Skip to content

Evidence request lists

Australian Information Security Manual

Evidence request list. 1081 controls, 1081 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Guidelines for communications infrastructure

ISM-0181
Cabling infrastructure is installed in accordance with relevant Australian Standards, as d

Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cabling infrastructure is installed in accordance with relevant Australian Stand
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0187
SECRET cables, when bundled together or run in conduit, are run exclusively in their own i

SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET cables, when bundled together or run in conduit, are run exclusively in t
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0194
In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit

In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit joints and TOP SECRET conduits connected by threaded lock nuts.

Artefacts an auditor will ask for
  • Evidence demonstrating: In shared facilities, a visible smear of conduit glue is used to seal all plasti
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0195
In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to

In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to seal all removable covers on TOP SECRET cable reticulation systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals a
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0198
When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Orga

When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Organisation is consulted and all directions provided are complied with.

Artefacts an auditor will ask for
  • Evidence demonstrating: When penetrating a TOP SECRET audio secure room, the Australian Security Intelli
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0201
Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre

Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre intervals and marked as 'TS RUN'.

Artefacts an auditor will ask for
  • Evidence demonstrating: Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0206
Cable labelling processes, and supporting cable labelling procedures, are developed, imple

Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cable labelling processes, and supporting cable labelling procedures, are develo
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0208
A cable register contains the following for each cable: - cable identifier - cable colour

A cable register contains the following for each cable: - cable identifier - cable colour - sensitivity/classification - source - destination - location - seal numbers (if applicable).

Artefacts an auditor will ask for
  • Evidence demonstrating: A cable register contains the following for each cable: - cable identifier - cab
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0211
A cable register is developed, implemented, maintained and verified on a regular basis.

A cable register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cable register is developed, implemented, maintained and verified on a regular
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0213
SECRET and TOP SECRET cables are terminated on their own individual patch panels.

SECRET and TOP SECRET cables are terminated on their own individual patch panels.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET and TOP SECRET cables are terminated on their own individual patch panels
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0216
TOP SECRET patch panels are installed in individual TOP SECRET cabinets.

TOP SECRET patch panels are installed in individual TOP SECRET cabinets.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET patch panels are installed in individual TOP SECRET cabinets.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0217
Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabi

Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabinet as a TOP SECRET patch panel: - a physical barrier in the cabinet is provided to separate patch panels - only personnel holding a Positive Vetting security clearance have access to the cabinet - approval from the TOP SECRET system's authorising officer is obtained prior to installation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where spatial constraints demand non-TOP SECRET patch panels be installed in the
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0218
If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wa

If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wall outlet boxes to IT equipment, they are run in a protective and easily inspected pathway that is clearly labelled at the IT equipment end with the wall outlet box's identifier.

Artefacts an auditor will ask for
  • Evidence demonstrating: If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0246
When an emanation security risk assessment is required, it is sought as early as possible

When an emanation security risk assessment is required, it is sought as early as possible in a system's life cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: When an emanation security risk assessment is required, it is sought as early as
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0249
System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployab

System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployable capability, contact ASD for an emanation security risk assessment.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0250
IT equipment meets industry and government standards relating to electromagnetic interfere

IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment meets industry and government standards relating to electromagnetic
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-0926
Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink

Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither sa
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1095
Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.

Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.

Artefacts an auditor will ask for
  • Evidence demonstrating: Wall outlet boxes denote the systems, cable identifiers and wall outlet box iden
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1096
Cables are labelled at each end with sufficient source and destination details to enable t

Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables are labelled at each end with sufficient source and destination details t
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1098
SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet wit

SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet with a division plate between any SECRET cables and non-SECRET cables.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET cables are terminated in an individual cabinet; or for small systems, a c
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1100
TOP SECRET cables are terminated in an individual TOP SECRET cabinet.

TOP SECRET cables are terminated in an individual TOP SECRET cabinet.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET cables are terminated in an individual TOP SECRET cabinet.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1101
In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or c

In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.

Artefacts an auditor will ask for
  • Evidence demonstrating: In TOP SECRET areas, cable reticulation systems leading into cabinets in server
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1102
Cable reticulation systems leading into cabinets are terminated as close as possible to th

Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cable reticulation systems leading into cabinets are terminated as close as poss
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1103
In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms

In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.

Artefacts an auditor will ask for
  • Evidence demonstrating: In TOP SECRET areas, cable reticulation systems leading into cabinets not in ser
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1105
SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.

SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1107
Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither s

Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1109
Wall outlet box covers are clear plastic.

Wall outlet box covers are clear plastic.

Artefacts an auditor will ask for
  • Evidence demonstrating: Wall outlet box covers are clear plastic.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1111
Fibre-optic cables are used for cabling infrastructure instead of copper cables.

Fibre-optic cables are used for cabling infrastructure instead of copper cables.

Artefacts an auditor will ask for
  • Evidence demonstrating: Fibre-optic cables are used for cabling infrastructure instead of copper cables.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1112
Cables in non-TOP SECRET areas are inspectable every five metres or less.

Cables in non-TOP SECRET areas are inspectable every five metres or less.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables in non-TOP SECRET areas are inspectable every five metres or less.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1114
Cable bundles or conduits sharing a common cable reticulation system have a dividing parti

Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cable bundles or conduits sharing a common cable reticulation system have a divi
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1115
Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.

Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables from cable trays to wall outlet boxes are run in flexible or plastic cond
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1116
A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.

A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.

Artefacts an auditor will ask for
  • Evidence demonstrating: A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1119
Cables in TOP SECRET areas are fully inspectable for their entire length.

Cables in TOP SECRET areas are fully inspectable for their entire length.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables in TOP SECRET areas are fully inspectable for their entire length.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1122
Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET ca

Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET cables are encased in conduit with all gaps between the TOP SECRET conduit and the wall filled with an appropriate sealing compound.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1123
A power distribution board with a feed from an Uninterruptible Power Supply is used to pow

A power distribution board with a feed from an Uninterruptible Power Supply is used to power all TOP SECRET IT equipment.

Artefacts an auditor will ask for
  • Evidence demonstrating: A power distribution board with a feed from an Uninterruptible Power Supply is u
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1130
In shared facilities, cables are run in an enclosed cable reticulation system.

In shared facilities, cables are run in an enclosed cable reticulation system.

Artefacts an auditor will ask for
  • Evidence demonstrating: In shared facilities, cables are run in an enclosed cable reticulation system.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1133
In shared facilities, TOP SECRET cables are not run in party walls.

In shared facilities, TOP SECRET cables are not run in party walls.

Artefacts an auditor will ask for
  • Evidence demonstrating: In shared facilities, TOP SECRET cables are not run in party walls.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1137
System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD f

System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security risk assessment.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners deploying SECRET or TOP SECRET systems within fixed facilities con
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1164
In shared facilities, conduits or the front covers of ducts, cable trays in floors and cei

In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.

Artefacts an auditor will ask for
  • Evidence demonstrating: In shared facilities, conduits or the front covers of ducts, cable trays in floo
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1216
SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appro

SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appropriate colour and labelled at inspection points.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET and TOP SECRET cables with non-conformant cable colouring are banded with
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1639
Building management cables are labelled with their purpose in black writing on a yellow ba

Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.

Artefacts an auditor will ask for
  • Evidence demonstrating: Building management cables are labelled with their purpose in black writing on a
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1640
Cables for foreign systems installed in Australian facilities are labelled at inspection p

Cables for foreign systems installed in Australian facilities are labelled at inspection points.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables for foreign systems installed in Australian facilities are labelled at in
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1645
Floor plan diagrams are developed, implemented, maintained and verified on a regular basis

Floor plan diagrams are developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: Floor plan diagrams are developed, implemented, maintained and verified on a reg
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1646
Floor plan diagrams contain the following: - cable paths (including ingress and egress poi

Floor plan diagrams contain the following: - cable paths (including ingress and egress points between floors) - cable reticulation system and conduit paths - floor concentration boxes - wall outlet boxes - network cabinets.

Artefacts an auditor will ask for
  • Evidence demonstrating: Floor plan diagrams contain the following: - cable paths (including ingress and
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1718
SECRET cables are coloured salmon pink.

SECRET cables are coloured salmon pink.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET cables are coloured salmon pink.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1719
TOP SECRET cables are coloured red.

TOP SECRET cables are coloured red.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET cables are coloured red.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1720
SECRET wall outlet boxes are coloured salmon pink.

SECRET wall outlet boxes are coloured salmon pink.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET wall outlet boxes are coloured salmon pink.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1721
TOP SECRET wall outlet boxes are coloured red.

TOP SECRET wall outlet boxes are coloured red.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET wall outlet boxes are coloured red.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1820
Cables for individual systems use a consistent colour.

Cables for individual systems use a consistent colour.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cables for individual systems use a consistent colour.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1821
TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their o

TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET cables, when bundled together or run in conduit, are run exclusively
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1822
Wall outlet boxes for individual systems use a consistent colour.

Wall outlet boxes for individual systems use a consistent colour.

Artefacts an auditor will ask for
  • Evidence demonstrating: Wall outlet boxes for individual systems use a consistent colour.
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1884
Emanation security doctrine produced by ASD for the management of emanation security matte

Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.

Artefacts an auditor will ask for
  • Evidence demonstrating: Emanation security doctrine produced by ASD for the management of emanation secu
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration
ISM-1885
Recommended actions contained within emanation security mitigation advice issued for syste

Recommended actions contained within emanation security mitigation advice issued for systems are implemented by system owners.

Artefacts an auditor will ask for
  • Evidence demonstrating: Recommended actions contained within emanation security mitigation advice issued
  • Cabling records and standards compliance
  • Emanation security assessments
  • Cable labelling/inspection records
Where this commonly fails
  • Cabling not installed to standard
  • No emanation security consideration

Guidelines for communications systems

ISM-0229
Personnel are advised of the permitted sensitivity or classification of information that c

Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of the permitted sensitivity or classification of informat
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0230
Personnel are advised of security risks posed by non-secure telephone systems in areas whe

Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of security risks posed by non-secure telephone systems in
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0231
When using cryptographic equipment to permit different levels of conversation for differen

When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using cryptographic equipment to permit different levels of conversation fo
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0232
Telephone systems used for sensitive or classified conversations encrypt all traffic that

Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Telephone systems used for sensitive or classified conversations encrypt all tra
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0233
Cordless telephone handsets and headsets are not used for sensitive or classified conversa

Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cordless telephone handsets and headsets are not used for sensitive or classifie
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0235
Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone s

Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.

Artefacts an auditor will ask for
  • Evidence demonstrating: Speakerphones are not used on telephone systems in TOP SECRET areas unless the t
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0236
Off-hook audio protection features are used on telephone systems in areas where background

Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.

Artefacts an auditor will ask for
  • Evidence demonstrating: Off-hook audio protection features are used on telephone systems in areas where
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0245
MFDs are not connected to digital telephone systems.

MFDs are not connected to digital telephone systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: MFDs are not connected to digital telephone systems.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0546
When video conferencing or IP telephony traffic passes through a gateway containing a fire

When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.

Artefacts an auditor will ask for
  • Evidence demonstrating: When video conferencing or IP telephony traffic passes through a gateway contain
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0547
Video conferencing and IP telephony calls are conducted using a secure real-time transport

Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.

Artefacts an auditor will ask for
  • Evidence demonstrating: Video conferencing and IP telephony calls are conducted using a secure real-time
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0548
Video conferencing and IP telephony calls are established using a secure session initiatio

Video conferencing and IP telephony calls are established using a secure session initiation protocol.

Artefacts an auditor will ask for
  • Evidence demonstrating: Video conferencing and IP telephony calls are established using a secure session
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0549
Video conferencing and IP telephony traffic is separated physically or logically from othe

Video conferencing and IP telephony traffic is separated physically or logically from other data traffic.

Artefacts an auditor will ask for
  • Evidence demonstrating: Video conferencing and IP telephony traffic is separated physically or logically
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0551
IP telephony is configured such that: - IP phones authenticate themselves to the call cont

IP telephony is configured such that: - IP phones authenticate themselves to the call controller upon registration - auto-registration is disabled and only authorised devices are allowed to access the network - unauthorised devices are blocked by default - all unused and prohibited functionality is disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: IP telephony is configured such that: - IP phones authenticate themselves to the
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0553
Authentication and authorisation is used for all actions on a video conferencing network,

Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation is used for all actions on a video conferencing
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0554
An encrypted and non-replayable two-way authentication scheme is used for call authenticat

An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: An encrypted and non-replayable two-way authentication scheme is used for call a
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0555
Authentication and authorisation is used for all actions on an IP telephony network, inclu

Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation is used for all actions on an IP telephony netw
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0556
Workstations are not connected to video conferencing units or IP phones unless the worksta

Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses Virtual Local Area Networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.

Artefacts an auditor will ask for
  • Evidence demonstrating: Workstations are not connected to video conferencing units or IP phones unless t
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0558
IP phones used in public areas do not have the ability to access data networks, voicemail

IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.

Artefacts an auditor will ask for
  • Evidence demonstrating: IP phones used in public areas do not have the ability to access data networks,
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0559
Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET

Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microphones (including headsets and USB handsets) and webcams are not used with
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0588
An MFD usage policy is developed, implemented and maintained.

An MFD usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An MFD usage policy is developed, implemented and maintained.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0589
MFDs are not used to scan or copy documents above the sensitivity or classification of net

MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.

Artefacts an auditor will ask for
  • Evidence demonstrating: MFDs are not used to scan or copy documents above the sensitivity or classificat
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0590
Authentication measures for MFDs are the same strength as those used for workstations on n

Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication measures for MFDs are the same strength as those used for worksta
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-0931
In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to

In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements.

Artefacts an auditor will ask for
  • Evidence demonstrating: In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets a
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1014
Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversation

Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Individual logins are implemented for IP phones used for SECRET or TOP SECRET co
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1019
A denial of service response plan for video conferencing and IP telephony services is deve

A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A denial of service response plan for video conferencing and IP telephony servic
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1036
MFDs are located in areas where their use can be observed.

MFDs are located in areas where their use can be observed.

Artefacts an auditor will ask for
  • Evidence demonstrating: MFDs are located in areas where their use can be observed.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1078
A telephone system usage policy is developed, implemented and maintained.

A telephone system usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A telephone system usage policy is developed, implemented and maintained.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1450
Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SE

Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microphones (including headsets and USB handsets) and webcams are not used with
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1562
Video conferencing and IP telephony infrastructure is hardened.

Video conferencing and IP telephony infrastructure is hardened.

Artefacts an auditor will ask for
  • Evidence demonstrating: Video conferencing and IP telephony infrastructure is hardened.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1805
A denial of service response plan for video conferencing and IP telephony services contain

A denial of service response plan for video conferencing and IP telephony services contains the following: - how to identify signs of a denial-of-service attack - how to identify the source of a denial-of-service attack - how capabilities can be maintained during a denial-of-service attack - what actions can be taken to respond to a denial-of-service attack.

Artefacts an auditor will ask for
  • Evidence demonstrating: A denial of service response plan for video conferencing and IP telephony servic
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1854
Users authenticate to MFDs before they can print, scan or copy documents.

Users authenticate to MFDs before they can print, scan or copy documents.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users authenticate to MFDs before they can print, scan or copy documents.
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-1855
Use of MFDs for printing, scanning and copying purposes, including the capture of shadow c

Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Use of MFDs for printing, scanning and copying purposes, including the capture o
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications
ISM-2075
Fax machines, and online fax services, are not used for sending or receiving fax messages.

Fax machines, and online fax services, are not used for sending or receiving fax messages.

Artefacts an auditor will ask for
  • Evidence demonstrating: Fax machines, and online fax services, are not used for sending or receiving fax
  • Telephone/video/fax usage policies
  • Classification/marking of communications
  • Configuration records
Where this commonly fails
  • No usage policy
  • Classification not enforced on communications

Guidelines for cryptography

ISM-0142
The compromise or suspected compromise of cryptographic equipment or associated keying mat

The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.

Artefacts an auditor will ask for
  • Evidence demonstrating: The compromise or suspected compromise of cryptographic equipment or associated
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0455
Where practical, cryptographic equipment, applications and libraries provide a means of da

Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where practical, cryptographic equipment, applications and libraries provide a m
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0457
Cryptographic equipment, applications or libraries that have completed a Common Criteria e

Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cryptographic equipment, applications or libraries that have completed a Common
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0459
Full disk encryption, or partial encryption where access controls will only allow writing

Full disk encryption, or partial encryption where access controls will only allow writing to the encrypted partition, is implemented when encrypting data at rest.

Artefacts an auditor will ask for
  • Evidence demonstrating: Full disk encryption, or partial encryption where access controls will only allo
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0460
HACE is used when encrypting media that contains SECRET or TOP SECRET data.

HACE is used when encrypting media that contains SECRET or TOP SECRET data.

Artefacts an auditor will ask for
  • Evidence demonstrating: HACE is used when encrypting media that contains SECRET or TOP SECRET data.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0462
When a user authenticates to the encryption functionality of IT equipment or media, it is

When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.

Artefacts an auditor will ask for
  • Evidence demonstrating: When a user authenticates to the encryption functionality of IT equipment or med
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0465
Cryptographic equipment, applications or libraries that have completed a Common Criteria e

Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cryptographic equipment, applications or libraries that have completed a Common
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0467
HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently s

HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: HACE is used to protect SECRET and TOP SECRET data when communicated over insuff
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0469
An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is

An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is used to protect data when communicated over network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic pr
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0471
Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment,

Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only AACAs or high assurance cryptographic algorithms are used by cryptographic
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0472
When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is

When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus of at least 204
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0474
When using ECDH for agreeing on encryption session keys, a base point order and key size o

When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDH for agreeing on encryption session keys, a base point order and
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0475
When using ECDSA for digital signatures, a base point order and key size of at least 224 b

When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDSA for digital signatures, a base point order and key size of at l
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0476
When using RSA for digital signatures, and transporting encryption session keys (and simil

When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using RSA for digital signatures, and transporting encryption session keys
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0477
When using RSA for digital signatures, and for transporting encryption session keys (and s

When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using RSA for digital signatures, and for transporting encryption session k
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0479
Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.

Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.

Artefacts an auditor will ask for
  • Evidence demonstrating: Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0481
Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment,

Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only AACPs or high assurance cryptographic protocols are used by cryptographic e
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0484
The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress x

The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx) - have a suitable login banner (Banner x) - have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60) - disable host-based authentication (HostbasedAuthentication no) - disable rhosts-based authentication (IgnoreRhosts yes) - disable the ability to login directly as root (PermitRootLogin no) - disable empty passwords (PermitEmptyPasswords no) - disable connection forwarding (AllowTCPForwarding no) - disable gateway ports (GatewayPorts no) - disable X11 forwarding (X11Forwarding no).

Artefacts an auditor will ask for
  • Evidence demonstrating: The SSH daemon is configured to: - only listen on the required interfaces (Liste
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0485
Public key-based authentication is used for SSH connections.

Public key-based authentication is used for SSH connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Public key-based authentication is used for SSH connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0487
When using logins without a password for SSH connections, the following are disabled: - ac

When using logins without a password for SSH connections, the following are disabled: - access from IP addresses that do not require access - port forwarding - agent credential forwarding - X11 forwarding - console access.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using logins without a password for SSH connections, the following are disa
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0488
If using remote access without the use of a password for SSH connections, the 'forced comm

If using remote access without the use of a password for SSH connections, the 'forced command' option is used to specify what command is executed and parameter checking is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: If using remote access without the use of a password for SSH connections, the 'f
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0489
When SSH-agent or similar key caching applications are used, it is limited to workstations

When SSH-agent or similar key caching applications are used, it is limited to workstations and servers with screen locks and key caches that are set to expire within four hours of inactivity.

Artefacts an auditor will ask for
  • Evidence demonstrating: When SSH-agent or similar key caching applications are used, it is limited to wo
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0490
Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.

Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME conne
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0494
Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel

Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Tunnel mode is used for IPsec connections; however, if using transport mode, an
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0496
The ESP protocol is used for authentication and encryption of IPsec connections.

The ESP protocol is used for authentication and encryption of IPsec connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: The ESP protocol is used for authentication and encryption of IPsec connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0498
A security association lifetime of less than four hours (14400 seconds) is used for IPsec

A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: A security association lifetime of less than four hours (14400 seconds) is used
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0499
Communications security doctrine and policy produced by ASD for the management and operati

Communications security doctrine and policy produced by ASD for the management and operation of HACE is complied with.

Artefacts an auditor will ask for
  • Evidence demonstrating: Communications security doctrine and policy produced by ASD for the management a
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0501
Keyed cryptographic equipment is transported based on the sensitivity or classification of

Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.

Artefacts an auditor will ask for
  • Evidence demonstrating: Keyed cryptographic equipment is transported based on the sensitivity or classif
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0507
Cryptographic key management processes, and supporting cryptographic key management proced

Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cryptographic key management processes, and supporting cryptographic key managem
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0994
ECDH is used in preference to DH.

ECDH is used in preference to DH.

Artefacts an auditor will ask for
  • Evidence demonstrating: ECDH is used in preference to DH.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0998
AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with

AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.

Artefacts an auditor will ask for
  • Evidence demonstrating: AUTH HMAC SHA2 256 128, AUTH HMAC SHA2 384 192, AUTH HMAC SHA2 512 256 or NONE (
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-0999
DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random E

DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072-bit MODP Group or 4096-bit MODP Group.

Artefacts an auditor will ask for
  • Evidence demonstrating: DH or ECDH is used for key establishment of IPsec connections, preferably 384-bi
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1000
PFS is used for IPsec connections.

PFS is used for IPsec connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: PFS is used for IPsec connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1080
An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm i

An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm is used when encrypting media.

Artefacts an auditor will ask for
  • Evidence demonstrating: An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic a
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1091
Keying material is changed when compromised or suspected of being compromised.

Keying material is changed when compromised or suspected of being compromised.

Artefacts an auditor will ask for
  • Evidence demonstrating: Keying material is changed when compromised or suspected of being compromised.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1139
Only the latest version of TLS is used for TLS connections.

Only the latest version of TLS is used for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only the latest version of TLS is used for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1233
IKE version 2 is used for key exchange when establishing IPsec connections.

IKE version 2 is used for key exchange when establishing IPsec connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: IKE version 2 is used for key exchange when establishing IPsec connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1369
AES-GCM is used for encryption of TLS connections.

AES-GCM is used for encryption of TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: AES-GCM is used for encryption of TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1370
Only server-initiated secure renegotiation is used for TLS connections.

Only server-initiated secure renegotiation is used for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only server-initiated secure renegotiation is used for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1372
DH or ECDH is used for key establishment of TLS connections.

DH or ECDH is used for key establishment of TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: DH or ECDH is used for key establishment of TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1373
Anonymous DH is not used for TLS connections.

Anonymous DH is not used for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Anonymous DH is not used for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1374
SHA-2-based certificates are used for TLS connections.

SHA-2-based certificates are used for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: SHA-2-based certificates are used for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1375
SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom funct

SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudora
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1446
When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.

When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1448
When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is u

When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using DH or ECDH for key establishment of TLS connections, the ephemeral va
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1449
SSH private keys are protected with a password or a key encryption key.

SSH private keys are protected with a password or a key encryption key.

Artefacts an auditor will ask for
  • Evidence demonstrating: SSH private keys are protected with a password or a key encryption key.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1453
Perfect Forward Secrecy (PFS) is used for TLS connections.

Perfect Forward Secrecy (PFS) is used for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Perfect Forward Secrecy (PFS) is used for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1506
The use of SSH version 1 is disabled for SSH connections.

The use of SSH version 1 is disabled for SSH connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: The use of SSH version 1 is disabled for SSH connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1553
TLS compression is disabled for TLS connections.

TLS compression is disabled for TLS connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: TLS compression is disabled for TLS connections.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1629
When using DH for agreeing on encryption session keys, a modulus and associated parameters

When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus and associated
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1759
When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is

When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is used, preferably 3072 bits.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using DH for agreeing on encryption session keys, a modulus of at least 307
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1761
When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves

When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1762
When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are us

When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 cur
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1763
When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, prefe

When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are u
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1764
When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably t

When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, pr
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1765
When using RSA for digital signatures, and transporting encryption session keys (and simil

When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 3072 bits is used, preferably 3072 bits.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using RSA for digital signatures, and transporting encryption session keys
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1766
When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-

When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 224 bits is used, prefe
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1767
When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA-

When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA-384 or SHA-512.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 256 bits is used, prefe
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1768
When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA-

When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA-384 or SHA-512.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using SHA-2 for hashing, an output size of at least 384 bits is used, prefe
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1769
When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably A
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1770
When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.

