Sample report. Generated from our live catalogue for a typical small-business stack: Microsoft Entra ID P1, Microsoft Intune Plan 1 and NinjaOne Backup. Run your own free check →
TERESEC CYBERSECURITY CONSULTING Security Coverage Report

Prepared for

Sample Pty Ltd

Security coverage report: what your licences already cover

Prepared 2026-10-09 · Microsoft Entra ID P1 · Microsoft Intune Plan 1 · NinjaOne Backup Device Backup

3products selected
3licence tiers
25capabilities in scope
2frameworks assessed
5findings

Framework coverage

ISM controls in our count reachable from the tiers you selected. ISM release 2026.09.4.

Australian ISM (2026.09.4) 208 / 1031

Of the ISM's 1143 controls (release 2026.09.4) we count the 1031 applicable to non-classified, OFFICIAL: Sensitive and PROTECTED systems; SECRET and TOP SECRET-only controls are excluded.

Essential Eight: Maturity Level 1 23 / 46

Maturity-level rows derive from ASD's own Essential Eight markings on ISM controls; each level counts the ISM controls ASD marks for it.

Essential Eight: Maturity Level 2 36 / 87

Maturity-level rows derive from ASD's own Essential Eight markings on ISM controls; each level counts the ISM controls ASD marks for it.

Essential Eight: Maturity Level 3 56 / 123

Maturity-level rows derive from ASD's own Essential Eight markings on ISM controls; each level counts the ISM controls ASD marks for it.

Coverage by cyber security principle

Principle groupControls covered
Govern 1 / 88
Identify 8 / 81
Protect 161 / 745
Detect 1 / 36
Respond 1 / 21
Recover 36 / 60

ASD's cyber security principles are published without a mapping to individual controls, so this roll-up assigns each ISM chapter to the principle group it chiefly serves (our reading, not ASD's).

Chapter by chapter

Every ISM control we count, with ASD's own wording, grouped by chapter: the ones your selection reaches and the ones it does not.

Looking up one control? Every control below is linked by its identifier, in ASD's wording for release 2026.09.4, for example #ISM-1685. "Reached" and "not reached" describe this sample stack, not yours.

See which of your own licences reach it: free, about 3 minutes →

Latest ISM release: ISM September 2026: What Changed and What to Check →

Communications infrastructure: 0 of 27 controls reached (5 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0181

    Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.

  • ISM-0206

    Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.

  • ISM-0208

    A cable register contains the following for each cable:

    - cable identifier

    - cable colour

    - sensitivity/classification

    - source

    - destination

    - location

    - seal numbers (if applicable).

  • ISM-0211

    A cable register is developed, implemented, maintained and regularly verified.

  • ISM-0250

    IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.

  • ISM-0926

    Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.

  • ISM-1095

    Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.

  • ISM-1096

    Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.

  • ISM-1101

    In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.

  • ISM-1102

    Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.

  • ISM-1103

    In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.

  • ISM-1107

    Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.

  • ISM-1109

    Wall outlet box covers are clear plastic.

  • ISM-1111

    Fibre-optic cables are used for cabling infrastructure instead of copper cables.

  • ISM-1112

    Cables in non-TOP SECRET areas are inspectable every five metres or less.

  • ISM-1114

    Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.

  • ISM-1115

    Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.

  • ISM-1119

    Cables in TOP SECRET areas are fully inspectable for their entire length.

  • ISM-1130

    In shared facilities, cables are run in an enclosed cable reticulation system.

  • ISM-1164

    In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.

  • ISM-1639

    Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.

  • ISM-1640

    Cables for foreign systems installed in Australian facilities are labelled at inspection points.

  • ISM-1645

    Floor plan diagrams are developed, implemented, maintained and regularly verified.

  • ISM-1646

    Floor plan diagrams contain the following:

    - cable paths (including ingress and egress points between floors)

    - cable reticulation system and conduit paths

    - floor concentration boxes

    - wall outlet boxes

    - network cabinets.

  • ISM-1820

    Cables for individual systems use a consistent colour.

  • ISM-1822

    Wall outlet boxes for individual systems use a consistent colour.

  • ISM-1884

    Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.

Communications systems: 3 of 32 controls reached (20 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0559

    Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.

  • ISM-1450

    Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.

  • ISM-1562

    Video conferencing and IP telephony infrastructure is hardened.

Not reached from your selection

  • ISM-0229

    Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.

  • ISM-0230

    Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.

  • ISM-0231

    When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.

  • ISM-0232

    Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.

  • ISM-0233

    Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted using ASD-approved cryptography.

  • ISM-0235

    Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.

  • ISM-0236

    Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.

  • ISM-0245

    MFDs are not connected to digital telephone systems.

  • ISM-0546

    When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.

  • ISM-0547

    Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.

  • ISM-0548

    Video conferencing and IP telephony calls are established using a secure session initiation protocol.

  • ISM-0549

    Video conferencing and IP telephony traffic is physically or logically separated from other data traffic.

  • ISM-0551

    IP telephony is configured such that:

    - IP phones authenticate themselves to the call controller upon registration

    - auto-registration is disabled and only authorised devices are allowed to access the network

    - unauthorised devices are blocked by default

    - all unused and prohibited functionality is disabled.

  • ISM-0553

    Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.

  • ISM-0554

    An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.

  • ISM-0555

    Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.

  • ISM-0556

    Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses virtual local area networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.

  • ISM-0558

    IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.

  • ISM-0588

    An MFD usage policy is developed, implemented and maintained.

  • ISM-0589

    MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.

  • ISM-0590

    Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.

  • ISM-0931

    In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements.

  • ISM-1019

    A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.

  • ISM-1036

    MFDs are placed in areas where their use can be observed.

  • ISM-1078

    A telephone system usage policy is developed, implemented and maintained.

  • ISM-1805

    A denial of service response plan for video conferencing and IP telephony services contains the following:

    - how to identify signs of a denial-of-service attack

    - how to identify the source of a denial-of-service attack

    - how capabilities can be maintained during a denial-of-service attack

    - what actions can be taken to respond to a denial-of-service attack.

  • ISM-1854

    Human users authenticate to MFDs before they can print, scan or copy documents.

  • ISM-1855

    Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.

  • ISM-2075

    Fax machines, and online fax services, are not used for sending or receiving fax messages.

Cryptography: 4 of 58 controls reached (52 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0484

    The SSH daemon is configured to:

    - only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx)

    - have a suitable login banner (Banner x)

    - have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60)

    - disable host-based authentication (HostbasedAuthentication no)

    - disable rhosts-based authentication (IgnoreRhosts yes)

    - disable the ability to log in directly as root (PermitRootLogin no)

    - disable empty passwords (PermitEmptyPasswords no)

    - disable connection forwarding (AllowTCPForwarding no)

    - disable gateway ports (GatewayPorts no)

    - disable X11 forwarding (X11Forwarding no).

  • ISM-0487

    When using logins without a password for SSH connections, the following are disabled:

    - access from IP addresses that do not require access

    - port forwarding

    - agent credential forwarding

    - X11 forwarding

    - console access.

  • ISM-0488

    If using remote access without the use of a password for SSH connections, the ‘forced command’ option is used to specify what command is executed and parameter checking is enabled.

