Evidence demonstrating: Only AACAs or high assurance cryptographic algorithms are used by cryptographic
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.
- Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus of at least 204
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.
- Evidence demonstrating: When using ECDH for agreeing on encryption session keys, a base point order and
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.
- Evidence demonstrating: When using ECDSA for digital signatures, a base point order and key size of at l
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.
- Evidence demonstrating: When using RSA for digital signatures, and transporting encryption session keys
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.
- Evidence demonstrating: When using RSA for digital signatures, and for transporting encryption session k
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.
- Evidence demonstrating: Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.
- Evidence demonstrating: Only AACPs or high assurance cryptographic protocols are used by cryptographic e
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx) - have a suitable login banner (Banner x) - have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60) - disable host-based authentication (HostbasedAuthentication no) - disable rhosts-based authentication (IgnoreRhosts yes) - disable the ability to login directly as root (PermitRootLogin no) - disable empty passwords (PermitEmptyPasswords no) - disable connection forwarding (AllowTCPForwarding no) - disable gateway ports (GatewayPorts no) - disable X11 forwarding (X11Forwarding no).
- Evidence demonstrating: The SSH daemon is configured to: - only listen on the required interfaces (Liste
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Public key-based authentication is used for SSH connections.
- Evidence demonstrating: Public key-based authentication is used for SSH connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using logins without a password for SSH connections, the following are disabled: - access from IP addresses that do not require access - port forwarding - agent credential forwarding - X11 forwarding - console access.
- Evidence demonstrating: When using logins without a password for SSH connections, the following are disa
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
If using remote access without the use of a password for SSH connections, the 'forced command' option is used to specify what command is executed and parameter checking is enabled.
- Evidence demonstrating: If using remote access without the use of a password for SSH connections, the 'f
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When SSH-agent or similar key caching applications are used, it is limited to workstations and servers with screen locks and key caches that are set to expire within four hours of inactivity.
- Evidence demonstrating: When SSH-agent or similar key caching applications are used, it is limited to wo
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.
- Evidence demonstrating: Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME conne
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.
- Evidence demonstrating: Tunnel mode is used for IPsec connections; however, if using transport mode, an
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
The ESP protocol is used for authentication and encryption of IPsec connections.
- Evidence demonstrating: The ESP protocol is used for authentication and encryption of IPsec connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.
- Evidence demonstrating: A security association lifetime of less than four hours (14400 seconds) is used
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Communications security doctrine and policy produced by ASD for the management and operation of HACE is complied with.
- Evidence demonstrating: Communications security doctrine and policy produced by ASD for the management a
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.
- Evidence demonstrating: Keyed cryptographic equipment is transported based on the sensitivity or classif
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.
- Evidence demonstrating: Cryptographic key management processes, and supporting cryptographic key managem
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
ECDH is used in preference to DH.
- Evidence demonstrating: ECDH is used in preference to DH.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.
- Evidence demonstrating: AUTH HMAC SHA2 256 128, AUTH HMAC SHA2 384 192, AUTH HMAC SHA2 512 256 or NONE (
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072-bit MODP Group or 4096-bit MODP Group.
- Evidence demonstrating: DH or ECDH is used for key establishment of IPsec connections, preferably 384-bi
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
PFS is used for IPsec connections.
- Evidence demonstrating: PFS is used for IPsec connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm is used when encrypting media.
- Evidence demonstrating: An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic a
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Keying material is changed when compromised or suspected of being compromised.
- Evidence demonstrating: Keying material is changed when compromised or suspected of being compromised.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Only the latest version of TLS is used for TLS connections.
- Evidence demonstrating: Only the latest version of TLS is used for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
IKE version 2 is used for key exchange when establishing IPsec connections.
- Evidence demonstrating: IKE version 2 is used for key exchange when establishing IPsec connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
AES-GCM is used for encryption of TLS connections.
- Evidence demonstrating: AES-GCM is used for encryption of TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Only server-initiated secure renegotiation is used for TLS connections.
- Evidence demonstrating: Only server-initiated secure renegotiation is used for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
DH or ECDH is used for key establishment of TLS connections.
- Evidence demonstrating: DH or ECDH is used for key establishment of TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Anonymous DH is not used for TLS connections.
- Evidence demonstrating: Anonymous DH is not used for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
SHA-2-based certificates are used for TLS connections.
- Evidence demonstrating: SHA-2-based certificates are used for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.
- Evidence demonstrating: SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudora
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.
- Evidence demonstrating: When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.
- Evidence demonstrating: When using DH or ECDH for key establishment of TLS connections, the ephemeral va
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
SSH private keys are protected with a password or a key encryption key.
- Evidence demonstrating: SSH private keys are protected with a password or a key encryption key.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Perfect Forward Secrecy (PFS) is used for TLS connections.
- Evidence demonstrating: Perfect Forward Secrecy (PFS) is used for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
The use of SSH version 1 is disabled for SSH connections.
- Evidence demonstrating: The use of SSH version 1 is disabled for SSH connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
TLS compression is disabled for TLS connections.
- Evidence demonstrating: TLS compression is disabled for TLS connections.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.
- Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus and associated
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is used, preferably 3072 bits.
- Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus of at least 307
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P-384 curve.
- Evidence demonstrating: When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.
- Evidence demonstrating: When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 cur
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P-384 curve.
- Evidence demonstrating: When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are u
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.
- Evidence demonstrating: When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, pr
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 3072 bits is used, preferably 3072 bits.
- Evidence demonstrating: When using RSA for digital signatures, and transporting encryption session keys
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.
- Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 224 bits is used, prefe
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA-384 or SHA-512.
- Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 256 bits is used, prefe
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA-384 or SHA-512.
- Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 384 bits is used, prefe
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.
- Evidence demonstrating: When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably A
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.
- Evidence demonstrating: When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.
- Evidence demonstrating: AES is used for encrypting IPsec connections, preferably ENCR AES GCM 16.
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.
- Evidence demonstrating: PRF HMAC SHA2 256, PRF HMAC SHA2 384 or PRF HMAC SHA2 512 is used for IPsec conn
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
HACE are issued an Approval for Use by ASD and operated in accordance with the latest version of their associated Australian Communications Security Instructions.
- Evidence demonstrating: HACE are issued an Approval for Use by ASD and operated in accordance with the l
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.
- Evidence demonstrating: The development and procurement of new cryptographic equipment, applications and
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.
- Evidence demonstrating: When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adheren
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.
- Evidence demonstrating: When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, prefer
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ML-DSA for digital signatures, the hedged variant is used whenever possible.
- Evidence demonstrating: When using ML-DSA for digital signatures, the hedged variant is used whenever po
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.
- Evidence demonstrating: Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performanc
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.
- Evidence demonstrating: When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-3
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.
- Evidence demonstrating: When using ML-KEM for encapsulating encryption session keys (and similar keys),
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.
- Evidence demonstrating: When a post-quantum traditional hybrid scheme is used, either the post-quantum c
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
A post-quantum cryptography transition plan is developed, implemented and maintained.
- Evidence demonstrating: A post-quantum cryptography transition plan is developed, implemented and mainta
- ASD-Approved algorithm/protocol configuration
- Key management procedures
- TLS/SSH/IPsec configuration
- Non-approved or weak algorithms
- Poor key management
Guidelines for cyber security documentation
A cyber security strategy is developed, implemented and maintained.
- Evidence demonstrating: A cyber security strategy is developed, implemented and maintained.
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Systems have a system security plan that includes an overview of the system (covering the system's purpose, the system boundary and how the system is managed) as well as an annex that covers applicable controls from this document and any additional controls that have been identified and implemented.
- Evidence demonstrating: Systems have a system security plan that includes an overview of the system (cov
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Systems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types of cyber security incidents likely to be encountered and the expected response to each type - how to report cyber security incidents, internally to an organisation and externally to relevant authorities - other parties which need to be informed in the event of a cyber security incident - the authority, or authorities, responsible for investigating and responding to cyber security incidents - the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority - the steps necessary to ensure the integrity of evidence relating to a cyber security incident - system contingency measures or a reference to such details if they are loca
- Evidence demonstrating: Systems have a cyber security incident response plan that covers the following:
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system's authorising officer.
- Evidence demonstrating: Organisational-level cyber security documentation is approved by the chief infor
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Cyber security documentation is reviewed at least annually and includes a 'current as at \[date\]' or equivalent statement.
- Evidence demonstrating: Cyber security documentation is reviewed at least annually and includes a 'curre
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Systems have a change and configuration management plan that includes: - the establishment and maintenance of authorised baseline configurations for systems - what constitutes routine and urgent changes to the configuration of systems - how changes to the configuration of systems will be requested, tracked and documented - who needs to be consulted prior to routine and urgent changes to the configuration of systems - who needs to approve routine and urgent changes to the configuration of systems - who needs to be notified of routine and urgent changes to the configuration of systems - what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.
- Evidence demonstrating: Systems have a change and configuration management plan that includes: - the est
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Systems have a continuous monitoring plan that includes: - conducting vulnerability scans for systems at least fortnightly - conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter - analysing identified vulnerabilities to determine their potential impact - implementing mitigations based on risk, effectiveness and cost.
- Evidence demonstrating: Systems have a continuous monitoring plan that includes: - conducting vulnerabil
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: - the scope of the security assessment - the system's strengths and weaknesses - security risks associated with the operation of the system - the effectiveness of the implementation of controls - any recommended remediation actions.
- Evidence demonstrating: At the conclusion of a security assessment for a system, a security assessment r
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
At the conclusion of a security assessment for a system, a plan of action and milestones is produced by the system owner.
- Evidence demonstrating: At the conclusion of a security assessment for a system, a plan of action and mi
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.
- Evidence demonstrating: Cyber security documentation, including notification of subsequent changes, is c
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
A system's security architecture is approved prior to the development of the system.
- Evidence demonstrating: A system's security architecture is approved prior to the development of the sys
- System security plans
- Standard operating procedures
- Current-as-at dates and approval records
- Documentation out of date
- No system security plan
- No annual review
Guidelines for cyber security incidents
Cyber security personnel have access to sufficient data sources and tools to ensure that systems can be monitored for key indicators of compromise.
- Evidence demonstrating: Cyber security personnel have access to sufficient data sources and tools to ens
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.
- Evidence demonstrating: Cyber security incidents are reported to the chief information security officer,
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
A cyber security incident register is developed, implemented and maintained.
- Evidence demonstrating: A cyber security incident register is developed, implemented and maintained.
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
When a data spill occurs, data owners are advised and access to the data is restricted.
- Evidence demonstrating: When a data spill occurs, data owners are advised and access to the data is rest
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.
- Evidence demonstrating: Legal advice is sought before allowing intrusion activity to continue on a syste
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
The integrity of evidence gathered during an investigation is maintained by investigators: - recording all of their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.
- Evidence demonstrating: The integrity of evidence gathered during an investigation is maintained by inve
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.
- Evidence demonstrating: Cyber security incidents are reported to ASD as soon as possible after they occu
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.
- Evidence demonstrating: A cyber security incident management policy, and associated cyber security incid
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
When malicious code is detected, the following steps are taken to handle the infection: - the infected systems are isolated - all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary - antivirus applications are used to remove the infection from infected systems and media - if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.
- Evidence demonstrating: When malicious code is detected, the following steps are taken to handle the inf
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Following intrusion remediation activities, full network traffic is captured for at least seven days and analysed to determine whether malicious actors have been successfully removed from the system.
- Evidence demonstrating: Following intrusion remediation activities, full network traffic is captured for
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.
- Evidence demonstrating: System owners are consulted before allowing intrusion activity to continue on a
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
An insider threat mitigation program is developed, implemented and maintained.
- Evidence demonstrating: An insider threat mitigation program is developed, implemented and maintained.
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Legal advice is sought regarding the development and implementation of an insider threat mitigation program.
- Evidence demonstrating: Legal advice is sought regarding the development and implementation of an inside
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Planning and coordination of intrusion remediation activities are conducted on a separate system to that which has been compromised.
- Evidence demonstrating: Planning and coordination of intrusion remediation activities are conducted on a
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.
- Evidence demonstrating: To the extent possible, all intrusion remediation activities are conducted in a
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.
- Evidence demonstrating: The cyber security incident management policy, including the associated cyber se
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
A cyber security incident register contains the following for each cyber security incident: - the date the cyber security incident occurred - the date the cyber security incident was discovered - a description of the cyber security incident - any actions taken in response to the cyber security incident - to whom the cyber security incident was reported.
- Evidence demonstrating: A cyber security incident register contains the following for each cyber securit
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Following the identification of a cyber security incident, the cyber security incident response plan is enacted.
- Evidence demonstrating: Following the identification of a cyber security incident, the cyber security in
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
- Evidence demonstrating: Cyber security incidents that involve customer data are reported to customers an
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
- Evidence demonstrating: Cyber security incidents that do not involve customer data are reported to custo
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
- Evidence demonstrating: Malicious code, when stored or communicated, is treated beforehand to prevent ac
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Malicious code processed for cyber security incident response or research purposes is done so in a dedicated analysis environment that is segregated from other systems.
- Evidence demonstrating: Malicious code processed for cyber security incident response or research purpos
- Cyber security incident response plan
- Incident register
- Post-incident review records
- Reports to ASD/ACSC
- No incident response plan
- Incidents not reported to ASD
- No post-incident review
Guidelines for cyber security roles
System owners, in consultation with each system's authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation's risk tolerances.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, identify
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.
- Evidence demonstrating: System owners obtain an authorisation to operate for each non-classified, OFFICI
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering information technology and operational technology).
- Evidence demonstrating: A CISO is appointed to provide cyber security leadership and guidance for their
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees the management of cyber security personnel within their organisation.
- Evidence demonstrating: The CISO oversees the management of cyber security personnel within their organi
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO regularly reports directly to their organisation's board of directors or executive committee on cyber security matters.
- Evidence demonstrating: The CISO regularly reports directly to their organisation's board of directors o
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.
- Evidence demonstrating: The CISO oversees the development, implementation and maintenance of a cyber sec
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO implements cyber security measurement metrics and key performance indicators for their organisation.
- Evidence demonstrating: The CISO implements cyber security measurement metrics and key performance indic
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising of key cyber security and business executives, which meets formally and on a regular basis.
- Evidence demonstrating: The CISO coordinates cyber security and business alignment through a cyber secur
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO coordinates security risk management activities between cyber security and business teams.
- Evidence demonstrating: The CISO coordinates security risk management activities between cyber security
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees cyber supply chain risk management activities for their organisation.
- Evidence demonstrating: The CISO oversees cyber supply chain risk management activities for their organi
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO receives and manages a dedicated cyber security budget for their organisation.
- Evidence demonstrating: The CISO receives and manages a dedicated cyber security budget for their organi
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO is fully aware of all cyber security incidents within their organisation.
- Evidence demonstrating: The CISO is fully aware of all cyber security incidents within their organisatio
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.
- Evidence demonstrating: The CISO contributes to the development, implementation and maintenance of busin
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
- Evidence demonstrating: The CISO oversees the development, implementation and maintenance of their organ
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
Each system has a designated system owner.
- Evidence demonstrating: Each system has a designated system owner.
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners, in consultation with each system's authorising officer, conduct a threat and risk assessment for each system.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, conduct a
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees their organisation's cyber security program and ensures their organisation's compliance with cyber security policy, standards, regulations and legislation.
- Evidence demonstrating: The CISO oversees their organisation's cyber security program and ensures their
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners register each system with its authorising officer.