When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1771
AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.

AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.

Artefacts an auditor will ask for
  • Evidence demonstrating: AES is used for encrypting IPsec connections, preferably ENCR AES GCM 16.
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1772
PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, p

PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.

Artefacts an auditor will ask for
  • Evidence demonstrating: PRF HMAC SHA2 256, PRF HMAC SHA2 384 or PRF HMAC SHA2 512 is used for IPsec conn
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1802
HACE are issued an Approval for Use by ASD and operated in accordance with the latest vers

HACE are issued an Approval for Use by ASD and operated in accordance with the latest version of their associated Australian Communications Security Instructions.

Artefacts an auditor will ask for
  • Evidence demonstrating: HACE are issued an Approval for Use by ASD and operated in accordance with the l
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1917
The development and procurement of new cryptographic equipment, applications and libraries

The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.

Artefacts an auditor will ask for
  • Evidence demonstrating: The development and procurement of new cryptographic equipment, applications and
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1990
When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-

When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adheren
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1991
When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DS

When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, prefer
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1992
When using ML-DSA for digital signatures, the hedged variant is used whenever possible.

When using ML-DSA for digital signatures, the hedged variant is used whenever possible.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ML-DSA for digital signatures, the hedged variant is used whenever po
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1993
Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of defau

Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.

Artefacts an auditor will ask for
  • Evidence demonstrating: Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performanc
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1994
When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA

When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.

Artefacts an auditor will ask for
  • Evidence demonstrating: When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-3
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1995
When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768

When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using ML-KEM for encapsulating encryption session keys (and similar keys),
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-1996
When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptograph

When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.

Artefacts an auditor will ask for
  • Evidence demonstrating: When a post-quantum traditional hybrid scheme is used, either the post-quantum c
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management
ISM-2073
A post-quantum cryptography transition plan is developed, implemented and maintained.

A post-quantum cryptography transition plan is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A post-quantum cryptography transition plan is developed, implemented and mainta
  • ASD-Approved algorithm/protocol configuration
  • Key management procedures
  • TLS/SSH/IPsec configuration
Where this commonly fails
  • Non-approved or weak algorithms
  • Poor key management

Guidelines for cyber security documentation

ISM-0039
A cyber security strategy is developed, implemented and maintained.

A cyber security strategy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cyber security strategy is developed, implemented and maintained.
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-0041
Systems have a system security plan that includes an overview of the system (covering the

Systems have a system security plan that includes an overview of the system (covering the system's purpose, the system boundary and how the system is managed) as well as an annex that covers applicable controls from this document and any additional controls that have been identified and implemented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems have a system security plan that includes an overview of the system (cov
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-0043
Systems have a cyber security incident response plan that covers the following: - guidelin

Systems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types of cyber security incidents likely to be encountered and the expected response to each type - how to report cyber security incidents, internally to an organisation and externally to relevant authorities - other parties which need to be informed in the event of a cyber security incident - the authority, or authorities, responsible for investigating and responding to cyber security incidents - the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority - the steps necessary to ensure the integrity of evidence relating to a cyber security incident - system contingency measures or a reference to such details if they are loca

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems have a cyber security incident response plan that covers the following:
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-0047
Organisational-level cyber security documentation is approved by the chief information sec

Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system's authorising officer.

Artefacts an auditor will ask for
  • Evidence demonstrating: Organisational-level cyber security documentation is approved by the chief infor
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-0888
Cyber security documentation is reviewed at least annually and includes a 'current as at \

Cyber security documentation is reviewed at least annually and includes a 'current as at \[date\]' or equivalent statement.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security documentation is reviewed at least annually and includes a 'curre
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-0912
Systems have a change and configuration management plan that includes: - the establishment

Systems have a change and configuration management plan that includes: - the establishment and maintenance of authorised baseline configurations for systems - what constitutes routine and urgent changes to the configuration of systems - how changes to the configuration of systems will be requested, tracked and documented - who needs to be consulted prior to routine and urgent changes to the configuration of systems - who needs to approve routine and urgent changes to the configuration of systems - who needs to be notified of routine and urgent changes to the configuration of systems - what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems have a change and configuration management plan that includes: - the est
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-1163
Systems have a continuous monitoring plan that includes: - conducting vulnerability scans

Systems have a continuous monitoring plan that includes: - conducting vulnerability scans for systems at least fortnightly - conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter - analysing identified vulnerabilities to determine their potential impact - implementing mitigations based on risk, effectiveness and cost.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems have a continuous monitoring plan that includes: - conducting vulnerabil
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-1563
At the conclusion of a security assessment for a system, a security assessment report is p

At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: - the scope of the security assessment - the system's strengths and weaknesses - security risks associated with the operation of the system - the effectiveness of the implementation of controls - any recommended remediation actions.

Artefacts an auditor will ask for
  • Evidence demonstrating: At the conclusion of a security assessment for a system, a security assessment r
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-1564
At the conclusion of a security assessment for a system, a plan of action and milestones i

At the conclusion of a security assessment for a system, a plan of action and milestones is produced by the system owner.

Artefacts an auditor will ask for
  • Evidence demonstrating: At the conclusion of a security assessment for a system, a plan of action and mi
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-1602
Cyber security documentation, including notification of subsequent changes, is communicate

Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security documentation, including notification of subsequent changes, is c
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review
ISM-1739
A system's security architecture is approved prior to the development of the system.

A system's security architecture is approved prior to the development of the system.

Artefacts an auditor will ask for
  • Evidence demonstrating: A system's security architecture is approved prior to the development of the sys
  • System security plans
  • Standard operating procedures
  • Current-as-at dates and approval records
Where this commonly fails
  • Documentation out of date
  • No system security plan
  • No annual review

Guidelines for cyber security incidents

ISM-0120
Cyber security personnel have access to sufficient data sources and tools to ensure that s

Cyber security personnel have access to sufficient data sources and tools to ensure that systems can be monitored for key indicators of compromise.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security personnel have access to sufficient data sources and tools to ens
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0123
Cyber security incidents are reported to the chief information security officer, or one of

Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security incidents are reported to the chief information security officer,
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0125
A cyber security incident register is developed, implemented and maintained.

A cyber security incident register is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cyber security incident register is developed, implemented and maintained.
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0133
When a data spill occurs, data owners are advised and access to the data is restricted.

When a data spill occurs, data owners are advised and access to the data is restricted.

Artefacts an auditor will ask for
  • Evidence demonstrating: When a data spill occurs, data owners are advised and access to the data is rest
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0137
Legal advice is sought before allowing intrusion activity to continue on a system for the

Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

Artefacts an auditor will ask for
  • Evidence demonstrating: Legal advice is sought before allowing intrusion activity to continue on a syste
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0138
The integrity of evidence gathered during an investigation is maintained by investigators:

The integrity of evidence gathered during an investigation is maintained by investigators: - recording all of their actions - maintaining a proper chain of custody - following all instructions provided by relevant law enforcement agencies.

Artefacts an auditor will ask for
  • Evidence demonstrating: The integrity of evidence gathered during an investigation is maintained by inve
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0140
Cyber security incidents are reported to ASD as soon as possible after they occur or are d

Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security incidents are reported to ASD as soon as possible after they occu
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0576
A cyber security incident management policy, and associated cyber security incident respon

A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cyber security incident management policy, and associated cyber security incid
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-0917
When malicious code is detected, the following steps are taken to handle the infection: -

When malicious code is detected, the following steps are taken to handle the infection: - the infected systems are isolated - all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary - antivirus applications are used to remove the infection from infected systems and media - if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.

Artefacts an auditor will ask for
  • Evidence demonstrating: When malicious code is detected, the following steps are taken to handle the inf
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1213
Following intrusion remediation activities, full network traffic is captured for at least

Following intrusion remediation activities, full network traffic is captured for at least seven days and analysed to determine whether malicious actors have been successfully removed from the system.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following intrusion remediation activities, full network traffic is captured for
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1609
System owners are consulted before allowing intrusion activity to continue on a system for

System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners are consulted before allowing intrusion activity to continue on a
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1625
An insider threat mitigation program is developed, implemented and maintained.

An insider threat mitigation program is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An insider threat mitigation program is developed, implemented and maintained.
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1626
Legal advice is sought regarding the development and implementation of an insider threat m

Legal advice is sought regarding the development and implementation of an insider threat mitigation program.

Artefacts an auditor will ask for
  • Evidence demonstrating: Legal advice is sought regarding the development and implementation of an inside
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1731
Planning and coordination of intrusion remediation activities are conducted on a separate

Planning and coordination of intrusion remediation activities are conducted on a separate system to that which has been compromised.

Artefacts an auditor will ask for
  • Evidence demonstrating: Planning and coordination of intrusion remediation activities are conducted on a
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1732
To the extent possible, all intrusion remediation activities are conducted in a coordinate

To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.

Artefacts an auditor will ask for
  • Evidence demonstrating: To the extent possible, all intrusion remediation activities are conducted in a
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1784
The cyber security incident management policy, including the associated cyber security inc

The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.

Artefacts an auditor will ask for
  • Evidence demonstrating: The cyber security incident management policy, including the associated cyber se
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1803
A cyber security incident register contains the following for each cyber security incident

A cyber security incident register contains the following for each cyber security incident: - the date the cyber security incident occurred - the date the cyber security incident was discovered - a description of the cyber security incident - any actions taken in response to the cyber security incident - to whom the cyber security incident was reported.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cyber security incident register contains the following for each cyber securit
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1819
Following the identification of a cyber security incident, the cyber security incident res

Following the identification of a cyber security incident, the cyber security incident response plan is enacted.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following the identification of a cyber security incident, the cyber security in
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1880
Cyber security incidents that involve customer data are reported to customers and the publ

Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security incidents that involve customer data are reported to customers an
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1881
Cyber security incidents that do not involve customer data are reported to customers and t

Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security incidents that do not involve customer data are reported to custo
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1969
Malicious code, when stored or communicated, is treated beforehand to prevent accidental e

Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.

Artefacts an auditor will ask for
  • Evidence demonstrating: Malicious code, when stored or communicated, is treated beforehand to prevent ac
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review
ISM-1970
Malicious code processed for cyber security incident response or research purposes is done

Malicious code processed for cyber security incident response or research purposes is done so in a dedicated analysis environment that is segregated from other systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Malicious code processed for cyber security incident response or research purpos
  • Cyber security incident response plan
  • Incident register
  • Post-incident review records
  • Reports to ASD/ACSC
Where this commonly fails
  • No incident response plan
  • Incidents not reported to ASD
  • No post-incident review

Guidelines for cyber security roles

ISM-0009
System owners, in consultation with each system's authorising officer, identify any supple

System owners, in consultation with each system's authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation's risk tolerances.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, identify
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0027
System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensit

System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners obtain an authorisation to operate for each non-classified, OFFICI
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0714
A CISO is appointed to provide cyber security leadership and guidance for their organisati

A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering information technology and operational technology).

Artefacts an auditor will ask for
  • Evidence demonstrating: A CISO is appointed to provide cyber security leadership and guidance for their
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0717
The CISO oversees the management of cyber security personnel within their organisation.

The CISO oversees the management of cyber security personnel within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees the management of cyber security personnel within their organi
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0718
The CISO regularly reports directly to their organisation's board of directors or executiv

The CISO regularly reports directly to their organisation's board of directors or executive committee on cyber security matters.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO regularly reports directly to their organisation's board of directors o
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0720
The CISO oversees the development, implementation and maintenance of a cyber security comm

The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees the development, implementation and maintenance of a cyber sec
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0724
The CISO implements cyber security measurement metrics and key performance indicators for

The CISO implements cyber security measurement metrics and key performance indicators for their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO implements cyber security measurement metrics and key performance indic
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0725
The CISO coordinates cyber security and business alignment through a cyber security steeri

The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising of key cyber security and business executives, which meets formally and on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO coordinates cyber security and business alignment through a cyber secur
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0726
The CISO coordinates security risk management activities between cyber security and busine

The CISO coordinates security risk management activities between cyber security and business teams.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO coordinates security risk management activities between cyber security
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0731
The CISO oversees cyber supply chain risk management activities for their organisation.

The CISO oversees cyber supply chain risk management activities for their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees cyber supply chain risk management activities for their organi
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0732
The CISO receives and manages a dedicated cyber security budget for their organisation.

The CISO receives and manages a dedicated cyber security budget for their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO receives and manages a dedicated cyber security budget for their organi
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0733
The CISO is fully aware of all cyber security incidents within their organisation.

The CISO is fully aware of all cyber security incidents within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO is fully aware of all cyber security incidents within their organisatio
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0734
The CISO contributes to the development, implementation and maintenance of business contin

The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO contributes to the development, implementation and maintenance of busin
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-0735
The CISO oversees the development, implementation and maintenance of their organisation's

The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees the development, implementation and maintenance of their organ
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1071
Each system has a designated system owner.

Each system has a designated system owner.

Artefacts an auditor will ask for
  • Evidence demonstrating: Each system has a designated system owner.
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1203
System owners, in consultation with each system's authorising officer, conduct a threat an

System owners, in consultation with each system's authorising officer, conduct a threat and risk assessment for each system.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, conduct a
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1478
The CISO oversees their organisation's cyber security program and ensures their organisati

The CISO oversees their organisation's cyber security program and ensures their organisation's compliance with cyber security policy, standards, regulations and legislation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees their organisation's cyber security program and ensures their
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1525
System owners register each system with its authorising officer.

System owners register each system with its authorising officer.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners register each system with its authorising officer.
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1526
System owners continuously monitor the security of each system, and manage associated cybe

System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners continuously monitor the security of each system, and manage assoc
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1587
System owners report the security status of each system to its authorising officer at leas

System owners report the security status of each system to its authorising officer at least annually.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners report the security status of each system to its authorising offic
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1617
The CISO regularly reviews and updates their organisation's cyber security program to ensu

The CISO regularly reviews and updates their organisation's cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO regularly reviews and updates their organisation's cyber security progr
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1618
The CISO oversees their organisation's response to cyber security incidents.

The CISO oversees their organisation's response to cyber security incidents.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO oversees their organisation's response to cyber security incidents.
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1633
System owners, in consultation with each system's authorising officer, determine the syste

System owners, in consultation with each system's authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, determine
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1634
System owners, in consultation with each system's authorising officer, select controls for

System owners, in consultation with each system's authorising officer, select controls for each system and tailor them to achieve desired security and resilience objectives.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, select co
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1635
System owners implement controls for each system and its operating environment.

System owners implement controls for each system and its operating environment.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners implement controls for each system and its operating environment.
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1636
System owners, in consultation with each system's authorising officer, ensure controls for

System owners, in consultation with each system's authorising officer, ensure controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation's own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, ensure co
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1918
The CISO regularly reports directly to their organisation's audit, risk and compliance com

The CISO regularly reports directly to their organisation's audit, risk and compliance committee (or equivalent) on cyber security matters.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO regularly reports directly to their organisation's audit, risk and comp
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1966
The CISO develops, implements, maintains and verifies on a regular basis a register of sys

The CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO develops, implements, maintains and verifies on a regular basis a regis
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1967
System owners, in consultation with each system's authorising officer, ensure controls for

System owners, in consultation with each system's authorising officer, ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and its operating environment, undergo a security assessment by ASD assessors (or their delegates) to determine if they have been implemented correctly and are operating as intended.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners, in consultation with each system's authorising officer, ensure co
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1968
System owners obtain an authorisation to operate for each TOP SECRET system, including for

System owners obtain an authorisation to operate for each TOP SECRET system, including for each sensitive compartmented information system, from Director-General ASD (or their delegate).

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners obtain an authorisation to operate for each TOP SECRET system, inc
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1997
The board of directors or executive committee defines clear roles and responsibilities for

The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee defines clear roles and responsibi
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1998
The board of directors or executive committee ensures that cyber security is integrated th

The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee ensures that cyber security is int
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-1999
The board of directors or executive committee ensures the cyber security strategy for thei

The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee ensures the cyber security strateg
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2000
The board of directors or executive committee seeks regular briefings or reporting on the

The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee seeks regular briefings or reporti
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2001
The board of directors or executive committee champions a positive cyber security culture

The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee champions a positive cyber securit
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2002
The board of directors or executive committee maintains a sufficient level of cyber securi

The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee maintains a sufficient level of cy
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2003
The board of directors or executive committee maintains awareness of key cyber security re

The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee maintains awareness of key cyber s
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2004
The board of directors or executive committee supports the development of cyber security s

The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee supports the development of cyber
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2005
The board of directors or executive committee understands the business criticality of thei

The board of directors or executive committee understands the business criticality of their organisation's systems, including at least a basic understanding of what exists, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee understands the business criticali
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2006
The board of directors or executive committee plans for major cyber security incidents, in

The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understand their duties in relation to such cyber security incidents.

Artefacts an auditor will ask for
  • Evidence demonstrating: The board of directors or executive committee plans for major cyber security inc
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2020
The CISO ensures sufficient cyber security personnel, with the right skills and experience

The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CISO ensures sufficient cyber security personnel, with the right skills and
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled
ISM-2021
System owners implement and maintain data minimisation practices for each of their systems

System owners implement and maintain data minimisation practices for each of their systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: System owners implement and maintain data minimisation practices for each of the
  • CISO appointment record
  • Role descriptions / RACI
  • Resourcing and reporting lines
Where this commonly fails
  • Accountable executive not designated
  • Cyber roles undefined or unfilled

Guidelines for data transfers

ISM-0657
When manually importing data to systems, the data is scanned for malicious and active cont

When manually importing data to systems, the data is scanned for malicious and active content.

Artefacts an auditor will ask for
  • Evidence demonstrating: When manually importing data to systems, the data is scanned for malicious and a
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0660
Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly.

Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data transfer logs for SECRET and TOP SECRET systems are fully verified at least
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0661
Users transferring data to and from systems are held accountable for data transfers they p

Users transferring data to and from systems are held accountable for data transfers they perform.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users transferring data to and from systems are held accountable for data transf
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0663
Data transfer processes, and supporting data transfer procedures, are developed, implement

Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data transfer processes, and supporting data transfer procedures, are developed,
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0664
Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustwort

Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustworthy source beforehand.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0665
Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services t

Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services that have been verified and authorised as such by the chief information security officer.

Artefacts an auditor will ask for
  • Evidence demonstrating: Trustworthy sources for SECRET and TOP SECRET systems are limited to people and
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0669
When manually exporting data from SECRET and TOP SECRET systems, digital signatures are va

When manually exporting data from SECRET and TOP SECRET systems, digital signatures are validated and keyword checks are performed within all textual data.

Artefacts an auditor will ask for
  • Evidence demonstrating: When manually exporting data from SECRET and TOP SECRET systems, digital signatu
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-0675
Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a tru

Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a trustworthy source.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data authorised for export from SECRET and TOP SECRET systems is digitally signe
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1187
When manually exporting data from systems, the data is checked for unsuitable protective m

When manually exporting data from systems, the data is checked for unsuitable protective markings.

Artefacts an auditor will ask for
  • Evidence demonstrating: When manually exporting data from systems, the data is checked for unsuitable pr
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1294
Data transfer logs for systems are partially verified at least monthly.

Data transfer logs for systems are partially verified at least monthly.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data transfer logs for systems are partially verified at least monthly.
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1535
Processes, and supporting procedures, are developed, implemented and maintained to prevent

Processes, and supporting procedures, are developed, implemented and maintained to prevent AUSTEO, AGAO and REL data in textual and non-textual formats from being exported to unsuitable foreign systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Processes, and supporting procedures, are developed, implemented and maintained
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1586
Data transfer logs are used to record all data imports and exports from systems.

Data transfer logs are used to record all data imports and exports from systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data transfer logs are used to record all data imports and exports from systems.
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1778
When manually importing data to systems, all data that fails security checks is quarantine

When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

Artefacts an auditor will ask for
  • Evidence demonstrating: When manually importing data to systems, all data that fails security checks is
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed
ISM-1779
When manually exporting data from systems, all data that fails security checks is quaranti

When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

Artefacts an auditor will ask for
  • Evidence demonstrating: When manually exporting data from systems, all data that fails security checks i
  • Data transfer logs
  • Export review and authorisation records
  • Content inspection / quarantine evidence
Where this commonly fails
  • Unauthorised data exports
  • Transfers not logged or reviewed

Guidelines for database systems

ISM-0393
Databases and their contents are classified based on the sensitivity or classification of

Databases and their contents are classified based on the sensitivity or classification of data that they contain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Databases and their contents are classified based on the sensitivity or classifi
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1243
A database register is developed, implemented, maintained and verified on a regular basis.

A database register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A database register is developed, implemented, maintained and verified on a regu
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1255
Database users' ability to access, insert, modify and remove database contents is restrict

Database users' ability to access, insert, modify and remove database contents is restricted based on their work duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: Database users' ability to access, insert, modify and remove database contents i
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1256
File-based access controls are applied to database files.

File-based access controls are applied to database files.

Artefacts an auditor will ask for
  • Evidence demonstrating: File-based access controls are applied to database files.
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1268
The need-to-know principle is enforced for database contents through the application of mi

The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: The need-to-know principle is enforced for database contents through the applica
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1269
Database servers and web servers are functionally separated.

Database servers and web servers are functionally separated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Database servers and web servers are functionally separated.
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1270
Database servers are placed on a different network segment to user workstations.

Database servers are placed on a different network segment to user workstations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Database servers are placed on a different network segment to user workstations.
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1271
Network access controls are implemented to restrict database server communications to stri

Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network access controls are implemented to restrict database server communicatio
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1272
If only local access to a database is required, networking functionality of database manag

If only local access to a database is required, networking functionality of database management system applications are disabled or directed to listen solely to the localhost interface.

Artefacts an auditor will ask for
  • Evidence demonstrating: If only local access to a database is required, networking functionality of data
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1273
Database servers for development, testing, staging and production environments are segrega

Database servers for development, testing, staging and production environments are segregated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Database servers for development, testing, staging and production environments a
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1274
Database contents from production environments are not used in non-production environments

Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

Artefacts an auditor will ask for
  • Evidence demonstrating: Database contents from production environments are not used in non-production en
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1277
Data communicated between database servers and web servers is encrypted.

Data communicated between database servers and web servers is encrypted.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data communicated between database servers and web servers is encrypted.
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges
ISM-1537
Security-relevant events for databases are centrally logged, including: - access or modifi

Security-relevant events for databases are centrally logged, including: - access or modification of particularly important content - addition of new users, especially privileged users - changes to user roles or privileges - attempts to elevate user privileges - queries containing comments - queries containing multiple embedded queries - database and query alerts or failures - database structure changes - database administrator actions - use of executable commands - database logons and logoffs.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for databases are centrally logged, including: - access
  • Database hardening configuration
  • Database access control records
  • Encryption of database communications/data
Where this commonly fails
  • Databases not hardened
  • Excessive database privileges

Guidelines for email

ISM-0264
An email usage policy is developed, implemented and maintained.

An email usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An email usage policy is developed, implemented and maintained.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0267
Access to non-approved webmail services is blocked.

Access to non-approved webmail services is blocked.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access to non-approved webmail services is blocked.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0269
Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To

Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To data are not sent to email distribution lists unless the nationality of all members of email distribution lists can be confirmed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Emails containing Australian Eyes Only, Australian Government Access Only or Rel
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0270
Protective markings are applied to emails and reflect the highest sensitivity or classific

Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Protective markings are applied to emails and reflect the highest sensitivity or
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0271
Protective marking tools do not automatically insert protective markings into emails.

Protective marking tools do not automatically insert protective markings into emails.

Artefacts an auditor will ask for
  • Evidence demonstrating: Protective marking tools do not automatically insert protective markings into em
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0272
Protective marking tools do not allow users to select protective markings that a system ha

Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.