  • ISM-0489

    When SSH-agent or similar key caching applications are used, cached private keys have a maximum lifetime of four hours and, where applicable, screen locks are used on workstations and servers.

Not reached from your selection

  • ISM-0142

    The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.

  • ISM-0455

    Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.

  • ISM-0457

    Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.

  • ISM-0462

    When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.

  • ISM-0465

    Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.

  • ISM-0469

    An AACP or high assurance cryptographic protocol is used when encrypting data in transit.

  • ISM-0471

    Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.

  • ISM-0472

    When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.

  • ISM-0474

    When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.

  • ISM-0475

    When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.

  • ISM-0476

    When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.

  • ISM-0477

    When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.

  • ISM-0479

    Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.

  • ISM-0481

    Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.

  • ISM-0485

    Public key-based authentication is used for SSH connections.

  • ISM-0490

    Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.

  • ISM-0494

    Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.

  • ISM-0496

    The ESP protocol is used for authentication and encryption of IPsec connections.

  • ISM-0498

    A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.

  • ISM-0501

    Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.

  • ISM-0507

    Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.

  • ISM-0994

    ECDH is used in preference to DH.

  • ISM-0998

    AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.

  • ISM-0999

    DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072-bit MODP Group or 4096-bit MODP Group.

  • ISM-1000

    PFS is used for IPsec connections.

  • ISM-1080

    An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.

  • ISM-1091

    Keying material is changed when compromised or suspected of being compromised.

  • ISM-1139

    Only the latest version of TLS is used for TLS connections.

  • ISM-1233

    IKE version 2 is used for key exchange when establishing IPsec connections.

  • ISM-1369

    AES-GCM is used for encryption of TLS connections.

  • ISM-1370

    Only server-initiated secure renegotiation is used for TLS connections.

  • ISM-1372

    The ephemeral variant of DH or ECDH is used for key establishment of TLS connections.

  • ISM-1373

    Anonymous DH is not used for TLS connections.

  • ISM-1374

    SHA-2-based certificates are used for TLS connections.

  • ISM-1375

    SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.

  • ISM-1446

    When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.

  • ISM-1449

    SSH private keys are protected with a password or a key encryption key.

  • ISM-1453

    Perfect Forward Secrecy (PFS) is used for TLS connections.

  • ISM-1506

    The use of SSH version 1 is disabled for SSH connections.

  • ISM-1553

    TLS compression is disabled for TLS connections.

  • ISM-1629

    When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.

  • ISM-1766

    When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.

  • ISM-1769

    When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

  • ISM-1771

    AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.

  • ISM-1772

    PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.

  • ISM-1917

    The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.

  • ISM-1990

    When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.

  • ISM-1991

    When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.

  • ISM-1992

    When using ML-DSA for digital signatures, the hedged variant is used whenever possible.

  • ISM-1993

    Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.

  • ISM-1994

    When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.

  • ISM-1995

    When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.

  • ISM-1996

    When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.

  • ISM-2073

    A post-quantum cryptography transition plan is developed, implemented and maintained.

Cyber security documentation: 1 of 11 controls reached (4 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0912

    Systems have a change and configuration management plan that includes:

    - the establishment and maintenance of authorised baseline configurations for systems

    - what constitutes routine and urgent changes to the configuration of systems

    - how changes to the configuration of systems will be requested, tracked and documented

    - who needs to be consulted prior to routine and urgent changes to the configuration of systems

    - who needs to approve routine and urgent changes to the configuration of systems

    - who needs to be notified of routine and urgent changes to the configuration of systems

    - what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.

Not reached from your selection

  • ISM-0039

    A cyber security strategy is developed, implemented and maintained.

  • ISM-0041

    Systems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is managed) as well as an annex that covers applicable security controls from this document and any additional security controls that have been identified and implemented.

  • ISM-0043

    Systems have a cyber security incident response plan that covers the following:

    - guidelines on what constitutes a cyber security incident

    - the types of cyber security incidents likely to be encountered and the expected response to each type

    - how to report cyber security incidents, internally to an organisation and externally to relevant authorities

    - other parties that need to be informed in the event of a cyber security incident

    - the authority, or authorities, responsible for investigating and responding to cyber security incidents

    - the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority

    - the steps necessary to ensure the integrity of evidence relating to a cyber security incident

    - system contingency measures or a reference to such details if they are in a separate document.

  • ISM-0047

    Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system’s authorising officer.

  • ISM-0888

    Cyber security documentation is reviewed at least annually and includes a ‘current as at \[date\]’ or equivalent statement.

  • ISM-1163

    Systems have a continuous monitoring plan that includes:

    - conducting security assessment activities to identify vulnerabilities

    - analysing identified vulnerabilities to determine their potential impact

    - implementing mitigations based on risk, effectiveness and cost.

  • ISM-1563

    At the conclusion of a security control assessment for a system, a security assessment report is produced by the assessor and covers:

    - the scope of the security control assessment

    - the system’s strengths and weaknesses

    - security risks associated with the operation of the system

    - the effectiveness of the implementation of security controls

    - any recommended remediation actions.

  • ISM-1564

    At the conclusion of a security control assessment for a system, a plan of action and milestones is produced by the system owner.

  • ISM-1602

    Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.

  • ISM-1739

    A system’s security architecture is approved prior to the development of the system.

Cyber security incidents: 1 of 21 controls reached (4 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0917

    When malicious code is detected, the following steps are taken to handle the infection:

    - the infected systems are isolated

    - all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary

    - antivirus applications are used to remove the infection from infected systems and media

    - if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.

Not reached from your selection

  • ISM-0123 ML2 ML3

    Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.

  • ISM-0125

    A cyber security incident register is developed, implemented and maintained.

  • ISM-0133

    When a data spill occurs, data owners are advised and access to the data is restricted.

  • ISM-0137

    Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

  • ISM-0138

    The integrity of evidence gathered during an investigation is maintained by investigators:

    - recording all their actions

    - maintaining a proper chain of custody

    - following all instructions provided by relevant law enforcement agencies.

  • ISM-0140 ML2 ML3

    Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.

  • ISM-0576

    A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.

  • ISM-1213

    Following intrusion remediation activities, enhanced monitoring is conducted until there is sufficient evidence-based confidence that malicious actors have been eradicated from a system and have not re-established access.

  • ISM-1609

    System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

  • ISM-1625

    An insider threat mitigation program is developed, implemented and maintained.

  • ISM-1626

    Legal advice is sought regarding the development and implementation of an insider threat mitigation program.

  • ISM-1731

    Planning and coordination of intrusion remediation activities are conducted using trusted systems separate from a compromised system.

  • ISM-1732

    Intrusion remediation activities are coordinated and sequenced to minimise opportunities for re-compromise of a system while balancing operational risk and business continuity requirements.

  • ISM-1784

    The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.

  • ISM-1803

    A cyber security incident register contains the following for each cyber security incident:

    - the date the cyber security incident occurred

    - the date the cyber security incident was discovered

    - a description of the cyber security incident

    - any actions taken in response to the cyber security incident

    - to whom the cyber security incident was reported.

  • ISM-1819 ML2 ML3

    Following the identification of a cyber security incident, the cyber security incident response plan is enacted.

  • ISM-1880

    Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

  • ISM-1881

    Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

  • ISM-1969

    Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.