- Evidence demonstrating: System owners register each system with its authorising officer.
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.
- Evidence demonstrating: System owners continuously monitor the security of each system, and manage assoc
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners report the security status of each system to its authorising officer at least annually.
- Evidence demonstrating: System owners report the security status of each system to its authorising offic
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO regularly reviews and updates their organisation's cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.
- Evidence demonstrating: The CISO regularly reviews and updates their organisation's cyber security progr
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO oversees their organisation's response to cyber security incidents.
- Evidence demonstrating: The CISO oversees their organisation's response to cyber security incidents.
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners, in consultation with each system's authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, determine
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners, in consultation with each system's authorising officer, select controls for each system and tailor them to achieve desired security and resilience objectives.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, select co
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners implement controls for each system and its operating environment.
- Evidence demonstrating: System owners implement controls for each system and its operating environment.
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners, in consultation with each system's authorising officer, ensure controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation's own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, ensure co
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO regularly reports directly to their organisation's audit, risk and compliance committee (or equivalent) on cyber security matters.
- Evidence demonstrating: The CISO regularly reports directly to their organisation's audit, risk and comp
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.
- Evidence demonstrating: The CISO develops, implements, maintains and verifies on a regular basis a regis
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners, in consultation with each system's authorising officer, ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and its operating environment, undergo a security assessment by ASD assessors (or their delegates) to determine if they have been implemented correctly and are operating as intended.
- Evidence demonstrating: System owners, in consultation with each system's authorising officer, ensure co
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners obtain an authorisation to operate for each TOP SECRET system, including for each sensitive compartmented information system, from Director-General ASD (or their delegate).
- Evidence demonstrating: System owners obtain an authorisation to operate for each TOP SECRET system, inc
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.
- Evidence demonstrating: The board of directors or executive committee defines clear roles and responsibi
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.
- Evidence demonstrating: The board of directors or executive committee ensures that cyber security is int
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.
- Evidence demonstrating: The board of directors or executive committee ensures the cyber security strateg
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.
- Evidence demonstrating: The board of directors or executive committee seeks regular briefings or reporti
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.
- Evidence demonstrating: The board of directors or executive committee champions a positive cyber securit
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.
- Evidence demonstrating: The board of directors or executive committee maintains a sufficient level of cy
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.
- Evidence demonstrating: The board of directors or executive committee maintains awareness of key cyber s
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.
- Evidence demonstrating: The board of directors or executive committee supports the development of cyber
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee understands the business criticality of their organisation's systems, including at least a basic understanding of what exists, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.
- Evidence demonstrating: The board of directors or executive committee understands the business criticali
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understand their duties in relation to such cyber security incidents.
- Evidence demonstrating: The board of directors or executive committee plans for major cyber security inc
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.
- Evidence demonstrating: The CISO ensures sufficient cyber security personnel, with the right skills and
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
System owners implement and maintain data minimisation practices for each of their systems.
- Evidence demonstrating: System owners implement and maintain data minimisation practices for each of the
- CISO appointment record
- Role descriptions / RACI
- Resourcing and reporting lines
- Accountable executive not designated
- Cyber roles undefined or unfilled
Guidelines for data transfers
When manually importing data to systems, the data is scanned for malicious and active content.
- Evidence demonstrating: When manually importing data to systems, the data is scanned for malicious and a
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly.
- Evidence demonstrating: Data transfer logs for SECRET and TOP SECRET systems are fully verified at least
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Users transferring data to and from systems are held accountable for data transfers they perform.
- Evidence demonstrating: Users transferring data to and from systems are held accountable for data transf
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.
- Evidence demonstrating: Data transfer processes, and supporting data transfer procedures, are developed,
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustworthy source beforehand.
- Evidence demonstrating: Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services that have been verified and authorised as such by the chief information security officer.
- Evidence demonstrating: Trustworthy sources for SECRET and TOP SECRET systems are limited to people and
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
When manually exporting data from SECRET and TOP SECRET systems, digital signatures are validated and keyword checks are performed within all textual data.
- Evidence demonstrating: When manually exporting data from SECRET and TOP SECRET systems, digital signatu
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a trustworthy source.
- Evidence demonstrating: Data authorised for export from SECRET and TOP SECRET systems is digitally signe
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
When manually exporting data from systems, the data is checked for unsuitable protective markings.
- Evidence demonstrating: When manually exporting data from systems, the data is checked for unsuitable pr
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data transfer logs for systems are partially verified at least monthly.
- Evidence demonstrating: Data transfer logs for systems are partially verified at least monthly.
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Processes, and supporting procedures, are developed, implemented and maintained to prevent AUSTEO, AGAO and REL data in textual and non-textual formats from being exported to unsuitable foreign systems.
- Evidence demonstrating: Processes, and supporting procedures, are developed, implemented and maintained
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Data transfer logs are used to record all data imports and exports from systems.
- Evidence demonstrating: Data transfer logs are used to record all data imports and exports from systems.
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.
- Evidence demonstrating: When manually importing data to systems, all data that fails security checks is
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.
- Evidence demonstrating: When manually exporting data from systems, all data that fails security checks i
- Data transfer logs
- Export review and authorisation records
- Content inspection / quarantine evidence
- Unauthorised data exports
- Transfers not logged or reviewed
Guidelines for database systems
Databases and their contents are classified based on the sensitivity or classification of data that they contain.
- Evidence demonstrating: Databases and their contents are classified based on the sensitivity or classifi
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
A database register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A database register is developed, implemented, maintained and verified on a regu
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Database users' ability to access, insert, modify and remove database contents is restricted based on their work duties.
- Evidence demonstrating: Database users' ability to access, insert, modify and remove database contents i
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
File-based access controls are applied to database files.
- Evidence demonstrating: File-based access controls are applied to database files.
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.
- Evidence demonstrating: The need-to-know principle is enforced for database contents through the applica
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Database servers and web servers are functionally separated.
- Evidence demonstrating: Database servers and web servers are functionally separated.
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Database servers are placed on a different network segment to user workstations.
- Evidence demonstrating: Database servers are placed on a different network segment to user workstations.
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.
- Evidence demonstrating: Network access controls are implemented to restrict database server communicatio
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
If only local access to a database is required, networking functionality of database management system applications are disabled or directed to listen solely to the localhost interface.
- Evidence demonstrating: If only local access to a database is required, networking functionality of data
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Database servers for development, testing, staging and production environments are segregated.
- Evidence demonstrating: Database servers for development, testing, staging and production environments a
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
- Evidence demonstrating: Database contents from production environments are not used in non-production en
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Data communicated between database servers and web servers is encrypted.
- Evidence demonstrating: Data communicated between database servers and web servers is encrypted.
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Security-relevant events for databases are centrally logged, including: - access or modification of particularly important content - addition of new users, especially privileged users - changes to user roles or privileges - attempts to elevate user privileges - queries containing comments - queries containing multiple embedded queries - database and query alerts or failures - database structure changes - database administrator actions - use of executable commands - database logons and logoffs.
- Evidence demonstrating: Security-relevant events for databases are centrally logged, including: - access
- Database hardening configuration
- Database access control records
- Encryption of database communications/data
- Databases not hardened
- Excessive database privileges
Guidelines for email
An email usage policy is developed, implemented and maintained.
- Evidence demonstrating: An email usage policy is developed, implemented and maintained.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Access to non-approved webmail services is blocked.
- Evidence demonstrating: Access to non-approved webmail services is blocked.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To data are not sent to email distribution lists unless the nationality of all members of email distribution lists can be confirmed.
- Evidence demonstrating: Emails containing Australian Eyes Only, Australian Government Access Only or Rel
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.
- Evidence demonstrating: Protective markings are applied to emails and reflect the highest sensitivity or
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Protective marking tools do not automatically insert protective markings into emails.
- Evidence demonstrating: Protective marking tools do not automatically insert protective markings into em
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.
- Evidence demonstrating: Protective marking tools do not allow users to select protective markings that a
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Email servers are configured to block, log and report emails with inappropriate protective markings.
- Evidence demonstrating: Email servers are configured to block, log and report emails with inappropriate
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Email servers only relay emails destined for or originating from their domains (including subdomains).
- Evidence demonstrating: Email servers only relay emails destined for or originating from their domains (
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Emails are routed via centralised email gateways.
- Evidence demonstrating: Emails are routed via centralised email gateways.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.
- Evidence demonstrating: Where backup or alternative email gateways are in place, they are maintained at
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation's centralised email gateways.
- Evidence demonstrating: When users send or receive emails, an authenticated and encrypted channel is use
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.
- Evidence demonstrating: Opportunistic TLS encryption is enabled on email servers that make incoming or o
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
SPF is used to specify authorised email servers (or lack thereof) for an organisation's domains (including subdomains).
- Evidence demonstrating: SPF is used to specify authorised email servers (or lack thereof) for an organis
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
DKIM signing is enabled on emails originating from an organisation's domains (including subdomains).
- Evidence demonstrating: DKIM signing is enabled on emails originating from an organisation's domains (in
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.
- Evidence demonstrating: The intended recipients of blocked inbound emails, and the senders of blocked ou
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.
- Evidence demonstrating: Notifications of undeliverable emails are only sent to senders that can be verif
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
DKIM signatures on incoming emails are verified.
- Evidence demonstrating: DKIM signatures on incoming emails are verified.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Email distribution list applications used by external senders is configured such that it does not break the validity of the sender's DKIM signature.
- Evidence demonstrating: Email distribution list applications used by external senders is configured such
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Protective marking tools do not allow users replying to or forwarding emails to select protective markings lower than previously used.
- Evidence demonstrating: Protective marking tools do not allow users replying to or forwarding emails to
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
SPF is used to verify the authenticity of incoming emails.
- Evidence demonstrating: SPF is used to verify the authenticity of incoming emails.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation's domains (including subdomains).
- Evidence demonstrating: A hard fail SPF record is used when specifying authorised email servers (or lack
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.
- Evidence demonstrating: Email content filtering is implemented to filter potentially harmful content in
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.
- Evidence demonstrating: Emails arriving via an external connection where the email source address uses a
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
DMARC records are configured for an organisation's domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.
- Evidence demonstrating: DMARC records are configured for an organisation's domains (including subdomains
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.
- Evidence demonstrating: MTA-STS is enabled to prevent the unencrypted transfer of emails between email s
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Incoming emails are rejected if they do not pass DMARC checks.
- Evidence demonstrating: Incoming emails are rejected if they do not pass DMARC checks.
- Email protective marking configuration
- SPF/DKIM/DMARC records
- Email content filtering configuration
- No DMARC/SPF/DKIM
- No email content filtering
- Protective marking not applied
Guidelines for enterprise mobility
Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.
- Evidence demonstrating: Paging, Multimedia Message Service, Short Message Service and messaging apps are
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.
- Evidence demonstrating: Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that have been issued an Approval for Use by ASD and are operated in accordance with the latest version of their associated Australian Communications Security Instruction.
- Evidence demonstrating: Mobile devices that access SECRET or TOP SECRET systems or data use mobile platf
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data.
- Evidence demonstrating: Privately-owned mobile devices and desktop computers do not access SECRET and TO
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.
- Evidence demonstrating: Mobile device emergency sanitisation processes, and supporting mobile device eme
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SECRET or TOP SECRET mobile device, the function is used as part of mobile device emergency sanitisation processes and procedures.
- Evidence demonstrating: If a cryptographic zeroise or sanitise function is provided for cryptographic ke
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
When accessing an organisation's network via a VPN connection, split tunnelling is disabled.
- Evidence demonstrating: When accessing an organisation's network via a VPN connection, split tunnelling
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices prevent personnel from installing non-approved applications once provisioned.
- Evidence demonstrating: Mobile devices prevent personnel from installing non-approved applications once
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.
- Evidence demonstrating: Mobile devices prevent personnel from disabling or modifying security functional
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.
- Evidence demonstrating: Sensitive or classified data is not viewed on mobile devices in public locations
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices encrypt their internal storage and any removable media.
- Evidence demonstrating: Mobile devices encrypt their internal storage and any removable media.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are carried or stored in a secured state when not being actively used.
- Evidence demonstrating: Mobile devices are carried or stored in a secured state when not being actively
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are kept under continual direct supervision when being actively used.
- Evidence demonstrating: Mobile devices are kept under continual direct supervision when being actively u
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.
- Evidence demonstrating: Mobile devices and desktop computers access the internet via an organisation's i
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
A mobile device usage policy is developed, implemented and maintained.
- Evidence demonstrating: A mobile device usage policy is developed, implemented and maintained.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.
- Evidence demonstrating: Personnel are advised of the sensitivity or classification permitted for voice a
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.
- Evidence demonstrating: If unable to carry or store mobile devices in a secured state, they are physical
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure.
- Evidence demonstrating: Mobile devices encrypt all sensitive or classified data communicated over public
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they: - provide credentials to foreign government officials - decrypt mobile devices for foreign government officials - have mobile devices taken out of sight by foreign government officials - have mobile devices or removable media stolen, including if later returned - lose mobile devices or removable media, including if later found - observe unusual behaviour of mobile devices.
- Evidence demonstrating: Personnel report the potential compromise of mobile devices, removable media or
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices.
- Evidence demonstrating: Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devic
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.
- Evidence demonstrating: Mobile Device Management solutions that have completed a Common Criteria evaluat
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.
- Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.
- Evidence demonstrating: Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile d
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.
- Evidence demonstrating: Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.
- Evidence demonstrating: Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile d
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Legal advice is sought prior to allowing privately-owned mobile devices and desktop computers to access systems or data.
- Evidence demonstrating: Legal advice is sought prior to allowing privately-owned mobile devices and desk
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel are advised of privacy and security risks when travelling overseas with mobile devices.
- Evidence demonstrating: Personnel are advised of privacy and security risks when travelling overseas wit
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel are advised to take the following precautions when using mobile devices: - never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes - never store credentials with mobile devices that they grant access to, such as in laptop computer bags - never lend mobile devices or removable media to untrusted people, even if briefly - never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging - never connect mobile devices to designated charging stations or wall outlet charging ports - never use gifted or unauthorised peripherals, chargers or removable media with mobile devices - never use removable media for data transfers or backups that have not been checked for malicious code beforehand - avoid reuse of removable media once used with other pa
- Evidence demonstrating: Personnel are advised to take the following precautions when using mobile device
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Upon returning from travelling overseas with mobile devices, personnel take the following actions: - sanitise and reset mobile devices, including all removable media - decommission any credentials that left their possession during their travel - report if significant doubt exists as to the integrity of any mobile devices or removable media.
- Evidence demonstrating: Upon returning from travelling overseas with mobile devices, personnel take the
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Security updates are applied to mobile devices as soon as they become available.
- Evidence demonstrating: Security updates are applied to mobile devices as soon as they become available.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.
- Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.
- Evidence demonstrating: Personnel using organisation-owned mobile devices or desktop computers to access
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
A mobile device management policy is developed, implemented and maintained.
- Evidence demonstrating: A mobile device management policy is developed, implemented and maintained.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
If travelling overseas with mobile devices to high or extreme risk countries, personnel are: - issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities - advised on how to apply and inspect tamper seals to key areas of mobile devices - advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.
- Evidence demonstrating: If travelling overseas with mobile devices to high or extreme risk countries, pe
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Before travelling overseas with mobile devices, personnel take the following actions: - record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers - update all operating systems and applications - remove all non-essential data, applications and user accounts - backup all remaining data, applications and settings.