Artefacts an auditor will ask for
  • Evidence demonstrating: Protective marking tools do not allow users to select protective markings that a
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0565
Email servers are configured to block, log and report emails with inappropriate protective

Email servers are configured to block, log and report emails with inappropriate protective markings.

Artefacts an auditor will ask for
  • Evidence demonstrating: Email servers are configured to block, log and report emails with inappropriate
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0567
Email servers only relay emails destined for or originating from their domains (including

Email servers only relay emails destined for or originating from their domains (including subdomains).

Artefacts an auditor will ask for
  • Evidence demonstrating: Email servers only relay emails destined for or originating from their domains (
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0569
Emails are routed via centralised email gateways.

Emails are routed via centralised email gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: Emails are routed via centralised email gateways.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0570
Where backup or alternative email gateways are in place, they are maintained at the same s

Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where backup or alternative email gateways are in place, they are maintained at
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0571
When users send or receive emails, an authenticated and encrypted channel is used to route

When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation's centralised email gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: When users send or receive emails, an authenticated and encrypted channel is use
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0572
Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing em

Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Opportunistic TLS encryption is enabled on email servers that make incoming or o
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0574
SPF is used to specify authorised email servers (or lack thereof) for an organisation's do

SPF is used to specify authorised email servers (or lack thereof) for an organisation's domains (including subdomains).

Artefacts an auditor will ask for
  • Evidence demonstrating: SPF is used to specify authorised email servers (or lack thereof) for an organis
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-0861
DKIM signing is enabled on emails originating from an organisation's domains (including su

DKIM signing is enabled on emails originating from an organisation's domains (including subdomains).

Artefacts an auditor will ask for
  • Evidence demonstrating: DKIM signing is enabled on emails originating from an organisation's domains (in
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1023
The intended recipients of blocked inbound emails, and the senders of blocked outbound ema

The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.

Artefacts an auditor will ask for
  • Evidence demonstrating: The intended recipients of blocked inbound emails, and the senders of blocked ou
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1024
Notifications of undeliverable emails are only sent to senders that can be verified via SP

Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.

Artefacts an auditor will ask for
  • Evidence demonstrating: Notifications of undeliverable emails are only sent to senders that can be verif
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1026
DKIM signatures on incoming emails are verified.

DKIM signatures on incoming emails are verified.

Artefacts an auditor will ask for
  • Evidence demonstrating: DKIM signatures on incoming emails are verified.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1027
Email distribution list applications used by external senders is configured such that it d

Email distribution list applications used by external senders is configured such that it does not break the validity of the sender's DKIM signature.

Artefacts an auditor will ask for
  • Evidence demonstrating: Email distribution list applications used by external senders is configured such
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1089
Protective marking tools do not allow users replying to or forwarding emails to select pro

Protective marking tools do not allow users replying to or forwarding emails to select protective markings lower than previously used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Protective marking tools do not allow users replying to or forwarding emails to
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1151
SPF is used to verify the authenticity of incoming emails.

SPF is used to verify the authenticity of incoming emails.

Artefacts an auditor will ask for
  • Evidence demonstrating: SPF is used to verify the authenticity of incoming emails.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1183
A hard fail SPF record is used when specifying authorised email servers (or lack thereof)

A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation's domains (including subdomains).

Artefacts an auditor will ask for
  • Evidence demonstrating: A hard fail SPF record is used when specifying authorised email servers (or lack
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1234
Email content filtering is implemented to filter potentially harmful content in email bodi

Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Email content filtering is implemented to filter potentially harmful content in
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1502
Emails arriving via an external connection where the email source address uses an internal

Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.

Artefacts an auditor will ask for
  • Evidence demonstrating: Emails arriving via an external connection where the email source address uses a
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1540
DMARC records are configured for an organisation's domains (including subdomains) such tha

DMARC records are configured for an organisation's domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.

Artefacts an auditor will ask for
  • Evidence demonstrating: DMARC records are configured for an organisation's domains (including subdomains
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1589
MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.

MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: MTA-STS is enabled to prevent the unencrypted transfer of emails between email s
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied
ISM-1799
Incoming emails are rejected if they do not pass DMARC checks.

Incoming emails are rejected if they do not pass DMARC checks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Incoming emails are rejected if they do not pass DMARC checks.
  • Email protective marking configuration
  • SPF/DKIM/DMARC records
  • Email content filtering configuration
Where this commonly fails
  • No DMARC/SPF/DKIM
  • No email content filtering
  • Protective marking not applied

Guidelines for enterprise mobility

ISM-0240
Paging, Multimedia Message Service, Short Message Service and messaging apps are not used

Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Paging, Multimedia Message Service, Short Message Service and messaging apps are
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0682
Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.

Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0687
Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that

Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that have been issued an Approval for Use by ASD and are operated in accordance with the latest version of their associated Australian Communications Security Instruction.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices that access SECRET or TOP SECRET systems or data use mobile platf
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0694
Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET s

Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privately-owned mobile devices and desktop computers do not access SECRET and TO
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0701
Mobile device emergency sanitisation processes, and supporting mobile device emergency san

Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile device emergency sanitisation processes, and supporting mobile device eme
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0702
If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SE

If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SECRET or TOP SECRET mobile device, the function is used as part of mobile device emergency sanitisation processes and procedures.

Artefacts an auditor will ask for
  • Evidence demonstrating: If a cryptographic zeroise or sanitise function is provided for cryptographic ke
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0705
When accessing an organisation's network via a VPN connection, split tunnelling is disable

When accessing an organisation's network via a VPN connection, split tunnelling is disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: When accessing an organisation's network via a VPN connection, split tunnelling
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0863
Mobile devices prevent personnel from installing non-approved applications once provisione

Mobile devices prevent personnel from installing non-approved applications once provisioned.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices prevent personnel from installing non-approved applications once
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0864
Mobile devices prevent personnel from disabling or modifying security functionality once p

Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices prevent personnel from disabling or modifying security functional
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0866
Sensitive or classified data is not viewed on mobile devices in public locations unless ca

Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Sensitive or classified data is not viewed on mobile devices in public locations
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0869
Mobile devices encrypt their internal storage and any removable media.

Mobile devices encrypt their internal storage and any removable media.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices encrypt their internal storage and any removable media.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0870
Mobile devices are carried or stored in a secured state when not being actively used.

Mobile devices are carried or stored in a secured state when not being actively used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are carried or stored in a secured state when not being actively
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0871
Mobile devices are kept under continual direct supervision when being actively used.

Mobile devices are kept under continual direct supervision when being actively used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are kept under continual direct supervision when being actively u
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-0874
Mobile devices and desktop computers access the internet via an organisation's internet ga

Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices and desktop computers access the internet via an organisation's i
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1082
A mobile device usage policy is developed, implemented and maintained.

A mobile device usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A mobile device usage policy is developed, implemented and maintained.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1083
Personnel are advised of the sensitivity or classification permitted for voice and data co

Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of the sensitivity or classification permitted for voice a
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1084
If unable to carry or store mobile devices in a secured state, they are physically transfe

If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.

Artefacts an auditor will ask for
  • Evidence demonstrating: If unable to carry or store mobile devices in a secured state, they are physical
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1085
Mobile devices encrypt all sensitive or classified data communicated over public network i

Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices encrypt all sensitive or classified data communicated over public
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1088
Personnel report the potential compromise of mobile devices, removable media or credential

Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they: - provide credentials to foreign government officials - decrypt mobile devices for foreign government officials - have mobile devices taken out of sight by foreign government officials - have mobile devices or removable media stolen, including if later returned - lose mobile devices or removable media, including if later found - observe unusual behaviour of mobile devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel report the potential compromise of mobile devices, removable media or
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1145
Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices.

Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devic
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1195
Mobile Device Management solutions that have completed a Common Criteria evaluation agains

Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile Device Management solutions that have completed a Common Criteria evaluat
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1196
Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain

Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1198
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is

Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile d
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1199
Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices ar

Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.

Artefacts an auditor will ask for
  • Evidence demonstrating: Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1200
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is

Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.

Artefacts an auditor will ask for
  • Evidence demonstrating: Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile d
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1297
Legal advice is sought prior to allowing privately-owned mobile devices and desktop comput

Legal advice is sought prior to allowing privately-owned mobile devices and desktop computers to access systems or data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Legal advice is sought prior to allowing privately-owned mobile devices and desk
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1298
Personnel are advised of privacy and security risks when travelling overseas with mobile d

Personnel are advised of privacy and security risks when travelling overseas with mobile devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of privacy and security risks when travelling overseas wit
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1299
Personnel are advised to take the following precautions when using mobile devices: - never

Personnel are advised to take the following precautions when using mobile devices: - never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes - never store credentials with mobile devices that they grant access to, such as in laptop computer bags - never lend mobile devices or removable media to untrusted people, even if briefly - never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging - never connect mobile devices to designated charging stations or wall outlet charging ports - never use gifted or unauthorised peripherals, chargers or removable media with mobile devices - never use removable media for data transfers or backups that have not been checked for malicious code beforehand - avoid reuse of removable media once used with other pa

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised to take the following precautions when using mobile device
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1300
Upon returning from travelling overseas with mobile devices, personnel take the following

Upon returning from travelling overseas with mobile devices, personnel take the following actions: - sanitise and reset mobile devices, including all removable media - decommission any credentials that left their possession during their travel - report if significant doubt exists as to the integrity of any mobile devices or removable media.

Artefacts an auditor will ask for
  • Evidence demonstrating: Upon returning from travelling overseas with mobile devices, personnel take the
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1366
Security updates are applied to mobile devices as soon as they become available.

Security updates are applied to mobile devices as soon as they become available.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security updates are applied to mobile devices as soon as they become available.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1400
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se

Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1482
Personnel using organisation-owned mobile devices or desktop computers to access classifie

Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel using organisation-owned mobile devices or desktop computers to access
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1533
A mobile device management policy is developed, implemented and maintained.

A mobile device management policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A mobile device management policy is developed, implemented and maintained.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1554
If travelling overseas with mobile devices to high or extreme risk countries, personnel ar

If travelling overseas with mobile devices to high or extreme risk countries, personnel are: - issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities - advised on how to apply and inspect tamper seals to key areas of mobile devices - advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.

Artefacts an auditor will ask for
  • Evidence demonstrating: If travelling overseas with mobile devices to high or extreme risk countries, pe
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1555
Before travelling overseas with mobile devices, personnel take the following actions: - re

Before travelling overseas with mobile devices, personnel take the following actions: - record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers - update all operating systems and applications - remove all non-essential data, applications and user accounts - backup all remaining data, applications and settings.

Artefacts an auditor will ask for
  • Evidence demonstrating: Before travelling overseas with mobile devices, personnel take the following act
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1556
If returning from travelling overseas with mobile devices to high or extreme risk countrie

If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions: - reset credentials used with mobile devices, including those used for remote access to their organisation's systems - monitor user accounts for any indicators of compromise, such as failed logon attempts.

Artefacts an auditor will ask for
  • Evidence demonstrating: If returning from travelling overseas with mobile devices to high or extreme ris
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1644
Sensitive or classified phone calls and conversations are not conducted in public location

Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.

Artefacts an auditor will ask for
  • Evidence demonstrating: Sensitive or classified phone calls and conversations are not conducted in publi
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1866
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se

Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately-owned mobile devices and desktop computers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1867
Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile pla

Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1868
SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand

SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand by ASD.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET and TOP SECRET mobile devices do not use removable media unless approved
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1886
Mobile devices are configured to operate in a supervised (or equivalent) mode.

Mobile devices are configured to operate in a supervised (or equivalent) mode.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured to operate in a supervised (or equivalent) mode.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1887
Mobile devices are configured with remote locate and wipe functionality.

Mobile devices are configured with remote locate and wipe functionality.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured with remote locate and wipe functionality.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-1888
Mobile devices are configured with secure password-based lock screens.

Mobile devices are configured with secure password-based lock screens.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured with secure password-based lock screens.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2095
Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Se

Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel using privately-owned mobile devices or desktop computers to access OF
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2096
Mobile devices are configured to enforce separation between organisational and personal mo

Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured to enforce separation between organisational and p
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2097
Mobile devices are configured with always on VPN functionality.

Mobile devices are configured with always on VPN functionality.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured with always on VPN functionality.
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2098
Mobile devices are configured to prevent data transfers over Universal Serial Bus connecti

Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are configured to prevent data transfers over Universal Serial Bu
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2099
Mobile devices are not connected to the infotainment systems of connected vehicles.

Mobile devices are not connected to the infotainment systems of connected vehicles.

Artefacts an auditor will ask for
  • Evidence demonstrating: Mobile devices are not connected to the infotainment systems of connected vehicl
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2100
Sensitive or classified data is not viewed on mobile devices within or near connected vehi

Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.

Artefacts an auditor will ask for
  • Evidence demonstrating: Sensitive or classified data is not viewed on mobile devices within or near conn
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process
ISM-2101
Sensitive or classified phone calls and conversations are not conducted within or near con

Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.

Artefacts an auditor will ask for
  • Evidence demonstrating: Sensitive or classified phone calls and conversations are not conducted within o
  • Mobile device management (MDM) configuration
  • Mobile device policy
  • Overseas travel briefings and device controls
Where this commonly fails
  • No MDM enforcement
  • BYOD allowed without controls
  • No travel security process

Guidelines for evaluated products

ISM-0280
If procuring an evaluated product, a product that has completed a PP-based evaluation, inc

If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.

Artefacts an auditor will ask for
  • Evidence demonstrating: If procuring an evaluated product, a product that has completed a PP-based evalu
  • Evaluated product selection records
  • Protection Profile / evaluation evidence
  • Evidence products run in their evaluated configuration
Where this commonly fails
  • Unevaluated products used for high assurance
  • Products not in evaluated configuration
ISM-0285
Evaluated products are delivered in a manner consistent with any delivery procedures defin

Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated products are delivered in a manner consistent with any delivery proced
  • Evaluated product selection records
  • Protection Profile / evaluation evidence
  • Evidence products run in their evaluated configuration
Where this commonly fails
  • Unevaluated products used for high assurance
  • Products not in evaluated configuration
ISM-0286
When procuring high assurance information technology (IT) equipment, ASD is contacted for

When procuring high assurance information technology (IT) equipment, ASD is contacted for any equipment-specific delivery procedures.

Artefacts an auditor will ask for
  • Evidence demonstrating: When procuring high assurance information technology (IT) equipment, ASD is cont
  • Evaluated product selection records
  • Protection Profile / evaluation evidence
  • Evidence products run in their evaluated configuration
Where this commonly fails
  • Unevaluated products used for high assurance
  • Products not in evaluated configuration
ISM-0289
Evaluated products are installed, configured, administered and operated in an evaluated co

Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated products are installed, configured, administered and operated in an ev
  • Evaluated product selection records
  • Protection Profile / evaluation evidence
  • Evidence products run in their evaluated configuration
Where this commonly fails
  • Unevaluated products used for high assurance
  • Products not in evaluated configuration
ISM-0290
High assurance IT equipment is installed, configured, administered and operated in an eval

High assurance IT equipment is installed, configured, administered and operated in an evaluated configuration and in accordance with ASD guidance.

Artefacts an auditor will ask for
  • Evidence demonstrating: High assurance IT equipment is installed, configured, administered and operated
  • Evaluated product selection records
  • Protection Profile / evaluation evidence
  • Evidence products run in their evaluated configuration
Where this commonly fails
  • Unevaluated products used for high assurance
  • Products not in evaluated configuration

Guidelines for gateways

ISM-0100
Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessm

Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IR
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0260
All web access, including that by internal servers, is conducted through web proxies.

All web access, including that by internal servers, is conducted through web proxies.

Artefacts an auditor will ask for
  • Evidence demonstrating: All web access, including that by internal servers, is conducted through web pro
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0261
The following details are centrally logged for websites accessed via web proxies: - web ad

The following details are centrally logged for websites accessed via web proxies: - web address - date and time - user - amount of data uploaded and downloaded - internal and external IP addresses.

Artefacts an auditor will ask for
  • Evidence demonstrating: The following details are centrally logged for websites accessed via web proxies
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0263
TLS traffic communicated through gateways is decrypted and inspected.

TLS traffic communicated through gateways is decrypted and inspected.

Artefacts an auditor will ask for
  • Evidence demonstrating: TLS traffic communicated through gateways is decrypted and inspected.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0591
Evaluated peripheral switches are used when sharing peripherals between systems.

Evaluated peripheral switches are used when sharing peripherals between systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated peripheral switches are used when sharing peripherals between systems.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0597
When planning, designing, implementing or introducing additional connectivity to CDSs, ASD

When planning, designing, implementing or introducing additional connectivity to CDSs, ASD is consulted and any directions provided by ASD are complied with.

Artefacts an auditor will ask for
  • Evidence demonstrating: When planning, designing, implementing or introducing additional connectivity to
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0610
Users are trained on the secure use of CDSs before access is granted.

Users are trained on the secure use of CDSs before access is granted.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users are trained on the secure use of CDSs before access is granted.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0611
System administrators for gateways are assigned the minimum privileges required to perform

System administrators for gateways are assigned the minimum privileges required to perform their duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators for gateways are assigned the minimum privileges required
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0612
System administrators for gateways are formally trained on the operation and management of

System administrators for gateways are formally trained on the operation and management of gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators for gateways are formally trained on the operation and man
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0613
System administrators for gateways that connect to Australian Eyes Only or Releasable To n

System administrators for gateways that connect to Australian Eyes Only or Releasable To networks are Australian nationals.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators for gateways that connect to Australian Eyes Only or Relea
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0616
Separation of duties is implemented in performing administrative activities for gateways.

Separation of duties is implemented in performing administrative activities for gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: Separation of duties is implemented in performing administrative activities for
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0619
Users authenticate to other networks accessed via gateways.

Users authenticate to other networks accessed via gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users authenticate to other networks accessed via gateways.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0622
IT equipment authenticates to other networks accessed via gateways.

IT equipment authenticates to other networks accessed via gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment authenticates to other networks accessed via gateways.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0626
CDSs are implemented between SECRET or TOP SECRET networks and any other networks belongin

CDSs are implemented between SECRET or TOP SECRET networks and any other networks belonging to different security domains.

Artefacts an auditor will ask for
  • Evidence demonstrating: CDSs are implemented between SECRET or TOP SECRET networks and any other network
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0628
Gateways are implemented between networks belonging to different security domains.

Gateways are implemented between networks belonging to different security domains.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways are implemented between networks belonging to different security domain
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0629
For gateways between networks belonging to different security domains, any shared componen

For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.

Artefacts an auditor will ask for
  • Evidence demonstrating: For gateways between networks belonging to different security domains, any share
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0631
Gateways only allow explicitly authorised data flows.

Gateways only allow explicitly authorised data flows.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways only allow explicitly authorised data flows.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0634
Security-relevant events for gateways are centrally logged, including: - data packets and

Security-relevant events for gateways are centrally logged, including: - data packets and data flows permitted through gateways - data packets and data flows attempting to leave gateways - real-time alerts for attempted intrusions.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for gateways are centrally logged, including: - data pa
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0635
CDSs implement isolated upward and downward network paths.

CDSs implement isolated upward and downward network paths.

Artefacts an auditor will ask for
  • Evidence demonstrating: CDSs implement isolated upward and downward network paths.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0637
Gateways implement a demilitarised zone if external parties require access to an organisat

Gateways implement a demilitarised zone if external parties require access to an organisation's services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways implement a demilitarised zone if external parties require access to an
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0639
Evaluated firewalls are used between networks belonging to different security domains.

Evaluated firewalls are used between networks belonging to different security domains.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated firewalls are used between networks belonging to different security do
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0643
Evaluated diodes are used for controlling the data flow of unidirectional gateways between

Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation's networks and public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated diodes are used for controlling the data flow of unidirectional gatewa
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0645
Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC

Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and public network infrastructure complete a high assurance evaluation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated diodes used for controlling the data flow of unidirectional gateways b
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0649
Files imported or exported via gateways or CDSs are filtered for allowed file types.

Files imported or exported via gateways or CDSs are filtered for allowed file types.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs are filtered for allowed file ty
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0651
Files identified by content filtering checks as malicious, or that cannot be inspected, ar

Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files identified by content filtering checks as malicious, or that cannot be ins
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0652
Files identified by content filtering checks as suspicious are quarantined until reviewed

Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files identified by content filtering checks as suspicious are quarantined until
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0659
Files imported or exported via gateways or CDSs undergo content filtering checks.

Files imported or exported via gateways or CDSs undergo content filtering checks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content filtering checks
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0670
Security-relevant events for CDSs are centrally logged.

Security-relevant events for CDSs are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for CDSs are centrally logged.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0677
Files imported or exported via gateways or CDSs that have a digital signature or cryptogra

Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs that have a digital signature or
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0958
An organisation-approved list of domain names, or list of website categories, is implement

An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: An organisation-approved list of domain names, or list of website categories, is
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0961
Client-side active content is restricted by web content filters to an organisation-approve

Client-side active content is restricted by web content filters to an organisation-approved list of domain names.

Artefacts an auditor will ask for
  • Evidence demonstrating: Client-side active content is restricted by web content filters to an organisati
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-0963
Web content filtering is implemented to filter potentially harmful web-based content.

Web content filtering is implemented to filter potentially harmful web-based content.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web content filtering is implemented to filter potentially harmful web-based con
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1037
Gateways undergo testing following configuration changes, and at regular intervals no more

Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate they conform to expected security configurations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways undergo testing following configuration changes, and at regular interva
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1157
Evaluated diodes are used for controlling the data flow of unidirectional gateways between

Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated diodes are used for controlling the data flow of unidirectional gatewa
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1158
Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC

Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and any other networks complete a high assurance evaluation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated diodes used for controlling the data flow of unidirectional gateways b
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1171
Attempts to access websites through their IP addresses instead of their domain names are b

Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Attempts to access websites through their IP addresses instead of their domain n
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1192
Gateways inspect and filter data flows at the transport and above network layers.

Gateways inspect and filter data flows at the transport and above network layers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways inspect and filter data flows at the transport and above network layers
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1236
Malicious domain names, dynamic domain names and domain names that can be registered anony

Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Malicious domain names, dynamic domain names and domain names that can be regist
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1237
Web content filtering is applied to outbound web traffic where appropriate.

Web content filtering is applied to outbound web traffic where appropriate.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web content filtering is applied to outbound web traffic where appropriate.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1284
Files imported or exported via gateways or CDSs undergo content validation.

Files imported or exported via gateways or CDSs undergo content validation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content validation.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1286
Files imported or exported via gateways or CDSs undergo content conversion.

Files imported or exported via gateways or CDSs undergo content conversion.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content conversion.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1287
Files imported or exported via gateways or CDSs undergo content sanitisation.

Files imported or exported via gateways or CDSs undergo content sanitisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content sanitisation.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1288
Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple

Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo antivirus scanning using
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1289
Archive files imported or exported via gateways or CDSs are unpacked in order to undergo c

Archive files imported or exported via gateways or CDSs are unpacked in order to undergo content filtering checks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Archive files imported or exported via gateways or CDSs are unpacked in order to
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1290
Archive files are unpacked in a controlled manner to ensure content filter performance or

Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.

Artefacts an auditor will ask for
  • Evidence demonstrating: Archive files are unpacked in a controlled manner to ensure content filter perfo
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1293
Encrypted files imported or exported via gateways or CDSs are decrypted in order to underg

Encrypted files imported or exported via gateways or CDSs are decrypted in order to undergo content filtering checks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Encrypted files imported or exported via gateways or CDSs are decrypted in order
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1389
Executable files imported via gateways or CDSs are automatically executed in a sandbox to

Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.

Artefacts an auditor will ask for
  • Evidence demonstrating: Executable files imported via gateways or CDSs are automatically executed in a s
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1427
Gateways perform ingress traffic filtering to detect and prevent IP source address spoofin

Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways perform ingress traffic filtering to detect and prevent IP source addre
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1457
Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET s

Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET systems, or between SECRET or TOP SECRET systems belonging to different security domains, preferably complete a high assurance evaluation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated peripheral switches used for sharing peripherals between SECRET and TO
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1480
Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET sy

Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET systems and any non-SECRET or TOP SECRET systems complete a high assurance evaluation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated peripheral switches used for sharing peripherals between SECRET or TOP
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1520
System administrators for gateways undergo appropriate employment screening, and where nec

System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators for gateways undergo appropriate employment screening, and
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1521
CDSs implement protocol breaks at each network layer.