  • ISM-1970

    Malicious code processing for cyber security incident response or research purposes is conducted in a dedicated analysis environment segregated from other systems.

Cyber security roles: 0 of 40 controls reached (6 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0009

    System owners, in consultation with each system’s authorising officer, identify any supplementary security controls required based upon the unique nature of each system, its operating environment and the organisation’s risk tolerances.

  • ISM-0027

    System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.

  • ISM-0714

    A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).

  • ISM-0717

    The CISO oversees the management of cyber security personnel within their organisation.

  • ISM-0718

    The CISO regularly reports directly to their organisation’s board of directors or executive committee on cyber security matters.

  • ISM-0720

    The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.

  • ISM-0724

    The CISO implements cyber security measurement metrics and key performance indicators for their organisation.

  • ISM-0725

    The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.

  • ISM-0726

    The CISO coordinates security risk management activities between cyber security and business teams.

  • ISM-0731

    The CISO oversees cyber supply chain risk management activities for their organisation.

  • ISM-0732

    The CISO receives and manages a dedicated cyber security budget for their organisation.

  • ISM-0733

    The CISO is fully aware of all cyber security incidents within their organisation.

  • ISM-0734

    The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.

  • ISM-0735

    The CISO oversees the development, implementation and maintenance of their organisation’s cyber security awareness training program.

  • ISM-1071

    Each system has a designated system owner.

  • ISM-1203

    System owners, in consultation with each system’s authorising officer, conduct a threat and risk assessment for each system.

  • ISM-1478

    The CISO oversees their organisation’s cyber security program and ensures their organisation’s compliance with cyber security policy, standards, regulations and legislation.

  • ISM-1525

    System owners register each system with its authorising officer.

  • ISM-1526

    System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and security controls.

  • ISM-1587

    System owners report the security status of each system to its authorising officer at least annually.

  • ISM-1617

    The CISO regularly reviews and updates their organisation’s cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.

  • ISM-1618

    The CISO oversees their organisation’s response to cyber security incidents.

  • ISM-1633

    System owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.

  • ISM-1634

    System owners, in consultation with each system’s authorising officer, select security controls for each system and tailor them to achieve desired security and resilience objectives.

  • ISM-1635

    System owners implement security controls for each system and its operating environment.

  • ISM-1636

    System owners, in consultation with each system’s authorising officer, ensure security controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security control assessment by their organisation’s own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.

  • ISM-1918

    The CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters.

  • ISM-1966

    The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.

  • ISM-1997

    The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.

  • ISM-1998

    The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.

  • ISM-1999

    The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.

  • ISM-2000

    The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.

  • ISM-2001

    The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.

  • ISM-2002

    The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.

  • ISM-2003

    The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.

  • ISM-2004

    The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.

  • ISM-2005

    The board of directors or executive committee understands the business criticality of their organisation’s systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.

  • ISM-2006

    The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.

  • ISM-2020

    The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.

  • ISM-2021

    System owners implement and maintain data minimisation practices for each of their systems.

Data transfers: 0 of 8 controls reached (6 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0657

    When manually importing data to systems, the data is scanned for malicious and active content.

  • ISM-0661

    Human users transferring data to and from systems are held accountable for data transfers they perform.

  • ISM-0663

    Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.

  • ISM-1187

    When manually exporting data from systems, the data is checked for unsuitable protective markings.

  • ISM-1294

    Data transfer logs for systems are partially verified at least monthly.

  • ISM-1586

    Data transfer logs are used to record all data imports and exports from systems.

  • ISM-1778

    When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

  • ISM-1779

    When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

Database systems: 2 of 13 controls reached (8 more reachable via our wider catalogue)

Reached from your selection

  • ISM-1269

    Database servers and web servers are functionally separated.

  • ISM-1272

    If only local access to a database is required, networking functionality of database management system applications is disabled or directed to listen solely to the localhost interface.

Not reached from your selection

  • ISM-0393

    Databases and their contents are classified based on the sensitivity or classification of data that they contain.

  • ISM-1243

    A database register is developed, implemented, maintained and regularly verified.

  • ISM-1255

    Database users’ ability to access, insert, modify and remove database contents is restricted based on their duties or functions.

  • ISM-1256

    File-based access controls are applied to database files.

  • ISM-1268

    The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.

  • ISM-1270

    Database servers are placed on a different network segment to workstations.

  • ISM-1271

    Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.

  • ISM-1273

    Database servers for development, testing, staging and production environments are segregated.

  • ISM-1274

    Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

  • ISM-1277

    Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.

  • ISM-1537

    Security-relevant events for databases are centrally logged, including:

    - access or modification of particularly important content

    - addition of new users, especially privileged users

    - changes to user roles or privileges

    - attempts to elevate user privileges

    - queries containing comments

    - queries containing multiple embedded queries

    - database and query alerts or failures

    - database structure changes

    - database administrator actions

    - use of executable commands

    - database logons and logoffs.

Email: 1 of 25 controls reached (23 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0567

    Email servers only relay emails destined for or originating from their domains (including subdomains).

Not reached from your selection

  • ISM-0264

    An email usage policy is developed, implemented and maintained.

  • ISM-0267

    Access to non-approved webmail services is blocked.

  • ISM-0270

    Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.

  • ISM-0271

    Protective marking tools do not automatically insert protective markings into emails.

  • ISM-0272

    Protective marking tools do not allow the selection of protective markings that a system has not been authorised to process, store or communicate.

  • ISM-0565

    Email servers are configured to block, log and report emails with inappropriate protective markings.

  • ISM-0569

    Emails are routed via centralised email gateways.

  • ISM-0570

    Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.

  • ISM-0571

    When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.

  • ISM-0572

    Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.

  • ISM-0574

    SPF is used to specify authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).

  • ISM-0861

    DKIM signing is enabled on emails originating from an organisation’s domains (including subdomains).

  • ISM-1023

    The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.

  • ISM-1024

    Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.

  • ISM-1026

    DKIM signatures on incoming emails are verified.

  • ISM-1027

    Email distribution list applications used by external senders is configured such that it does not break the validity of the sender’s DKIM signature.

  • ISM-1089

    When replying to or forwarding emails, protective marking tools do not allow the selection of protective markings lower than previously used.

  • ISM-1151

    SPF is used to verify the authenticity of incoming emails.

  • ISM-1183

    A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).

  • ISM-1234

    Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.

  • ISM-1502

    Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.

  • ISM-1540

    DMARC records are configured for an organisation’s domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.

  • ISM-1589

    MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.

  • ISM-1799

    Incoming emails are rejected if they do not pass DMARC checks.

Enterprise mobility: 22 of 45 controls reached (16 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0701

    Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.

  • ISM-0863

    Mobile devices prevent personnel from installing non-approved applications once provisioned.

  • ISM-0864

    Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.

  • ISM-0869

    Mobile devices encrypt their internal storage and any removable media using ASD-approved cryptography.

  • ISM-1195

    Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.

  • ISM-1196

    Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.

  • ISM-1198

    Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.

  • ISM-1199

    Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.

  • ISM-1200

    Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.

  • ISM-1366

    Security updates are applied to mobile devices as soon as they become available.

  • ISM-1400

    Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.

  • ISM-1482

    Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.

