{
  "release": "2026.09.4",
  "attribution": "ISM text © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au.",
  "controls": {
    "ISM-0421": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.",
      "applicability": [
        "NC",
        "OS",
        "P"
      ],
      "essentialEight": [],
      "revision": "11",
      "updated": "Dec-25"
    },
    "ISM-0428": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Session locking"
      ],
      "statement": "Services are configured with a session lock that:\n\n- activates after a maximum of 15 minutes of human user inactivity, a maximum of 12 hours of overall session time or when manually activated\n- blocks access to all session content\n- requires re-authentication by human users using all authentication factors to unlock the session\n- denies human users the ability to disable the session locking mechanism.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "11",
      "updated": "Sep-26"
    },
    "ISM-0430": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Suspension of access to systems"
      ],
      "statement": "Access to systems and their resources are removed or suspended the same day users no longer have a legitimate requirement for access.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "9",
      "updated": "Sep-26"
    },
    "ISM-0445": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Privileged access to systems"
      ],
      "statement": "Privileged human users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML1",
        "ML2",
        "ML3"
      ],
      "revision": "9",
      "updated": "Sep-26"
    },
    "ISM-0853": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Session termination"
      ],
      "statement": "Interactive user sessions are terminated and workstations are restarted at least daily.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "5",
      "updated": "Sep-26"
    },
    "ISM-1404": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Suspension of access to systems"
      ],
      "statement": "Unprivileged access to systems and their resources are disabled after 45 days of inactivity.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "5",
      "updated": "Jun-25"
    },
    "ISM-1507": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Privileged access to systems"
      ],
      "statement": "Requests for privileged access to systems and their resources are validated when first requested.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML1",
        "ML2",
        "ML3"
      ],
      "revision": "4",
      "updated": "Jun-25"
    },
    "ISM-1509": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Privileged access to systems"
      ],
      "statement": "Privileged access events are centrally logged.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML2",
        "ML3"
      ],
      "revision": "3",
      "updated": "Dec-23"
    },
    "ISM-1558": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Passwords using a sequence of words for single-factor authentication are not constructed using:\n\n- a list of categorised words\n- a real sentence in a natural language\n- song lyrics, movie or television show quotes, literature, or any other publicly available material\n- less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "3",
      "updated": "Dec-25"
    },
    "ISM-1559": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.",
      "applicability": [
        "NC",
        "OS",
        "P"
      ],
      "essentialEight": [],
      "revision": "4",
      "updated": "Dec-25"
    },
    "ISM-1591": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Suspension of access to systems"
      ],
      "statement": "Access to systems and their resources are removed or suspended as soon as practicable when users are detected undertaking malicious activities.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "2",
      "updated": "Sep-26"
    },
    "ISM-1614": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Emergency access to systems"
      ],
      "statement": "Break glass account credentials are changed by the account custodian after they are accessed by any other party.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Aug-20"
    },
    "ISM-1615": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Emergency access to systems"
      ],
      "statement": "Break glass accounts are tested after credentials are changed.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Aug-20"
    },
    "ISM-1619": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts"
      ],
      "statement": "Service accounts are created as group Managed Service Accounts.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Oct-20"
    },
    "ISM-1647": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Suspension of access to systems"
      ],
      "statement": "Privileged access to systems and their resources are disabled after 12 months unless revalidated.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML2",
        "ML3"
      ],
      "revision": "2",
      "updated": "Jun-25"
    },
    "ISM-1648": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Suspension of access to systems"
      ],
      "statement": "Privileged access to systems and their resources are disabled after 45 days of inactivity.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML2",
        "ML3"
      ],
      "revision": "2",
      "updated": "Jun-25"
    },
    "ISM-1685": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts"
      ],
      "statement": "Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [
        "ML2",
        "ML3"
      ],
      "revision": "2",
      "updated": "Jun-23"
    },
    "ISM-1795": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts"
      ],
      "statement": "Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "2",
      "updated": "Sep-24"
    },
    "ISM-1888": {
      "path": [
        "Guidelines for enterprise mobility",
        "Mobile device management",
        "Maintaining mobile device security"
      ],
      "statement": "Mobile devices are configured with secure password-based lock screens.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "1",
      "updated": "Mar-26"
    },
    "ISM-1953": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts"
      ],
      "statement": "Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Sep-24"
    },
    "ISM-1954": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts"
      ],
      "statement": "Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Sep-24"
    },
    "ISM-2012": {
      "path": [
        "Guidelines for system access",
        "Identity and access management",
        "Screen locking"
      ],
      "statement": "Systems are configured with a screen lock that:\n\n- activates after a maximum of 15 minutes of human user inactivity, or when manually activated\n- conceals all content on the screen\n- ensures that the screen does not enter a power saving state before the screen lock is activated\n- requires re-authentication by human users using all authentication factors to unlock the system\n- denies human users the ability to disable the screen locking mechanism.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "1",
      "updated": "Sep-26"
    },
    "ISM-2035": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "1",
      "updated": "Jun-26"
    },
    "ISM-2036": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "Security responsibilities for software developers are identified and documented.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Jun-25"
    },
    "ISM-2037": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "2",
      "updated": "Jun-26"
    },
    "ISM-2038": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "A software developer cyber security knowledge and skills register is developed, implemented and maintained.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "2",
      "updated": "Sep-26"
    },
    "ISM-2040": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "Secure programming practices for the chosen programming language are used for software development.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Jun-25"
    },
    "ISM-2066": {
      "path": [
        "Guidelines for software development",
        "Web application development",
        "Secure web application design and development"
      ],
      "statement": "Web application sessions are centrally managed server side.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Jun-25"
    },
    "ISM-2078": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Dec-25"
    },
    "ISM-2079": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Maximum length limits for passwords are not less than 64 characters.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Dec-25"
    },
    "ISM-2080": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "Password complexity requirements are not imposed for passwords.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Dec-25"
    },
    "ISM-2081": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Password strength"
      ],
      "statement": "All ASCII printable characters are supported for passwords.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Dec-25"
    },
    "ISM-2120": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "A secure software development policy is developed, implemented and maintained.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Jun-26"
    },
    "ISM-2121": {
      "path": [
        "Guidelines for software development",
        "Software development fundamentals",
        "Secure software development"
      ],
      "statement": "Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Jun-26"
    },
    "ISM-2147": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Protecting authentication artefacts"
      ],
      "statement": "Authentication tokens, session cookies and refresh tokens are cryptographically bound to the device on which they were issued.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Sep-26"
    },
    "ISM-2148": {
      "path": [
        "Guidelines for system access",
        "Credential management",
        "Protecting authentication artefacts"
      ],
      "statement": "Active sessions, refresh tokens and other authentication artefacts are revoked when credentials are reset or re-enrolled, when credentials are compromised or suspected of being compromised, when a device no longer meets compliance requirements, or when high-risk sign-in activity is detected.",
      "applicability": [
        "NC",
        "OS",
        "P",
        "S",
        "TS"
      ],
      "essentialEight": [],
      "revision": "0",
      "updated": "Sep-26"
    }
  }
}