- Evidence demonstrating: Before travelling overseas with mobile devices, personnel take the following act
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions: - reset credentials used with mobile devices, including those used for remote access to their organisation's systems - monitor user accounts for any indicators of compromise, such as failed logon attempts.
- Evidence demonstrating: If returning from travelling overseas with mobile devices to high or extreme ris
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.
- Evidence demonstrating: Sensitive or classified phone calls and conversations are not conducted in publi
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately-owned mobile devices and desktop computers.
- Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.
- Evidence demonstrating: Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand by ASD.
- Evidence demonstrating: SECRET and TOP SECRET mobile devices do not use removable media unless approved
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured to operate in a supervised (or equivalent) mode.
- Evidence demonstrating: Mobile devices are configured to operate in a supervised (or equivalent) mode.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured with remote locate and wipe functionality.
- Evidence demonstrating: Mobile devices are configured with remote locate and wipe functionality.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured with secure password-based lock screens.
- Evidence demonstrating: Mobile devices are configured with secure password-based lock screens.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.
- Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.
- Evidence demonstrating: Mobile devices are configured to enforce separation between organisational and p
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured with always on VPN functionality.
- Evidence demonstrating: Mobile devices are configured with always on VPN functionality.
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.
- Evidence demonstrating: Mobile devices are configured to prevent data transfers over Universal Serial Bu
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Mobile devices are not connected to the infotainment systems of connected vehicles.
- Evidence demonstrating: Mobile devices are not connected to the infotainment systems of connected vehicl
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.
- Evidence demonstrating: Sensitive or classified data is not viewed on mobile devices within or near conn
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.
- Evidence demonstrating: Sensitive or classified phone calls and conversations are not conducted within o
- Mobile device management (MDM) configuration
- Mobile device policy
- Overseas travel briefings and device controls
- No MDM enforcement
- BYOD allowed without controls
- No travel security process
Guidelines for evaluated products
If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.
- Evidence demonstrating: If procuring an evaluated product, a product that has completed a PP-based evalu
- Evaluated product selection records
- Protection Profile / evaluation evidence
- Evidence products run in their evaluated configuration
- Unevaluated products used for high assurance
- Products not in evaluated configuration
Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.
- Evidence demonstrating: Evaluated products are delivered in a manner consistent with any delivery proced
- Evaluated product selection records
- Protection Profile / evaluation evidence
- Evidence products run in their evaluated configuration
- Unevaluated products used for high assurance
- Products not in evaluated configuration
When procuring high assurance information technology (IT) equipment, ASD is contacted for any equipment-specific delivery procedures.
- Evidence demonstrating: When procuring high assurance information technology (IT) equipment, ASD is cont
- Evaluated product selection records
- Protection Profile / evaluation evidence
- Evidence products run in their evaluated configuration
- Unevaluated products used for high assurance
- Products not in evaluated configuration
Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.
- Evidence demonstrating: Evaluated products are installed, configured, administered and operated in an ev
- Evaluated product selection records
- Protection Profile / evaluation evidence
- Evidence products run in their evaluated configuration
- Unevaluated products used for high assurance
- Products not in evaluated configuration
High assurance IT equipment is installed, configured, administered and operated in an evaluated configuration and in accordance with ASD guidance.
- Evidence demonstrating: High assurance IT equipment is installed, configured, administered and operated
- Evaluated product selection records
- Protection Profile / evaluation evidence
- Evidence products run in their evaluated configuration
- Unevaluated products used for high assurance
- Products not in evaluated configuration
Guidelines for gateways
Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IR
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
All web access, including that by internal servers, is conducted through web proxies.
- Evidence demonstrating: All web access, including that by internal servers, is conducted through web pro
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
The following details are centrally logged for websites accessed via web proxies: - web address - date and time - user - amount of data uploaded and downloaded - internal and external IP addresses.
- Evidence demonstrating: The following details are centrally logged for websites accessed via web proxies
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
TLS traffic communicated through gateways is decrypted and inspected.
- Evidence demonstrating: TLS traffic communicated through gateways is decrypted and inspected.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated peripheral switches are used when sharing peripherals between systems.
- Evidence demonstrating: Evaluated peripheral switches are used when sharing peripherals between systems.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
When planning, designing, implementing or introducing additional connectivity to CDSs, ASD is consulted and any directions provided by ASD are complied with.
- Evidence demonstrating: When planning, designing, implementing or introducing additional connectivity to
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Users are trained on the secure use of CDSs before access is granted.
- Evidence demonstrating: Users are trained on the secure use of CDSs before access is granted.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
System administrators for gateways are assigned the minimum privileges required to perform their duties.
- Evidence demonstrating: System administrators for gateways are assigned the minimum privileges required
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
System administrators for gateways are formally trained on the operation and management of gateways.
- Evidence demonstrating: System administrators for gateways are formally trained on the operation and man
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
System administrators for gateways that connect to Australian Eyes Only or Releasable To networks are Australian nationals.
- Evidence demonstrating: System administrators for gateways that connect to Australian Eyes Only or Relea
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Separation of duties is implemented in performing administrative activities for gateways.
- Evidence demonstrating: Separation of duties is implemented in performing administrative activities for
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Users authenticate to other networks accessed via gateways.
- Evidence demonstrating: Users authenticate to other networks accessed via gateways.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
IT equipment authenticates to other networks accessed via gateways.
- Evidence demonstrating: IT equipment authenticates to other networks accessed via gateways.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
CDSs are implemented between SECRET or TOP SECRET networks and any other networks belonging to different security domains.
- Evidence demonstrating: CDSs are implemented between SECRET or TOP SECRET networks and any other network
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways are implemented between networks belonging to different security domains.
- Evidence demonstrating: Gateways are implemented between networks belonging to different security domain
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.
- Evidence demonstrating: For gateways between networks belonging to different security domains, any share
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways only allow explicitly authorised data flows.
- Evidence demonstrating: Gateways only allow explicitly authorised data flows.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Security-relevant events for gateways are centrally logged, including: - data packets and data flows permitted through gateways - data packets and data flows attempting to leave gateways - real-time alerts for attempted intrusions.
- Evidence demonstrating: Security-relevant events for gateways are centrally logged, including: - data pa
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
CDSs implement isolated upward and downward network paths.
- Evidence demonstrating: CDSs implement isolated upward and downward network paths.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways implement a demilitarised zone if external parties require access to an organisation's services.
- Evidence demonstrating: Gateways implement a demilitarised zone if external parties require access to an
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated firewalls are used between networks belonging to different security domains.
- Evidence demonstrating: Evaluated firewalls are used between networks belonging to different security do
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation's networks and public network infrastructure.
- Evidence demonstrating: Evaluated diodes are used for controlling the data flow of unidirectional gatewa
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and public network infrastructure complete a high assurance evaluation.
- Evidence demonstrating: Evaluated diodes used for controlling the data flow of unidirectional gateways b
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs are filtered for allowed file types.
- Evidence demonstrating: Files imported or exported via gateways or CDSs are filtered for allowed file ty
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.
- Evidence demonstrating: Files identified by content filtering checks as malicious, or that cannot be ins
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.
- Evidence demonstrating: Files identified by content filtering checks as suspicious are quarantined until
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo content filtering checks.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content filtering checks
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Security-relevant events for CDSs are centrally logged.
- Evidence demonstrating: Security-relevant events for CDSs are centrally logged.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.
- Evidence demonstrating: Files imported or exported via gateways or CDSs that have a digital signature or
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.
- Evidence demonstrating: An organisation-approved list of domain names, or list of website categories, is
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Client-side active content is restricted by web content filters to an organisation-approved list of domain names.
- Evidence demonstrating: Client-side active content is restricted by web content filters to an organisati
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Web content filtering is implemented to filter potentially harmful web-based content.
- Evidence demonstrating: Web content filtering is implemented to filter potentially harmful web-based con
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate they conform to expected security configurations.
- Evidence demonstrating: Gateways undergo testing following configuration changes, and at regular interva
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.
- Evidence demonstrating: Evaluated diodes are used for controlling the data flow of unidirectional gatewa
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and any other networks complete a high assurance evaluation.
- Evidence demonstrating: Evaluated diodes used for controlling the data flow of unidirectional gateways b
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.
- Evidence demonstrating: Attempts to access websites through their IP addresses instead of their domain n
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways inspect and filter data flows at the transport and above network layers.
- Evidence demonstrating: Gateways inspect and filter data flows at the transport and above network layers
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.
- Evidence demonstrating: Malicious domain names, dynamic domain names and domain names that can be regist
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Web content filtering is applied to outbound web traffic where appropriate.
- Evidence demonstrating: Web content filtering is applied to outbound web traffic where appropriate.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo content validation.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content validation.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo content conversion.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content conversion.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo content sanitisation.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content sanitisation.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo antivirus scanning using
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Archive files imported or exported via gateways or CDSs are unpacked in order to undergo content filtering checks.
- Evidence demonstrating: Archive files imported or exported via gateways or CDSs are unpacked in order to
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.
- Evidence demonstrating: Archive files are unpacked in a controlled manner to ensure content filter perfo
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Encrypted files imported or exported via gateways or CDSs are decrypted in order to undergo content filtering checks.
- Evidence demonstrating: Encrypted files imported or exported via gateways or CDSs are decrypted in order
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.
- Evidence demonstrating: Executable files imported via gateways or CDSs are automatically executed in a s
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.
- Evidence demonstrating: Gateways perform ingress traffic filtering to detect and prevent IP source addre
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET systems, or between SECRET or TOP SECRET systems belonging to different security domains, preferably complete a high assurance evaluation.
- Evidence demonstrating: Evaluated peripheral switches used for sharing peripherals between SECRET and TO
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET systems and any non-SECRET or TOP SECRET systems complete a high assurance evaluation.
- Evidence demonstrating: Evaluated peripheral switches used for sharing peripherals between SECRET or TOP
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.
- Evidence demonstrating: System administrators for gateways undergo appropriate employment screening, and
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
CDSs implement protocol breaks at each network layer.
- Evidence demonstrating: CDSs implement protocol breaks at each network layer.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
CDSs implement independent security-enforcing functions for upward and downward network paths.
- Evidence demonstrating: CDSs implement independent security-enforcing functions for upward and downward
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
A sample of security-relevant events relating to data transfer policies are taken at least every three months and assessed against security policies for CDSs to identify any operational failures.
- Evidence demonstrating: A sample of security-relevant events relating to data transfer policies are take
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Content filters used by CDSs undergo rigorous security testing to ensure they perform as expected and cannot be bypassed.
- Evidence demonstrating: Content filters used by CDSs undergo rigorous security testing to ensure they pe
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Evaluated firewalls are used between an organisation's networks and public network infrastructure.
- Evidence demonstrating: Evaluated firewalls are used between an organisation's networks and public netwo
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
System administrators for gateways that connect to Australian Government Access Only networks are Australian nationals or seconded foreign nationals.
- Evidence demonstrating: System administrators for gateways that connect to Australian Government Access
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Gateways are managed via a secure path isolated from all connected networks.
- Evidence demonstrating: Gateways are managed via a secure path isolated from all connected networks.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.
- Evidence demonstrating: Public IP addresses controlled by, or used by, an organisation are signed by val
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
If using a WAF, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.
- Evidence demonstrating: If using a WAF, disclosing the IP addresses of web servers under an organisation
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Files imported or exported via gateways or CDSs undergo content checking.
- Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content checking.
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.
- Evidence demonstrating: Routes for RPKI-registered IP addresses that are advertised from invalid Autonom
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: TOP SECRET gateways undergo a security assessment by ASD assessors (or their del
- Gateway configuration
- Firewall rule-set and review records
- Cross Domain Solution / web & content filtering configuration
- Firewall rules not reviewed
- Unrestricted gateway data flows
Guidelines for information technology equipment
IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.
- Evidence demonstrating: IT equipment is classified based on the highest sensitivity or classification of
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment, with the exception of high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.
- Evidence demonstrating: IT equipment, with the exception of high assurance IT equipment, is labelled wit
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
ASD's approval is sought before applying labels to external surfaces of high assurance IT equipment.
- Evidence demonstrating: ASD's approval is sought before applying labels to external surfaces of high ass
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared technician.
- Evidence demonstrating: Maintenance and repairs of IT equipment is carried out on site by an appropriate
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
If an appropriately cleared technician is not used to undertake maintenance or repairs of IT equipment, the technician is escorted by someone who: - is appropriately cleared and briefed - takes due care to ensure that data is not disclosed - takes all responsible measures to ensure the integrity of the IT equipment - has the authority to direct the technician - is sufficiently familiar with the IT equipment to understand the work being performed.
- Evidence demonstrating: If an appropriately cleared technician is not used to undertake maintenance or r
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
If an appropriately cleared technician is not used to undertake maintenance or repairs of IT equipment, the IT equipment and associated media is sanitised before maintenance or repair work is undertaken.
- Evidence demonstrating: If an appropriately cleared technician is not used to undertake maintenance or r
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment maintained or repaired off site is done so at facilities approved for handling the sensitivity or classification of the IT equipment.
- Evidence demonstrating: IT equipment maintained or repaired off site is done so at facilities approved f
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.
- Evidence demonstrating: IT equipment containing media is sanitised by removing the media from the IT equ
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data that cannot be sanitised in situ, is returned to Australia for destruction.
- Evidence demonstrating: IT equipment, including associated media, that is located overseas and has proce
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.
- Evidence demonstrating: IT equipment sanitisation processes, and supporting IT equipment sanitisation pr
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
High assurance IT equipment is destroyed prior to its disposal.
- Evidence demonstrating: High assurance IT equipment is destroyed prior to its disposal.
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.
- Evidence demonstrating: Following sanitisation, destruction or declassification, a formal administrative
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.
- Evidence demonstrating: At least three pages of random text with no blank areas are printed on each colo
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.
- Evidence demonstrating: When unable to sanitise printer cartridges or MFD print drums, they are destroye
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
When disposing of IT equipment that has been designed or modified to meet emanation security standards, ASD is contacted for requirements relating to its disposal.
- Evidence demonstrating: When disposing of IT equipment that has been designed or modified to meet emanat
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
A networked IT equipment register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A networked IT equipment register is developed, implemented, maintained and veri
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period of time.
- Evidence demonstrating: Televisions and computer monitors with minor burn-in or image persistence are sa
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
ASD's approval is sought before undertaking any maintenance or repairs to high assurance IT equipment.
- Evidence demonstrating: ASD's approval is sought before undertaking any maintenance or repairs to high a
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.
- Evidence demonstrating: Labels and markings indicating the owner, sensitivity, classification or any oth
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data, is sanitised in situ.
- Evidence demonstrating: IT equipment, including associated media, that is located overseas and has proce
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner which cannot be removed or a print is visible on the image transfer roller.
- Evidence demonstrating: MFD print drums and image transfer rollers are inspected and destroyed if there
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.
- Evidence demonstrating: Printer and MFD platens are inspected and destroyed if any text or images are re
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.
- Evidence demonstrating: Printers and MFDs are checked to ensure no pages are trapped in the paper path d
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Televisions and computer monitors that cannot be sanitised are destroyed.
- Evidence demonstrating: Televisions and computer monitors that cannot be sanitised are destroyed.
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Memory in network devices is sanitised using the following processes, in order of preference: - following device-specific guidance provided in evaluation documentation - following vendor sanitisation guidance - loading a dummy configuration file, performing a factory reset and then reinstalling firmware.