  • ISM-1533

    A mobile device management policy is developed, implemented and maintained.

  • ISM-1554

    If travelling overseas with mobile devices to high or extreme risk countries, personnel are:

    - issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities

    - advised on how to apply and inspect tamper seals to key areas of mobile devices

    - advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.

  • ISM-1866

    Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately owned mobile devices and desktop computers.

  • ISM-1886

    Mobile devices are configured to operate in a supervised (or equivalent) mode.

  • ISM-1887

    Mobile devices are configured with remote locate and wipe functionality.

  • ISM-1888 Explained in the ISM-0428 guide →

    Mobile devices are configured with secure password-based lock screens.

  • ISM-2095

    Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.

  • ISM-2096

    Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.

  • ISM-2098

    Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.

  • ISM-2099

    Mobile devices are not connected to the infotainment systems of connected vehicles.

Not reached from your selection

  • ISM-0240

    Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.

  • ISM-0705

    When accessing an organisation’s network via a VPN connection, split tunnelling is disabled.

  • ISM-0866

    Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.

  • ISM-0870

    Mobile devices are carried or stored in a secured state when not being actively used.

  • ISM-0871

    Mobile devices are kept under continual direct supervision when being actively used.

  • ISM-0874

    Mobile devices and desktop computers access the internet via an organisation’s internet gateway rather than via a direct connection to the internet.

  • ISM-1082

    A mobile device usage policy is developed, implemented and maintained.

  • ISM-1083

    Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.

  • ISM-1084

    If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.

  • ISM-1085

    Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.

  • ISM-1088

    Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they:

    - provide credentials to foreign government officials

    - decrypt mobile devices for foreign government officials

    - have mobile devices taken out of sight by foreign government officials

    - have mobile devices or removable media stolen, including if later returned

    - lose mobile devices or removable media, including if later found

    - observe unusual behaviour of mobile devices.

  • ISM-1297

    Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.

  • ISM-1298

    Personnel are advised of privacy and security risks when travelling overseas with mobile devices.

  • ISM-1299

    Personnel are advised to take the following precautions when using mobile devices:

    - never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes

    - never store credentials with mobile devices that they grant access to, such as in laptop computer bags

    - never lend mobile devices or removable media to untrusted people, even if briefly

    - never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging

    - never connect mobile devices to designated charging stations or wall outlet charging ports

    - never use gifted or unauthorised peripherals, chargers or removable media with mobile devices

    - never use removable media for data transfers or backups that have not been checked for malicious code beforehand

    - avoid reuse of removable media once used with other parties’ systems or mobile devices

    - avoid connecting mobile devices to open or untrusted Wi-Fi networks

    - consider disabling any communications capabilities of mobile devices when not in use, such as Wi-Fi, Bluetooth, Near Field Communication and ultra-wideband

    - consider periodically rebooting mobile devices

    - consider using a VPN connection to encrypt all cellular and wireless communications

    - consider using encrypted email or messaging apps for all communications.

  • ISM-1300

    Upon returning from travelling overseas with mobile devices, personnel take the following actions:

    - sanitise and reset mobile devices, including all removable media

    - decommission any credentials that left their possession during their travel

    - report if significant doubt exists as to the integrity of any mobile devices or removable media.

  • ISM-1555

    Before travelling overseas with mobile devices, personnel take the following actions:

    - record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers

    - update all operating systems and applications

    - remove all non-essential data, applications and user accounts

    - backup all remaining data, applications and settings.

  • ISM-1556

    If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions:

    - reset credentials used with mobile devices, including those used for remote access to their organisation’s systems

    - monitor user accounts for any indicators of compromise, such as failed logon attempts.

  • ISM-1644

    Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.

  • ISM-1867

    Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.

  • ISM-2097

    Mobile devices are configured with always on VPN functionality.

  • ISM-2100

    Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.

  • ISM-2101

    Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.

  • ISM-2108

    Mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.

Evaluated products: 1 of 3 controls reached (2 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0289

    Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.

Not reached from your selection

  • ISM-0280

    If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.

  • ISM-0285

    Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.

Gateways: 0 of 47 controls reached (43 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0100

    Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

  • ISM-0260

    All web access, including that by internal servers, is conducted through web proxies.

  • ISM-0261

    The following details are centrally logged for websites accessed via web proxies:

    - web address

    - date and time

    - user

    - amount of data uploaded and downloaded

    - internal and external IP addresses.

  • ISM-0263

    TLS traffic communicated through gateways is decrypted and inspected.

  • ISM-0591

    Evaluated peripheral switches are used when sharing peripherals between systems.

  • ISM-0611

    System administrators for gateways are assigned the minimum privileges required to perform their duties.

  • ISM-0612

    System administrators for gateways are formally trained on the operation and management of gateways.

  • ISM-0616

    Separation of duties is implemented in performing administrative activities for gateways.

  • ISM-0619

    Users authenticate to other networks accessed via gateways.

  • ISM-0622

    IT equipment authenticates to other networks accessed via gateways.

  • ISM-0628

    Gateways are implemented between networks belonging to different security domains.

  • ISM-0629

    For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.

  • ISM-0631

    Gateways only allow explicitly authorised data flows.

  • ISM-0634

    Security-relevant events for gateways are centrally logged, including:

    - data packets and data flows permitted through gateways

    - data packets and data flows attempting to leave gateways

    - real-time alerts for attempted intrusions.

  • ISM-0637

    Gateways implement a demilitarised zone if external parties require access to an organisation’s services.

  • ISM-0639

    Evaluated firewalls are used between networks belonging to different security domains.

  • ISM-0643

    Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation’s networks and public network infrastructure.

  • ISM-0649

    Files imported or exported via gateways or CDSs are filtered for allowed file types.

  • ISM-0651

    Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.

  • ISM-0652

    Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.

  • ISM-0659

    Files imported or exported via gateways or CDSs undergo content filtering checks.

  • ISM-0677

    Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.

  • ISM-0958

    An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.

  • ISM-0961

    Client-side active content is restricted by web content filters to an organisation-approved list of domain names.

  • ISM-0963

    Web content filtering is implemented to filter potentially harmful web-based content.

  • ISM-1037

    Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate that they conform to expected security configurations.

  • ISM-1157

    Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.

  • ISM-1171

    Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.

  • ISM-1192

    Gateways inspect and filter data flows at the transport and above network layers.

  • ISM-1236

    Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.

  • ISM-1237

    Web content filtering is applied to outbound web traffic where appropriate.

  • ISM-1284

    Files imported or exported via gateways or CDSs undergo content validation.

  • ISM-1286

    Files imported or exported via gateways or CDSs undergo content conversion.

  • ISM-1287

    Files imported or exported via gateways or CDSs undergo content sanitisation.

  • ISM-1288

    Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.

  • ISM-1289

    Archive files imported or exported via gateways or CDSs are unpacked to undergo content filtering checks.

  • ISM-1290

    Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.

  • ISM-1293

    Encrypted files imported or exported via gateways or CDSs are decrypted to undergo content filtering checks.

  • ISM-1389

    Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.

  • ISM-1427

    Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.

  • ISM-1520

    System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.

  • ISM-1528

    Evaluated firewalls are used between an organisation’s networks and public network infrastructure.