CDSs implement protocol breaks at each network layer.

Artefacts an auditor will ask for
  • Evidence demonstrating: CDSs implement protocol breaks at each network layer.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1522
CDSs implement independent security-enforcing functions for upward and downward network pa

CDSs implement independent security-enforcing functions for upward and downward network paths.

Artefacts an auditor will ask for
  • Evidence demonstrating: CDSs implement independent security-enforcing functions for upward and downward
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1523
A sample of security-relevant events relating to data transfer policies are taken at least

A sample of security-relevant events relating to data transfer policies are taken at least every three months and assessed against security policies for CDSs to identify any operational failures.

Artefacts an auditor will ask for
  • Evidence demonstrating: A sample of security-relevant events relating to data transfer policies are take
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1524
Content filters used by CDSs undergo rigorous security testing to ensure they perform as e

Content filters used by CDSs undergo rigorous security testing to ensure they perform as expected and cannot be bypassed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Content filters used by CDSs undergo rigorous security testing to ensure they pe
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1528
Evaluated firewalls are used between an organisation's networks and public network infrast

Evaluated firewalls are used between an organisation's networks and public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated firewalls are used between an organisation's networks and public netwo
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1773
System administrators for gateways that connect to Australian Government Access Only netwo

System administrators for gateways that connect to Australian Government Access Only networks are Australian nationals or seconded foreign nationals.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators for gateways that connect to Australian Government Access
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1774
Gateways are managed via a secure path isolated from all connected networks.

Gateways are managed via a secure path isolated from all connected networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Gateways are managed via a secure path isolated from all connected networks.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1783
Public IP addresses controlled by, or used by, an organisation are signed by valid ROA rec

Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.

Artefacts an auditor will ask for
  • Evidence demonstrating: Public IP addresses controlled by, or used by, an organisation are signed by val
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1862
If using a WAF, disclosing the IP addresses of web servers under an organisation's control

If using a WAF, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: If using a WAF, disclosing the IP addresses of web servers under an organisation
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-1965
Files imported or exported via gateways or CDSs undergo content checking.

Files imported or exported via gateways or CDSs undergo content checking.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files imported or exported via gateways or CDSs undergo content checking.
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-2018
Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous System

Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.

Artefacts an auditor will ask for
  • Evidence demonstrating: Routes for RPKI-registered IP addresses that are advertised from invalid Autonom
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows
ISM-2019
TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), u

TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: TOP SECRET gateways undergo a security assessment by ASD assessors (or their del
  • Gateway configuration
  • Firewall rule-set and review records
  • Cross Domain Solution / web & content filtering configuration
Where this commonly fails
  • Firewall rules not reviewed
  • Unrestricted gateway data flows

Guidelines for information technology equipment

ISM-0293
IT equipment is classified based on the highest sensitivity or classification of data that

IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment is classified based on the highest sensitivity or classification of
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0294
IT equipment, with the exception of high assurance IT equipment, is labelled with protecti

IT equipment, with the exception of high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment, with the exception of high assurance IT equipment, is labelled wit
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0296
ASD's approval is sought before applying labels to external surfaces of high assurance IT

ASD's approval is sought before applying labels to external surfaces of high assurance IT equipment.

Artefacts an auditor will ask for
  • Evidence demonstrating: ASD's approval is sought before applying labels to external surfaces of high ass
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0305
Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared

Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared technician.

Artefacts an auditor will ask for
  • Evidence demonstrating: Maintenance and repairs of IT equipment is carried out on site by an appropriate
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0306
If an appropriately cleared technician is not used to undertake maintenance or repairs of

If an appropriately cleared technician is not used to undertake maintenance or repairs of IT equipment, the technician is escorted by someone who: - is appropriately cleared and briefed - takes due care to ensure that data is not disclosed - takes all responsible measures to ensure the integrity of the IT equipment - has the authority to direct the technician - is sufficiently familiar with the IT equipment to understand the work being performed.

Artefacts an auditor will ask for
  • Evidence demonstrating: If an appropriately cleared technician is not used to undertake maintenance or r
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0307
If an appropriately cleared technician is not used to undertake maintenance or repairs of

If an appropriately cleared technician is not used to undertake maintenance or repairs of IT equipment, the IT equipment and associated media is sanitised before maintenance or repair work is undertaken.

Artefacts an auditor will ask for
  • Evidence demonstrating: If an appropriately cleared technician is not used to undertake maintenance or r
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0310
IT equipment maintained or repaired off site is done so at facilities approved for handlin

IT equipment maintained or repaired off site is done so at facilities approved for handling the sensitivity or classification of the IT equipment.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment maintained or repaired off site is done so at facilities approved f
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0311
IT equipment containing media is sanitised by removing the media from the IT equipment or

IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment containing media is sanitised by removing the media from the IT equ
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0312
IT equipment, including associated media, that is located overseas and has processed, stor

IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data that cannot be sanitised in situ, is returned to Australia for destruction.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment, including associated media, that is located overseas and has proce
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0313
IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures,

IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment sanitisation processes, and supporting IT equipment sanitisation pr
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0315
High assurance IT equipment is destroyed prior to its disposal.

High assurance IT equipment is destroyed prior to its disposal.

Artefacts an auditor will ask for
  • Evidence demonstrating: High assurance IT equipment is destroyed prior to its disposal.
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0316
Following sanitisation, destruction or declassification, a formal administrative decision

Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, destruction or declassification, a formal administrative
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0317
At least three pages of random text with no blank areas are printed on each colour printer

At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.

Artefacts an auditor will ask for
  • Evidence demonstrating: At least three pages of random text with no blank areas are printed on each colo
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0318
When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per e

When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: When unable to sanitise printer cartridges or MFD print drums, they are destroye
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0321
When disposing of IT equipment that has been designed or modified to meet emanation securi

When disposing of IT equipment that has been designed or modified to meet emanation security standards, ASD is contacted for requirements relating to its disposal.

Artefacts an auditor will ask for
  • Evidence demonstrating: When disposing of IT equipment that has been designed or modified to meet emanat
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-0336
A networked IT equipment register is developed, implemented, maintained and verified on a

A networked IT equipment register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A networked IT equipment register is developed, implemented, maintained and veri
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1076
Televisions and computer monitors with minor burn-in or image persistence are sanitised by

Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period of time.

Artefacts an auditor will ask for
  • Evidence demonstrating: Televisions and computer monitors with minor burn-in or image persistence are sa
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1079
ASD's approval is sought before undertaking any maintenance or repairs to high assurance I

ASD's approval is sought before undertaking any maintenance or repairs to high assurance IT equipment.

Artefacts an auditor will ask for
  • Evidence demonstrating: ASD's approval is sought before undertaking any maintenance or repairs to high a
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1217
Labels and markings indicating the owner, sensitivity, classification or any other marking

Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.

Artefacts an auditor will ask for
  • Evidence demonstrating: Labels and markings indicating the owner, sensitivity, classification or any oth
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1218
IT equipment, including associated media, that is located overseas and has processed, stor

IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data, is sanitised in situ.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment, including associated media, that is located overseas and has proce
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1219
MFD print drums and image transfer rollers are inspected and destroyed if there is remnant

MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner which cannot be removed or a print is visible on the image transfer roller.

Artefacts an auditor will ask for
  • Evidence demonstrating: MFD print drums and image transfer rollers are inspected and destroyed if there
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1220
Printer and MFD platens are inspected and destroyed if any text or images are retained on

Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.

Artefacts an auditor will ask for
  • Evidence demonstrating: Printer and MFD platens are inspected and destroyed if any text or images are re
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1221
Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a pa

Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.

Artefacts an auditor will ask for
  • Evidence demonstrating: Printers and MFDs are checked to ensure no pages are trapped in the paper path d
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1222
Televisions and computer monitors that cannot be sanitised are destroyed.

Televisions and computer monitors that cannot be sanitised are destroyed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Televisions and computer monitors that cannot be sanitised are destroyed.
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1223
Memory in network devices is sanitised using the following processes, in order of preferen

Memory in network devices is sanitised using the following processes, in order of preference: - following device-specific guidance provided in evaluation documentation - following vendor sanitisation guidance - loading a dummy configuration file, performing a factory reset and then reinstalling firmware.

Artefacts an auditor will ask for
  • Evidence demonstrating: Memory in network devices is sanitised using the following processes, in order o
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1534
Printer ribbons in printers and MFDs are removed and destroyed.

Printer ribbons in printers and MFDs are removed and destroyed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Printer ribbons in printers and MFDs are removed and destroyed.
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1550
IT equipment disposal processes, and supporting IT equipment disposal procedures, are deve

IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment disposal processes, and supporting IT equipment disposal procedures
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1551
An IT equipment management policy is developed, implemented and maintained.

An IT equipment management policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An IT equipment management policy is developed, implemented and maintained.
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1598
Following maintenance or repair activities for IT equipment, the IT equipment is inspected

Following maintenance or repair activities for IT equipment, the IT equipment is inspected to confirm it retains its approved configuration and that no unauthorised modifications have taken place.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following maintenance or repair activities for IT equipment, the IT equipment is
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1599
IT equipment is handled in a manner suitable for its sensitivity or classification.

IT equipment is handled in a manner suitable for its sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment is handled in a manner suitable for its sensitivity or classificati
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1741
IT equipment destruction processes, and supporting IT equipment destruction procedures, ar

IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment destruction processes, and supporting IT equipment destruction proc
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1742
IT equipment that cannot be sanitised is destroyed.

IT equipment that cannot be sanitised is destroyed.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment that cannot be sanitised is destroyed.
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1858
IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictiv

IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment is hardened using ASD and vendor hardening guidance, with the most
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1869
A non-networked IT equipment register is developed, implemented, maintained and verified o

A non-networked IT equipment register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A non-networked IT equipment register is developed, implemented, maintained and
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register
ISM-1913
Approved configurations for IT equipment are developed, implemented and maintained.

Approved configurations for IT equipment are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Approved configurations for IT equipment are developed, implemented and maintain
  • IT equipment register
  • Sanitisation/destruction records
  • Disposal and movement records
Where this commonly fails
  • Equipment not sanitised before disposal
  • No equipment register

Guidelines for media

ISM-0323
Media is classified to the highest sensitivity or classification of data it stores, unless

Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media is classified to the highest sensitivity or classification of data it stor
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0325
Any media connected to a system with a higher sensitivity or classification than the media

Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.

Artefacts an auditor will ask for
  • Evidence demonstrating: Any media connected to a system with a higher sensitivity or classification than
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0330
Before reclassifying media to a lower sensitivity or classification, the media is sanitise

Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.

Artefacts an auditor will ask for
  • Evidence demonstrating: Before reclassifying media to a lower sensitivity or classification, the media i
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0332
Media, with the exception of internally mounted fixed media within information technology

Media, with the exception of internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media, with the exception of internally mounted fixed media within information t
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0337
Media is only used with systems that are authorised to process, store or communicate its s

Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media is only used with systems that are authorised to process, store or communi
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0347
When transferring data manually between two systems belonging to different security domain

When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.

Artefacts an auditor will ask for
  • Evidence demonstrating: When transferring data manually between two systems belonging to different secur
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0348
Media sanitisation processes, and supporting media sanitisation procedures, are developed,

Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media sanitisation processes, and supporting media sanitisation procedures, are
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0350
The following media types are destroyed prior to their disposal: - microfiche and microfil

The following media types are destroyed prior to their disposal: - microfiche and microfilm - optical discs - programmable read-only memory - read-only memory - other types of media that cannot be sanitised.

Artefacts an auditor will ask for
  • Evidence demonstrating: The following media types are destroyed prior to their disposal: - microfiche an
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0351
Volatile media is sanitised by removing its power for at least 10 minutes.

Volatile media is sanitised by removing its power for at least 10 minutes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Volatile media is sanitised by removing its power for at least 10 minutes.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0352
SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its e

SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

Artefacts an auditor will ask for
  • Evidence demonstrating: SECRET and TOP SECRET volatile media is sanitised by overwriting it at least onc
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0354
Non-volatile magnetic media is sanitised by overwriting it at least once (or three times i

Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-volatile magnetic media is sanitised by overwriting it at least once (or thr
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0356
Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its clas

Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retain
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0357
Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified

Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-volatile EPROM media is sanitised by applying three times the manufacturer's
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0358
Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains

Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains its classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM medi
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0359
Non-volatile flash memory media is sanitised by overwriting it at least twice in its entir

Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-volatile flash memory media is sanitised by overwriting it at least twice in
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0360
Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its

Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media re
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0361
Magnetic media is destroyed using a degausser with a suitable magnetic field strength and

Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Magnetic media is destroyed using a degausser with a suitable magnetic field str
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0362
Product-specific directions provided by degausser manufacturers are followed.

Product-specific directions provided by degausser manufacturers are followed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Product-specific directions provided by degausser manufacturers are followed.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0363
Media destruction processes, and supporting media destruction procedures, are developed, i

Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media destruction processes, and supporting media destruction procedures, are de
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0368
Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results i

Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0370
The destruction of media is performed under the supervision of at least one cleared person

The destruction of media is performed under the supervision of at least one cleared person.

Artefacts an auditor will ask for
  • Evidence demonstrating: The destruction of media is performed under the supervision of at least one clea
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0371
Personnel supervising the destruction of media supervise its handling to the point of dest

Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel supervising the destruction of media supervise its handling to the poi
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0372
The destruction of media storing accountable material is performed under the supervision o

The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.

Artefacts an auditor will ask for
  • Evidence demonstrating: The destruction of media storing accountable material is performed under the sup
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0373
Personnel supervising the destruction of media storing accountable material supervise its

Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel supervising the destruction of media storing accountable material supe
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0374
Media disposal processes, and supporting media disposal procedures, are developed, impleme

Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media disposal processes, and supporting media disposal procedures, are develope
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0375
Following sanitisation, destruction or declassification, a formal administrative decision

Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, destruction or declassification, a formal administrative
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0378
Labels and markings indicating the owner, sensitivity, classification or any other marking

Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.

Artefacts an auditor will ask for
  • Evidence demonstrating: Labels and markings indicating the owner, sensitivity, classification or any oth
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0831
Media is handled in a manner suitable for its sensitivity or classification.

Media is handled in a manner suitable for its sensitivity or classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media is handled in a manner suitable for its sensitivity or classification.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0835
Following sanitisation, TOP SECRET volatile media retains its classification if it stored

Following sanitisation, TOP SECRET volatile media retains its classification if it stored static data for an extended period of time, or had data repeatedly stored on or written to the same memory location for an extended period of time.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following sanitisation, TOP SECRET volatile media retains its classification if
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0836
Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety wit

Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-volatile EEPROM media is sanitised by overwriting it at least once in its en
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0839
The destruction of media storing accountable material is not outsourced.

The destruction of media storing accountable material is not outsourced.

Artefacts an auditor will ask for
  • Evidence demonstrating: The destruction of media storing accountable material is not outsourced.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0840
When outsourcing the destruction of media storing non-accountable material, a National Ass

When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO's Protective Security Circular-167, is used.

Artefacts an auditor will ask for
  • Evidence demonstrating: When outsourcing the destruction of media storing non-accountable material, a Na
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-0947
When transferring data manually between two systems belonging to different security domain

When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.

Artefacts an auditor will ask for
  • Evidence demonstrating: When transferring data manually between two systems belonging to different secur
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1059
All data stored on media is encrypted.

All data stored on media is encrypted.

Artefacts an auditor will ask for
  • Evidence demonstrating: All data stored on media is encrypted.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1065
The host-protected area and device configuration overlay table are reset prior to the sani

The host-protected area and device configuration overlay table are reset prior to the sanitisation of non-volatile magnetic hard drives.

Artefacts an auditor will ask for
  • Evidence demonstrating: The host-protected area and device configuration overlay table are reset prior t
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1067
The ATA secure erase command is used, in addition to block overwriting software, to ensure

The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.

Artefacts an auditor will ask for
  • Evidence demonstrating: The ATA secure erase command is used, in addition to block overwriting software,
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1160
If using degaussers to destroy media, degaussers evaluated by the United States' National

If using degaussers to destroy media, degaussers evaluated by the United States' National Security Agency are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: If using degaussers to destroy media, degaussers evaluated by the United States'
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1359
A removable media usage policy is developed, implemented and maintained.

A removable media usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A removable media usage policy is developed, implemented and maintained.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1361
Security Construction and Equipment Committee-approved equipment or ASIO-approved equipmen

Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security Construction and Equipment Committee-approved equipment or ASIO-approve
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1517
Equipment that is capable of reducing microform to a fine powder, with resultant particles

Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.

Artefacts an auditor will ask for
  • Evidence demonstrating: Equipment that is capable of reducing microform to a fine powder, with resultant
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1549
A media management policy is developed, implemented and maintained.

A media management policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A media management policy is developed, implemented and maintained.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1600
Media is sanitised before it is used for the first time.

Media is sanitised before it is used for the first time.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media is sanitised before it is used for the first time.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1641
Following the use of a degausser, magnetic media is physically damaged by deforming any in

Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Following the use of a degausser, magnetic media is physically damaged by deform
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1642
Media is sanitised before it is reused in a different security domain.

Media is sanitised before it is reused in a different security domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media is sanitised before it is reused in a different security domain.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1713
A removable media register is developed, implemented, maintained and verified on a regular

A removable media register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A removable media register is developed, implemented, maintained and verified on
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1722
Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disin

Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.

Artefacts an auditor will ask for
  • Evidence demonstrating: Electrostatic memory devices are destroyed using a furnace/incinerator, hammer m
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1723
Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrato

Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

Artefacts an auditor will ask for
  • Evidence demonstrating: Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, di
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1724
Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator,

Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.

Artefacts an auditor will ask for
  • Evidence demonstrating: Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disi
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1725
Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, dega

Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

Artefacts an auditor will ask for
  • Evidence demonstrating: Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegr
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1726
Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grind

Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.

Artefacts an auditor will ask for
  • Evidence demonstrating: Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegra
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1727
Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrato

Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.

Artefacts an auditor will ask for
  • Evidence demonstrating: Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or di
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1728
The resulting media waste particles from the destruction of SECRET media is stored and han

The resulting media waste particles from the destruction of SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, PROTECTED if greater than 3 mm and less than or equal to 6 mm, or SECRET if greater than 6 mm and less than or equal to 9 mm.

Artefacts an auditor will ask for
  • Evidence demonstrating: The resulting media waste particles from the destruction of SECRET media is stor
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1729
The resulting media waste particles from the destruction of TOP SECRET media is stored and

The resulting media waste particles from the destruction of TOP SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, or SECRET if greater than 3 mm and less than or equal to 9 mm.

Artefacts an auditor will ask for
  • Evidence demonstrating: The resulting media waste particles from the destruction of TOP SECRET media is
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media
ISM-1735
Media that cannot be successfully sanitised is destroyed prior to its disposal.

Media that cannot be successfully sanitised is destroyed prior to its disposal.

Artefacts an auditor will ask for
  • Evidence demonstrating: Media that cannot be successfully sanitised is destroyed prior to its disposal.
  • Media register
  • Sanitisation/destruction logs
  • Media labelling and classification records
Where this commonly fails
  • Media not sanitised before reuse/disposal
  • Unlabelled or misclassified media

Guidelines for networking

ISM-0385
Servers maintain effective functional separation with other servers allowing them to opera

Servers maintain effective functional separation with other servers allowing them to operate independently.

Artefacts an auditor will ask for
  • Evidence demonstrating: Servers maintain effective functional separation with other servers allowing the
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0516
Network documentation includes high-level network diagrams showing all connections into ne

Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network documentation includes high-level network diagrams showing all connectio
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0518
Network documentation is developed, implemented and maintained.

Network documentation is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network documentation is developed, implemented and maintained.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0520
Network access controls are implemented on networks to prevent the connection of unauthori

Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network access controls are implemented on networks to prevent the connection of
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0521
IPv6 functionality is disabled in dual-stack network devices unless it is being used.

IPv6 functionality is disabled in dual-stack network devices unless it is being used.

Artefacts an auditor will ask for
  • Evidence demonstrating: IPv6 functionality is disabled in dual-stack network devices unless it is being
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0529
VLANs are not used to separate network traffic between networks belonging to different sec

VLANs are not used to separate network traffic between networks belonging to different security domains.

Artefacts an auditor will ask for
  • Evidence demonstrating: VLANs are not used to separate network traffic between networks belonging to dif
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0530
Network devices managing VLANs are administered from the most trusted security domain.

Network devices managing VLANs are administered from the most trusted security domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices managing VLANs are administered from the most trusted security d
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0534
Unused physical ports on network devices are disabled.

Unused physical ports on network devices are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unused physical ports on network devices are disabled.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0535
Network devices managing VLANs belonging to different security domains do not share VLAN t

Network devices managing VLANs belonging to different security domains do not share VLAN trunks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices managing VLANs belonging to different security domains do not sh
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-0536
Public wireless networks provided for general public use are segregated from all other org

Public wireless networks provided for general public use are segregated from all other organisation networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Public wireless networks provided for general public use are segregated from all
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1006
Security measures are implemented to prevent unauthorised access to network management tra

Security measures are implemented to prevent unauthorised access to network management traffic.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security measures are implemented to prevent unauthorised access to network mana
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1013
The effective range of wireless communications outside an organisation's area of control i

The effective range of wireless communications outside an organisation's area of control is limited by implementing RF shielding on facilities in which SECRET or TOP SECRET wireless networks are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The effective range of wireless communications outside an organisation's area of
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1028
A NIDS or NIPS is deployed in gateways between an organisation's networks and other networ

A NIDS or NIPS is deployed in gateways between an organisation's networks and other networks they do not manage.

Artefacts an auditor will ask for
  • Evidence demonstrating: A NIDS or NIPS is deployed in gateways between an organisation's networks and ot
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1030
A NIDS or NIPS is located immediately inside the outermost firewall for gateways and confi

A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.

Artefacts an auditor will ask for
  • Evidence demonstrating: A NIDS or NIPS is located immediately inside the outermost firewall for gateways
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1178
Network documentation provided to a third party, or published in public tender documentati

Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network documentation provided to a third party, or published in public tender d
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1181
Networks are segregated into multiple network zones according to the criticality of server

Networks are segregated into multiple network zones according to the criticality of servers, services and data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Networks are segregated into multiple network zones according to the criticality
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1182
Network access controls are implemented to limit the flow of network traffic within and be

Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network access controls are implemented to limit the flow of network traffic wit
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1186
IPv6 capable network security appliances are used on IPv6 and dual-stack networks.

IPv6 capable network security appliances are used on IPv6 and dual-stack networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: IPv6 capable network security appliances are used on IPv6 and dual-stack network
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1304
Default user accounts or credentials for network devices, including for any pre-configured

Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Artefacts an auditor will ask for
  • Evidence demonstrating: Default user accounts or credentials for network devices, including for any pre-
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1311
SNMP version 1 and SNMP version 2 are not used on networks.

SNMP version 1 and SNMP version 2 are not used on networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: SNMP version 1 and SNMP version 2 are not used on networks.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1312
All default SNMP community strings on network devices are changed and write access is disa

All default SNMP community strings on network devices are changed and write access is disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: All default SNMP community strings on network devices are changed and write acce
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1314
All wireless devices are Wi-Fi Alliance certified.

All wireless devices are Wi-Fi Alliance certified.

Artefacts an auditor will ask for
  • Evidence demonstrating: All wireless devices are Wi-Fi Alliance certified.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1315
The administrative interface on wireless access points is disabled for wireless network co

The administrative interface on wireless access points is disabled for wireless network connections.

Artefacts an auditor will ask for
  • Evidence demonstrating: The administrative interface on wireless access points is disabled for wireless
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1316
Default SSIDs of wireless access points are changed.

Default SSIDs of wireless access points are changed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Default SSIDs of wireless access points are changed.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1317
SSIDs of non-public wireless networks are not readily associated with an organisation, the

SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: SSIDs of non-public wireless networks are not readily associated with an organis
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1318
SSID broadcasting is not disabled on wireless access points.

SSID broadcasting is not disabled on wireless access points.