- Evidence demonstrating: Memory in network devices is sanitised using the following processes, in order o
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Printer ribbons in printers and MFDs are removed and destroyed.
- Evidence demonstrating: Printer ribbons in printers and MFDs are removed and destroyed.
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.
- Evidence demonstrating: IT equipment disposal processes, and supporting IT equipment disposal procedures
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
An IT equipment management policy is developed, implemented and maintained.
- Evidence demonstrating: An IT equipment management policy is developed, implemented and maintained.
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Following maintenance or repair activities for IT equipment, the IT equipment is inspected to confirm it retains its approved configuration and that no unauthorised modifications have taken place.
- Evidence demonstrating: Following maintenance or repair activities for IT equipment, the IT equipment is
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment is handled in a manner suitable for its sensitivity or classification.
- Evidence demonstrating: IT equipment is handled in a manner suitable for its sensitivity or classificati
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.
- Evidence demonstrating: IT equipment destruction processes, and supporting IT equipment destruction proc
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment that cannot be sanitised is destroyed.
- Evidence demonstrating: IT equipment that cannot be sanitised is destroyed.
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: IT equipment is hardened using ASD and vendor hardening guidance, with the most
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
A non-networked IT equipment register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A non-networked IT equipment register is developed, implemented, maintained and
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Approved configurations for IT equipment are developed, implemented and maintained.
- Evidence demonstrating: Approved configurations for IT equipment are developed, implemented and maintain
- IT equipment register
- Sanitisation/destruction records
- Disposal and movement records
- Equipment not sanitised before disposal
- No equipment register
Guidelines for media
Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.
- Evidence demonstrating: Media is classified to the highest sensitivity or classification of data it stor
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.
- Evidence demonstrating: Any media connected to a system with a higher sensitivity or classification than
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.
- Evidence demonstrating: Before reclassifying media to a lower sensitivity or classification, the media i
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media, with the exception of internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.
- Evidence demonstrating: Media, with the exception of internally mounted fixed media within information t
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.
- Evidence demonstrating: Media is only used with systems that are authorised to process, store or communi
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.
- Evidence demonstrating: When transferring data manually between two systems belonging to different secur
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.
- Evidence demonstrating: Media sanitisation processes, and supporting media sanitisation procedures, are
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The following media types are destroyed prior to their disposal: - microfiche and microfilm - optical discs - programmable read-only memory - read-only memory - other types of media that cannot be sanitised.
- Evidence demonstrating: The following media types are destroyed prior to their disposal: - microfiche an
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Volatile media is sanitised by removing its power for at least 10 minutes.
- Evidence demonstrating: Volatile media is sanitised by removing its power for at least 10 minutes.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
- Evidence demonstrating: SECRET and TOP SECRET volatile media is sanitised by overwriting it at least onc
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.
- Evidence demonstrating: Non-volatile magnetic media is sanitised by overwriting it at least once (or thr
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its classification.
- Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retain
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
- Evidence demonstrating: Non-volatile EPROM media is sanitised by applying three times the manufacturer's
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains its classification.
- Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM medi
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.
- Evidence demonstrating: Non-volatile flash memory media is sanitised by overwriting it at least twice in
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its classification.
- Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media re
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.
- Evidence demonstrating: Magnetic media is destroyed using a degausser with a suitable magnetic field str
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Product-specific directions provided by degausser manufacturers are followed.
- Evidence demonstrating: Product-specific directions provided by degausser manufacturers are followed.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.
- Evidence demonstrating: Media destruction processes, and supporting media destruction procedures, are de
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.
- Evidence demonstrating: Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The destruction of media is performed under the supervision of at least one cleared person.
- Evidence demonstrating: The destruction of media is performed under the supervision of at least one clea
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.
- Evidence demonstrating: Personnel supervising the destruction of media supervise its handling to the poi
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.
- Evidence demonstrating: The destruction of media storing accountable material is performed under the sup
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.
- Evidence demonstrating: Personnel supervising the destruction of media storing accountable material supe
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.
- Evidence demonstrating: Media disposal processes, and supporting media disposal procedures, are develope
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.
- Evidence demonstrating: Following sanitisation, destruction or declassification, a formal administrative
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.
- Evidence demonstrating: Labels and markings indicating the owner, sensitivity, classification or any oth
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media is handled in a manner suitable for its sensitivity or classification.
- Evidence demonstrating: Media is handled in a manner suitable for its sensitivity or classification.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following sanitisation, TOP SECRET volatile media retains its classification if it stored static data for an extended period of time, or had data repeatedly stored on or written to the same memory location for an extended period of time.
- Evidence demonstrating: Following sanitisation, TOP SECRET volatile media retains its classification if
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
- Evidence demonstrating: Non-volatile EEPROM media is sanitised by overwriting it at least once in its en
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The destruction of media storing accountable material is not outsourced.
- Evidence demonstrating: The destruction of media storing accountable material is not outsourced.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO's Protective Security Circular-167, is used.
- Evidence demonstrating: When outsourcing the destruction of media storing non-accountable material, a Na
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.
- Evidence demonstrating: When transferring data manually between two systems belonging to different secur
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
All data stored on media is encrypted.
- Evidence demonstrating: All data stored on media is encrypted.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The host-protected area and device configuration overlay table are reset prior to the sanitisation of non-volatile magnetic hard drives.
- Evidence demonstrating: The host-protected area and device configuration overlay table are reset prior t
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.
- Evidence demonstrating: The ATA secure erase command is used, in addition to block overwriting software,
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
If using degaussers to destroy media, degaussers evaluated by the United States' National Security Agency are used.
- Evidence demonstrating: If using degaussers to destroy media, degaussers evaluated by the United States'
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
A removable media usage policy is developed, implemented and maintained.
- Evidence demonstrating: A removable media usage policy is developed, implemented and maintained.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.
- Evidence demonstrating: Security Construction and Equipment Committee-approved equipment or ASIO-approve
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.
- Evidence demonstrating: Equipment that is capable of reducing microform to a fine powder, with resultant
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
A media management policy is developed, implemented and maintained.
- Evidence demonstrating: A media management policy is developed, implemented and maintained.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media is sanitised before it is used for the first time.
- Evidence demonstrating: Media is sanitised before it is used for the first time.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.
- Evidence demonstrating: Following the use of a degausser, magnetic media is physically damaged by deform
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media is sanitised before it is reused in a different security domain.
- Evidence demonstrating: Media is sanitised before it is reused in a different security domain.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
A removable media register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A removable media register is developed, implemented, maintained and verified on
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.
- Evidence demonstrating: Electrostatic memory devices are destroyed using a furnace/incinerator, hammer m
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.
- Evidence demonstrating: Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, di
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.
- Evidence demonstrating: Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disi
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.
- Evidence demonstrating: Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegr
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.
- Evidence demonstrating: Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegra
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.
- Evidence demonstrating: Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or di
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The resulting media waste particles from the destruction of SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, PROTECTED if greater than 3 mm and less than or equal to 6 mm, or SECRET if greater than 6 mm and less than or equal to 9 mm.
- Evidence demonstrating: The resulting media waste particles from the destruction of SECRET media is stor
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
The resulting media waste particles from the destruction of TOP SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, or SECRET if greater than 3 mm and less than or equal to 9 mm.
- Evidence demonstrating: The resulting media waste particles from the destruction of TOP SECRET media is
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Media that cannot be successfully sanitised is destroyed prior to its disposal.
- Evidence demonstrating: Media that cannot be successfully sanitised is destroyed prior to its disposal.
- Media register
- Sanitisation/destruction logs
- Media labelling and classification records
- Media not sanitised before reuse/disposal
- Unlabelled or misclassified media
Guidelines for networking
Servers maintain effective functional separation with other servers allowing them to operate independently.
- Evidence demonstrating: Servers maintain effective functional separation with other servers allowing the
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.
- Evidence demonstrating: Network documentation includes high-level network diagrams showing all connectio
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network documentation is developed, implemented and maintained.
- Evidence demonstrating: Network documentation is developed, implemented and maintained.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.
- Evidence demonstrating: Network access controls are implemented on networks to prevent the connection of
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
IPv6 functionality is disabled in dual-stack network devices unless it is being used.
- Evidence demonstrating: IPv6 functionality is disabled in dual-stack network devices unless it is being
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
VLANs are not used to separate network traffic between networks belonging to different security domains.
- Evidence demonstrating: VLANs are not used to separate network traffic between networks belonging to dif
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network devices managing VLANs are administered from the most trusted security domain.
- Evidence demonstrating: Network devices managing VLANs are administered from the most trusted security d
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Unused physical ports on network devices are disabled.
- Evidence demonstrating: Unused physical ports on network devices are disabled.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network devices managing VLANs belonging to different security domains do not share VLAN trunks.
- Evidence demonstrating: Network devices managing VLANs belonging to different security domains do not sh
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Public wireless networks provided for general public use are segregated from all other organisation networks.
- Evidence demonstrating: Public wireless networks provided for general public use are segregated from all
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Security measures are implemented to prevent unauthorised access to network management traffic.
- Evidence demonstrating: Security measures are implemented to prevent unauthorised access to network mana
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
The effective range of wireless communications outside an organisation's area of control is limited by implementing RF shielding on facilities in which SECRET or TOP SECRET wireless networks are used.
- Evidence demonstrating: The effective range of wireless communications outside an organisation's area of
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
A NIDS or NIPS is deployed in gateways between an organisation's networks and other networks they do not manage.
- Evidence demonstrating: A NIDS or NIPS is deployed in gateways between an organisation's networks and ot
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.
- Evidence demonstrating: A NIDS or NIPS is located immediately inside the outermost firewall for gateways
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.
- Evidence demonstrating: Network documentation provided to a third party, or published in public tender d
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Networks are segregated into multiple network zones according to the criticality of servers, services and data.
- Evidence demonstrating: Networks are segregated into multiple network zones according to the criticality
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.
- Evidence demonstrating: Network access controls are implemented to limit the flow of network traffic wit
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
IPv6 capable network security appliances are used on IPv6 and dual-stack networks.
- Evidence demonstrating: IPv6 capable network security appliances are used on IPv6 and dual-stack network
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
- Evidence demonstrating: Default user accounts or credentials for network devices, including for any pre-
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
SNMP version 1 and SNMP version 2 are not used on networks.
- Evidence demonstrating: SNMP version 1 and SNMP version 2 are not used on networks.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
All default SNMP community strings on network devices are changed and write access is disabled.
- Evidence demonstrating: All default SNMP community strings on network devices are changed and write acce
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
All wireless devices are Wi-Fi Alliance certified.
- Evidence demonstrating: All wireless devices are Wi-Fi Alliance certified.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
The administrative interface on wireless access points is disabled for wireless network connections.
- Evidence demonstrating: The administrative interface on wireless access points is disabled for wireless
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Default SSIDs of wireless access points are changed.
- Evidence demonstrating: Default SSIDs of wireless access points are changed.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.
- Evidence demonstrating: SSIDs of non-public wireless networks are not readily associated with an organis
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
SSID broadcasting is not disabled on wireless access points.
- Evidence demonstrating: SSID broadcasting is not disabled on wireless access points.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Static addressing is not used for assigning IP addresses on wireless networks.
- Evidence demonstrating: Static addressing is not used for assigning IP addresses on wireless networks.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
MAC address filtering is not used to restrict which devices can connect to wireless networks.
- Evidence demonstrating: MAC address filtering is not used to restrict which devices can connect to wirel
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.
- Evidence demonstrating: 802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Evaluated supplicants, authenticators, wireless access points and authentication servers are used in wireless networks.
- Evidence demonstrating: Evaluated supplicants, authenticators, wireless access points and authentication
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Certificates are required for devices and users accessing wireless networks.
- Evidence demonstrating: Certificates are required for devices and users accessing wireless networks.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Certificates are generated using an evaluated certificate authority or hardware security module.
- Evidence demonstrating: Certificates are generated using an evaluated certificate authority or hardware
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Certificates are protected by logical and physical access controls, encryption, and user authentication.
- Evidence demonstrating: Certificates are protected by logical and physical access controls, encryption,
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
The PMK caching period is not set to greater than 1440 minutes (24 hours).
- Evidence demonstrating: The PMK caching period is not set to greater than 1440 minutes (24 hours).
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.
- Evidence demonstrating: WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrit
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Wireless networks implement sufficient frequency separation from other wireless networks.
- Evidence demonstrating: Wireless networks implement sufficient frequency separation from other wireless
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Wireless access points enable the use of the 802.11w amendment to protect management frames.
- Evidence demonstrating: Wireless access points enable the use of the 802.11w amendment to protect manage
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.
- Evidence demonstrating: Instead of deploying a small number of wireless access points that broadcast on
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.
- Evidence demonstrating: Network devices managing VLANs terminate VLANs belonging to different security d
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
- Evidence demonstrating: Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
IPv6 tunnelling is blocked by network security appliances at externally-connected network boundaries.
- Evidence demonstrating: IPv6 tunnelling is blocked by network security appliances at externally-connecte
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.
- Evidence demonstrating: Dynamically assigned IPv6 addresses are configured with Dynamic Host Configurati
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: - their capacity to withstand denial-of-service attacks - costs likely to be incurred as a result of denial-of-service attacks - availability monitoring and thresholds for notification of denial-of-service attacks - thresholds for turning off any online services or functionality during denial-of-service attacks - pre-approved actions that can be undertaken during denial-of-service attacks - any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.
- Evidence demonstrating: Denial-of-service attack mitigation strategies are discussed with cloud service
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.
- Evidence demonstrating: Domain names for online services are protected via registrar locking and confirm
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.
- Evidence demonstrating: Critical online services are segregated from other online services that are more
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Cloud service providers are used for hosting online services.
- Evidence demonstrating: Cloud service providers are used for hosting online services.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Where a high availability requirement exists for website hosting, CDNs that cache websites are used.
- Evidence demonstrating: Where a high availability requirement exists for website hosting, CDNs that cach
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
If using CDNs, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.
- Evidence demonstrating: If using CDNs, disclosing the IP addresses of web servers under an organisation'
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.
- Evidence demonstrating: Communications between authenticators and a RADIUS server are encapsulated with
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Servers minimise communications with other servers at the network and file system level.
- Evidence demonstrating: Servers minimise communications with other servers at the network and file syste
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
VLANs are not used to separate network traffic between an organisation's networks and public network infrastructure.
- Evidence demonstrating: VLANs are not used to separate network traffic between an organisation's network
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
An organisation's networks are segregated from their service providers' networks.
- Evidence demonstrating: An organisation's networks are segregated from their service providers' networks
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Cloud service providers' ability to dynamically scale resources in response to a genuine spike in demand is discussed and verified as part of capacity and availability planning for online services.
- Evidence demonstrating: Cloud service providers' ability to dynamically scale resources in response to a
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.
- Evidence demonstrating: Where a high availability requirement exists for online services, the services a
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Continuous real-time monitoring of the capacity and availability of online services is performed.
- Evidence demonstrating: Continuous real-time monitoring of the capacity and availability of online servi
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Inbound network connections from anonymity networks are blocked.
- Evidence demonstrating: Inbound network connections from anonymity networks are blocked.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Outbound network connections to anonymity networks are blocked.
- Evidence demonstrating: Outbound network connections to anonymity networks are blocked.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Settings for wireless access points are hardened.