  • ISM-1774

    Gateways are managed via a secure path isolated from all connected networks.

  • ISM-1783

    Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.

  • ISM-1862

    If using a WAF, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.

  • ISM-1965

    Files imported or exported via gateways or CDSs undergo content checking.

  • ISM-2018

    Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.

Information technology equipment: 3 of 29 controls reached (4 more reachable via our wider catalogue)

Reached from your selection

  • ISM-1598

    Following maintenance or repairs to IT equipment, it is inspected to confirm that it retains its approved configuration and that no unauthorised modifications have been made.

  • ISM-1858

    IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1913

    Approved configurations for IT equipment are developed, implemented and maintained.

Not reached from your selection

  • ISM-0293

    IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.

  • ISM-0294

    IT equipment, except for high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.

  • ISM-0305

    Maintenance or repairs of IT equipment are carried out on site by an appropriately cleared technician.

  • ISM-0306

    If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who:

    - has the authority to direct the technician

    - is appropriately cleared and briefed

    - is sufficiently familiar with the IT equipment to understand the work being undertaken

    - takes all responsible measures to ensure the integrity of the IT equipment

    - takes due care to ensure that data is not disclosed.

  • ISM-0307

    If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the IT equipment and associated media are sanitised before maintenance or repairs.

  • ISM-0310

    IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.

  • ISM-0311

    IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.

  • ISM-0313

    IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.

  • ISM-0316

    Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.

  • ISM-0317

    At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.

  • ISM-0318

    When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.

  • ISM-0336

    A networked IT equipment register is developed, implemented, maintained and regularly verified.

  • ISM-1076

    Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period.

  • ISM-1217

    Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.

  • ISM-1219

    MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner that cannot be removed or a print is visible on the image transfer roller.

  • ISM-1220

    Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.

  • ISM-1221

    Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.

  • ISM-1222

    Televisions and computer monitors that cannot be sanitised are destroyed.

  • ISM-1223

    Memory in network devices is sanitised using the following processes, in order of preference:

    - following device-specific guidance provided in evaluation documentation

    - following vendor sanitisation guidance

    - loading a dummy configuration file, performing a factory reset and then reinstalling firmware.

  • ISM-1534

    Printer ribbons in printers and MFDs are removed and destroyed.

  • ISM-1550

    IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.

  • ISM-1551

    An IT equipment management policy is developed, implemented and maintained.

  • ISM-1599

    IT equipment is handled in a manner suitable for its sensitivity or classification.

  • ISM-1741

    IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.

  • ISM-1742

    IT equipment that cannot be sanitised is destroyed.

  • ISM-1869

    A non-networked IT equipment register is developed, implemented, maintained and regularly verified.

Media: 4 of 49 controls reached (5 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0459

    Full disk encryption, or partial encryption where access controls only allow writing to encrypted partitions or volumes, is implemented when encrypting media.

  • ISM-1059

    All data stored on media is encrypted using ASD-approved cryptography.

  • ISM-1713

    A removable media register is developed, implemented, maintained and regularly verified.

  • ISM-2109

    Pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.

Not reached from your selection

  • ISM-0323

    Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.

  • ISM-0325

    Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.

  • ISM-0330

    Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.

  • ISM-0332

    Media, except for internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.

  • ISM-0337

    Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.

  • ISM-0347

    When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.

  • ISM-0348

    Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.

  • ISM-0350

    The following media types are destroyed prior to their disposal:

    - microfiche and microfilm

    - optical discs

    - programmable read-only memory

    - read-only memory

    - other types of media that cannot be sanitised.

  • ISM-0351

    Volatile media is sanitised by removing its power for at least 10 minutes.

  • ISM-0354

    Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.

  • ISM-0357

    Non-volatile EPROM media is sanitised by applying three times the manufacturer’s specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

  • ISM-0359

    Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.

  • ISM-0361

    Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.

  • ISM-0362

    Product-specific directions provided by degausser manufacturers are followed.

  • ISM-0363

    Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.

  • ISM-0368

    Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.

  • ISM-0370

    The destruction of media is performed under the supervision of at least one cleared person.

  • ISM-0371

    Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.

  • ISM-0372

    The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.

  • ISM-0373

    Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.

  • ISM-0374

    Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.

  • ISM-0375

    Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.

  • ISM-0378

    Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.

  • ISM-0831

    Media is handled in a manner suitable for its sensitivity or classification.

  • ISM-0836

    Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

  • ISM-0839

    The destruction of media storing accountable material is not outsourced.

  • ISM-0840

    When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO’s Protective Security Circular-167, is used.

  • ISM-0947

    When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.

  • ISM-1065

    The host-protected area and device configuration overlay table are reset prior to the sanitisation of non-volatile magnetic hard drives.

  • ISM-1067

    The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.

  • ISM-1160

    If using degaussers to destroy media, degaussers evaluated by the United States’ National Security Agency are used.

  • ISM-1359

    A removable media usage policy is developed, implemented and maintained.

  • ISM-1361

    Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.

  • ISM-1517

    Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.

  • ISM-1549

    A media management policy is developed, implemented and maintained.

  • ISM-1600

    Media is sanitised before it is used for the first time.

  • ISM-1641

    Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.

  • ISM-1642

    Media is sanitised before it is reused in a different security domain.

  • ISM-1722

    Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.

  • ISM-1723

    Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

  • ISM-1724

    Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.

  • ISM-1725

    Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

  • ISM-1726

    Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.

  • ISM-1727

    Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.

  • ISM-1735

    Media that cannot be successfully sanitised is destroyed prior to its disposal.

Networking: 14 of 77 controls reached (63 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0385

    Servers maintain effective functional separation from each other.

  • ISM-0534

    Unused physical ports on network devices are disabled.

  • ISM-1304

    Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

  • ISM-1311

    SNMP version 1 and SNMP version 2 are not used on networks.

  • ISM-1312

    All default SNMP community strings on network devices are changed and write access is disabled.

  • ISM-1428

    Unless explicitly required, IPv6 tunnelling is disabled on all network devices.

  • ISM-1430

    Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.

  • ISM-1479

    Servers minimise communications with other servers at the network and file system level.

  • ISM-1800

    Network devices are flashed with trusted firmware before they are used for the first time.

  • ISM-1801

    Network devices are restarted at least monthly.

  • ISM-1912

    Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.

  • ISM-1962

    SMB version 1 is not used on networks.

  • ISM-2161

    The integrity of network device firmware and running configurations is verified against an approved known-good baseline following patching, on detection of anomalous behaviour and at least monthly.

  • ISM-2162

    Unneeded components, services and functionality of network devices are disabled or removed.

Not reached from your selection

  • ISM-0516

    Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.

  • ISM-0518

    Network documentation is developed, implemented and maintained.

  • ISM-0520

    Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.

  • ISM-0529

    VLANs are not used to separate network traffic between networks belonging to different security domains.

  • ISM-0530

    Network devices managing VLANs are administered from the most trusted security domain.

  • ISM-0535

    Network devices managing VLANs belonging to different security domains do not share VLAN trunks.

  • ISM-0536

    Public wireless networks provided for public use are segregated from all other organisation networks.

  • ISM-1006

    Security measures are implemented to prevent unauthorised access to network management traffic.

  • ISM-1028

    A NIDS or NIPS is deployed in gateways between an organisation’s networks and other networks they do not manage.