Artefacts an auditor will ask for
  • Evidence demonstrating: SSID broadcasting is not disabled on wireless access points.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1319
Static addressing is not used for assigning IP addresses on wireless networks.

Static addressing is not used for assigning IP addresses on wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Static addressing is not used for assigning IP addresses on wireless networks.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1320
MAC address filtering is not used to restrict which devices can connect to wireless networ

MAC address filtering is not used to restrict which devices can connect to wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: MAC address filtering is not used to restrict which devices can connect to wirel
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1321
802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentic

802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: 802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1322
Evaluated supplicants, authenticators, wireless access points and authentication servers a

Evaluated supplicants, authenticators, wireless access points and authentication servers are used in wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Evaluated supplicants, authenticators, wireless access points and authentication
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1323
Certificates are required for devices and users accessing wireless networks.

Certificates are required for devices and users accessing wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Certificates are required for devices and users accessing wireless networks.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1324
Certificates are generated using an evaluated certificate authority or hardware security m

Certificates are generated using an evaluated certificate authority or hardware security module.

Artefacts an auditor will ask for
  • Evidence demonstrating: Certificates are generated using an evaluated certificate authority or hardware
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1327
Certificates are protected by logical and physical access controls, encryption, and user a

Certificates are protected by logical and physical access controls, encryption, and user authentication.

Artefacts an auditor will ask for
  • Evidence demonstrating: Certificates are protected by logical and physical access controls, encryption,
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1330
The PMK caching period is not set to greater than 1440 minutes (24 hours).

The PMK caching period is not set to greater than 1440 minutes (24 hours).

Artefacts an auditor will ask for
  • Evidence demonstrating: The PMK caching period is not set to greater than 1440 minutes (24 hours).
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1332
WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all w

WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.

Artefacts an auditor will ask for
  • Evidence demonstrating: WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrit
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1334
Wireless networks implement sufficient frequency separation from other wireless networks.

Wireless networks implement sufficient frequency separation from other wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Wireless networks implement sufficient frequency separation from other wireless
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1335
Wireless access points enable the use of the 802.11w amendment to protect management frame

Wireless access points enable the use of the 802.11w amendment to protect management frames.

Artefacts an auditor will ask for
  • Evidence demonstrating: Wireless access points enable the use of the 802.11w amendment to protect manage
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1338
Instead of deploying a small number of wireless access points that broadcast on high power

Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Instead of deploying a small number of wireless access points that broadcast on
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1364
Network devices managing VLANs terminate VLANs belonging to different security domains on

Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices managing VLANs terminate VLANs belonging to different security d
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1428
Unless explicitly required, IPv6 tunnelling is disabled on all network devices.

Unless explicitly required, IPv6 tunnelling is disabled on all network devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1429
IPv6 tunnelling is blocked by network security appliances at externally-connected network

IPv6 tunnelling is blocked by network security appliances at externally-connected network boundaries.

Artefacts an auditor will ask for
  • Evidence demonstrating: IPv6 tunnelling is blocked by network security appliances at externally-connecte
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1430
Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protoco

Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.

Artefacts an auditor will ask for
  • Evidence demonstrating: Dynamically assigned IPv6 addresses are configured with Dynamic Host Configurati
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1431
Denial-of-service attack mitigation strategies are discussed with cloud service providers,

Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: - their capacity to withstand denial-of-service attacks - costs likely to be incurred as a result of denial-of-service attacks - availability monitoring and thresholds for notification of denial-of-service attacks - thresholds for turning off any online services or functionality during denial-of-service attacks - pre-approved actions that can be undertaken during denial-of-service attacks - any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.

Artefacts an auditor will ask for
  • Evidence demonstrating: Denial-of-service attack mitigation strategies are discussed with cloud service
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1432
Domain names for online services are protected via registrar locking and confirming that d

Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.

Artefacts an auditor will ask for
  • Evidence demonstrating: Domain names for online services are protected via registrar locking and confirm
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1436
Critical online services are segregated from other online services that are more likely to

Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Critical online services are segregated from other online services that are more
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1437
Cloud service providers are used for hosting online services.

Cloud service providers are used for hosting online services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cloud service providers are used for hosting online services.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1438
Where a high availability requirement exists for website hosting, CDNs that cache websites

Where a high availability requirement exists for website hosting, CDNs that cache websites are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where a high availability requirement exists for website hosting, CDNs that cach
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1439
If using CDNs, disclosing the IP addresses of web servers under an organisation's control

If using CDNs, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: If using CDNs, disclosing the IP addresses of web servers under an organisation'
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1454
Communications between authenticators and a RADIUS server are encapsulated with an additio

Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.

Artefacts an auditor will ask for
  • Evidence demonstrating: Communications between authenticators and a RADIUS server are encapsulated with
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1479
Servers minimise communications with other servers at the network and file system level.

Servers minimise communications with other servers at the network and file system level.

Artefacts an auditor will ask for
  • Evidence demonstrating: Servers minimise communications with other servers at the network and file syste
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1532
VLANs are not used to separate network traffic between an organisation's networks and publ

VLANs are not used to separate network traffic between an organisation's networks and public network infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: VLANs are not used to separate network traffic between an organisation's network
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1577
An organisation's networks are segregated from their service providers' networks.

An organisation's networks are segregated from their service providers' networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: An organisation's networks are segregated from their service providers' networks
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1579
Cloud service providers' ability to dynamically scale resources in response to a genuine s

Cloud service providers' ability to dynamically scale resources in response to a genuine spike in demand is discussed and verified as part of capacity and availability planning for online services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cloud service providers' ability to dynamically scale resources in response to a
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1580
Where a high availability requirement exists for online services, the services are archite

Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where a high availability requirement exists for online services, the services a
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1581
Continuous real-time monitoring of the capacity and availability of online services is per

Continuous real-time monitoring of the capacity and availability of online services is performed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Continuous real-time monitoring of the capacity and availability of online servi
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1627
Inbound network connections from anonymity networks are blocked.

Inbound network connections from anonymity networks are blocked.

Artefacts an auditor will ask for
  • Evidence demonstrating: Inbound network connections from anonymity networks are blocked.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1628
Outbound network connections to anonymity networks are blocked.

Outbound network connections to anonymity networks are blocked.

Artefacts an auditor will ask for
  • Evidence demonstrating: Outbound network connections to anonymity networks are blocked.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1710
Settings for wireless access points are hardened.

Settings for wireless access points are hardened.

Artefacts an auditor will ask for
  • Evidence demonstrating: Settings for wireless access points are hardened.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1711
User identity confidentiality is used if available with EAP-TLS implementations.

User identity confidentiality is used if available with EAP-TLS implementations.

Artefacts an auditor will ask for
  • Evidence demonstrating: User identity confidentiality is used if available with EAP-TLS implementations.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1712
The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications a

The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.

Artefacts an auditor will ask for
  • Evidence demonstrating: The use of FT (802.11r) is disabled unless authenticator-to-authenticator commun
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1781
All data communicated over network infrastructure is encrypted.

All data communicated over network infrastructure is encrypted.

Artefacts an auditor will ask for
  • Evidence demonstrating: All data communicated over network infrastructure is encrypted.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1782
A protective DNS service is used to block access to known malicious domain names.

A protective DNS service is used to block access to known malicious domain names.

Artefacts an auditor will ask for
  • Evidence demonstrating: A protective DNS service is used to block access to known malicious domain names
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1800
Network devices are flashed with trusted firmware before they are used for the first time.

Network devices are flashed with trusted firmware before they are used for the first time.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices are flashed with trusted firmware before they are used for the f
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1801
Network devices are restarted on at least a monthly basis.

Network devices are restarted on at least a monthly basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices are restarted on at least a monthly basis.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1863
Networked management interfaces for IT equipment are not directly exposed to the internet.

Networked management interfaces for IT equipment are not directly exposed to the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Networked management interfaces for IT equipment are not directly exposed to the
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1912
Network documentation includes device settings for all critical servers, high-value server

Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network documentation includes device settings for all critical servers, high-va
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1962
SMB version 1 is not used on networks.

SMB version 1 is not used on networks.

Artefacts an auditor will ask for
  • Evidence demonstrating: SMB version 1 is not used on networks.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1963
Security-relevant events for internet-facing network devices are centrally logged.

Security-relevant events for internet-facing network devices are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for internet-facing network devices are centrally logge
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-1964
Security-relevant events for non-internet-facing network devices are centrally logged.

Security-relevant events for non-internet-facing network devices are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for non-internet-facing network devices are centrally l
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-2017
DNS traffic is encrypted by clients and servers wherever supported.

DNS traffic is encrypted by clients and servers wherever supported.

Artefacts an auditor will ask for
  • Evidence demonstrating: DNS traffic is encrypted by clients and servers wherever supported.
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic
ISM-2068
Internet connectivity for networked devices is strictly limited to those that require acce

Internet connectivity for networked devices is strictly limited to those that require access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Internet connectivity for networked devices is strictly limited to those that re
  • Network segmentation diagrams
  • Access control lists
  • Wireless network configuration
Where this commonly fails
  • Flat/unsegmented network
  • Unrestricted network traffic

Guidelines for personnel security

ISM-0078
Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under

Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under the control of an Australian national working for or on behalf of the Australian Government.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems processing, storing or communicating AUSTEO or AGAO data remain at all t
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0252
Cyber security awareness training is undertaken annually by all personnel and covers: - th

Cyber security awareness training is undertaken annually by all personnel and covers: - the purpose of the cyber security awareness training - security appointments and contacts - authorised use of systems and their resources - protection of systems and their resources - reporting of cyber security incidents and suspected compromises of systems and their resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security awareness training is undertaken annually by all personnel and co
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0258
A web usage policy is developed, implemented and maintained.

A web usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A web usage policy is developed, implemented and maintained.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0405
Requests for unprivileged access to systems and their resources are validated when first r

Requests for unprivileged access to systems and their resources are validated when first requested.

Artefacts an auditor will ask for
  • Evidence demonstrating: Requests for unprivileged access to systems and their resources are validated wh
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0407
A secure record is maintained for the life of systems and their resources that covers the

A secure record is maintained for the life of systems and their resources that covers the following for each user: - their user identification - their signed agreement to abide by system usage policies - who authorised their access - when their access was granted - the level of access they were granted - when their access, and their level of access, was last reviewed - when their level of access was changed, and to what extent (if applicable) - when their access was withdrawn (if applicable).

Artefacts an auditor will ask for
  • Evidence demonstrating: A secure record is maintained for the life of systems and their resources that c
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0409
Foreign nationals, including seconded foreign nationals, do not have access to systems tha

Foreign nationals, including seconded foreign nationals, do not have access to systems that process, store or communicate AUSTEO or REL data unless effective controls are in place to ensure such data is not accessible to them.

Artefacts an auditor will ask for
  • Evidence demonstrating: Foreign nationals, including seconded foreign nationals, do not have access to s
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0411
Foreign nationals, excluding seconded foreign nationals, do not have access to systems tha

Foreign nationals, excluding seconded foreign nationals, do not have access to systems that process, store or communicate AGAO data unless effective controls are in place to ensure such data is not accessible to them.

Artefacts an auditor will ask for
  • Evidence demonstrating: Foreign nationals, excluding seconded foreign nationals, do not have access to s
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0414
Personnel granted access to systems and their resources are uniquely identifiable.

Personnel granted access to systems and their resources are uniquely identifiable.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel granted access to systems and their resources are uniquely identifiabl
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0415
The use of shared user accounts is strictly controlled, and personnel using such accounts

The use of shared user accounts is strictly controlled, and personnel using such accounts are uniquely identifiable.

Artefacts an auditor will ask for
  • Evidence demonstrating: The use of shared user accounts is strictly controlled, and personnel using such
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0420
Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are fo

Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are foreign nationals are identified as such, including by their specific nationality.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0430
Access to systems and their resources are removed or suspended the same day personnel no l

Access to systems and their resources are removed or suspended the same day personnel no longer have a legitimate requirement for access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access to systems and their resources are removed or suspended the same day pers
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0432
Access requirements for systems and their resources are documented in their system securit

Access requirements for systems and their resources are documented in their system security plan.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access requirements for systems and their resources are documented in their syst
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0434
Personnel undergo appropriate employment screening and, where necessary, hold an appropria

Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel undergo appropriate employment screening and, where necessary, hold an
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0435
Personnel receive any necessary briefings before being granted access to systems and their

Personnel receive any necessary briefings before being granted access to systems and their resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel receive any necessary briefings before being granted access to systems
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0441
When personnel are granted temporary access to systems and their resources, effective cont

When personnel are granted temporary access to systems and their resources, effective controls are put in place to restrict their access to only data required for them to undertake their duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: When personnel are granted temporary access to systems and their resources, effe
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0443
Temporary access is not granted to systems that process, store or communicate caveated or

Temporary access is not granted to systems that process, store or communicate caveated or sensitive compartmented information.

Artefacts an auditor will ask for
  • Evidence demonstrating: Temporary access is not granted to systems that process, store or communicate ca
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0445
Privileged users are assigned a dedicated privileged user account to be used solely for du

Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged users are assigned a dedicated privileged user account to be used sol
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0446
Foreign nationals, including seconded foreign nationals, do not have privileged access to

Foreign nationals, including seconded foreign nationals, do not have privileged access to systems that process, store or communicate AUSTEO or REL data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Foreign nationals, including seconded foreign nationals, do not have privileged
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0447
Foreign nationals, excluding seconded foreign nationals, do not have privileged access to

Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Foreign nationals, excluding seconded foreign nationals, do not have privileged
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0817
Personnel are advised of what suspicious contact via online services is and how to report

Personnel are advised of what suspicious contact via online services is and how to report it.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of what suspicious contact via online services is and how
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0820
Personnel are advised to not post work information to unauthorised online services and to

Personnel are advised to not post work information to unauthorised online services and to report cases where such information is posted.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised to not post work information to unauthorised online servic
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0821
Personnel are advised of security risks associated with posting personal information to on

Personnel are advised of security risks associated with posting personal information to online services and are encouraged to use any available privacy settings to restrict who can view such information.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised of security risks associated with posting personal informa
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0824
Personnel are advised not to send or receive files via unauthorised online services.

Personnel are advised not to send or receive files via unauthorised online services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised not to send or receive files via unauthorised online servi
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-0854
AUSTEO and AGAO data can only be accessed from systems under the sole control of the Austr

AUSTEO and AGAO data can only be accessed from systems under the sole control of the Australian Government that are located within facilities authorised by the Australian Government.

Artefacts an auditor will ask for
  • Evidence demonstrating: AUSTEO and AGAO data can only be accessed from systems under the sole control of
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1146
Personnel are advised to maintain separate work and personal user accounts for online serv

Personnel are advised to maintain separate work and personal user accounts for online services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel are advised to maintain separate work and personal user accounts for o
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1175
Privileged user accounts (excluding those explicitly authorised to access online services)

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts (excluding those explicitly authorised to access online
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1263
Unique privileged user accounts are used for administering individual server applications.

Unique privileged user accounts are used for administering individual server applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unique privileged user accounts are used for administering individual server app
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1404
Unprivileged access to systems and their resources are disabled after 45 days of inactivit

Unprivileged access to systems and their resources are disabled after 45 days of inactivity.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged access to systems and their resources are disabled after 45 days of
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1507
Requests for privileged access to systems and their resources are validated when first req

Requests for privileged access to systems and their resources are validated when first requested.

Artefacts an auditor will ask for
  • Evidence demonstrating: Requests for privileged access to systems and their resources are validated when
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1508
Privileged access to systems and their resources is limited to only what is required for u

Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged access to systems and their resources is limited to only what is requ
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1509
Privileged access events are centrally logged.

Privileged access events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged access events are centrally logged.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1565
Tailored privileged user training is undertaken annually by all privileged users.

Tailored privileged user training is undertaken annually by all privileged users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Tailored privileged user training is undertaken annually by all privileged users
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1566
Use of unprivileged access is centrally logged.

Use of unprivileged access is centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Use of unprivileged access is centrally logged.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1583
Personnel who are contractors are identified as such.

Personnel who are contractors are identified as such.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel who are contractors are identified as such.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1591
Access to systems and their resources are removed or suspended as soon as practicable when

Access to systems and their resources are removed or suspended as soon as practicable when personnel are detected undertaking malicious activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access to systems and their resources are removed or suspended as soon as practi
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1610
A method of emergency access to systems and their resources is documented and tested at le

A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: A method of emergency access to systems and their resources is documented and te
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1611
Break glass accounts are only used when normal authentication processes cannot be used.

Break glass accounts are only used when normal authentication processes cannot be used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Break glass accounts are only used when normal authentication processes cannot b
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1612
Break glass accounts are only used for specific authorised activities.

Break glass accounts are only used for specific authorised activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Break glass accounts are only used for specific authorised activities.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1613
Use of break glass accounts is centrally logged.

Use of break glass accounts is centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Use of break glass accounts is centrally logged.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1614
Break glass account credentials are changed by the account custodian after they are access

Break glass account credentials are changed by the account custodian after they are accessed by any other party.

Artefacts an auditor will ask for
  • Evidence demonstrating: Break glass account credentials are changed by the account custodian after they
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1615
Break glass accounts are tested after credentials are changed.

Break glass accounts are tested after credentials are changed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Break glass accounts are tested after credentials are changed.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1647
Privileged access to systems and their resources are disabled after 12 months unless reval

Privileged access to systems and their resources are disabled after 12 months unless revalidated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged access to systems and their resources are disabled after 12 months un
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1648
Privileged access to systems and their resources are disabled after 45 days of inactivity.

Privileged access to systems and their resources are disabled after 45 days of inactivity.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged access to systems and their resources are disabled after 45 days of i
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1649
Just-in-time administration is used for the administration of systems and their resources.

Just-in-time administration is used for the administration of systems and their resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Just-in-time administration is used for the administration of systems and their
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1650
Privileged user account and security group management events are centrally logged.

Privileged user account and security group management events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user account and security group management events are centrally logge
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1740
Personnel dealing with banking details and payment requests are advised of what business e

Personnel dealing with banking details and payment requests are advised of what business email compromise is, how to manage such situations and how to report it.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel dealing with banking details and payment requests are advised of what
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1852
Unprivileged access to systems and their resources is limited to only what is required for

Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged access to systems and their resources is limited to only what is re
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1864
A system usage policy is developed, implemented and maintained.

A system usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A system usage policy is developed, implemented and maintained.
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1865
Personnel agree to abide by system usage policies before being granted access to systems a

Personnel agree to abide by system usage policies before being granted access to systems and their resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel agree to abide by system usage policies before being granted access to
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-1883
Privileged user accounts explicitly authorised to access online services are strictly limi

Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts explicitly authorised to access online services are str
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-2022
A cyber security awareness training register is developed, implemented and maintained.

A cyber security awareness training register is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cyber security awareness training register is developed, implemented and maint
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-2071
Personnel dealing with user account details are advised of what social engineering attacks

Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.

Artefacts an auditor will ask for
  • Evidence demonstrating: Personnel dealing with user account details are advised of what social engineeri
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access
ISM-2074
A general-purpose artificial intelligence usage policy is developed, implemented and maint

A general-purpose artificial intelligence usage policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A general-purpose artificial intelligence usage policy is developed, implemented
  • Cyber security awareness training records
  • Access provisioning/deprovisioning records
  • Employment screening / clearance records
Where this commonly fails
  • No awareness training
  • Access not removed on termination
  • No screening for privileged access

Guidelines for physical security

ISM-0161
IT equipment and media are secured when not in use.

IT equipment and media are secured when not in use.

Artefacts an auditor will ask for
  • Evidence demonstrating: IT equipment and media are secured when not in use.
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-0164
Unauthorised people are prevented from observing systems, in particular workstation displa

Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised people are prevented from observing systems, in particular workstat
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-0225
Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.

Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-0810
Classified systems are secured in facilities that meet the requirements for a security zon

Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Classified systems are secured in facilities that meet the requirements for a se
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-0813
Server rooms, communications rooms and security containers are not left in unsecured state

Server rooms, communications rooms and security containers are not left in unsecured states.

Artefacts an auditor will ask for
  • Evidence demonstrating: Server rooms, communications rooms and security containers are not left in unsec
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-0829
Security measures are used to detect and respond to unauthorised RF devices in SECRET and

Security measures are used to detect and respond to unauthorised RF devices in SECRET and TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security measures are used to detect and respond to unauthorised RF devices in S
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1053
Classified servers, network devices and cryptographic equipment are secured in server room

Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.

Artefacts an auditor will ask for
  • Evidence demonstrating: Classified servers, network devices and cryptographic equipment are secured in s
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1074
Keys or equivalent access mechanisms to server rooms, communications rooms and security co

Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Keys or equivalent access mechanisms to server rooms, communications rooms and s
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1296
Physical security is implemented to protect network devices in public areas from physical

Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Physical security is implemented to protect network devices in public areas from
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1530
Classified servers, network devices and cryptographic equipment are secured in security co

Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.

Artefacts an auditor will ask for
  • Evidence demonstrating: Classified servers, network devices and cryptographic equipment are secured in s
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1543
An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, impl

An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: An authorised RF and IR device register for SECRET and TOP SECRET areas is devel
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1973
Non-classified systems are secured in suitably secure facilities.

Non-classified systems are secured in suitably secure facilities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified systems are secured in suitably secure facilities.
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1974
Non-classified servers, network devices and cryptographic equipment are secured in suitabl

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified servers, network devices and cryptographic equipment are secured
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-1975
Non-classified servers, network devices and cryptographic equipment are secured in suitabl

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-classified servers, network devices and cryptographic equipment are secured
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-2007
An authorised medical device register for SECRET and TOP SECRET areas is developed, implem

An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: An authorised medical device register for SECRET and TOP SECRET areas is develop
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-2008
Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, a

Medical devices that are authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Australian Register of Therapeutic Goods - have been prescribed by a legally qualified medical practitioner - have been commercially purchased within Australia - do not have inbuilt cellular connectivity - are capable of operating independently of mobile devices - where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Medical devices that are authorised to be brought into SECRET and TOP SECRET are
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-2009
Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.

Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-2069
An authorised photographic and video recording device register for SECRET and TOP SECRET a

An authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: An authorised photographic and video recording device register for SECRET and TO
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted
ISM-2070
Unauthorised photographic and video recording devices are not brought into SECRET and TOP

Unauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised photographic and video recording devices are not brought into SECRE
  • Facility/server room access controls
  • Security container records
  • Physical access logs
Where this commonly fails
  • Unsecured server/communications rooms
  • Physical access not restricted

Guidelines for procurement and outsourcing

ISM-0072
Security requirements associated with the confidentiality, integrity and availability of d

Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and reviewed on a regular and ongoing basis to ensure they remain fit for purpose.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security requirements associated with the confidentiality, integrity and availab
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-0141
The requirement for service providers to report cyber security incidents to a designated p

The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: The requirement for service providers to report cyber security incidents to a de
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1073
An organisation's systems are not accessed or administered by a service provider unless a

An organisation's systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.

Artefacts an auditor will ask for
  • Evidence demonstrating: An organisation's systems are not accessed or administered by a service provider
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1395
Service providers, including any subcontractors, provide an appropriate level of protectio

Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Service providers, including any subcontractors, provide an appropriate level of
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1451
Types of data and its ownership is documented in contractual arrangements with service pro

Types of data and its ownership is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Types of data and its ownership is documented in contractual arrangements with s
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1452
A supply chain risk assessment is performed for suppliers of operating systems, applicatio

A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services in order to assess the impact to a system's security risk profile.

Artefacts an auditor will ask for
  • Evidence demonstrating: A supply chain risk assessment is performed for suppliers of operating systems,
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1529
Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud servi

Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only community or private clouds are used for outsourced SECRET and TOP SECRET c
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1567
Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Suppliers identified as high risk by a cyber supply chain risk assessment are no
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1568
Operating systems, applications, IT equipment, OT equipment and services are procured from

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1569
A shared responsibility model is created, documented and shared between suppliers and thei

A shared responsibility model is created, documented and shared between suppliers and their customers in order to articulate the security responsibilities of each party.