- Evidence demonstrating: Settings for wireless access points are hardened.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
User identity confidentiality is used if available with EAP-TLS implementations.
- Evidence demonstrating: User identity confidentiality is used if available with EAP-TLS implementations.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.
- Evidence demonstrating: The use of FT (802.11r) is disabled unless authenticator-to-authenticator commun
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
All data communicated over network infrastructure is encrypted.
- Evidence demonstrating: All data communicated over network infrastructure is encrypted.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
A protective DNS service is used to block access to known malicious domain names.
- Evidence demonstrating: A protective DNS service is used to block access to known malicious domain names
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network devices are flashed with trusted firmware before they are used for the first time.
- Evidence demonstrating: Network devices are flashed with trusted firmware before they are used for the f
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network devices are restarted on at least a monthly basis.
- Evidence demonstrating: Network devices are restarted on at least a monthly basis.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Networked management interfaces for IT equipment are not directly exposed to the internet.
- Evidence demonstrating: Networked management interfaces for IT equipment are not directly exposed to the
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.
- Evidence demonstrating: Network documentation includes device settings for all critical servers, high-va
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
SMB version 1 is not used on networks.
- Evidence demonstrating: SMB version 1 is not used on networks.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Security-relevant events for internet-facing network devices are centrally logged.
- Evidence demonstrating: Security-relevant events for internet-facing network devices are centrally logge
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Security-relevant events for non-internet-facing network devices are centrally logged.
- Evidence demonstrating: Security-relevant events for non-internet-facing network devices are centrally l
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
DNS traffic is encrypted by clients and servers wherever supported.
- Evidence demonstrating: DNS traffic is encrypted by clients and servers wherever supported.
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Internet connectivity for networked devices is strictly limited to those that require access.
- Evidence demonstrating: Internet connectivity for networked devices is strictly limited to those that re
- Network segmentation diagrams
- Access control lists
- Wireless network configuration
- Flat/unsegmented network
- Unrestricted network traffic
Guidelines for personnel security
Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under the control of an Australian national working for or on behalf of the Australian Government.
- Evidence demonstrating: Systems processing, storing or communicating AUSTEO or AGAO data remain at all t
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Cyber security awareness training is undertaken annually by all personnel and covers: - the purpose of the cyber security awareness training - security appointments and contacts - authorised use of systems and their resources - protection of systems and their resources - reporting of cyber security incidents and suspected compromises of systems and their resources.
- Evidence demonstrating: Cyber security awareness training is undertaken annually by all personnel and co
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A web usage policy is developed, implemented and maintained.
- Evidence demonstrating: A web usage policy is developed, implemented and maintained.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Requests for unprivileged access to systems and their resources are validated when first requested.
- Evidence demonstrating: Requests for unprivileged access to systems and their resources are validated wh
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A secure record is maintained for the life of systems and their resources that covers the following for each user: - their user identification - their signed agreement to abide by system usage policies - who authorised their access - when their access was granted - the level of access they were granted - when their access, and their level of access, was last reviewed - when their level of access was changed, and to what extent (if applicable) - when their access was withdrawn (if applicable).
- Evidence demonstrating: A secure record is maintained for the life of systems and their resources that c
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Foreign nationals, including seconded foreign nationals, do not have access to systems that process, store or communicate AUSTEO or REL data unless effective controls are in place to ensure such data is not accessible to them.
- Evidence demonstrating: Foreign nationals, including seconded foreign nationals, do not have access to s
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Foreign nationals, excluding seconded foreign nationals, do not have access to systems that process, store or communicate AGAO data unless effective controls are in place to ensure such data is not accessible to them.
- Evidence demonstrating: Foreign nationals, excluding seconded foreign nationals, do not have access to s
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel granted access to systems and their resources are uniquely identifiable.
- Evidence demonstrating: Personnel granted access to systems and their resources are uniquely identifiabl
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
The use of shared user accounts is strictly controlled, and personnel using such accounts are uniquely identifiable.
- Evidence demonstrating: The use of shared user accounts is strictly controlled, and personnel using such
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are foreign nationals are identified as such, including by their specific nationality.
- Evidence demonstrating: Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Access to systems and their resources are removed or suspended the same day personnel no longer have a legitimate requirement for access.
- Evidence demonstrating: Access to systems and their resources are removed or suspended the same day pers
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Access requirements for systems and their resources are documented in their system security plan.
- Evidence demonstrating: Access requirements for systems and their resources are documented in their syst
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.
- Evidence demonstrating: Personnel undergo appropriate employment screening and, where necessary, hold an
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel receive any necessary briefings before being granted access to systems and their resources.
- Evidence demonstrating: Personnel receive any necessary briefings before being granted access to systems
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
When personnel are granted temporary access to systems and their resources, effective controls are put in place to restrict their access to only data required for them to undertake their duties.
- Evidence demonstrating: When personnel are granted temporary access to systems and their resources, effe
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Temporary access is not granted to systems that process, store or communicate caveated or sensitive compartmented information.
- Evidence demonstrating: Temporary access is not granted to systems that process, store or communicate ca
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
- Evidence demonstrating: Privileged users are assigned a dedicated privileged user account to be used sol
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Foreign nationals, including seconded foreign nationals, do not have privileged access to systems that process, store or communicate AUSTEO or REL data.
- Evidence demonstrating: Foreign nationals, including seconded foreign nationals, do not have privileged
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.
- Evidence demonstrating: Foreign nationals, excluding seconded foreign nationals, do not have privileged
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel are advised of what suspicious contact via online services is and how to report it.
- Evidence demonstrating: Personnel are advised of what suspicious contact via online services is and how
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel are advised to not post work information to unauthorised online services and to report cases where such information is posted.
- Evidence demonstrating: Personnel are advised to not post work information to unauthorised online servic
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel are advised of security risks associated with posting personal information to online services and are encouraged to use any available privacy settings to restrict who can view such information.
- Evidence demonstrating: Personnel are advised of security risks associated with posting personal informa
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel are advised not to send or receive files via unauthorised online services.
- Evidence demonstrating: Personnel are advised not to send or receive files via unauthorised online servi
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
AUSTEO and AGAO data can only be accessed from systems under the sole control of the Australian Government that are located within facilities authorised by the Australian Government.
- Evidence demonstrating: AUSTEO and AGAO data can only be accessed from systems under the sole control of
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel are advised to maintain separate work and personal user accounts for online services.
- Evidence demonstrating: Personnel are advised to maintain separate work and personal user accounts for o
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
- Evidence demonstrating: Privileged user accounts (excluding those explicitly authorised to access online
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Unique privileged user accounts are used for administering individual server applications.
- Evidence demonstrating: Unique privileged user accounts are used for administering individual server app
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Unprivileged access to systems and their resources are disabled after 45 days of inactivity.
- Evidence demonstrating: Unprivileged access to systems and their resources are disabled after 45 days of
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Requests for privileged access to systems and their resources are validated when first requested.
- Evidence demonstrating: Requests for privileged access to systems and their resources are validated when
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
- Evidence demonstrating: Privileged access to systems and their resources is limited to only what is requ
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged access events are centrally logged.
- Evidence demonstrating: Privileged access events are centrally logged.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Tailored privileged user training is undertaken annually by all privileged users.
- Evidence demonstrating: Tailored privileged user training is undertaken annually by all privileged users
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Use of unprivileged access is centrally logged.
- Evidence demonstrating: Use of unprivileged access is centrally logged.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel who are contractors are identified as such.
- Evidence demonstrating: Personnel who are contractors are identified as such.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Access to systems and their resources are removed or suspended as soon as practicable when personnel are detected undertaking malicious activities.
- Evidence demonstrating: Access to systems and their resources are removed or suspended as soon as practi
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.
- Evidence demonstrating: A method of emergency access to systems and their resources is documented and te
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Break glass accounts are only used when normal authentication processes cannot be used.
- Evidence demonstrating: Break glass accounts are only used when normal authentication processes cannot b
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Break glass accounts are only used for specific authorised activities.
- Evidence demonstrating: Break glass accounts are only used for specific authorised activities.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Use of break glass accounts is centrally logged.
- Evidence demonstrating: Use of break glass accounts is centrally logged.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Break glass account credentials are changed by the account custodian after they are accessed by any other party.
- Evidence demonstrating: Break glass account credentials are changed by the account custodian after they
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Break glass accounts are tested after credentials are changed.
- Evidence demonstrating: Break glass accounts are tested after credentials are changed.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged access to systems and their resources are disabled after 12 months unless revalidated.
- Evidence demonstrating: Privileged access to systems and their resources are disabled after 12 months un
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged access to systems and their resources are disabled after 45 days of inactivity.
- Evidence demonstrating: Privileged access to systems and their resources are disabled after 45 days of i
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Just-in-time administration is used for the administration of systems and their resources.
- Evidence demonstrating: Just-in-time administration is used for the administration of systems and their
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged user account and security group management events are centrally logged.
- Evidence demonstrating: Privileged user account and security group management events are centrally logge
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel dealing with banking details and payment requests are advised of what business email compromise is, how to manage such situations and how to report it.
- Evidence demonstrating: Personnel dealing with banking details and payment requests are advised of what
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
- Evidence demonstrating: Unprivileged access to systems and their resources is limited to only what is re
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A system usage policy is developed, implemented and maintained.
- Evidence demonstrating: A system usage policy is developed, implemented and maintained.
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel agree to abide by system usage policies before being granted access to systems and their resources.
- Evidence demonstrating: Personnel agree to abide by system usage policies before being granted access to
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
- Evidence demonstrating: Privileged user accounts explicitly authorised to access online services are str
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A cyber security awareness training register is developed, implemented and maintained.
- Evidence demonstrating: A cyber security awareness training register is developed, implemented and maint
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.
- Evidence demonstrating: Personnel dealing with user account details are advised of what social engineeri
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
A general-purpose artificial intelligence usage policy is developed, implemented and maintained.
- Evidence demonstrating: A general-purpose artificial intelligence usage policy is developed, implemented
- Cyber security awareness training records
- Access provisioning/deprovisioning records
- Employment screening / clearance records
- No awareness training
- Access not removed on termination
- No screening for privileged access
Guidelines for physical security
IT equipment and media are secured when not in use.
- Evidence demonstrating: IT equipment and media are secured when not in use.
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.
- Evidence demonstrating: Unauthorised people are prevented from observing systems, in particular workstat
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.
- Evidence demonstrating: Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.
- Evidence demonstrating: Classified systems are secured in facilities that meet the requirements for a se
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Server rooms, communications rooms and security containers are not left in unsecured states.
- Evidence demonstrating: Server rooms, communications rooms and security containers are not left in unsec
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Security measures are used to detect and respond to unauthorised RF devices in SECRET and TOP SECRET areas.
- Evidence demonstrating: Security measures are used to detect and respond to unauthorised RF devices in S
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.
- Evidence demonstrating: Classified servers, network devices and cryptographic equipment are secured in s
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.
- Evidence demonstrating: Keys or equivalent access mechanisms to server rooms, communications rooms and s
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.
- Evidence demonstrating: Physical security is implemented to protect network devices in public areas from
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.
- Evidence demonstrating: Classified servers, network devices and cryptographic equipment are secured in s
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: An authorised RF and IR device register for SECRET and TOP SECRET areas is devel
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Non-classified systems are secured in suitably secure facilities.
- Evidence demonstrating: Non-classified systems are secured in suitably secure facilities.
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
- Evidence demonstrating: Non-classified servers, network devices and cryptographic equipment are secured
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.
- Evidence demonstrating: Non-classified servers, network devices and cryptographic equipment are secured
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: An authorised medical device register for SECRET and TOP SECRET areas is develop
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Australian Register of Therapeutic Goods - have been prescribed by a legally qualified medical practitioner - have been commercially purchased within Australia - do not have inbuilt cellular connectivity - are capable of operating independently of mobile devices - where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas.
- Evidence demonstrating: Medical devices that are authorised to be brought into SECRET and TOP SECRET are
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
- Evidence demonstrating: Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
An authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: An authorised photographic and video recording device register for SECRET and TO
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Unauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas.
- Evidence demonstrating: Unauthorised photographic and video recording devices are not brought into SECRE
- Facility/server room access controls
- Security container records
- Physical access logs
- Unsecured server/communications rooms
- Physical access not restricted
Guidelines for procurement and outsourcing
Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and reviewed on a regular and ongoing basis to ensure they remain fit for purpose.
- Evidence demonstrating: Security requirements associated with the confidentiality, integrity and availab
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.
- Evidence demonstrating: The requirement for service providers to report cyber security incidents to a de
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
An organisation's systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.
- Evidence demonstrating: An organisation's systems are not accessed or administered by a service provider
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.
- Evidence demonstrating: Service providers, including any subcontractors, provide an appropriate level of
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Types of data and its ownership is documented in contractual arrangements with service providers.
- Evidence demonstrating: Types of data and its ownership is documented in contractual arrangements with s
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services in order to assess the impact to a system's security risk profile.
- Evidence demonstrating: A supply chain risk assessment is performed for suppliers of operating systems,
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud services.
- Evidence demonstrating: Only community or private clouds are used for outsourced SECRET and TOP SECRET c
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Suppliers identified as high risk by a cyber supply chain risk assessment are not used.
- Evidence demonstrating: Suppliers identified as high risk by a cyber supply chain risk assessment are no
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.
- Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A shared responsibility model is created, documented and shared between suppliers and their customers in order to articulate the security responsibilities of each party.
- Evidence demonstrating: A shared responsibility model is created, documented and shared between supplier
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The right to verify compliance with security requirements is documented in contractual arrangements with service providers.
- Evidence demonstrating: The right to verify compliance with security requirements is documented in contr
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.
- Evidence demonstrating: The regions or availability zones where data will be processed, stored and commu
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Access to all logs relating to an organisation's data and services is documented in contractual arrangements with service providers.
- Evidence demonstrating: Access to all logs relating to an organisation's data and services is documented
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The storage of data in a portable manner that allows for backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.
- Evidence demonstrating: The storage of data in a portable manner that allows for backups, service migrat
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.
- Evidence demonstrating: A minimum notification period of one month for the cessation of any services by
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
If an organisation's systems are accessed or administered by a service provider in an unauthorised manner, the organisation is immediately notified.
- Evidence demonstrating: If an organisation's systems are accessed or administered by a service provider
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.
- Evidence demonstrating: Suppliers of operating systems, applications, IT equipment, OT equipment and ser
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.
- Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
An outsourced cloud service register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: An outsourced cloud service register is developed, implemented, maintained and v
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
An outsourced cloud service register contains the following for each outsourced cloud service: - cloud service provider's name - cloud service's name - purpose for using the cloud service - sensitivity or classification of data involved - due date for the next security assessment of the cloud service - contractual arrangements for the cloud service - point of contact for users of the cloud service - 24/7 contact details for the cloud service provider.
- Evidence demonstrating: An outsourced cloud service register contains the following for each outsourced
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A managed service register is developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: A managed service register is developed, implemented, maintained and verified on
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A managed service register contains the following for each managed service: - managed service provider's name - managed service's name - purpose for using the managed service - sensitivity or classification of data involved - due date for the next security assessment of the managed service - contractual arrangements for the managed service - point of contact for users of the managed service - 24/7 contact details for the managed service provider.
- Evidence demonstrating: A managed service register contains the following for each managed service: - ma
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The right to verify compliance with security requirements documented in contractual arrangements with service providers is exercised on a regular and ongoing basis.
- Evidence demonstrating: The right to verify compliance with security requirements documented in contract
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A supplier relationship management policy is developed, implemented and maintained.
