ISM assessment · Guides
ISM Controls Explained in Plain English
The Australian Signals Directorate's Information Security Manual (ISM) sets out more than a thousand controls. These guides explain the ones people ask about most: what each control requires, why it matters, what gets in the way, and the evidence that shows it is met.
ISM-1648Suspension of access to systemsDisable Idle Admin Access After 45 DaysISM-1648 says privileged access is disabled after 45 days without use. What counts as inactive, how to automate it, the exceptions and evidence to keep.
ISM-0428Session lockingLock Idle Sessions After 15 MinutesISM-0428 says online services lock after 15 idle minutes or 12 hours in all, and unlock only with every factor. What that means and the evidence to keep.
ISM-2121Secure software developmentSecurity Skills for Software DevelopersISM-2121 says developers without the security skills a task needs are not used for it. What that means for staff, contractors and AI, and the evidence.
ISM-1685Credential managementPasswords for Admin and Service AccountsISM-1685 says break glass, local admin and service account credentials must be long, unique, random and managed. What that means and the evidence to keep.
ISM-2080Password strengthWhy Password Complexity Rules Are OutASD's ISM-2080 says not to impose password complexity rules. What it means, why length and banned-password checks work better, and the evidence to keep.
What the ISM is, who it applies to and how an assessment works: the ISM explained.