Artefacts an auditor will ask for
  • Evidence demonstrating: A shared responsibility model is created, documented and shared between supplier
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1570
Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTE

Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1571
The right to verify compliance with security requirements is documented in contractual arr

The right to verify compliance with security requirements is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: The right to verify compliance with security requirements is documented in contr
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1572
The regions or availability zones where data will be processed, stored and communicated, a

The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: The regions or availability zones where data will be processed, stored and commu
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1573
Access to all logs relating to an organisation's data and services is documented in contra

Access to all logs relating to an organisation's data and services is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access to all logs relating to an organisation's data and services is documented
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1574
The storage of data in a portable manner that allows for backups, service migration and se

The storage of data in a portable manner that allows for backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: The storage of data in a portable manner that allows for backups, service migrat
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1575
A minimum notification period of one month for the cessation of any services by a service

A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: A minimum notification period of one month for the cessation of any services by
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1576
If an organisation's systems are accessed or administered by a service provider in an unau

If an organisation's systems are accessed or administered by a service provider in an unauthorised manner, the organisation is immediately notified.

Artefacts an auditor will ask for
  • Evidence demonstrating: If an organisation's systems are accessed or administered by a service provider
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1631
Suppliers of operating systems, applications, IT equipment, OT equipment and services asso

Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.

Artefacts an auditor will ask for
  • Evidence demonstrating: Suppliers of operating systems, applications, IT equipment, OT equipment and ser
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1632
Operating systems, applications, IT equipment, OT equipment and services are procured from

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1637
An outsourced cloud service register is developed, implemented, maintained and verified on

An outsourced cloud service register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: An outsourced cloud service register is developed, implemented, maintained and v
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1638
An outsourced cloud service register contains the following for each outsourced cloud serv

An outsourced cloud service register contains the following for each outsourced cloud service: - cloud service provider's name - cloud service's name - purpose for using the cloud service - sensitivity or classification of data involved - due date for the next security assessment of the cloud service - contractual arrangements for the cloud service - point of contact for users of the cloud service - 24/7 contact details for the cloud service provider.

Artefacts an auditor will ask for
  • Evidence demonstrating: An outsourced cloud service register contains the following for each outsourced
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1736
A managed service register is developed, implemented, maintained and verified on a regular

A managed service register is developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: A managed service register is developed, implemented, maintained and verified on
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1737
A managed service register contains the following for each managed service: - managed serv

A managed service register contains the following for each managed service: - managed service provider's name - managed service's name - purpose for using the managed service - sensitivity or classification of data involved - due date for the next security assessment of the managed service - contractual arrangements for the managed service - point of contact for users of the managed service - 24/7 contact details for the managed service provider.

Artefacts an auditor will ask for
  • Evidence demonstrating: A managed service register contains the following for each managed service: - ma
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1738
The right to verify compliance with security requirements documented in contractual arrang

The right to verify compliance with security requirements documented in contractual arrangements with service providers is exercised on a regular and ongoing basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: The right to verify compliance with security requirements documented in contract
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1785
A supplier relationship management policy is developed, implemented and maintained.

A supplier relationship management policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A supplier relationship management policy is developed, implemented and maintain
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1786
An approved supplier list is developed, implemented and maintained.

An approved supplier list is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An approved supplier list is developed, implemented and maintained.
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1787
Operating systems, applications, IT equipment, OT equipment and services are sourced from

Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are sou
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1788
Multiple potential suppliers are identified for sourcing critical operating systems, appli

Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multiple potential suppliers are identified for sourcing critical operating syst
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1789
Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserv

Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.

Artefacts an auditor will ask for
  • Evidence demonstrating: Sufficient spares of critical IT equipment and OT equipment are sourced and kept
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1790
Operating systems, applications, IT equipment, OT equipment and services are delivered in

Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are del
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1791
The integrity of operating systems, applications, IT equipment, OT equipment and services

The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: The integrity of operating systems, applications, IT equipment, OT equipment and
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1792
The authenticity of operating systems, applications, IT equipment, OT equipment and servic

The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: The authenticity of operating systems, applications, IT equipment, OT equipment
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1793
Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SEC

Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECT
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1794
A minimum notification period of one month by service providers for significant changes to

A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: A minimum notification period of one month by service providers for significant
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1804
Break clauses associated with failure to meet security requirements are documented in cont

Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Break clauses associated with failure to meet security requirements are document
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1882
Operating systems, applications, IT equipment, OT equipment and services are procured from

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems, applications, IT equipment, OT equipment and services are pro
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1971
Managed service providers and their TOP SECRET managed services, including sensitive compa

Managed service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Managed service providers and their TOP SECRET managed services, including sensi
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements
ISM-1972
Outsourced cloud service providers and their TOP SECRET cloud services, including sensitiv

Outsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Outsourced cloud service providers and their TOP SECRET cloud services, includin
  • Supplier/cyber supply chain risk assessments
  • Contracts with security clauses
  • Cloud/managed service assessments (e.g. IRAP)
Where this commonly fails
  • No supplier security assessment
  • Missing contractual security requirements

Guidelines for software development

ISM-0400
Development, testing, staging and production environments are segregated.

Development, testing, staging and production environments are segregated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Development, testing, staging and production environments are segregated.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-0401
Secure by Design principles and practices are followed throughout the software development

Secure by Design principles and practices are followed throughout the software development life cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: Secure by Design principles and practices are followed throughout the software d
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-0402
Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to

Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to its initial release, any subsequent releases and periodically in order to attempt to identify any previously unidentified vulnerabilities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-0971
The OWASP Application Security Verification Standard is used in the development of web app

The OWASP Application Security Verification Standard is used in the development of web applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: The OWASP Application Security Verification Standard is used in the development
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1238
Threat modelling is used in support of the software development life cycle.

Threat modelling is used in support of the software development life cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: Threat modelling is used in support of the software development life cycle.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1239
Robust web application frameworks are used in the development of web applications.

Robust web application frameworks are used in the development of web applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Robust web application frameworks are used in the development of web application
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1240
Validation and sanitisation are performed on all input received over the internet by softw

Validation and sanitisation are performed on all input received over the internet by software.

Artefacts an auditor will ask for
  • Evidence demonstrating: Validation and sanitisation are performed on all input received over the interne
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1241
Output encoding is performed on all output produced by web applications.

Output encoding is performed on all output produced by web applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Output encoding is performed on all output produced by web applications.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1275
All queries to databases from software are filtered for legitimate content and correct syn

All queries to databases from software are filtered for legitimate content and correct syntax.

Artefacts an auditor will ask for
  • Evidence demonstrating: All queries to databases from software are filtered for legitimate content and c
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1276
Parameterised queries or stored procedures, instead of dynamically generated queries, are

Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.

Artefacts an auditor will ask for
  • Evidence demonstrating: Parameterised queries or stored procedures, instead of dynamically generated que
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1278
Software is designed or configured to provide as little error information as possible abou

Software is designed or configured to provide as little error information as possible about the structure of databases.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software is designed or configured to provide as little error information as pos
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1419
Development and modification of software only takes place in development environments.

Development and modification of software only takes place in development environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Development and modification of software only takes place in development environ
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1420
Data from production environments is not used in non-production environments unless the no

Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data from production environments is not used in non-production environments unl
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1422
Unauthorised access to the authoritative source for software is prevented.

Unauthorised access to the authoritative source for software is prevented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised access to the authoritative source for software is prevented.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1424
Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame

Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1536
All queries to databases from software that are initiated by users, and any resulting cras

All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: All queries to databases from software that are initiated by users, and any resu
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1552
All web application content is offered exclusively using HTTPS.

All web application content is offered exclusively using HTTPS.

Artefacts an auditor will ask for
  • Evidence demonstrating: All web application content is offered exclusively using HTTPS.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1616
A vulnerability disclosure program is implemented to assist with the secure development an

A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability disclosure program is implemented to assist with the secure deve
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1717
A 'security.txt' file is hosted for each of an organisation's internet-facing website doma

A 'security.txt' file is hosted for each of an organisation's internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation's products and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: A 'security.txt' file is hosted for each of an organisation's internet-facing we
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1730
A software bill of materials is produced and made available to consumers of software.

A software bill of materials is produced and made available to consumers of software.

Artefacts an auditor will ask for
  • Evidence demonstrating: A software bill of materials is produced and made available to consumers of soft
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1754
Vulnerabilities identified in software are resolved in a timely manner.

Vulnerabilities identified in software are resolved in a timely manner.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vulnerabilities identified in software are resolved in a timely manner.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1755
A vulnerability disclosure policy is developed, implemented and maintained.

A vulnerability disclosure policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability disclosure policy is developed, implemented and maintained.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1756
Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, ar

Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vulnerability disclosure processes, and supporting vulnerability disclosure proc
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1780
SecDevOps practices are used for software development.

SecDevOps practices are used for software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: SecDevOps practices are used for software development.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1796
Files containing executable content are digitally signed by a certificate with a verifiabl

Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: Files containing executable content are digitally signed by a certificate with a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1797
Installers, patches and updates are digitally signed or provided with cryptographic checks

Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: Installers, patches and updates are digitally signed or provided with cryptograp
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1798
Secure configuration guidance, in the form of a hardening guide or loosening guide, is pro

Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: Secure configuration guidance, in the form of a hardening guide or loosening gui
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1816
Unauthorised modification of the authoritative source for software is prevented.

Unauthorised modification of the authoritative source for software is prevented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unauthorised modification of the authoritative source for software is prevented.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1817
Authentication and authorisation of clients is performed when clients call network APIs th

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1818
Authentication and authorisation of clients is performed when clients call network APIs th

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1849
The OWASP Top 10 Proactive Controls are used in the development of web applications.

The OWASP Top 10 Proactive Controls are used in the development of web applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: The OWASP Top 10 Proactive Controls are used in the development of web applicati
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1850
The OWASP Top 10 are mitigated in the development of web applications.

The OWASP Top 10 are mitigated in the development of web applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: The OWASP Top 10 are mitigated in the development of web applications.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1851
The OWASP API Security Top 10 are mitigated in the development of web APIs.

The OWASP API Security Top 10 are mitigated in the development of web APIs.

Artefacts an auditor will ask for
  • Evidence demonstrating: The OWASP API Security Top 10 are mitigated in the development of web APIs.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1908
Vulnerabilities identified in software are publicly disclosed in a responsible and timely

Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vulnerabilities identified in software are publicly disclosed in a responsible a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1909
In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent

In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.

Artefacts an auditor will ask for
  • Evidence demonstrating: In resolving vulnerabilities, root cause analysis is performed and, to the great
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1910
Network API calls that facilitate modification of data, or access to data not authorised f

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network API calls that facilitate modification of data, or access to data not au
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1911
Security-relevant usage, error messages and crashes for software are centrally logged.

Security-relevant usage, error messages and crashes for software are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant usage, error messages and crashes for software are centrally l
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1922
The OWASP Mobile Application Security Verification Standard is used in the development of

The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: The OWASP Mobile Application Security Verification Standard is used in the devel
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-1924
Generative artificial intelligence applications evaluate user prompts to detect and mitiga

Generative artificial intelligence applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.

Artefacts an auditor will ask for
  • Evidence demonstrating: Generative artificial intelligence applications evaluate user prompts to detect
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2013
Authentication and authorisation of clients is performed when clients call network APIs th

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2014
Authentication and authorisation of clients is performed when clients call network APIs th

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication and authorisation of clients is performed when clients call netwo
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2015
Network API calls that facilitate modification of data, or access to data not authorised f

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network API calls that facilitate modification of data, or access to data not au
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2016
Validation and sanitisation are performed on all input received over a local network by so

Validation and sanitisation are performed on all input received over a local network by software.

Artefacts an auditor will ask for
  • Evidence demonstrating: Validation and sanitisation are performed on all input received over a local net
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2023
An authoritative source for software is established and maintained.

An authoritative source for software is established and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An authoritative source for software is established and maintained.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2024
The authoritative source for software is used for all software development activities.

The authoritative source for software is used for all software development activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: The authoritative source for software is used for all software development activ
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2025
An issue tracking solution is used to link software development tasks to security issues a

An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.

Artefacts an auditor will ask for
  • Evidence demonstrating: An issue tracking solution is used to link software development tasks to securit
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2026
All software artefacts are scanned for malicious content before being imported into the au

All software artefacts are scanned for malicious content before being imported into the authoritative source for software.

Artefacts an auditor will ask for
  • Evidence demonstrating: All software artefacts are scanned for malicious content before being imported i
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2027
All software artefacts are verified by a digital signature, or a secure hash provided over

All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.

Artefacts an auditor will ask for
  • Evidence demonstrating: All software artefacts are verified by a digital signature, or a secure hash pro
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2028
All software artefacts are tested to detect known weaknesses using static application secu

All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.

Artefacts an auditor will ask for
  • Evidence demonstrating: All software artefacts are tested to detect known weaknesses using static applic
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2029
The authoritative source for software restricts the use and import of third-party librarie

The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.

Artefacts an auditor will ask for
  • Evidence demonstrating: The authoritative source for software restricts the use and import of third-part
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2030
Scanning is used during commits to identify plain text or encoded secrets and keys, which

Scanning is used during commits to identify plain text or encoded secrets and keys, which are then blocked from being stored in the authoritative source for software.

Artefacts an auditor will ask for
  • Evidence demonstrating: Scanning is used during commits to identify plain text or encoded secrets and ke
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2031
Compilers, interpreters and build tools (including pipelines) that provide security featur

Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Compilers, interpreters and build tools (including pipelines) that provide secur
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2032
The build solution ensures that all automated testing is completed without warnings, alert

The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.

Artefacts an auditor will ask for
  • Evidence demonstrating: The build solution ensures that all automated testing is completed without warni
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2033
All software security requirements are documented, stored securely and maintained througho

All software security requirements are documented, stored securely and maintained throughout the software development life cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: All software security requirements are documented, stored securely and maintaine
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2034
Security design decisions are documented and reviewed throughout the software development

Security design decisions are documented and reviewed throughout the software development cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security design decisions are documented and reviewed throughout the software de
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2035
Security roles, responsibilities and knowledge requirements required to support the softwa

Security roles, responsibilities and knowledge requirements required to support the software development life cycle are identified and documented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security roles, responsibilities and knowledge requirements required to support
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2036
Security responsibilities for software developers are identified and documented.

Security responsibilities for software developers are identified and documented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security responsibilities for software developers are identified and documented.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2037
Software developers that lack sufficient cyber security knowledge and skills required for

Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training on secure software development and programming practices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software developers that lack sufficient cyber security knowledge and skills req
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2038
A software developer cyber security knowledge and skills register is implemented and maint

A software developer cyber security knowledge and skills register is implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A software developer cyber security knowledge and skills register is implemented
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2039
The software threat model is reviewed throughout the software development life cycle to en

The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.

Artefacts an auditor will ask for
  • Evidence demonstrating: The software threat model is reviewed throughout the software development life c
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2040
Secure programming practices for the chosen programming language are used for software dev

Secure programming practices for the chosen programming language are used for software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: Secure programming practices for the chosen programming language are used for so
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2041
Memory-safe programming languages, or less preferably memory-safe programming practices, a

Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.

Artefacts an auditor will ask for
  • Evidence demonstrating: Memory-safe programming languages, or less preferably memory-safe programming pr
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2042
Secure by Default principles and practices are followed throughout the software developmen

Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Secure by Default principles and practices are followed throughout the software
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2043
Software is architected and structured to support readability and maintainability.

Software is architected and structured to support readability and maintainability.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software is architected and structured to support readability and maintainabilit
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2044
Software has no default credentials; however, if credentials are required, they are create

Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software has no default credentials; however, if credentials are required, they
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2045
Application backwards compatibility does not compromise any security measures or features.

Application backwards compatibility does not compromise any security measures or features.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application backwards compatibility does not compromise any security measures or
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2046
Where software allows user impersonation, sensitive data is not logged and appropriate per

Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where software allows user impersonation, sensitive data is not logged and appro
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2047
Where software allows an authentication factor to be reset, the user is notified of the re

Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where software allows an authentication factor to be reset, the user is notified
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2048
Where software supports multiple user roles, non-administrative users are prevented from a

Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where software supports multiple user roles, non-administrative users are preven
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2049
When user permissions or credentials are changed, software forces all impacted users to re

When user permissions or credentials are changed, software forces all impacted users to re-authenticate.

Artefacts an auditor will ask for
  • Evidence demonstrating: When user permissions or credentials are changed, software forces all impacted u
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2050
When digital signatures are processed by software, they are validated against a certificat

When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.

Artefacts an auditor will ask for
  • Evidence demonstrating: When digital signatures are processed by software, they are validated against a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2051
Software generates sufficient event logs to support the detection of cyber security events

Software generates sufficient event logs to support the detection of cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software generates sufficient event logs to support the detection of cyber secur
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2052
Event logs produced by software ensure that any sensitive data is protected.

Event logs produced by software ensure that any sensitive data is protected.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs produced by software ensure that any sensitive data is protected.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2053
End of life procedures for software, covering how to remove the software and how to archiv

End of life procedures for software, covering how to remove the software and how to archive or destroy any user accounts and data, are produced and made available to consumers.

Artefacts an auditor will ask for
  • Evidence demonstrating: End of life procedures for software, covering how to remove the software and how
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2054
If a software bill of materials is available for imported third-party software components,

If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.

Artefacts an auditor will ask for
  • Evidence demonstrating: If a software bill of materials is available for imported third-party software c
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2055
If a software build provenance is available for imported third-party software components,

If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.

Artefacts an auditor will ask for
  • Evidence demonstrating: If a software build provenance is available for imported third-party software co
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2056
A software build provenance is produced and made available to consumers of software.

A software build provenance is produced and made available to consumers of software.

Artefacts an auditor will ask for
  • Evidence demonstrating: A software build provenance is produced and made available to consumers of softw
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2057
All input validation rules are documented, matched in code and tested with both positive a

All input validation rules are documented, matched in code and tested with both positive and negative unit testing or integration testing.

Artefacts an auditor will ask for
  • Evidence demonstrating: All input validation rules are documented, matched in code and tested with both
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2058
Data sources and serialised data inputs are validated before being deserialised.

Data sources and serialised data inputs are validated before being deserialised.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data sources and serialised data inputs are validated before being deserialised.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2059
File uploads or input are restricted to specific file types, with malicious content scanni

File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.

Artefacts an auditor will ask for
  • Evidence demonstrating: File uploads or input are restricted to specific file types, with malicious cont
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2060
Code reviews are utilised to ensure software meets Secure by Design principles and practic

Code reviews are utilised to ensure software meets Secure by Design principles and practices as well as secure programming practices.

Artefacts an auditor will ask for
  • Evidence demonstrating: Code reviews are utilised to ensure software meets Secure by Design principles a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2061
Software developer-supported security-focused peer reviews are conducted on all critical a

Software developer-supported security-focused peer reviews are conducted on all critical and security-focused software components.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software developer-supported security-focused peer reviews are conducted on all
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2062
Unit testing and integration testing, covering both positive and negative use cases, are u

Unit testing and integration testing, covering both positive and negative use cases, are used to ensure code quality and security.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unit testing and integration testing, covering both positive and negative use ca
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2063
If supported, web application session cookies set the HttpOnly flag, Secure flag and the S

If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.

Artefacts an auditor will ask for
  • Evidence demonstrating: If supported, web application session cookies set the HttpOnly flag, Secure flag
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2064
Web application session cookies contain only digitally signed opaque bearer tokens.

Web application session cookies contain only digitally signed opaque bearer tokens.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web application session cookies contain only digitally signed opaque bearer toke
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2065
Web application session cookies using opaque bearer tokens that are not digitally signed u

Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web application session cookies using opaque bearer tokens that are not digitall
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2066
Web application sessions are centrally managed server side.

Web application sessions are centrally managed server side.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web application sessions are centrally managed server side.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2067
Web applications that support Single Sign On equally support Single Logout.

Web applications that support Single Sign On equally support Single Logout.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web applications that support Single Sign On equally support Single Logout.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2072
Artificial intelligence models are stored in a non-executable file format that does not al

Artificial intelligence models are stored in a non-executable file format that does not allow arbitrary code execution.

Artefacts an auditor will ask for
  • Evidence demonstrating: Artificial intelligence models are stored in a non-executable file format that d
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2082
If a cryptographic bill of materials is available for imported third-party software compon

If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.

Artefacts an auditor will ask for
  • Evidence demonstrating: If a cryptographic bill of materials is available for imported third-party softw
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2083
A cryptographic bill of materials is produced and made available to consumers of software.

A cryptographic bill of materials is produced and made available to consumers of software.

Artefacts an auditor will ask for
  • Evidence demonstrating: A cryptographic bill of materials is produced and made available to consumers of
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2084
Artificial intelligence-specific documentation, including model and system cards (or equiv

Artificial intelligence-specific documentation, including model and system cards (or equivalent artefacts), is used to document model characteristics, system architectures, use cases and security risks.

Artefacts an auditor will ask for
  • Evidence demonstrating: Artificial intelligence-specific documentation, including model and system cards
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2085
The exposure of exact artificial intelligence model confidence scores in API responses or

The exposure of exact artificial intelligence model confidence scores in API responses or user interfaces is prevented.

Artefacts an auditor will ask for
  • Evidence demonstrating: The exposure of exact artificial intelligence model confidence scores in API res
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2086
The source and integrity of artificial intelligence models, structures and weights are ver

The source and integrity of artificial intelligence models, structures and weights are verified.

Artefacts an auditor will ask for
  • Evidence demonstrating: The source and integrity of artificial intelligence models, structures and weigh
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2087
The source and integrity of training data for artificial intelligence models is verified.

The source and integrity of training data for artificial intelligence models is verified.

Artefacts an auditor will ask for
  • Evidence demonstrating: The source and integrity of training data for artificial intelligence models is
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2088
Data validation and verification techniques are used to ensure the reliability and accurac

Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by artificial intelligence models.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data validation and verification techniques are used to ensure the reliability a
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2089
Artificial intelligence model performance metrics are monitored and anomalies are investig

Artificial intelligence model performance metrics are monitored and anomalies are investigated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Artificial intelligence model performance metrics are monitored and anomalies ar
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2090
Rate limiting is applied to inference queries for artificial intelligence models.

Rate limiting is applied to inference queries for artificial intelligence models.

Artefacts an auditor will ask for
  • Evidence demonstrating: Rate limiting is applied to inference queries for artificial intelligence models
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2091
Resource limits are enforced for artificial intelligence models.

Resource limits are enforced for artificial intelligence models.

Artefacts an auditor will ask for
  • Evidence demonstrating: Resource limits are enforced for artificial intelligence models.
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2092
Access control policies are implemented to enforce fine-grained permissions for artificial

Access control policies are implemented to enforce fine-grained permissions for artificial intelligence applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access control policies are implemented to enforce fine-grained permissions for
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2093
Role-based access controls are implemented for artificial intelligence applications to res

Role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Role-based access controls are implemented for artificial intelligence applicati
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2094
Content filtering is implemented by artificial intelligence applications to detect and blo

Content filtering is implemented by artificial intelligence applications to detect and block sensitive data exposure and improper output.

Artefacts an auditor will ask for
  • Evidence demonstrating: Content filtering is implemented by artificial intelligence applications to dete
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2102
Existing software artefacts in the authoritative source for software are periodically test

Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.

Artefacts an auditor will ask for
  • Evidence demonstrating: Existing software artefacts in the authoritative source for software are periodi
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated
ISM-2103
Organisational data generated, collected or processed by artificial intelligence applicati

Organisational data generated, collected or processed by artificial intelligence applications is not used for training, fine-tuning or improving artificial intelligence models unless informed and explicit consent has been obtained from data owners in advance.

Artefacts an auditor will ask for
  • Evidence demonstrating: Organisational data generated, collected or processed by artificial intelligence
  • Secure SDLC procedures
  • Threat modelling records
  • Security testing results
  • Environment segregation evidence
Where this commonly fails
  • No security testing
  • Production data used in test
  • Dev/test/prod not segregated

Guidelines for system hardening

ISM-0341
Automatic execution features for removable media are disabled.

Automatic execution features for removable media are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Automatic execution features for removable media are disabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0343
If there is no business requirement for writing to removable media and devices, such funct

If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Artefacts an auditor will ask for
  • Evidence demonstrating: If there is no business requirement for writing to removable media and devices,
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0345
External communication interfaces that allow DMA are disabled.