  • ISM-1030

    A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.

  • ISM-1178

    Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.

  • ISM-1181

    Networks are segregated into multiple network zones according to the criticality of servers, services and data.

  • ISM-1182

    Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.

  • ISM-1186

    IPv6 capable network security appliances are used on IPv6 and dual-stack networks.

  • ISM-1314

    All wireless devices are Wi-Fi Alliance certified.

  • ISM-1315

    The administrative interface on wireless access points is disabled for wireless network connections.

  • ISM-1316

    Default SSIDs of wireless access points are changed.

  • ISM-1317

    SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.

  • ISM-1318

    SSID broadcasting is not disabled on wireless access points.

  • ISM-1319

    Static addressing is not used for assigning IP addresses on wireless networks.

  • ISM-1320

    MAC address filtering is not used to restrict which devices can connect to wireless networks.

  • ISM-1321

    802.1X with EAP-TLS is used for mutual authentication and key exchange; with all other EAP methods disabled on supplicants and authentication servers.

  • ISM-1322

    Evaluated supplicants, authenticators and authentication servers are used for 802.1X authentication implementations.

  • ISM-1323

    X.509 certificates are required for devices and human users authenticating to networks using 802.1X.

  • ISM-1324

    X.509 certificates are generated using an evaluated certificate authority or hardware security module.

  • ISM-1327

    X.509 certificates are protected by logical and physical access controls and encryption, with those issued to human users requiring authentication before use.

  • ISM-1330

    The PMK caching period is not set to greater than 1440 minutes (24 hours).

  • ISM-1332

    WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.

  • ISM-1334

    Wireless networks implement sufficient frequency separation from other wireless networks.

  • ISM-1335

    Wireless access points enable the use of the 802.11w amendment to protect management frames.

  • ISM-1338

    Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.

  • ISM-1364

    Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.

  • ISM-1429

    IPv6 tunnelling is blocked by network security appliances at externally connected network boundaries.

  • ISM-1431

    Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically:

    - their capacity to withstand denial-of-service attacks

    - costs likely to be incurred as a result of denial-of-service attacks

    - availability monitoring and thresholds for notification of denial-of-service attacks

    - thresholds for turning off any online services or functionality during denial-of-service attacks

    - pre-approved actions that can be undertaken during denial-of-service attacks

    - any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.

  • ISM-1432

    Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.

  • ISM-1436

    Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.

  • ISM-1437

    Cloud service providers are used for hosting online services.

  • ISM-1438

    Where a high availability requirement exists for website hosting, CDNs that cache websites are used.

  • ISM-1439

    If using CDNs, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.

  • ISM-1454

    Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.

  • ISM-1532

    VLANs are not used to separate network traffic between an organisation’s networks and public network infrastructure.

  • ISM-1577

    An organisation’s networks are segregated from their service providers’ networks.

  • ISM-1579

    Cloud service providers’ ability to scale resources dynamically in response to genuine spikes in demand is discussed and verified as part of capacity and availability planning for online services.

  • ISM-1580

    Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.

  • ISM-1581

    Continuous real-time monitoring of the capacity and availability of online services is performed.

  • ISM-1627

    Inbound network connections from anonymity networks are blocked.

  • ISM-1628

    Outbound network connections to anonymity networks are blocked.

  • ISM-1710

    Settings for wireless access points are hardened.

  • ISM-1711

    User identity confidentiality is used if available with EAP-TLS implementations.

  • ISM-1712

    The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.

  • ISM-1781

    All data communicated over network infrastructure is encrypted using ASD-approved cryptography.

  • ISM-1782

    A protective DNS service is used to block access to known malicious domain names.

  • ISM-1863

    Networked management interfaces for IT equipment are not directly exposed to the internet.

  • ISM-1963

    Security-relevant events for internet-facing network devices are centrally logged.

  • ISM-1964

    Security-relevant events for non-internet-facing network devices are centrally logged.

  • ISM-2017

    DNS traffic is encrypted by clients and servers using ASD-approved cryptography.

  • ISM-2068

    Internet connectivity for networked devices is strictly limited to those that require access.

  • ISM-2160

    Networked management interfaces for IT equipment are only accessible from a dedicated management network that is segregated from the wider network and the internet.

  • ISM-2163

    When using MACsec, confidentiality protection mode is enabled using GCM-AES-128, GCM-AES-256, GCM-AES-XPN-128 or GCM-AES-XPN-256, preferably GCM-AES-256 or GCM-AES-XPN-256.

  • ISM-2164

    A connectivity association lifetime of less than 24 hours (86400 seconds) is used for MACsec connections.

  • ISM-2165

    When using EAP-TLS, each device performs a fresh EAP-TLS authentication each time a new Connectivity Association Key is required.

  • ISM-2166

    A secure association lifetime of less than four hours (14400 seconds) is used for MACsec connections.

  • ISM-2167

    The use of a Pre-Shared Key as a fallback authentication method for MACsec is disabled.

Personnel security: 0 of 17 controls reached (15 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0252

    Cyber security awareness training is undertaken annually by all personnel and covers:

    - the purpose of the cyber security awareness training

    - security appointments and contacts

    - authorised use of systems and their resources

    - protection of systems and their resources

    - reporting of cyber security incidents and suspected compromises of systems and their resources.

  • ISM-0258

    A web usage policy is developed, implemented and maintained.

  • ISM-0817

    Personnel are advised of what suspicious contact via online services is and how to report it.

  • ISM-0820

    Personnel are advised not to post work-related information on unauthorised online services, and to report cases where such information is posted.

  • ISM-0821

    Personnel are advised of security risks associated with posting personal information on online services.

  • ISM-0824

    Personnel are advised not to send or receive files via unauthorised online services.

  • ISM-1146

    Personnel are advised to maintain separate personal user accounts from any work user accounts they use for online services.

  • ISM-1565

    Tailored privileged user training is undertaken annually by all personnel with privileged access to systems and their resources.

  • ISM-1740

    Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.

  • ISM-2022

    A cyber security awareness training register is developed, implemented and maintained.

  • ISM-2071

    Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.

  • ISM-2074

    A general-purpose AI usage policy is developed, implemented and maintained.

  • ISM-2104

    Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted.

  • ISM-2105

    Personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such information is posted.

  • ISM-2106

    Personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases where such information is posted.

  • ISM-2107

    Personnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.

  • ISM-2126

    Personnel positively identify requestors using a pre-established authentication method or independent trusted communication channel before actioning requests to modify user account details, modify banking details or conduct financial transactions.

Physical security: 0 of 11 controls reached

Not reached from your selection

  • ISM-0161

    IT equipment and media are secured when not in use.

  • ISM-0164

    Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.

  • ISM-0810

    Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.

  • ISM-0813

    Server rooms, communications rooms and security containers are not left in unsecured states.

  • ISM-1053

    Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.

  • ISM-1074

    Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.

  • ISM-1296

    Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.

  • ISM-1530

    Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.

  • ISM-1973

    Non-classified systems are secured in suitably secure facilities.

  • ISM-1974

    Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.

  • ISM-1975

    Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.

Procurement and outsourcing: 0 of 37 controls reached (20 more reachable via our wider catalogue)

Not reached from your selection

  • ISM-0072

    Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.