- Evidence demonstrating: A supplier relationship management policy is developed, implemented and maintain
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
An approved supplier list is developed, implemented and maintained.
- Evidence demonstrating: An approved supplier list is developed, implemented and maintained.
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.
- Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are sou
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.
- Evidence demonstrating: Multiple potential suppliers are identified for sourcing critical operating syst
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.
- Evidence demonstrating: Sufficient spares of critical IT equipment and OT equipment are sourced and kept
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.
- Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are del
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.
- Evidence demonstrating: The integrity of operating systems, applications, IT equipment, OT equipment and
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.
- Evidence demonstrating: The authenticity of operating systems, applications, IT equipment, OT equipment
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECT
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.
- Evidence demonstrating: A minimum notification period of one month by service providers for significant
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.
- Evidence demonstrating: Break clauses associated with failure to meet security requirements are document
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.
- Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Managed service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: Managed service providers and their TOP SECRET managed services, including sensi
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Outsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.
- Evidence demonstrating: Outsourced cloud service providers and their TOP SECRET cloud services, includin
- Supplier/cyber supply chain risk assessments
- Contracts with security clauses
- Cloud/managed service assessments (e.g. IRAP)
- No supplier security assessment
- Missing contractual security requirements
Guidelines for software development
Development, testing, staging and production environments are segregated.
- Evidence demonstrating: Development, testing, staging and production environments are segregated.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Secure by Design principles and practices are followed throughout the software development life cycle.
- Evidence demonstrating: Secure by Design principles and practices are followed throughout the software d
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to its initial release, any subsequent releases and periodically in order to attempt to identify any previously unidentified vulnerabilities.
- Evidence demonstrating: Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The OWASP Application Security Verification Standard is used in the development of web applications.
- Evidence demonstrating: The OWASP Application Security Verification Standard is used in the development
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Threat modelling is used in support of the software development life cycle.
- Evidence demonstrating: Threat modelling is used in support of the software development life cycle.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Robust web application frameworks are used in the development of web applications.
- Evidence demonstrating: Robust web application frameworks are used in the development of web application
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Validation and sanitisation are performed on all input received over the internet by software.
- Evidence demonstrating: Validation and sanitisation are performed on all input received over the interne
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Output encoding is performed on all output produced by web applications.
- Evidence demonstrating: Output encoding is performed on all output produced by web applications.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All queries to databases from software are filtered for legitimate content and correct syntax.
- Evidence demonstrating: All queries to databases from software are filtered for legitimate content and c
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.
- Evidence demonstrating: Parameterised queries or stored procedures, instead of dynamically generated que
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software is designed or configured to provide as little error information as possible about the structure of databases.
- Evidence demonstrating: Software is designed or configured to provide as little error information as pos
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Development and modification of software only takes place in development environments.
- Evidence demonstrating: Development and modification of software only takes place in development environ
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
- Evidence demonstrating: Data from production environments is not used in non-production environments unl
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Unauthorised access to the authoritative source for software is prevented.
- Evidence demonstrating: Unauthorised access to the authoritative source for software is prevented.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.
- Evidence demonstrating: Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.
- Evidence demonstrating: All queries to databases from software that are initiated by users, and any resu
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All web application content is offered exclusively using HTTPS.
- Evidence demonstrating: All web application content is offered exclusively using HTTPS.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.
- Evidence demonstrating: A vulnerability disclosure program is implemented to assist with the secure deve
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A 'security.txt' file is hosted for each of an organisation's internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation's products and services.
- Evidence demonstrating: A 'security.txt' file is hosted for each of an organisation's internet-facing we
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A software bill of materials is produced and made available to consumers of software.
- Evidence demonstrating: A software bill of materials is produced and made available to consumers of soft
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Vulnerabilities identified in software are resolved in a timely manner.
- Evidence demonstrating: Vulnerabilities identified in software are resolved in a timely manner.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A vulnerability disclosure policy is developed, implemented and maintained.
- Evidence demonstrating: A vulnerability disclosure policy is developed, implemented and maintained.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.
- Evidence demonstrating: Vulnerability disclosure processes, and supporting vulnerability disclosure proc
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
SecDevOps practices are used for software development.
- Evidence demonstrating: SecDevOps practices are used for software development.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.
- Evidence demonstrating: Files containing executable content are digitally signed by a certificate with a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.
- Evidence demonstrating: Installers, patches and updates are digitally signed or provided with cryptograp
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.
- Evidence demonstrating: Secure configuration guidance, in the form of a hardening guide or loosening gui
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Unauthorised modification of the authoritative source for software is prevented.
- Evidence demonstrating: Unauthorised modification of the authoritative source for software is prevented.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.
- Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.
- Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The OWASP Top 10 Proactive Controls are used in the development of web applications.
- Evidence demonstrating: The OWASP Top 10 Proactive Controls are used in the development of web applicati
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The OWASP Top 10 are mitigated in the development of web applications.
- Evidence demonstrating: The OWASP Top 10 are mitigated in the development of web applications.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The OWASP API Security Top 10 are mitigated in the development of web APIs.
- Evidence demonstrating: The OWASP API Security Top 10 are mitigated in the development of web APIs.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.
- Evidence demonstrating: Vulnerabilities identified in software are publicly disclosed in a responsible a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.
- Evidence demonstrating: In resolving vulnerabilities, root cause analysis is performed and, to the great
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.
- Evidence demonstrating: Network API calls that facilitate modification of data, or access to data not au
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Security-relevant usage, error messages and crashes for software are centrally logged.
- Evidence demonstrating: Security-relevant usage, error messages and crashes for software are centrally l
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.
- Evidence demonstrating: The OWASP Mobile Application Security Verification Standard is used in the devel
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Generative artificial intelligence applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.
- Evidence demonstrating: Generative artificial intelligence applications evaluate user prompts to detect
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.
- Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.
- Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.
- Evidence demonstrating: Network API calls that facilitate modification of data, or access to data not au
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Validation and sanitisation are performed on all input received over a local network by software.
- Evidence demonstrating: Validation and sanitisation are performed on all input received over a local net
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
An authoritative source for software is established and maintained.
- Evidence demonstrating: An authoritative source for software is established and maintained.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The authoritative source for software is used for all software development activities.
- Evidence demonstrating: The authoritative source for software is used for all software development activ
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.
- Evidence demonstrating: An issue tracking solution is used to link software development tasks to securit
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All software artefacts are scanned for malicious content before being imported into the authoritative source for software.
- Evidence demonstrating: All software artefacts are scanned for malicious content before being imported i
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.
- Evidence demonstrating: All software artefacts are verified by a digital signature, or a secure hash pro
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.
- Evidence demonstrating: All software artefacts are tested to detect known weaknesses using static applic
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.
- Evidence demonstrating: The authoritative source for software restricts the use and import of third-part
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Scanning is used during commits to identify plain text or encoded secrets and keys, which are then blocked from being stored in the authoritative source for software.
- Evidence demonstrating: Scanning is used during commits to identify plain text or encoded secrets and ke
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.
- Evidence demonstrating: Compilers, interpreters and build tools (including pipelines) that provide secur
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.
- Evidence demonstrating: The build solution ensures that all automated testing is completed without warni
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All software security requirements are documented, stored securely and maintained throughout the software development life cycle.
- Evidence demonstrating: All software security requirements are documented, stored securely and maintaine
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Security design decisions are documented and reviewed throughout the software development cycle.
- Evidence demonstrating: Security design decisions are documented and reviewed throughout the software de
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Security roles, responsibilities and knowledge requirements required to support the software development life cycle are identified and documented.
- Evidence demonstrating: Security roles, responsibilities and knowledge requirements required to support
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Security responsibilities for software developers are identified and documented.
- Evidence demonstrating: Security responsibilities for software developers are identified and documented.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training on secure software development and programming practices.
- Evidence demonstrating: Software developers that lack sufficient cyber security knowledge and skills req
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A software developer cyber security knowledge and skills register is implemented and maintained.
- Evidence demonstrating: A software developer cyber security knowledge and skills register is implemented
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.
- Evidence demonstrating: The software threat model is reviewed throughout the software development life c
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Secure programming practices for the chosen programming language are used for software development.
- Evidence demonstrating: Secure programming practices for the chosen programming language are used for so
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.
- Evidence demonstrating: Memory-safe programming languages, or less preferably memory-safe programming pr
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.
- Evidence demonstrating: Secure by Default principles and practices are followed throughout the software
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software is architected and structured to support readability and maintainability.
- Evidence demonstrating: Software is architected and structured to support readability and maintainabilit
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.
- Evidence demonstrating: Software has no default credentials; however, if credentials are required, they
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Application backwards compatibility does not compromise any security measures or features.
- Evidence demonstrating: Application backwards compatibility does not compromise any security measures or
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.
- Evidence demonstrating: Where software allows user impersonation, sensitive data is not logged and appro
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.
- Evidence demonstrating: Where software allows an authentication factor to be reset, the user is notified
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.
- Evidence demonstrating: Where software supports multiple user roles, non-administrative users are preven
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
When user permissions or credentials are changed, software forces all impacted users to re-authenticate.
- Evidence demonstrating: When user permissions or credentials are changed, software forces all impacted u
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.
- Evidence demonstrating: When digital signatures are processed by software, they are validated against a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software generates sufficient event logs to support the detection of cyber security events.
- Evidence demonstrating: Software generates sufficient event logs to support the detection of cyber secur
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Event logs produced by software ensure that any sensitive data is protected.
- Evidence demonstrating: Event logs produced by software ensure that any sensitive data is protected.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
End of life procedures for software, covering how to remove the software and how to archive or destroy any user accounts and data, are produced and made available to consumers.
- Evidence demonstrating: End of life procedures for software, covering how to remove the software and how
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.
- Evidence demonstrating: If a software bill of materials is available for imported third-party software c
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.
- Evidence demonstrating: If a software build provenance is available for imported third-party software co
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A software build provenance is produced and made available to consumers of software.
- Evidence demonstrating: A software build provenance is produced and made available to consumers of softw
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
All input validation rules are documented, matched in code and tested with both positive and negative unit testing or integration testing.
- Evidence demonstrating: All input validation rules are documented, matched in code and tested with both
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Data sources and serialised data inputs are validated before being deserialised.
- Evidence demonstrating: Data sources and serialised data inputs are validated before being deserialised.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.
- Evidence demonstrating: File uploads or input are restricted to specific file types, with malicious cont
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Code reviews are utilised to ensure software meets Secure by Design principles and practices as well as secure programming practices.
- Evidence demonstrating: Code reviews are utilised to ensure software meets Secure by Design principles a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Software developer-supported security-focused peer reviews are conducted on all critical and security-focused software components.
- Evidence demonstrating: Software developer-supported security-focused peer reviews are conducted on all
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Unit testing and integration testing, covering both positive and negative use cases, are used to ensure code quality and security.
- Evidence demonstrating: Unit testing and integration testing, covering both positive and negative use ca
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.
- Evidence demonstrating: If supported, web application session cookies set the HttpOnly flag, Secure flag
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Web application session cookies contain only digitally signed opaque bearer tokens.
- Evidence demonstrating: Web application session cookies contain only digitally signed opaque bearer toke
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.
- Evidence demonstrating: Web application session cookies using opaque bearer tokens that are not digitall
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Web application sessions are centrally managed server side.
- Evidence demonstrating: Web application sessions are centrally managed server side.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Web applications that support Single Sign On equally support Single Logout.
- Evidence demonstrating: Web applications that support Single Sign On equally support Single Logout.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Artificial intelligence models are stored in a non-executable file format that does not allow arbitrary code execution.
- Evidence demonstrating: Artificial intelligence models are stored in a non-executable file format that d
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.
- Evidence demonstrating: If a cryptographic bill of materials is available for imported third-party softw
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
A cryptographic bill of materials is produced and made available to consumers of software.
- Evidence demonstrating: A cryptographic bill of materials is produced and made available to consumers of
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Artificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics, system architectures, use cases and security risks.
- Evidence demonstrating: Artificial intelligence-specific documentation, including model and system cards
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented.
- Evidence demonstrating: The exposure of exact artificial intelligence model confidence scores in API res
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The source and integrity of artificial intelligence models, structures and weights are verified.
- Evidence demonstrating: The source and integrity of artificial intelligence models, structures and weigh
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
The source and integrity of training data for artificial intelligence models is verified.
- Evidence demonstrating: The source and integrity of training data for artificial intelligence models is
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models.
- Evidence demonstrating: Data validation and verification techniques are used to ensure the reliability a
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Artificial intelligence model performance metrics are monitored and anomalies are investigated.
- Evidence demonstrating: Artificial intelligence model performance metrics are monitored and anomalies ar
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Rate limiting is applied to inference queries for artificial intelligence models.
- Evidence demonstrating: Rate limiting is applied to inference queries for artificial intelligence models
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Resource limits are enforced for artificial intelligence models.
- Evidence demonstrating: Resource limits are enforced for artificial intelligence models.
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Access control policies are implemented to enforce fine-grained permissions for artificial intelligence applications.
- Evidence demonstrating: Access control policies are implemented to enforce fine-grained permissions for
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.
- Evidence demonstrating: Role-based access controls are implemented for artificial intelligence applicati
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Content filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output.
- Evidence demonstrating: Content filtering is implemented by artificial intelligence applications to dete
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.
- Evidence demonstrating: Existing software artefacts in the authoritative source for software are periodi
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Organisational data generated, collected or processed by artificial intelligence applications is not used for training, fine-tuning or improving artificial intelligence models unless informed and explicit consent has been obtained from data owners in advance.
- Evidence demonstrating: Organisational data generated, collected or processed by artificial intelligence
- Secure SDLC procedures
- Threat modelling records
- Security testing results
- Environment segregation evidence
- No security testing
- Production data used in test
- Dev/test/prod not segregated
Guidelines for system hardening
Automatic execution features for removable media are disabled.
- Evidence demonstrating: Automatic execution features for removable media are disabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
- Evidence demonstrating: If there is no business requirement for writing to removable media and devices,
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
External communication interfaces that allow DMA are disabled.
- Evidence demonstrating: External communication interfaces that allow DMA are disabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.
- Evidence demonstrating: Unneeded user accounts, components, services and functionality of operating syst
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged users do not have the ability to uninstall or disable approved applications.
- Evidence demonstrating: Unprivileged users do not have the ability to uninstall or disable approved appl
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
- Evidence demonstrating: Default user accounts or credentials for operating systems, including for any pr
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Systems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.
- Evidence demonstrating: Systems have a logon banner that reminds users of their security responsibilitie
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.
- Evidence demonstrating: When systems cannot support multi-factor authentication, single-factor authentic
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.
- Evidence demonstrating: Physical credentials are kept separate from systems they are used to authenticat
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.
- Evidence demonstrating: Passwords used for single-factor authentication on non-classified, OFFICIAL: Sen
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 characters.
- Evidence demonstrating: Passwords used for single-factor authentication on TOP SECRET systems are a mini
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Services are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users - blocks access to all session content - requires users to re-authenticate using all authentication factors to unlock the session - denies users the ability to disable the session locking mechanism.
- Evidence demonstrating: Services are configured with a session lock that: - activates after a maximum of
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for Microsoft Windows operating systems are centrally logged.
- Evidence demonstrating: Security-relevant events for Microsoft Windows operating systems are centrally l
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is implemented on workstations.