External communication interfaces that allow DMA are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: External communication interfaces that allow DMA are disabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0380
Unneeded user accounts, components, services and functionality of operating systems are di

Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unneeded user accounts, components, services and functionality of operating syst
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0382
Unprivileged users do not have the ability to uninstall or disable approved applications.

Unprivileged users do not have the ability to uninstall or disable approved applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged users do not have the ability to uninstall or disable approved appl
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0383
Default user accounts or credentials for operating systems, including for any pre-configur

Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Artefacts an auditor will ask for
  • Evidence demonstrating: Default user accounts or credentials for operating systems, including for any pr
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0408
Systems have a logon banner that reminds users of their security responsibilities when acc

Systems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems have a logon banner that reminds users of their security responsibilitie
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0417
When systems cannot support multi-factor authentication, single-factor authentication usin

When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.

Artefacts an auditor will ask for
  • Evidence demonstrating: When systems cannot support multi-factor authentication, single-factor authentic
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0418
Physical credentials are kept separate from systems they are used to authenticate to, exce

Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Physical credentials are kept separate from systems they are used to authenticat
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0421
Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and

Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for single-factor authentication on non-classified, OFFICIAL: Sen
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0422
Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20

Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for single-factor authentication on TOP SECRET systems are a mini
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0428
Services are configured with a session lock that: - activates after a maximum of 15 minute

Services are configured with a session lock that: - activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users - blocks access to all session content - requires users to re-authenticate using all authentication factors to unlock the session - denies users the ability to disable the session locking mechanism.

Artefacts an auditor will ask for
  • Evidence demonstrating: Services are configured with a session lock that: - activates after a maximum of
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0582
Security-relevant events for Microsoft Windows operating systems are centrally logged.

Security-relevant events for Microsoft Windows operating systems are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for Microsoft Windows operating systems are centrally l
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0843
Application control is implemented on workstations.

Application control is implemented on workstations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is implemented on workstations.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0846
All users (with the exception of local administrator accounts and break glass accounts) ca

All users (with the exception of local administrator accounts and break glass accounts) cannot disable, bypass or be exempted from application control.

Artefacts an auditor will ask for
  • Evidence demonstrating: All users (with the exception of local administrator accounts and break glass ac
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0853
On a daily basis, outside of business hours and after an appropriate period of inactivity,

On a daily basis, outside of business hours and after an appropriate period of inactivity, user sessions are terminated and workstations are restarted.

Artefacts an auditor will ask for
  • Evidence demonstrating: On a daily basis, outside of business hours and after an appropriate period of i
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0938
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0955
Application control is implemented using cryptographic hash rules, publisher certificate r

Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is implemented using cryptographic hash rules, publisher cer
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-0974
Multi-factor authentication is used to authenticate unprivileged users of systems.

Multi-factor authentication is used to authenticate unprivileged users of systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate unprivileged users of system
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1034
A HIPS or EDR solution is implemented on critical servers and high-value servers.

A HIPS or EDR solution is implemented on critical servers and high-value servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: A HIPS or EDR solution is implemented on critical servers and high-value servers
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1055
LAN Manager and NT LAN Manager authentication methods are disabled.

LAN Manager and NT LAN Manager authentication methods are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: LAN Manager and NT LAN Manager authentication methods are disabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1173
Multi-factor authentication is used to authenticate privileged users of systems.

Multi-factor authentication is used to authenticate privileged users of systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate privileged users of systems.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1227
Credentials set for user accounts are randomly generated.

Credentials set for user accounts are randomly generated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials set for user accounts are randomly generated.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1235
Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clien

Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clients, PDF applications and security products are restricted to an organisation-approved set.

Artefacts an auditor will ask for
  • Evidence demonstrating: Add-ons, extensions and plug-ins for office productivity suites, web browsers, e
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1245
All temporary installation files and logs created during server application installation p

All temporary installation files and logs created during server application installation processes are removed after server applications have been installed.

Artefacts an auditor will ask for
  • Evidence demonstrating: All temporary installation files and logs created during server application inst
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1246
Server applications are hardened using ASD and vendor hardening guidance, with the most re

Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Server applications are hardened using ASD and vendor hardening guidance, with t
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1247
Unneeded user accounts, components, services and functionality of server applications are

Unneeded user accounts, components, services and functionality of server applications are disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unneeded user accounts, components, services and functionality of server applica
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1249
Server applications are configured to run as a separate user account with the minimum priv

Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.

Artefacts an auditor will ask for
  • Evidence demonstrating: Server applications are configured to run as a separate user account with the mi
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1250
The user accounts under which server applications run have limited access to their underly

The user accounts under which server applications run have limited access to their underlying server's file system.

Artefacts an auditor will ask for
  • Evidence demonstrating: The user accounts under which server applications run have limited access to the
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1260
Default user accounts or credentials for server applications, including for any pre-config

Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Artefacts an auditor will ask for
  • Evidence demonstrating: Default user accounts or credentials for server applications, including for any
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1341
A HIPS or EDR solution is implemented on workstations.

A HIPS or EDR solution is implemented on workstations.

Artefacts an auditor will ask for
  • Evidence demonstrating: A HIPS or EDR solution is implemented on workstations.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1392
When implementing application control using path rules, only approved users can modify app

When implementing application control using path rules, only approved users can modify approved files and write to approved folders.

Artefacts an auditor will ask for
  • Evidence demonstrating: When implementing application control using path rules, only approved users can
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1401
Multi-factor authentication uses either: something users have and something users know, or

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication uses either: something users have and something user
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1402
Credentials stored on systems are protected by a password manager; a hardware security mod

Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials stored on systems are protected by a password manager; a hardware se
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1403
User accounts, except for break glass accounts, are locked out after a maximum of five fai

User accounts, except for break glass accounts, are locked out after a maximum of five failed logon attempts.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts, except for break glass accounts, are locked out after a maximum o
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1406
SOEs are used for workstations and servers.

SOEs are used for workstations and servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: SOEs are used for workstations and servers.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1407
The latest release, or the previous release, of operating systems are used.

The latest release, or the previous release, of operating systems are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The latest release, or the previous release, of operating systems are used.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1408
Where supported, 64-bit versions of operating systems are used.

Where supported, 64-bit versions of operating systems are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Where supported, 64-bit versions of operating systems are used.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1409
Operating systems are hardened using ASD and vendor hardening guidance, with the most rest

Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems are hardened using ASD and vendor hardening guidance, with the
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1412
Web browsers are hardened using ASD and vendor hardening guidance, with the most restricti

Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web browsers are hardened using ASD and vendor hardening guidance, with the most
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1416
A software firewall is implemented on workstations and servers to restrict inbound and out

A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.

Artefacts an auditor will ask for
  • Evidence demonstrating: A software firewall is implemented on workstations and servers to restrict inbou
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1417
An antivirus application is implemented on workstations and servers with: - signature-base

An antivirus application is implemented on workstations and servers with: - signature-based detection functionality enabled and set to a high level - heuristic-based detection functionality enabled and set to a high level - reputation rating functionality enabled - ransomware protection functionality enabled - detection signatures configured to update on at least a daily basis - regular scanning configured for all fixed disks and removable media.

Artefacts an auditor will ask for
  • Evidence demonstrating: An antivirus application is implemented on workstations and servers with: - sign
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1418
If there is no business requirement for reading from removable media and devices, such fun

If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Artefacts an auditor will ask for
  • Evidence demonstrating: If there is no business requirement for reading from removable media and devices
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1460
When using a software-based isolation mechanism to share a physical server's hardware, the

When using a software-based isolation mechanism to share a physical server's hardware, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1461
When using a software-based isolation mechanism to share a physical server's hardware for

When using a software-based isolation mechanism to share a physical server's hardware for SECRET or TOP SECRET computing environments, the physical server and all computing environments are of the same classification and belong to the same security domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1467
The latest release of office productivity suites, web browsers and their extensions, email

The latest release of office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The latest release of office productivity suites, web browsers and their extensi
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1470
Unneeded components, services and functionality of office productivity suites, web browser

Unneeded components, services and functionality of office productivity suites, web browsers, email clients, PDF applications and security products are disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unneeded components, services and functionality of office productivity suites, w
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1471
When implementing application control using publisher certificate rules, publisher names a

When implementing application control using publisher certificate rules, publisher names and product names are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: When implementing application control using publisher certificate rules, publish
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1483
The latest release of internet-facing server applications are used.

The latest release of internet-facing server applications are used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The latest release of internet-facing server applications are used.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1485
Web browsers do not process web advertisements from the internet.

Web browsers do not process web advertisements from the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web browsers do not process web advertisements from the internet.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1486
Web browsers do not process Java from the internet.

Web browsers do not process Java from the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web browsers do not process Java from the internet.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1487
Only privileged users responsible for checking that Microsoft Office macros are free of ma

Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only privileged users responsible for checking that Microsoft Office macros are
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1488
Microsoft Office macros in files originating from the internet are blocked.

Microsoft Office macros in files originating from the internet are blocked.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros in files originating from the internet are blocked.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1489
Microsoft Office macro security settings cannot be changed by users.

Microsoft Office macro security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macro security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1490
Application control is implemented on internet-facing servers.

Application control is implemented on internet-facing servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is implemented on internet-facing servers.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1491
Unprivileged users are prevented from running script execution engines, including: - Windo

Unprivileged users are prevented from running script execution engines, including: - Windows Script Host (cscript.exe and wscript.exe) - PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe) - Command Prompt (cmd.exe) - Windows Management Instrumentation (wmic.exe) - Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged users are prevented from running script execution engines, includin
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1492
Operating system exploit protection functionality is enabled.

Operating system exploit protection functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating system exploit protection functionality is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1504
Multi-factor authentication is used to authenticate users to their organisation's online s

Multi-factor authentication is used to authenticate users to their organisation's online services that process, store or communicate their organisation's sensitive data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate users to their organisation'
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1505
Multi-factor authentication is used to authenticate users of data repositories.

Multi-factor authentication is used to authenticate users of data repositories.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate users of data repositories.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1542
Microsoft Office is configured to prevent activation of Object Linking and Embedding packa

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office is configured to prevent activation of Object Linking and Embed
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1544
Microsoft's recommended application blocklist is implemented.

Microsoft's recommended application blocklist is implemented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft's recommended application blocklist is implemented.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1546
Users are authenticated before they are granted access to a system and its resources.

Users are authenticated before they are granted access to a system and its resources.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users are authenticated before they are granted access to a system and its resou
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1557
Passwords used for single-factor authentication on SECRET systems are a minimum of 17 char

Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for single-factor authentication on SECRET systems are a minimum
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1558
Passwords using a sequence of words for single-factor authentication are not constructed u

Passwords using a sequence of words for single-factor authentication are not constructed using: - a list of categorised words - a real sentence in a natural language - song lyrics, movie or television show quotes, literature, or any other publicly available material - less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords using a sequence of words for single-factor authentication are not con
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1559
Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and

Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sens
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1560
Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 charac

Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for multi-factor authentication on SECRET systems are a minimum o
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1561
Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 c

Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords used for multi-factor authentication on TOP SECRET systems are a minim
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1582
Application control rulesets are validated on an annual or more frequent basis.

Application control rulesets are validated on an annual or more frequent basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control rulesets are validated on an annual or more frequent basis.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1584
Unprivileged users are prevented from bypassing, disabling or modifying security functiona

Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged users are prevented from bypassing, disabling or modifying security
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1585
Web browser security settings cannot be changed by users.

Web browser security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Web browser security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1588
SOEs are reviewed and updated at least annually.

SOEs are reviewed and updated at least annually.

Artefacts an auditor will ask for
  • Evidence demonstrating: SOEs are reviewed and updated at least annually.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1590
Credentials for user accounts are changed if: - they are compromised - they are suspected

Credentials for user accounts are changed if: - they are compromised - they are suspected of being compromised - they are discovered stored on networks in the clear - they are discovered being transferred across networks in the clear - membership of a shared user account changes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for user accounts are changed if: - they are compromised - they are
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1592
Unprivileged users do not have the ability to install unapproved applications.

Unprivileged users do not have the ability to install unapproved applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged users do not have the ability to install unapproved applications.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1593
Users provide sufficient evidence to verify their identity when requesting new credentials

Users provide sufficient evidence to verify their identity when requesting new credentials.

Artefacts an auditor will ask for
  • Evidence demonstrating: Users provide sufficient evidence to verify their identity when requesting new c
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1594
Credentials are provided to users via a secure communications channel or, if not possible,

Credentials are provided to users via a secure communications channel or, if not possible, split into two parts with one part provided to users and the other part provided to supervisors.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials are provided to users via a secure communications channel or, if not
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1595
Credentials provided to users are changed on first use.

Credentials provided to users are changed on first use.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials provided to users are changed on first use.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1596
Credentials are not reused by users across different systems.

Credentials are not reused by users across different systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials are not reused by users across different systems.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1597
Credentials are obscured as they are entered into systems.

Credentials are obscured as they are entered into systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials are obscured as they are entered into systems.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1601
Microsoft's attack surface reduction rules are implemented.

Microsoft's attack surface reduction rules are implemented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft's attack surface reduction rules are implemented.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1603
Authentication methods susceptible to replay attacks are disabled.

Authentication methods susceptible to replay attacks are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Authentication methods susceptible to replay attacks are disabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1604
When using a software-based isolation mechanism to share a physical server's hardware, the

When using a software-based isolation mechanism to share a physical server's hardware, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1605
When using a software-based isolation mechanism to share a physical server's hardware, the

When using a software-based isolation mechanism to share a physical server's hardware, the underlying operating system is hardened.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1606
When using a software-based isolation mechanism to share a physical server's hardware, pat

When using a software-based isolation mechanism to share a physical server's hardware, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1607
When using a software-based isolation mechanism to share a physical server's hardware, int

When using a software-based isolation mechanism to share a physical server's hardware, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1608
SOEs provided by third parties are scanned for malicious code and configurations.

SOEs provided by third parties are scanned for malicious code and configurations.

Artefacts an auditor will ask for
  • Evidence demonstrating: SOEs provided by third parties are scanned for malicious code and configurations
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1619
Service accounts are created as group Managed Service Accounts.

Service accounts are created as group Managed Service Accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: Service accounts are created as group Managed Service Accounts.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1620
Privileged user accounts are members of the Protected Users security group.

Privileged user accounts are members of the Protected Users security group.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts are members of the Protected Users security group.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1621
Windows PowerShell 2.0 is disabled or removed.

Windows PowerShell 2.0 is disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Windows PowerShell 2.0 is disabled or removed.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1622
PowerShell is configured to use Constrained Language Mode.

PowerShell is configured to use Constrained Language Mode.

Artefacts an auditor will ask for
  • Evidence demonstrating: PowerShell is configured to use Constrained Language Mode.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1623
PowerShell module logging, script block logging and transcription events are centrally log

PowerShell module logging, script block logging and transcription events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: PowerShell module logging, script block logging and transcription events are cen
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1624
PowerShell script block logs are protected by Protected Event Logging functionality.

PowerShell script block logs are protected by Protected Event Logging functionality.

Artefacts an auditor will ask for
  • Evidence demonstrating: PowerShell script block logs are protected by Protected Event Logging functional
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1654
Internet Explorer 11 is disabled or removed.

Internet Explorer 11 is disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Internet Explorer 11 is disabled or removed.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1655
.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1656
Application control is implemented on non-internet-facing servers.

Application control is implemented on non-internet-facing servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is implemented on non-internet-facing servers.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1657
Application control restricts the execution of executables, libraries, scripts, installers

Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control restricts the execution of executables, libraries, scripts,
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1658
Application control restricts the execution of drivers to an organisation-approved set.

Application control restricts the execution of drivers to an organisation-approved set.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control restricts the execution of drivers to an organisation-approv
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1659
Microsoft's vulnerable driver blocklist is implemented.

Microsoft's vulnerable driver blocklist is implemented.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft's vulnerable driver blocklist is implemented.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1660
Allowed and blocked application control events are centrally logged.

Allowed and blocked application control events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Allowed and blocked application control events are centrally logged.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1667
Microsoft Office is blocked from creating child processes.

Microsoft Office is blocked from creating child processes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office is blocked from creating child processes.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1668
Microsoft Office is blocked from creating executable content.

Microsoft Office is blocked from creating executable content.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office is blocked from creating executable content.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1669
Microsoft Office is blocked from injecting code into other processes.

Microsoft Office is blocked from injecting code into other processes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office is blocked from injecting code into other processes.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1670
PDF applications are blocked from creating child processes.

PDF applications are blocked from creating child processes.

Artefacts an auditor will ask for
  • Evidence demonstrating: PDF applications are blocked from creating child processes.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1671
Microsoft Office macros are disabled for users that do not have a demonstrated business re

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros are disabled for users that do not have a demonstrated b
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1672
Microsoft Office macro antivirus scanning is enabled.

Microsoft Office macro antivirus scanning is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macro antivirus scanning is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1673
Microsoft Office macros are blocked from making Win32 API calls.

Microsoft Office macros are blocked from making Win32 API calls.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros are blocked from making Win32 API calls.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1674
Only Microsoft Office macros running from within a sandboxed environment, a Trusted Locati

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.

Artefacts an auditor will ask for
  • Evidence demonstrating: Only Microsoft Office macros running from within a sandboxed environment, a Trus
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1675
Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via t

Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros digitally signed by an untrusted publisher cannot be ena
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1676
Microsoft Office's list of trusted publishers is validated on an annual or more frequent b

Microsoft Office's list of trusted publishers is validated on an annual or more frequent basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office's list of trusted publishers is validated on an annual or more
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1679
Multi-factor authentication is used to authenticate users to third-party online services t

Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation's sensitive data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate users to third-party online
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1680
Multi-factor authentication (where available) is used to authenticate users to third-party

Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation's non-sensitive data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication (where available) is used to authenticate users to t
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1681
Multi-factor authentication is used to authenticate customers to online customer services

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate customers to online customer
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1682
Multi-factor authentication used for authenticating users of systems is phishing-resistant

Multi-factor authentication used for authenticating users of systems is phishing-resistant.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication used for authenticating users of systems is phishing
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1683
Successful and unsuccessful multi-factor authentication events are centrally logged.

Successful and unsuccessful multi-factor authentication events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Successful and unsuccessful multi-factor authentication events are centrally log
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1685
Credentials for break glass accounts, local administrator accounts and service accounts ar

Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for break glass accounts, local administrator accounts and service a
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1686
Credential Guard functionality is enabled.

Credential Guard functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credential Guard functionality is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1743
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1745
Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is ena

Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functional
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1746
When implementing application control using path rules, only approved users can change fil

When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.

Artefacts an auditor will ask for
  • Evidence demonstrating: When implementing application control using path rules, only approved users can
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1748
Email client security settings cannot be changed by users.

Email client security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Email client security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1749
Cached credentials are limited to one previous logon.

Cached credentials are limited to one previous logon.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cached credentials are limited to one previous logon.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1795
Credentials for built-in Administrator accounts, break glass accounts, local administrator

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for built-in Administrator accounts, break glass accounts, local adm
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1806
Default user accounts or credentials for user applications, including for any pre-configur

Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Artefacts an auditor will ask for
  • Evidence demonstrating: Default user accounts or credentials for user applications, including for any pr
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1823
Office productivity suite security settings cannot be changed by users.

Office productivity suite security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Office productivity suite security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1824
PDF application security settings cannot be changed by users.

PDF application security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: PDF application security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1825
Security product security settings cannot be changed by users.

Security product security settings cannot be changed by users.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security product security settings cannot be changed by users.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1826
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.

Artefacts an auditor will ask for
  • Evidence demonstrating: Vendors that have demonstrated a commitment to Secure by Design and Secure by De
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1827
Microsoft AD DS domain controllers are administered using dedicated domain administrator u

Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft AD DS domain controllers are administered using dedicated domain admin
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1828
The Print Spooler service is disabled on Microsoft AD DS domain controllers.

The Print Spooler service is disabled on Microsoft AD DS domain controllers.

Artefacts an auditor will ask for
  • Evidence demonstrating: The Print Spooler service is disabled on Microsoft AD DS domain controllers.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1829
Passwords are not stored in Group Policy Preferences.

Passwords are not stored in Group Policy Preferences.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords are not stored in Group Policy Preferences.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1830
Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA server

Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1832
Only service accounts and computer accounts are configured with Service Principal Names (S

Only service accounts and computer accounts are configured with Service Principal Names (SPNs).

Artefacts an auditor will ask for
  • Evidence demonstrating: Only service accounts and computer accounts are configured with Service Principa
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1833
User accounts are provisioned with the minimum privileges required.

User accounts are provisioned with the minimum privileges required.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts are provisioned with the minimum privileges required.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1834
Duplicate SPNs do not exist within the domain.

Duplicate SPNs do not exist within the domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Duplicate SPNs do not exist within the domain.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1835
Privileged user accounts are configured as sensitive and cannot be delegated.

Privileged user accounts are configured as sensitive and cannot be delegated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts are configured as sensitive and cannot be delegated.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1836
User accounts require Kerberos pre-authentication.

User accounts require Kerberos pre-authentication.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts require Kerberos pre-authentication.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1838
The UserPassword attribute for user accounts is not used.

The UserPassword attribute for user accounts is not used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The UserPassword attribute for user accounts is not used.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1839
Account properties accessible by unprivileged users are not used to store passwords.

Account properties accessible by unprivileged users are not used to store passwords.

Artefacts an auditor will ask for
  • Evidence demonstrating: Account properties accessible by unprivileged users are not used to store passwo
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1840
User account passwords do not use reversible encryption.

User account passwords do not use reversible encryption.

Artefacts an auditor will ask for
  • Evidence demonstrating: User account passwords do not use reversible encryption.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1841
Unprivileged user accounts cannot add machines to the domain.

Unprivileged user accounts cannot add machines to the domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts cannot add machines to the domain.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1842
Dedicated privileged service accounts are used to add machines to the domain.

Dedicated privileged service accounts are used to add machines to the domain.

Artefacts an auditor will ask for
  • Evidence demonstrating: Dedicated privileged service accounts are used to add machines to the domain.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1843
User accounts with unconstrained delegation are reviewed at least annually, and those with

User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts with unconstrained delegation are reviewed at least annually, and
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1844
Computer accounts that are not Microsoft AD DS domain controllers are not trusted for dele

Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.

Artefacts an auditor will ask for
  • Evidence demonstrating: Computer accounts that are not Microsoft AD DS domain controllers are not truste
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1845
When a user account is disabled, it is removed from all security group memberships.

When a user account is disabled, it is removed from all security group memberships.

Artefacts an auditor will ask for
  • Evidence demonstrating: When a user account is disabled, it is removed from all security group membershi
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1846
The Pre-Windows 2000 Compatible Access security group does not contain user accounts.

The Pre-Windows 2000 Compatible Access security group does not contain user accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: The Pre-Windows 2000 Compatible Access security group does not contain user acco
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1847
Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are change

Credentials for the Kerberos Key Distribution Center's service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for the Kerberos Key Distribution Center's service account (KRBTGT)
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1848
When using a software-based isolation mechanism to share a physical server's hardware, the

When using a software-based isolation mechanism to share a physical server's hardware, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.

Artefacts an auditor will ask for
  • Evidence demonstrating: When using a software-based isolation mechanism to share a physical server's har
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1859
Office productivity suites are hardened using ASD and vendor hardening guidance, with the

Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Office productivity suites are hardened using ASD and vendor hardening guidance,
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1860
PDF applications are hardened using ASD and vendor hardening guidance, with the most restr

PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: PDF applications are hardened using ASD and vendor hardening guidance, with the
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1861
Local Security Authority protection functionality is enabled.

Local Security Authority protection functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Local Security Authority protection functionality is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1870
Application control is applied to user profiles and temporary folders used by operating sy

Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is applied to user profiles and temporary folders used by op
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1871
Application control is applied to all locations other than user profiles and temporary fol

Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.