  • ISM-0141

    The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.

  • ISM-1073

    An organisation’s systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.

  • ISM-1395

    Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.

  • ISM-1451

    Types of data and its ownership is documented in contractual arrangements with service providers.

  • ISM-1452

    A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system’s security risk profile.

  • ISM-1567

    Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

  • ISM-1568

    Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.

  • ISM-1569

    A shared responsibility model is created, documented and shared between suppliers and their customers to articulate the security responsibilities of each party.

  • ISM-1570

    Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

  • ISM-1571

    The right to verify compliance with security requirements is documented in contractual arrangements with service providers.

  • ISM-1572

    The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.

  • ISM-1573

    Access to all logs relating to an organisation’s data and services is documented in contractual arrangements with service providers.

  • ISM-1574

    The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.

  • ISM-1575

    A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.

  • ISM-1576

    If an organisation’s systems are accessed or administered by a service provider in an unauthorised manner, it is treated as a cyber security incident and the organisation is immediately notified.

  • ISM-1631

    Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.

  • ISM-1632

    Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.

  • ISM-1637

    An outsourced cloud service register is developed, implemented, maintained and regularly verified.

  • ISM-1638

    An outsourced cloud service register contains the following for each outsourced cloud service:

    - cloud service provider’s name

    - cloud service’s name

    - purpose for using the cloud service

    - sensitivity or classification of data involved

    - due date for the next security control assessment of the cloud service

    - contractual arrangements for the cloud service

    - organisational point of contact for the cloud service

    - 24/7 contact details for the cloud service provider.

  • ISM-1736

    A managed service register is developed, implemented, maintained and regularly verified.

  • ISM-1737

    A managed service register contains the following for each managed service:

    - managed service provider’s name

    - managed service’s name

    - purpose for using the managed service

    - sensitivity or classification of data involved

    - due date for the next security control assessment of the managed service

    - contractual arrangements for the managed service

    - organisational point of contact for the managed service

    - 24/7 contact details for the managed service provider.

  • ISM-1738

    The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.

  • ISM-1785

    A supplier relationship management policy is developed, implemented and maintained.

  • ISM-1786

    An approved supplier list is developed, implemented and maintained.

  • ISM-1787

    Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.

  • ISM-1788

    Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.

  • ISM-1789

    Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.

  • ISM-1790

    Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.

  • ISM-1791

    The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

  • ISM-1792

    The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

  • ISM-1793

    Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

  • ISM-1794

    A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.

  • ISM-1804

    Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.

  • ISM-1882

    Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.

  • ISM-2124

    Access by a service provider to an organisation’s systems is restricted to remote management tools, source network addresses and time windows explicitly approved by the organisation.

  • ISM-2125

    All access to an organisation’s systems by a service provider is independently logged by the organisation in a manner that the service provider cannot modify or delete, and analysed in a timely manner to detect any anomalous, unexpected or unauthorised activity.

Security assurance: 1 of 36 controls reached (34 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0988

    An accurate and consistent time source is used for event logging.

Not reached from your selection

  • ISM-0109 ML3

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

  • ISM-0120

    Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.

  • ISM-0580

    A security monitoring policy is developed, implemented and maintained.

  • ISM-0585

    For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.

  • ISM-1228 ML2 ML3

    Cyber security events are analysed in a timely manner to identify cyber security incidents.

  • ISM-1405

    A centralised event logging facility is implemented.

  • ISM-1698 ML1 ML2 ML3

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

  • ISM-1699 ML1 ML2 ML3

    A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ISM-1700 ML2 ML3

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ISM-1701 ML1 ML2 ML3

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

  • ISM-1702 ML1 ML2 ML3

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

  • ISM-1703 ML3

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.

  • ISM-1752

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.

  • ISM-1807 ML1 ML2 ML3

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ISM-1808 ML1 ML2 ML3

    A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

  • ISM-1815 ML2 ML3

    Event logs are protected from unauthorised modification and deletion.

  • ISM-1900 ML3

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.

  • ISM-1906 ML2 ML3

    Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.

  • ISM-1907 ML3

    Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.

  • ISM-1921

    The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.

  • ISM-1959

    To the extent possible, event logs are captured and stored in a consistent and structured format.

  • ISM-1960

    Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.

  • ISM-1961

    Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.

  • ISM-1983

    Event logs sent to a centralised event logging facility are sent as soon as possible after they occur.

  • ISM-1984

    Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.

  • ISM-1985

    Event logs are protected from unauthorised access.

  • ISM-1986

    Event logs from critical servers are analysed in a timely manner to detect cyber security events.

  • ISM-1987

    Event logs from security products are analysed in a timely manner to detect cyber security events.

  • ISM-1988

    Event logs are retained in a searchable manner for at least 12 months.

  • ISM-1989

    Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.

  • ISM-2116

    Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.

  • ISM-2117

    Suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.

  • ISM-2118

    Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least every six months thereafter.

  • ISM-2119

    Suitable AI models are used to augment vulnerability assessments and penetration tests.

  • ISM-2153

    Threat hunting activities, informed by current strategic and sector-specific cyber threat intelligence, are conducted at least every three months.

Software development: 1 of 114 controls reached (73 more reachable via our wider catalogue)

Reached from your selection

  • ISM-2067

    Web applications that support Single Sign On equally support Single Logout.

Not reached from your selection

  • ISM-0400

    Development, testing, staging and production environments are segregated.

  • ISM-0401

    Secure by Design principles and practices are followed throughout the software development life cycle.

  • ISM-0402

    Software is comprehensively tested for vulnerabilities using SAST, DAST and SCA prior to its initial release, any subsequent release, and periodically to help identify any previously unidentified vulnerabilities.

  • ISM-0971

    The OWASP Application Security Verification Standard is used in the development of web applications.

  • ISM-1238

    Threat modelling is used in support of the software development life cycle.

  • ISM-1239

    Robust web application frameworks are used in the development of web applications.

  • ISM-1240

    Validation and sanitisation are performed on all input received over the internet by software.

  • ISM-1241

    Output encoding is performed on all output produced by web applications.

  • ISM-1275

    All queries to databases from software are filtered for legitimate content and correct syntax.

  • ISM-1276

    Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.

  • ISM-1278

    Software is designed or configured to provide as little error information as possible about the structure of databases.

  • ISM-1419

    Development and modification of software only take place in development environments.

  • ISM-1420

    Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

  • ISM-1422

    Unauthorised access to the authoritative source for software is prevented.

  • ISM-1424

    Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.

  • ISM-1536

    All queries to databases from software, and any resulting crash or error messages, are centrally logged.

  • ISM-1552

    All web application content is offered exclusively using HTTPS.

  • ISM-1616

    A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.

  • ISM-1717

    A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.

  • ISM-1730

    A software bill of materials is produced and made available to consumers of software.

  • ISM-1754

    Vulnerabilities identified in software are resolved in a timely manner.

  • ISM-1755

    A vulnerability disclosure policy is developed, implemented and maintained.

  • ISM-1756

    Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.

  • ISM-1780

    SecDevOps practices are used for software development.

  • ISM-1796

    Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.

  • ISM-1797

    Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.

  • ISM-1798

    Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.

  • ISM-1816

    Unauthorised modification of the authoritative source for software is prevented.