- Evidence demonstrating: Application control is implemented on workstations.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
All users (with the exception of local administrator accounts and break glass accounts) cannot disable, bypass or be exempted from application control.
- Evidence demonstrating: All users (with the exception of local administrator accounts and break glass ac
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
On a daily basis, outside of business hours and after an appropriate period of inactivity, user sessions are terminated and workstations are restarted.
- Evidence demonstrating: On a daily basis, outside of business hours and after an appropriate period of i
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.
- Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.
- Evidence demonstrating: Application control is implemented using cryptographic hash rules, publisher cer
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate unprivileged users of systems.
- Evidence demonstrating: Multi-factor authentication is used to authenticate unprivileged users of system
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
A HIPS or EDR solution is implemented on critical servers and high-value servers.
- Evidence demonstrating: A HIPS or EDR solution is implemented on critical servers and high-value servers
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
LAN Manager and NT LAN Manager authentication methods are disabled.
- Evidence demonstrating: LAN Manager and NT LAN Manager authentication methods are disabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate privileged users of systems.
- Evidence demonstrating: Multi-factor authentication is used to authenticate privileged users of systems.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials set for user accounts are randomly generated.
- Evidence demonstrating: Credentials set for user accounts are randomly generated.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clients, PDF applications and security products are restricted to an organisation-approved set.
- Evidence demonstrating: Add-ons, extensions and plug-ins for office productivity suites, web browsers, e
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
All temporary installation files and logs created during server application installation processes are removed after server applications have been installed.
- Evidence demonstrating: All temporary installation files and logs created during server application inst
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: Server applications are hardened using ASD and vendor hardening guidance, with t
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unneeded user accounts, components, services and functionality of server applications are disabled or removed.
- Evidence demonstrating: Unneeded user accounts, components, services and functionality of server applica
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.
- Evidence demonstrating: Server applications are configured to run as a separate user account with the mi
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The user accounts under which server applications run have limited access to their underlying server's file system.
- Evidence demonstrating: The user accounts under which server applications run have limited access to the
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
- Evidence demonstrating: Default user accounts or credentials for server applications, including for any
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
A HIPS or EDR solution is implemented on workstations.
- Evidence demonstrating: A HIPS or EDR solution is implemented on workstations.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When implementing application control using path rules, only approved users can modify approved files and write to approved folders.
- Evidence demonstrating: When implementing application control using path rules, only approved users can
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
- Evidence demonstrating: Multi-factor authentication uses either: something users have and something user
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.
- Evidence demonstrating: Credentials stored on systems are protected by a password manager; a hardware se
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts, except for break glass accounts, are locked out after a maximum of five failed logon attempts.
- Evidence demonstrating: User accounts, except for break glass accounts, are locked out after a maximum o
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
SOEs are used for workstations and servers.
- Evidence demonstrating: SOEs are used for workstations and servers.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The latest release, or the previous release, of operating systems are used.
- Evidence demonstrating: The latest release, or the previous release, of operating systems are used.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Where supported, 64-bit versions of operating systems are used.
- Evidence demonstrating: Where supported, 64-bit versions of operating systems are used.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: Operating systems are hardened using ASD and vendor hardening guidance, with the
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: Web browsers are hardened using ASD and vendor hardening guidance, with the most
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.
- Evidence demonstrating: A software firewall is implemented on workstations and servers to restrict inbou
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
An antivirus application is implemented on workstations and servers with: - signature-based detection functionality enabled and set to a high level - heuristic-based detection functionality enabled and set to a high level - reputation rating functionality enabled - ransomware protection functionality enabled - detection signatures configured to update on at least a daily basis - regular scanning configured for all fixed disks and removable media.
- Evidence demonstrating: An antivirus application is implemented on workstations and servers with: - sign
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
- Evidence demonstrating: If there is no business requirement for reading from removable media and devices
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware for SECRET or TOP SECRET computing environments, the physical server and all computing environments are of the same classification and belong to the same security domain.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The latest release of office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are used.
- Evidence demonstrating: The latest release of office productivity suites, web browsers and their extensi
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unneeded components, services and functionality of office productivity suites, web browsers, email clients, PDF applications and security products are disabled or removed.
- Evidence demonstrating: Unneeded components, services and functionality of office productivity suites, w
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When implementing application control using publisher certificate rules, publisher names and product names are used.
- Evidence demonstrating: When implementing application control using publisher certificate rules, publish
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The latest release of internet-facing server applications are used.
- Evidence demonstrating: The latest release of internet-facing server applications are used.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Web browsers do not process web advertisements from the internet.
- Evidence demonstrating: Web browsers do not process web advertisements from the internet.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Web browsers do not process Java from the internet.
- Evidence demonstrating: Web browsers do not process Java from the internet.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.
- Evidence demonstrating: Only privileged users responsible for checking that Microsoft Office macros are
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros in files originating from the internet are blocked.
- Evidence demonstrating: Microsoft Office macros in files originating from the internet are blocked.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macro security settings cannot be changed by users.
- Evidence demonstrating: Microsoft Office macro security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is implemented on internet-facing servers.
- Evidence demonstrating: Application control is implemented on internet-facing servers.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged users are prevented from running script execution engines, including: - Windows Script Host (cscript.exe and wscript.exe) - PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe) - Command Prompt (cmd.exe) - Windows Management Instrumentation (wmic.exe) - Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).
- Evidence demonstrating: Unprivileged users are prevented from running script execution engines, includin
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Operating system exploit protection functionality is enabled.
- Evidence demonstrating: Operating system exploit protection functionality is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.
- Evidence demonstrating: Multi-factor authentication is used to authenticate users to their organisation'
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate users of data repositories.
- Evidence demonstrating: Multi-factor authentication is used to authenticate users of data repositories.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.
- Evidence demonstrating: Microsoft Office is configured to prevent activation of Object Linking and Embed
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft's recommended application blocklist is implemented.
- Evidence demonstrating: Microsoft's recommended application blocklist is implemented.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Users are authenticated before they are granted access to a system and its resources.
- Evidence demonstrating: Users are authenticated before they are granted access to a system and its resou
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.
- Evidence demonstrating: Passwords used for single-factor authentication on SECRET systems are a minimum
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords using a sequence of words for single-factor authentication are not constructed using: - a list of categorised words - a real sentence in a natural language - song lyrics, movie or television show quotes, literature, or any other publicly available material - less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.
- Evidence demonstrating: Passwords using a sequence of words for single-factor authentication are not con
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
- Evidence demonstrating: Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sens
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.
- Evidence demonstrating: Passwords used for multi-factor authentication on SECRET systems are a minimum o
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.
- Evidence demonstrating: Passwords used for multi-factor authentication on TOP SECRET systems are a minim
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control rulesets are validated on an annual or more frequent basis.
- Evidence demonstrating: Application control rulesets are validated on an annual or more frequent basis.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.
- Evidence demonstrating: Unprivileged users are prevented from bypassing, disabling or modifying security
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Web browser security settings cannot be changed by users.
- Evidence demonstrating: Web browser security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
SOEs are reviewed and updated at least annually.
- Evidence demonstrating: SOEs are reviewed and updated at least annually.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for user accounts are changed if: - they are compromised - they are suspected of being compromised - they are discovered stored on networks in the clear - they are discovered being transferred across networks in the clear - membership of a shared user account changes.
- Evidence demonstrating: Credentials for user accounts are changed if: - they are compromised - they are
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged users do not have the ability to install unapproved applications.
- Evidence demonstrating: Unprivileged users do not have the ability to install unapproved applications.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Users provide sufficient evidence to verify their identity when requesting new credentials.
- Evidence demonstrating: Users provide sufficient evidence to verify their identity when requesting new c
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials are provided to users via a secure communications channel or, if not possible, split into two parts with one part provided to users and the other part provided to supervisors.
- Evidence demonstrating: Credentials are provided to users via a secure communications channel or, if not
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials provided to users are changed on first use.
- Evidence demonstrating: Credentials provided to users are changed on first use.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials are not reused by users across different systems.
- Evidence demonstrating: Credentials are not reused by users across different systems.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials are obscured as they are entered into systems.
- Evidence demonstrating: Credentials are obscured as they are entered into systems.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft's attack surface reduction rules are implemented.
- Evidence demonstrating: Microsoft's attack surface reduction rules are implemented.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Authentication methods susceptible to replay attacks are disabled.
- Evidence demonstrating: Authentication methods susceptible to replay attacks are disabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, the underlying operating system is hardened.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
SOEs provided by third parties are scanned for malicious code and configurations.
- Evidence demonstrating: SOEs provided by third parties are scanned for malicious code and configurations
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Service accounts are created as group Managed Service Accounts.
- Evidence demonstrating: Service accounts are created as group Managed Service Accounts.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Privileged user accounts are members of the Protected Users security group.
- Evidence demonstrating: Privileged user accounts are members of the Protected Users security group.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Windows PowerShell 2.0 is disabled or removed.
- Evidence demonstrating: Windows PowerShell 2.0 is disabled or removed.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PowerShell is configured to use Constrained Language Mode.
- Evidence demonstrating: PowerShell is configured to use Constrained Language Mode.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PowerShell module logging, script block logging and transcription events are centrally logged.
- Evidence demonstrating: PowerShell module logging, script block logging and transcription events are cen
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PowerShell script block logs are protected by Protected Event Logging functionality.
- Evidence demonstrating: PowerShell script block logs are protected by Protected Event Logging functional
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Internet Explorer 11 is disabled or removed.
- Evidence demonstrating: Internet Explorer 11 is disabled or removed.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
- Evidence demonstrating: .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is implemented on non-internet-facing servers.
- Evidence demonstrating: Application control is implemented on non-internet-facing servers.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.
- Evidence demonstrating: Application control restricts the execution of executables, libraries, scripts,
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control restricts the execution of drivers to an organisation-approved set.
- Evidence demonstrating: Application control restricts the execution of drivers to an organisation-approv
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft's vulnerable driver blocklist is implemented.
- Evidence demonstrating: Microsoft's vulnerable driver blocklist is implemented.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Allowed and blocked application control events are centrally logged.
- Evidence demonstrating: Allowed and blocked application control events are centrally logged.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office is blocked from creating child processes.
- Evidence demonstrating: Microsoft Office is blocked from creating child processes.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office is blocked from creating executable content.
- Evidence demonstrating: Microsoft Office is blocked from creating executable content.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office is blocked from injecting code into other processes.
- Evidence demonstrating: Microsoft Office is blocked from injecting code into other processes.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PDF applications are blocked from creating child processes.
- Evidence demonstrating: PDF applications are blocked from creating child processes.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
- Evidence demonstrating: Microsoft Office macros are disabled for users that do not have a demonstrated b
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macro antivirus scanning is enabled.
- Evidence demonstrating: Microsoft Office macro antivirus scanning is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros are blocked from making Win32 API calls.
- Evidence demonstrating: Microsoft Office macros are blocked from making Win32 API calls.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.
- Evidence demonstrating: Only Microsoft Office macros running from within a sandboxed environment, a Trus
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.
- Evidence demonstrating: Microsoft Office macros digitally signed by an untrusted publisher cannot be ena
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office's list of trusted publishers is validated on an annual or more frequent basis.
- Evidence demonstrating: Microsoft Office's list of trusted publishers is validated on an annual or more
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.
- Evidence demonstrating: Multi-factor authentication is used to authenticate users to third-party online
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.
- Evidence demonstrating: Multi-factor authentication (where available) is used to authenticate users to t
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
- Evidence demonstrating: Multi-factor authentication is used to authenticate customers to online customer
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
- Evidence demonstrating: Multi-factor authentication used for authenticating users of systems is phishing
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Successful and unsuccessful multi-factor authentication events are centrally logged.
- Evidence demonstrating: Successful and unsuccessful multi-factor authentication events are centrally log
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
- Evidence demonstrating: Credentials for break glass accounts, local administrator accounts and service a
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credential Guard functionality is enabled.
- Evidence demonstrating: Credential Guard functionality is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.
- Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.
- Evidence demonstrating: Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functional
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.
- Evidence demonstrating: When implementing application control using path rules, only approved users can
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Email client security settings cannot be changed by users.
- Evidence demonstrating: Email client security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Cached credentials are limited to one previous logon.
- Evidence demonstrating: Cached credentials are limited to one previous logon.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.
- Evidence demonstrating: Credentials for built-in Administrator accounts, break glass accounts, local adm
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
- Evidence demonstrating: Default user accounts or credentials for user applications, including for any pr
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Office productivity suite security settings cannot be changed by users.
- Evidence demonstrating: Office productivity suite security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PDF application security settings cannot be changed by users.
- Evidence demonstrating: PDF application security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security product security settings cannot be changed by users.
- Evidence demonstrating: Security product security settings cannot be changed by users.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.
- Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
- Evidence demonstrating: Microsoft AD DS domain controllers are administered using dedicated domain admin
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The Print Spooler service is disabled on Microsoft AD DS domain controllers.
- Evidence demonstrating: The Print Spooler service is disabled on Microsoft AD DS domain controllers.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords are not stored in Group Policy Preferences.
- Evidence demonstrating: Passwords are not stored in Group Policy Preferences.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.
- Evidence demonstrating: Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Only service accounts and computer accounts are configured with Service Principal Names (SPNs).
- Evidence demonstrating: Only service accounts and computer accounts are configured with Service Principa
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts are provisioned with the minimum privileges required.
- Evidence demonstrating: User accounts are provisioned with the minimum privileges required.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Duplicate SPNs do not exist within the domain.
- Evidence demonstrating: Duplicate SPNs do not exist within the domain.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Privileged user accounts are configured as sensitive and cannot be delegated.
- Evidence demonstrating: Privileged user accounts are configured as sensitive and cannot be delegated.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts require Kerberos pre-authentication.
- Evidence demonstrating: User accounts require Kerberos pre-authentication.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The UserPassword attribute for user accounts is not used.
- Evidence demonstrating: The UserPassword attribute for user accounts is not used.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Account properties accessible by unprivileged users are not used to store passwords.
- Evidence demonstrating: Account properties accessible by unprivileged users are not used to store passwo
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User account passwords do not use reversible encryption.
- Evidence demonstrating: User account passwords do not use reversible encryption.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged user accounts cannot add machines to the domain.
- Evidence demonstrating: Unprivileged user accounts cannot add machines to the domain.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Dedicated privileged service accounts are used to add machines to the domain.
- Evidence demonstrating: Dedicated privileged service accounts are used to add machines to the domain.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.
- Evidence demonstrating: User accounts with unconstrained delegation are reviewed at least annually, and
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.
- Evidence demonstrating: Computer accounts that are not Microsoft AD DS domain controllers are not truste
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When a user account is disabled, it is removed from all security group memberships.
- Evidence demonstrating: When a user account is disabled, it is removed from all security group membershi
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The Pre-Windows 2000 Compatible Access security group does not contain user accounts.
- Evidence demonstrating: The Pre-Windows 2000 Compatible Access security group does not contain user acco
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.
- Evidence demonstrating: Credentials for the Kerberos Key Distribution Center's service account (KRBTGT)
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When using a software-based isolation mechanism to share a physical server's hardware, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.
- Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: Office productivity suites are hardened using ASD and vendor hardening guidance,
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
- Evidence demonstrating: PDF applications are hardened using ASD and vendor hardening guidance, with the
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Local Security Authority protection functionality is enabled.
- Evidence demonstrating: Local Security Authority protection functionality is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.
- Evidence demonstrating: Application control is applied to user profiles and temporary folders used by op
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.