Artefacts an auditor will ask for
  • Evidence demonstrating: Application control is applied to all locations other than user profiles and tem
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1872
Multi-factor authentication used for authenticating users of online services is phishing-r

Multi-factor authentication used for authenticating users of online services is phishing-resistant.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication used for authenticating users of online services is
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1873
Multi-factor authentication used for authenticating customers of online customer services

Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication used for authenticating customers of online customer
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1874
Multi-factor authentication used for authenticating customers of online customer services

Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication used for authenticating customers of online customer
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1875
Networks are scanned at least monthly to identify any credentials that are being stored in

Networks are scanned at least monthly to identify any credentials that are being stored in the clear.

Artefacts an auditor will ask for
  • Evidence demonstrating: Networks are scanned at least monthly to identify any credentials that are being
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1889
Command line process creation events are centrally logged.

Command line process creation events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Command line process creation events are centrally logged.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1890
Microsoft Office macros are checked to ensure they are free of malicious code before being

Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros are checked to ensure they are free of malicious code be
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1891
Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be

Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft Office macros digitally signed by signatures other than V3 signatures
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1892
Multi-factor authentication is used to authenticate users to their organisation's online c

Multi-factor authentication is used to authenticate users to their organisation's online customer services that process, store or communicate their organisation's sensitive customer data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate users to their organisation'
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1893
Multi-factor authentication is used to authenticate users to third-party online customer s

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation's sensitive customer data.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication is used to authenticate users to third-party online
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1894
Multi-factor authentication used for authenticating users of data repositories is phishing

Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.

Artefacts an auditor will ask for
  • Evidence demonstrating: Multi-factor authentication used for authenticating users of data repositories i
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1895
Successful and unsuccessful single-factor authentication events are centrally logged.

Successful and unsuccessful single-factor authentication events are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Successful and unsuccessful single-factor authentication events are centrally lo
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1896
Memory integrity functionality is enabled.

Memory integrity functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Memory integrity functionality is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1897
Remote Credential Guard functionality is enabled.

Remote Credential Guard functionality is enabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: Remote Credential Guard functionality is enabled.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1914
Approved configurations for operating systems are developed, implemented and maintained.

Approved configurations for operating systems are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Approved configurations for operating systems are developed, implemented and mai
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1915
Approved configurations for user applications are developed, implemented and maintained.

Approved configurations for user applications are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Approved configurations for user applications are developed, implemented and mai
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1916
Approved configurations for server applications are developed, implemented and maintained.

Approved configurations for server applications are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Approved configurations for server applications are developed, implemented and m
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1919
When multi-factor authentication is used to authenticate users or customers to online serv

When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.

Artefacts an auditor will ask for
  • Evidence demonstrating: When multi-factor authentication is used to authenticate users or customers to o
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1920
When multi-factor authentication is used to authenticate users to online services, online

When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories - that process, store or communicate their organisation's sensitive data or sensitive customer data - users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: When multi-factor authentication is used to authenticate users to online service
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1926
Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers an

Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1927
Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS

Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Micros
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1928
Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS

Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted, stored securely and only accessible to backup administrator accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Micro
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1929
Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain control

Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS doma
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1930
Passwords are prevented from being stored in Group Policy Preferences.

Passwords are prevented from being stored in Group Policy Preferences.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords are prevented from being stored in Group Policy Preferences.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1931
SID Filtering is enabled for domain and forest trusts.

SID Filtering is enabled for domain and forest trusts.

Artefacts an auditor will ask for
  • Evidence demonstrating: SID Filtering is enabled for domain and forest trusts.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1932
The number of service accounts configured with an SPN is minimised.

The number of service accounts configured with an SPN is minimised.

Artefacts an auditor will ask for
  • Evidence demonstrating: The number of service accounts configured with an SPN is minimised.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1933
Service accounts configured with an SPN do not have DCSync permissions.

Service accounts configured with an SPN do not have DCSync permissions.

Artefacts an auditor will ask for
  • Evidence demonstrating: Service accounts configured with an SPN do not have DCSync permissions.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1934
User accounts with DCSync permissions are reviewed at least annually, and those without an

User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts with DCSync permissions are reviewed at least annually, and those
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1935
Computer accounts are not configured for unconstrained delegation.

Computer accounts are not configured for unconstrained delegation.

Artefacts an auditor will ask for
  • Evidence demonstrating: Computer accounts are not configured for unconstrained delegation.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1936
The sIDHistory attribute for user accounts is not used.

The sIDHistory attribute for user accounts is not used.

Artefacts an auditor will ask for
  • Evidence demonstrating: The sIDHistory attribute for user accounts is not used.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1937
User accounts are checked at least weekly for the presence of the sIDHistory attribute.

User accounts are checked at least weekly for the presence of the sIDHistory attribute.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts are checked at least weekly for the presence of the sIDHistory att
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1938
The Domain Computers security group does not have write or modify permissions to any Micro

The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.

Artefacts an auditor will ask for
  • Evidence demonstrating: The Domain Computers security group does not have write or modify permissions to
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1939
The number of user accounts that are members of the Domain Admins, Enterprise Admins or ot

The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.

Artefacts an auditor will ask for
  • Evidence demonstrating: The number of user accounts that are members of the Domain Admins, Enterprise Ad
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1940
Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-p

Service accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Service accounts are not members of the Domain Admins, Enterprise Admins or othe
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1941
Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly-

Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly-privileged security groups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Computer accounts are not members of the Domain Admins, Enterprise Admins or oth
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1942
The Domain Computers security group is not a member of any privileged or highly-privileged

The Domain Computers security group is not a member of any privileged or highly-privileged security groups.

Artefacts an auditor will ask for
  • Evidence demonstrating: The Domain Computers security group is not a member of any privileged or highly-
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1943
Strong mapping between certificates and users is enforced.

Strong mapping between certificates and users is enforced.

Artefacts an auditor will ask for
  • Evidence demonstrating: Strong mapping between certificates and users is enforced.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1944
The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.

The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.

Artefacts an auditor will ask for
  • Evidence demonstrating: The EDITF ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA confi
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1945
The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.

The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.

Artefacts an auditor will ask for
  • Evidence demonstrating: The CT FLAG ENROLLEE SUPPLIES SUBJECT flag is removed from certificate templates
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1946
Unprivileged user accounts do not have write access to certificate templates.

Unprivileged user accounts do not have write access to certificate templates.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts do not have write access to certificate templates.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1947
Extended Key Usages that enable user authentication are removed.

Extended Key Usages that enable user authentication are removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Extended Key Usages that enable user authentication are removed.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1948
CA Certificate Manager approval is required for certificate templates that allow a Subject

CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.

Artefacts an auditor will ask for
  • Evidence demonstrating: CA Certificate Manager approval is required for certificate templates that allow
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1949
Microsoft AD FS servers are administered using a dedicated service account that is not use

Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft AD FS servers are administered using a dedicated service account that
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1950
Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial

Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled followi
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1951
Hard match takeover is disabled for Microsoft Entra Connect servers.

Hard match takeover is disabled for Microsoft Entra Connect servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Hard match takeover is disabled for Microsoft Entra Connect servers.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1952
Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra

Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts are not synchronised between Microsoft AD DS and Micros
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1953
Credentials for the built-in Administrator account in each domain are long, unique, unpred

Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for the built-in Administrator account in each domain are long, uniq
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1954
Credentials for built-in Administrator accounts, break glass accounts, local administrator

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for built-in Administrator accounts, break glass accounts, local adm
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1955
Credentials for computer accounts are changed if they are compromised, they are suspected

Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credentials for computer accounts are changed if they are compromised, they are
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1956
Microsoft AD FS token-signing and encryption certificates are changed twice in quick succe

Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Microsoft AD FS token-signing and encryption certificates are changed twice in q
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1957
Private keys for Microsoft AD CS CA servers are protected by a hardware security module.

Private keys for Microsoft AD CS CA servers are protected by a hardware security module.

Artefacts an auditor will ask for
  • Evidence demonstrating: Private keys for Microsoft AD CS CA servers are protected by a hardware security
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1976
Security-relevant events for Apple macOS operating systems are centrally logged.

Security-relevant events for Apple macOS operating systems are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for Apple macOS operating systems are centrally logged.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1977
Security-relevant events for Linux operating systems are centrally logged.

Security-relevant events for Linux operating systems are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for Linux operating systems are centrally logged.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1978
Security-relevant events for server applications on internet-facing servers are centrally

Security-relevant events for server applications on internet-facing servers are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for server applications on internet-facing servers are
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1979
Security-relevant events for server applications on non-internet-facing servers are centra

Security-relevant events for server applications on non-internet-facing servers are centrally logged.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security-relevant events for server applications on non-internet-facing servers
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-1980
Credential hint functionality is not used for systems.

Credential hint functionality is not used for systems.

Artefacts an auditor will ask for
  • Evidence demonstrating: Credential hint functionality is not used for systems.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2010
Service accounts configured with an SPN use the Advanced Encryption Standard for encryptio

Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.

Artefacts an auditor will ask for
  • Evidence demonstrating: Service accounts configured with an SPN use the Advanced Encryption Standard for
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2011
When phishing-resistant multi-factor authentication is used by user accounts, other non-ph

When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: When phishing-resistant multi-factor authentication is used by user accounts, ot
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2012
Systems are configured with a screen lock that: - activates after a maximum of 15 minutes

Systems are configured with a screen lock that: - activates after a maximum of 15 minutes of user inactivity, or when manually activated by users - conceals all content on the screen - ensures that the screen does not enter a power saving state before the screen lock is activated - requires users to re-authenticate using all authentication factors to unlock the system - denies users the ability to disable the screen locking mechanism.

Artefacts an auditor will ask for
  • Evidence demonstrating: Systems are configured with a screen lock that: - activates after a maximum of 1
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2076
Security questions are not used for authentication purposes.

Security questions are not used for authentication purposes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Security questions are not used for authentication purposes.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2077
Email is not used for out-of-band authentication purposes.

Email is not used for out-of-band authentication purposes.

Artefacts an auditor will ask for
  • Evidence demonstrating: Email is not used for out-of-band authentication purposes.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2078
Passwords appearing in lists of commonly used passwords or lists of compromised passwords

Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.

Artefacts an auditor will ask for
  • Evidence demonstrating: Passwords appearing in lists of commonly used passwords or lists of compromised
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2079
Maximum length limits for passwords are not less than 64 characters.

Maximum length limits for passwords are not less than 64 characters.

Artefacts an auditor will ask for
  • Evidence demonstrating: Maximum length limits for passwords are not less than 64 characters.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2080
Password complexity requirements are not imposed for passwords.

Password complexity requirements are not imposed for passwords.

Artefacts an auditor will ask for
  • Evidence demonstrating: Password complexity requirements are not imposed for passwords.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced
ISM-2081
All ASCII printable characters are supported for passwords.

All ASCII printable characters are supported for passwords.

Artefacts an auditor will ask for
  • Evidence demonstrating: All ASCII printable characters are supported for passwords.
  • Hardening baselines (ASD/vendor guidance)
  • Application control configuration
  • Multi-factor authentication configuration
  • Build/configuration evidence
Where this commonly fails
  • Default or unhardened configurations
  • Application control not implemented
  • MFA not enforced

Guidelines for system management

ISM-0042
System administration processes, and supporting system administration procedures, are deve

System administration processes, and supporting system administration procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administration processes, and supporting system administration procedures
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-0298
A centralised and managed approach that maintains the integrity of patches or updates, and

A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.

Artefacts an auditor will ask for
  • Evidence demonstrating: A centralised and managed approach that maintains the integrity of patches or up
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-0300
Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equi

Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in high assuran
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-0304
Applications other than office productivity suites, web browsers and their extensions, ema

Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Applications other than office productivity suites, web browsers and their exten
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1143
Patch management processes, and supporting patch management procedures, are developed, imp

Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patch management processes, and supporting patch management procedures, are deve
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1211
System administrators perform system administration activities in accordance with the syst

System administrators perform system administration activities in accordance with the system's change and configuration management plan.

Artefacts an auditor will ask for
  • Evidence demonstrating: System administrators perform system administration activities in accordance wit
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1380
Privileged users use separate privileged and unprivileged operating environments.

Privileged users use separate privileged and unprivileged operating environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged users use separate privileged and unprivileged operating environments
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1385
Administrative infrastructure is segregated from the wider network and the internet.

Administrative infrastructure is segregated from the wider network and the internet.

Artefacts an auditor will ask for
  • Evidence demonstrating: Administrative infrastructure is segregated from the wider network and the inter
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1386
Network management traffic can only originate from administrative infrastructure.

Network management traffic can only originate from administrative infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network management traffic can only originate from administrative infrastructure
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1387
Administrative activities are conducted through jump servers.

Administrative activities are conducted through jump servers.

Artefacts an auditor will ask for
  • Evidence demonstrating: Administrative activities are conducted through jump servers.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1493
Software registers for workstations, servers, network devices and networked IT equipment a

Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and verified on a regular basis.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software registers for workstations, servers, network devices and networked IT e
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1501
Operating systems that are no longer supported by vendors are replaced.

Operating systems that are no longer supported by vendors are replaced.

Artefacts an auditor will ask for
  • Evidence demonstrating: Operating systems that are no longer supported by vendors are replaced.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1510
A digital preservation policy is developed, implemented and maintained.

A digital preservation policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: A digital preservation policy is developed, implemented and maintained.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1511
Backups of data, applications and settings are performed and retained in accordance with b

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

Artefacts an auditor will ask for
  • Evidence demonstrating: Backups of data, applications and settings are performed and retained in accorda
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1515
Restoration of data, applications and settings from backups to a common point in time is t

Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Artefacts an auditor will ask for
  • Evidence demonstrating: Restoration of data, applications and settings from backups to a common point in
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1547
Data backup processes, and supporting data backup procedures, are developed, implemented a

Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data backup processes, and supporting data backup procedures, are developed, imp
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1548
Data restoration processes, and supporting data restoration procedures, are developed, imp

Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: Data restoration processes, and supporting data restoration procedures, are deve
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1643
Software registers contain versions and patch histories of applications, drivers, operatin

Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.

Artefacts an auditor will ask for
  • Evidence demonstrating: Software registers contain versions and patch histories of applications, drivers
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1687
Privileged operating environments are not virtualised within unprivileged operating enviro

Privileged operating environments are not virtualised within unprivileged operating environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged operating environments are not virtualised within unprivileged operat
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1688
Unprivileged user accounts cannot logon to privileged operating environments.

Unprivileged user accounts cannot logon to privileged operating environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts cannot logon to privileged operating environments.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1689
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivil

Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts (excluding local administrator accounts) cannot logon t
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1690
Patches, updates or other vendor mitigations for vulnerabilities in online services are ap

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in online servi
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1691
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1692
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1693
Patches, updates or other vendor mitigations for vulnerabilities in applications other tha

Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in applications
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1694
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1695
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1696
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1697
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in drivers are
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1698
A vulnerability scanner is used at least daily to identify missing patches or updates for

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least daily to identify missing patches or up
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1699
A vulnerability scanner is used at least weekly to identify missing patches or updates for

A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least weekly to identify missing patches or u
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1700
A vulnerability scanner is used at least fortnightly to identify missing patches or update

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1701
A vulnerability scanner is used at least daily to identify missing patches or updates for

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least daily to identify missing patches or up
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1702
A vulnerability scanner is used at least fortnightly to identify missing patches or update

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1703
A vulnerability scanner is used at least fortnightly to identify missing patches or update

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1704
Office productivity suites, web browsers and their extensions, email clients, PDF applicat

Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Office productivity suites, web browsers and their extensions, email clients, PD
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1705
Privileged user accounts (excluding backup administrator accounts) cannot access backups b

Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) cannot access
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1706
Privileged user accounts (excluding backup administrator accounts) cannot access their own

Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) cannot access
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1707
Privileged user accounts (excluding backup administrator accounts) are prevented from modi

Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Privileged user accounts (excluding backup administrator accounts) are prevented
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1708
Backup administrator accounts are prevented from modifying and deleting backups during the

Backup administrator accounts are prevented from modifying and deleting backups during their retention period.

Artefacts an auditor will ask for
  • Evidence demonstrating: Backup administrator accounts are prevented from modifying and deleting backups
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1750
Administrative infrastructure for critical servers, high-value servers and regular servers

Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.

Artefacts an auditor will ask for
  • Evidence demonstrating: Administrative infrastructure for critical servers, high-value servers and regul
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1751
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1752
A vulnerability scanner is used at least fortnightly to identify missing patches or update

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1753
Internet-facing network devices that are no longer supported by vendors are replaced.

Internet-facing network devices that are no longer supported by vendors are replaced.

Artefacts an auditor will ask for
  • Evidence demonstrating: Internet-facing network devices that are no longer supported by vendors are repl
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1807
An automated method of asset discovery is used at least fortnightly to support the detecti

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: An automated method of asset discovery is used at least fortnightly to support t
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1808
A vulnerability scanner with an up-to-date vulnerability database is used for vulnerabilit

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner with an up-to-date vulnerability database is used for vu
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1809
When applications, operating systems, network devices or networked IT equipment that are n

When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.

Artefacts an auditor will ask for
  • Evidence demonstrating: When applications, operating systems, network devices or networked IT equipment
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1810
Backups of data, applications and settings are synchronised to enable restoration to a com

Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

Artefacts an auditor will ask for
  • Evidence demonstrating: Backups of data, applications and settings are synchronised to enable restoratio
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1811
Backups of data, applications and settings are retained in a secure and resilient manner.

Backups of data, applications and settings are retained in a secure and resilient manner.

Artefacts an auditor will ask for
  • Evidence demonstrating: Backups of data, applications and settings are retained in a secure and resilien
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1812
Unprivileged user accounts cannot access backups belonging to other user accounts.

Unprivileged user accounts cannot access backups belonging to other user accounts.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts cannot access backups belonging to other user account
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1813
Unprivileged user accounts cannot access their own backups.

Unprivileged user accounts cannot access their own backups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts cannot access their own backups.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1814
Unprivileged user accounts are prevented from modifying and deleting backups.

Unprivileged user accounts are prevented from modifying and deleting backups.

Artefacts an auditor will ask for
  • Evidence demonstrating: Unprivileged user accounts are prevented from modifying and deleting backups.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1876
Patches, updates or other vendor mitigations for vulnerabilities in online services are ap

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in online servi
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1877
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of i

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1878
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of I

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1879
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied wi

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in drivers are
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1898
Secure Admin Workstations are used in the performance of administrative activities.

Secure Admin Workstations are used in the performance of administrative activities.

Artefacts an auditor will ask for
  • Evidence demonstrating: Secure Admin Workstations are used in the performance of administrative activiti
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1899
Network devices that do not belong to administrative infrastructure cannot initiate connec

Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.

Artefacts an auditor will ask for
  • Evidence demonstrating: Network devices that do not belong to administrative infrastructure cannot initi
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1900
A vulnerability scanner is used at least fortnightly to identify missing patches or update

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.

Artefacts an auditor will ask for
  • Evidence demonstrating: A vulnerability scanner is used at least fortnightly to identify missing patches
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1901
Patches, updates or other vendor mitigations for vulnerabilities in office productivity su

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in office produ
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1902
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of w

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in operating sy
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1903
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in firmware are
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1904
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied w

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Artefacts an auditor will ask for
  • Evidence demonstrating: Patches, updates or other vendor mitigations for vulnerabilities in firmware are
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1905
Online services that are no longer supported by vendors are removed.

Online services that are no longer supported by vendors are removed.

Artefacts an auditor will ask for
  • Evidence demonstrating: Online services that are no longer supported by vendors are removed.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1921
The likelihood of system compromise is frequently assessed when working exploits exist for

The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.

Artefacts an auditor will ask for
  • Evidence demonstrating: The likelihood of system compromise is frequently assessed when working exploits
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1958
User accounts with DCSync permissions cannot logon to unprivileged operating environments.

User accounts with DCSync permissions cannot logon to unprivileged operating environments.

Artefacts an auditor will ask for
  • Evidence demonstrating: User accounts with DCSync permissions cannot logon to unprivileged operating env
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1981
Non-internet-facing network devices that are no longer supported by vendors are replaced.

Non-internet-facing network devices that are no longer supported by vendors are replaced.

Artefacts an auditor will ask for
  • Evidence demonstrating: Non-internet-facing network devices that are no longer supported by vendors are
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled
ISM-1982
Networked IT equipment that is no longer supported by vendors is replaced.

Networked IT equipment that is no longer supported by vendors is replaced.

Artefacts an auditor will ask for
  • Evidence demonstrating: Networked IT equipment that is no longer supported by vendors is replaced.
  • Patch management records and SLAs
  • Privileged administration procedures
  • Backup and restoration test records
Where this commonly fails
  • Unpatched systems beyond SLA
  • Untested backups
  • Privileged access not controlled

Guidelines for system monitoring

ISM-0109
Event logs from workstations are analysed in a timely manner to detect cyber security even

Event logs from workstations are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from workstations are analysed in a timely manner to detect cyber sec
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-0580
An event logging policy is developed, implemented and maintained.

An event logging policy is developed, implemented and maintained.

Artefacts an auditor will ask for
  • Evidence demonstrating: An event logging policy is developed, implemented and maintained.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-0585
For each event logged, the date and time of the event, the relevant user or process, the r

For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.

Artefacts an auditor will ask for
  • Evidence demonstrating: For each event logged, the date and time of the event, the relevant user or proc
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-0988
An accurate and consistent time source is used for event logging.

An accurate and consistent time source is used for event logging.

Artefacts an auditor will ask for
  • Evidence demonstrating: An accurate and consistent time source is used for event logging.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1228
Cyber security events are analysed in a timely manner to identify cyber security incidents

Cyber security events are analysed in a timely manner to identify cyber security incidents.

Artefacts an auditor will ask for
  • Evidence demonstrating: Cyber security events are analysed in a timely manner to identify cyber security
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1405
A centralised event logging facility is implemented.

A centralised event logging facility is implemented.

Artefacts an auditor will ask for
  • Evidence demonstrating: A centralised event logging facility is implemented.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1815
Event logs are protected from unauthorised modification and deletion.

Event logs are protected from unauthorised modification and deletion.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs are protected from unauthorised modification and deletion.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1906
Event logs from internet-facing servers are analysed in a timely manner to detect cyber se

Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from internet-facing servers are analysed in a timely manner to detec
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1907
Event logs from non-internet-facing servers are analysed in a timely manner to detect cybe

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from non-internet-facing servers are analysed in a timely manner to d
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1959
To the extent possible, event logs are captured and stored in a consistent and structured

To the extent possible, event logs are captured and stored in a consistent and structured format.

Artefacts an auditor will ask for
  • Evidence demonstrating: To the extent possible, event logs are captured and stored in a consistent and s
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1960
Event logs from internet-facing network devices are analysed in a timely manner to detect

Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from internet-facing network devices are analysed in a timely manner
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1961
Event logs from non-internet-facing network devices are analysed in a timely manner to det

Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from non-internet-facing network devices are analysed in a timely man
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1983
Event logs sent to a centralised event logging facility are done so as soon as possible af

Event logs sent to a centralised event logging facility are done so as soon as possible after they occur.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs sent to a centralised event logging facility are done so as soon as p
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1984
Event logs sent to a centralised event logging facility are encrypted in transit.

Event logs sent to a centralised event logging facility are encrypted in transit.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs sent to a centralised event logging facility are encrypted in transit
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1985
Event logs are protected from unauthorised access.

Event logs are protected from unauthorised access.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs are protected from unauthorised access.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1986
Event logs from critical servers are analysed in a timely manner to detect cyber security

Event logs from critical servers are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from critical servers are analysed in a timely manner to detect cyber
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1987
Event logs from security products are analysed in a timely manner to detect cyber security

Event logs from security products are analysed in a timely manner to detect cyber security events.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs from security products are analysed in a timely manner to detect cybe
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1988
Event logs are retained in a searchable manner for at least 12 months.

Event logs are retained in a searchable manner for at least 12 months.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs are retained in a searchable manner for at least 12 months.
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
ISM-1989
Event logs are retained as per minimum retention requirements for various classes of recor

Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia's Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.

Artefacts an auditor will ask for
  • Evidence demonstrating: Event logs are retained as per minimum retention requirements for various classe
  • Centralised event logging configuration
  • Log retention settings
  • Event analysis / alert records
Where this commonly fails
  • Logs not centralised
  • Insufficient retention
  • Events not analysed in a timely manner
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Australian Information Security Manual framework page.