- Evidence demonstrating: Application control is applied to all locations other than user profiles and tem
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication used for authenticating users of online services is phishing-resistant.
- Evidence demonstrating: Multi-factor authentication used for authenticating users of online services is
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
- Evidence demonstrating: Multi-factor authentication used for authenticating customers of online customer
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
- Evidence demonstrating: Multi-factor authentication used for authenticating customers of online customer
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Networks are scanned at least monthly to identify any credentials that are being stored in the clear.
- Evidence demonstrating: Networks are scanned at least monthly to identify any credentials that are being
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Command line process creation events are centrally logged.
- Evidence demonstrating: Command line process creation events are centrally logged.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.
- Evidence demonstrating: Microsoft Office macros are checked to ensure they are free of malicious code be
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.
- Evidence demonstrating: Microsoft Office macros digitally signed by signatures other than V3 signatures
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.
- Evidence demonstrating: Multi-factor authentication is used to authenticate users to their organisation'
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.
- Evidence demonstrating: Multi-factor authentication is used to authenticate users to third-party online
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
- Evidence demonstrating: Multi-factor authentication used for authenticating users of data repositories i
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Successful and unsuccessful single-factor authentication events are centrally logged.
- Evidence demonstrating: Successful and unsuccessful single-factor authentication events are centrally lo
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Memory integrity functionality is enabled.
- Evidence demonstrating: Memory integrity functionality is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Remote Credential Guard functionality is enabled.
- Evidence demonstrating: Remote Credential Guard functionality is enabled.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Approved configurations for operating systems are developed, implemented and maintained.
- Evidence demonstrating: Approved configurations for operating systems are developed, implemented and mai
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Approved configurations for user applications are developed, implemented and maintained.
- Evidence demonstrating: Approved configurations for user applications are developed, implemented and mai
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Approved configurations for server applications are developed, implemented and maintained.
- Evidence demonstrating: Approved configurations for server applications are developed, implemented and m
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.
- Evidence demonstrating: When multi-factor authentication is used to authenticate users or customers to o
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories - that process, store or communicate their organisation's sensitive data or sensitive customer data - users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.
- Evidence demonstrating: When multi-factor authentication is used to authenticate users to online service
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.
- Evidence demonstrating: Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.
- Evidence demonstrating: Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Micros
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted, stored securely and only accessible to backup administrator accounts.
- Evidence demonstrating: Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Micro
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.
- Evidence demonstrating: Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS doma
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords are prevented from being stored in Group Policy Preferences.
- Evidence demonstrating: Passwords are prevented from being stored in Group Policy Preferences.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
SID Filtering is enabled for domain and forest trusts.
- Evidence demonstrating: SID Filtering is enabled for domain and forest trusts.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The number of service accounts configured with an SPN is minimised.
- Evidence demonstrating: The number of service accounts configured with an SPN is minimised.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Service accounts configured with an SPN do not have DCSync permissions.
- Evidence demonstrating: Service accounts configured with an SPN do not have DCSync permissions.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.
- Evidence demonstrating: User accounts with DCSync permissions are reviewed at least annually, and those
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Computer accounts are not configured for unconstrained delegation.
- Evidence demonstrating: Computer accounts are not configured for unconstrained delegation.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The sIDHistory attribute for user accounts is not used.
- Evidence demonstrating: The sIDHistory attribute for user accounts is not used.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
User accounts are checked at least weekly for the presence of the sIDHistory attribute.
- Evidence demonstrating: User accounts are checked at least weekly for the presence of the sIDHistory att
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.
- Evidence demonstrating: The Domain Computers security group does not have write or modify permissions to
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.
- Evidence demonstrating: The number of user accounts that are members of the Domain Admins, Enterprise Ad
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
- Evidence demonstrating: Service accounts are not members of the Domain Admins, Enterprise Admins or othe
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.
- Evidence demonstrating: Computer accounts are not members of the Domain Admins, Enterprise Admins or oth
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The Domain Computers security group is not a member of any privileged or highly-privileged security groups.
- Evidence demonstrating: The Domain Computers security group is not a member of any privileged or highly-
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Strong mapping between certificates and users is enforced.
- Evidence demonstrating: Strong mapping between certificates and users is enforced.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
- Evidence demonstrating: The EDITF ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA confi
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
- Evidence demonstrating: The CT FLAG ENROLLEE SUPPLIES SUBJECT flag is removed from certificate templates
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Unprivileged user accounts do not have write access to certificate templates.
- Evidence demonstrating: Unprivileged user accounts do not have write access to certificate templates.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Extended Key Usages that enable user authentication are removed.
- Evidence demonstrating: Extended Key Usages that enable user authentication are removed.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.
- Evidence demonstrating: CA Certificate Manager approval is required for certificate templates that allow
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.
- Evidence demonstrating: Microsoft AD FS servers are administered using a dedicated service account that
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.
- Evidence demonstrating: Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled followi
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Hard match takeover is disabled for Microsoft Entra Connect servers.
- Evidence demonstrating: Hard match takeover is disabled for Microsoft Entra Connect servers.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.
- Evidence demonstrating: Privileged user accounts are not synchronised between Microsoft AD DS and Micros
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.
- Evidence demonstrating: Credentials for the built-in Administrator account in each domain are long, uniq
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.
- Evidence demonstrating: Credentials for built-in Administrator accounts, break glass accounts, local adm
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.
- Evidence demonstrating: Credentials for computer accounts are changed if they are compromised, they are
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.
- Evidence demonstrating: Microsoft AD FS token-signing and encryption certificates are changed twice in q
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Private keys for Microsoft AD CS CA servers are protected by a hardware security module.
- Evidence demonstrating: Private keys for Microsoft AD CS CA servers are protected by a hardware security
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for Apple macOS operating systems are centrally logged.
- Evidence demonstrating: Security-relevant events for Apple macOS operating systems are centrally logged.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for Linux operating systems are centrally logged.
- Evidence demonstrating: Security-relevant events for Linux operating systems are centrally logged.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for server applications on internet-facing servers are centrally logged.
- Evidence demonstrating: Security-relevant events for server applications on internet-facing servers are
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security-relevant events for server applications on non-internet-facing servers are centrally logged.
- Evidence demonstrating: Security-relevant events for server applications on non-internet-facing servers
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Credential hint functionality is not used for systems.
- Evidence demonstrating: Credential hint functionality is not used for systems.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.
- Evidence demonstrating: Service accounts configured with an SPN use the Advanced Encryption Standard for
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.
- Evidence demonstrating: When phishing-resistant multi-factor authentication is used by user accounts, ot
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Systems are configured with a screen lock that: - activates after a maximum of 15 minutes of user inactivity, or when manually activated by users - conceals all content on the screen - ensures that the screen does not enter a power saving state before the screen lock is activated - requires users to re-authenticate using all authentication factors to unlock the system - denies users the ability to disable the screen locking mechanism.
- Evidence demonstrating: Systems are configured with a screen lock that: - activates after a maximum of 1
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Security questions are not used for authentication purposes.
- Evidence demonstrating: Security questions are not used for authentication purposes.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Email is not used for out-of-band authentication purposes.
- Evidence demonstrating: Email is not used for out-of-band authentication purposes.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.
- Evidence demonstrating: Passwords appearing in lists of commonly used passwords or lists of compromised
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Maximum length limits for passwords are not less than 64 characters.
- Evidence demonstrating: Maximum length limits for passwords are not less than 64 characters.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Password complexity requirements are not imposed for passwords.
- Evidence demonstrating: Password complexity requirements are not imposed for passwords.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
All ASCII printable characters are supported for passwords.
- Evidence demonstrating: All ASCII printable characters are supported for passwords.
- Hardening baselines (ASD/vendor guidance)
- Application control configuration
- Multi-factor authentication configuration
- Build/configuration evidence
- Default or unhardened configurations
- Application control not implemented
- MFA not enforced
Guidelines for system management
System administration processes, and supporting system administration procedures, are developed, implemented and maintained.
- Evidence demonstrating: System administration processes, and supporting system administration procedures
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.
- Evidence demonstrating: A centralised and managed approach that maintains the integrity of patches or up
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in high assuran
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
- Evidence demonstrating: Applications other than office productivity suites, web browsers and their exten
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.
- Evidence demonstrating: Patch management processes, and supporting patch management procedures, are deve
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
System administrators perform system administration activities in accordance with the system's change and configuration management plan.
- Evidence demonstrating: System administrators perform system administration activities in accordance wit
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged users use separate privileged and unprivileged operating environments.
- Evidence demonstrating: Privileged users use separate privileged and unprivileged operating environments
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Administrative infrastructure is segregated from the wider network and the internet.
- Evidence demonstrating: Administrative infrastructure is segregated from the wider network and the inter
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Network management traffic can only originate from administrative infrastructure.
- Evidence demonstrating: Network management traffic can only originate from administrative infrastructure
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Administrative activities are conducted through jump servers.
- Evidence demonstrating: Administrative activities are conducted through jump servers.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and verified on a regular basis.
- Evidence demonstrating: Software registers for workstations, servers, network devices and networked IT e
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Operating systems that are no longer supported by vendors are replaced.
- Evidence demonstrating: Operating systems that are no longer supported by vendors are replaced.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A digital preservation policy is developed, implemented and maintained.
- Evidence demonstrating: A digital preservation policy is developed, implemented and maintained.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
- Evidence demonstrating: Backups of data, applications and settings are performed and retained in accorda
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
- Evidence demonstrating: Restoration of data, applications and settings from backups to a common point in
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.
- Evidence demonstrating: Data backup processes, and supporting data backup procedures, are developed, imp
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.
- Evidence demonstrating: Data restoration processes, and supporting data restoration procedures, are deve
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.
- Evidence demonstrating: Software registers contain versions and patch histories of applications, drivers
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged operating environments are not virtualised within unprivileged operating environments.
- Evidence demonstrating: Privileged operating environments are not virtualised within unprivileged operat
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Unprivileged user accounts cannot logon to privileged operating environments.
- Evidence demonstrating: Unprivileged user accounts cannot logon to privileged operating environments.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
- Evidence demonstrating: Privileged user accounts (excluding local administrator accounts) cannot logon t
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in online servi
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in applications
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in drivers are
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
- Evidence demonstrating: A vulnerability scanner is used at least daily to identify missing patches or up
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
- Evidence demonstrating: A vulnerability scanner is used at least weekly to identify missing patches or u
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
- Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
- Evidence demonstrating: A vulnerability scanner is used at least daily to identify missing patches or up
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
- Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.
- Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
- Evidence demonstrating: Office productivity suites, web browsers and their extensions, email clients, PD
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.
- Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) cannot access
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.
- Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) cannot access
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.
- Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) are prevented
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Backup administrator accounts are prevented from modifying and deleting backups during their retention period.
- Evidence demonstrating: Backup administrator accounts are prevented from modifying and deleting backups
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.
- Evidence demonstrating: Administrative infrastructure for critical servers, high-value servers and regul
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.
- Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Internet-facing network devices that are no longer supported by vendors are replaced.
- Evidence demonstrating: Internet-facing network devices that are no longer supported by vendors are repl
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
- Evidence demonstrating: An automated method of asset discovery is used at least fortnightly to support t
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
- Evidence demonstrating: A vulnerability scanner with an up-to-date vulnerability database is used for vu
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.
- Evidence demonstrating: When applications, operating systems, network devices or networked IT equipment
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
- Evidence demonstrating: Backups of data, applications and settings are synchronised to enable restoratio
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Backups of data, applications and settings are retained in a secure and resilient manner.
- Evidence demonstrating: Backups of data, applications and settings are retained in a secure and resilien
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Unprivileged user accounts cannot access backups belonging to other user accounts.
- Evidence demonstrating: Unprivileged user accounts cannot access backups belonging to other user account
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Unprivileged user accounts cannot access their own backups.
- Evidence demonstrating: Unprivileged user accounts cannot access their own backups.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Unprivileged user accounts are prevented from modifying and deleting backups.
- Evidence demonstrating: Unprivileged user accounts are prevented from modifying and deleting backups.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in online servi
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in drivers are
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Secure Admin Workstations are used in the performance of administrative activities.
- Evidence demonstrating: Secure Admin Workstations are used in the performance of administrative activiti
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.
- Evidence demonstrating: Network devices that do not belong to administrative infrastructure cannot initi
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
- Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in firmware are
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
- Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in firmware are
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Online services that are no longer supported by vendors are removed.
- Evidence demonstrating: Online services that are no longer supported by vendors are removed.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.
- Evidence demonstrating: The likelihood of system compromise is frequently assessed when working exploits
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
User accounts with DCSync permissions cannot logon to unprivileged operating environments.
- Evidence demonstrating: User accounts with DCSync permissions cannot logon to unprivileged operating env
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Non-internet-facing network devices that are no longer supported by vendors are replaced.
- Evidence demonstrating: Non-internet-facing network devices that are no longer supported by vendors are
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Networked IT equipment that is no longer supported by vendors is replaced.
- Evidence demonstrating: Networked IT equipment that is no longer supported by vendors is replaced.
- Patch management records and SLAs
- Privileged administration procedures
- Backup and restoration test records
- Unpatched systems beyond SLA
- Untested backups
- Privileged access not controlled
Guidelines for system monitoring
Event logs from workstations are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from workstations are analysed in a timely manner to detect cyber sec
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
An event logging policy is developed, implemented and maintained.
- Evidence demonstrating: An event logging policy is developed, implemented and maintained.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.
- Evidence demonstrating: For each event logged, the date and time of the event, the relevant user or proc
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
An accurate and consistent time source is used for event logging.
- Evidence demonstrating: An accurate and consistent time source is used for event logging.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Cyber security events are analysed in a timely manner to identify cyber security incidents.
- Evidence demonstrating: Cyber security events are analysed in a timely manner to identify cyber security
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
A centralised event logging facility is implemented.
- Evidence demonstrating: A centralised event logging facility is implemented.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs are protected from unauthorised modification and deletion.
- Evidence demonstrating: Event logs are protected from unauthorised modification and deletion.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from internet-facing servers are analysed in a timely manner to detec
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from non-internet-facing servers are analysed in a timely manner to d
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
To the extent possible, event logs are captured and stored in a consistent and structured format.
- Evidence demonstrating: To the extent possible, event logs are captured and stored in a consistent and s
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from internet-facing network devices are analysed in a timely manner
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from non-internet-facing network devices are analysed in a timely man
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs sent to a centralised event logging facility are done so as soon as possible after they occur.
- Evidence demonstrating: Event logs sent to a centralised event logging facility are done so as soon as p
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs sent to a centralised event logging facility are encrypted in transit.
- Evidence demonstrating: Event logs sent to a centralised event logging facility are encrypted in transit
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs are protected from unauthorised access.
- Evidence demonstrating: Event logs are protected from unauthorised access.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from critical servers are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from critical servers are analysed in a timely manner to detect cyber
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs from security products are analysed in a timely manner to detect cyber security events.
- Evidence demonstrating: Event logs from security products are analysed in a timely manner to detect cybe
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs are retained in a searchable manner for at least 12 months.
- Evidence demonstrating: Event logs are retained in a searchable manner for at least 12 months.
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia's Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.
- Evidence demonstrating: Event logs are retained as per minimum retention requirements for various classe
- Centralised event logging configuration
- Log retention settings
- Event analysis / alert records
- Logs not centralised
- Insufficient retention
- Events not analysed in a timely manner
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Information Security Manual framework page.