  • ISM-1817

    Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.

  • ISM-1818

    Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.

  • ISM-1849

    The OWASP Top 10 Proactive Controls are used in the development of web applications.

  • ISM-1850

    The OWASP Top 10 are mitigated in the development of web applications.

  • ISM-1851

    The OWASP API Security Top 10 are mitigated in the development of web APIs.

  • ISM-1908

    Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.

  • ISM-1909

    In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.

  • ISM-1910

    Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.

  • ISM-1911

    Security-relevant usage, error messages and crashes for software are centrally logged.

  • ISM-1922

    The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.

  • ISM-1924

    Generative AI applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.

  • ISM-2013

    Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.

  • ISM-2014

    Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.

  • ISM-2015

    Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.

  • ISM-2016

    Validation and sanitisation are performed on all input received over a local network by software.

  • ISM-2023

    An authoritative source for software is established and maintained.

  • ISM-2024

    The authoritative source for software is used for all software development activities.

  • ISM-2025

    An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.

  • ISM-2026

    All software artefacts are scanned for malicious content before being imported into the authoritative source for software.

  • ISM-2027

    All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.

  • ISM-2028

    All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.

  • ISM-2029

    The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.

  • ISM-2030

    Scanning is used during commits to identify plain text or encoded credentials, keys and secrets, which are then blocked from being stored in the authoritative source for software.

  • ISM-2031

    Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.

  • ISM-2032

    The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.

  • ISM-2033

    All software security requirements are documented, stored securely and maintained throughout the software development life cycle.

  • ISM-2034

    Security design decisions are documented and reviewed throughout the software development cycle.

  • ISM-2035 Explained in the ISM-2121 guide →

    Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.

  • ISM-2036 Explained in the ISM-2121 guide →

    Security responsibilities for software developers are identified and documented.

  • ISM-2037 Explained in the ISM-2121 guide →

    Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.

  • ISM-2038 Explained in the ISM-2121 guide →

    A software developer cyber security knowledge and skills register is developed, implemented and maintained.

  • ISM-2039

    The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.

  • ISM-2040 Explained in the ISM-2121 guide →

    Secure programming practices for the chosen programming language are used for software development.

  • ISM-2041

    Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.

  • ISM-2042

    Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.

  • ISM-2043

    Software is architected and structured to support readability and maintainability.

  • ISM-2044

    Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.

  • ISM-2045

    Application backwards compatibility does not compromise any security measures or features.

  • ISM-2046

    Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.

  • ISM-2047

    Where software allows an authentication factor to be reset for a human user, the human user is notified of the reset through a secondary channel.

  • ISM-2048

    Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.

  • ISM-2049

    When user permissions or credentials are changed, software forces all impacted users to re-authenticate.

  • ISM-2050

    When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.

  • ISM-2051

    Software generates sufficient event logs to support the detection of cyber security events.

  • ISM-2052

    Event logs produced by software ensure that any sensitive data is protected.

  • ISM-2053

    End of life procedures for software, including procedures for software removal and the archival or destruction of user accounts and data, are produced and made available to consumers.

  • ISM-2054

    If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.

  • ISM-2055

    If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.

  • ISM-2056

    A software build provenance is produced and made available to consumers of software.

  • ISM-2057

    All input validation rules are documented, implemented in code, and tested using both positive and negative unit tests and integration tests.

  • ISM-2058

    Data sources and serialised data inputs are validated before being deserialised.

  • ISM-2059

    File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.

  • ISM-2060

    Code reviews are utilised to ensure software components meets Secure by Design principles and practices as well as secure programming practices.

  • ISM-2061

    Peer reviews are conducted on all critical and security-related software components.

  • ISM-2062

    Unit testing and integration testing, covering both positive and negative use cases, are used for software components to ensure code quality and correctness.

  • ISM-2063

    If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.

  • ISM-2064

    Web application session cookies contain only digitally signed opaque bearer tokens.

  • ISM-2065

    Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.

  • ISM-2066 Explained in the ISM-0428 guide →

    Web application sessions are centrally managed server side.

  • ISM-2072

    AI models are stored in a non-executable file format that does not allow arbitrary code execution.

  • ISM-2082

    If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.

  • ISM-2083

    A cryptographic bill of materials is produced and made available to consumers of software.

  • ISM-2084

    AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.

  • ISM-2085

    The exposure of exact AI model confidence scores in API outputs or user interfaces is prevented.

  • ISM-2086

    The source and integrity of AI models, structures and weights are verified.

  • ISM-2087

    The source and integrity of training data for AI models is verified.

  • ISM-2088

    Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by AI models.

  • ISM-2089

    AI model performance metrics are monitored and anomalies are investigated.

  • ISM-2090

    Rate limiting is applied to inference queries for AI models.

  • ISM-2091

    Resource limits are enforced for AI models.

  • ISM-2092

    Access control policies are implemented to enforce fine-grained permissions for AI applications.

  • ISM-2093

    Role-based access controls are implemented for AI applications to restrict access to sensitive data.

  • ISM-2094

    Content filtering is implemented by AI applications to detect and block sensitive data exposure and improper output.

  • ISM-2102

    Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.

  • ISM-2103

    Organisational data generated, collected or processed by AI applications is not used for training, fine-tuning or improving AI models unless informed and explicit consent has been obtained from data owners in advance.

  • ISM-2120 Explained in the ISM-2121 guide →

    A secure software development policy is developed, implemented and maintained.

  • ISM-2121 Plain-English guide →

    Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.

  • ISM-2122

    Suitable AI models are used to augment software security testing.

  • ISM-2123

    All prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.

  • ISM-2154

    Software artefact dependencies are pinned to approved versions in source code.

  • ISM-2155

    Software is built using reproducible build practices that enable independent verification that release artefacts were produced from the stated source code.

  • ISM-2156

    Agentic AI applications are restricted to the minimum set of tools, functions and permissions required for their intended purpose.

  • ISM-2157

    Tools invoked by agentic AI applications are subject to both the access controls of the invoking user and agent-specific, task-scoped authorisation, with effective permissions limited to the minimum permitted by both.

  • ISM-2158

    External content retrieved by agentic AI applications is treated as untrusted data throughout processing, is clearly delimited from system instructions, is subject to validation and sanitisation measures applied to other untrusted input, remains untrusted following such processing, and is prevented from modifying or overriding system instructions, security policies, access controls, tool permissions or human approval requirements.

  • ISM-2159

    All tool invocations, external requests and outputs generated by agentic AI applications are centrally logged with sufficient detail to support cyber security incident investigations.

System access: 61 of 111 controls reached (41 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0408

    Systems have a logon banner that reminds personnel of their security responsibilities when accessing the system and its resources.

  • ISM-0417

    When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.

  • ISM-0421 Explained in the ISM-2080 guide →

    Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.

  • ISM-0428 Plain-English guide →

    Services are configured with a session lock that:

    - activates after a maximum of 15 minutes of human user inactivity, a maximum of 12 hours of overall session time or when manually activated

    - blocks access to all session content

    - requires re-authentication by human users using all authentication factors to unlock the session

    - denies human users the ability to disable the session locking mechanism.

  • ISM-0853 Explained in the ISM-0428 guide →

    Interactive user sessions are terminated and workstations are restarted at least daily.

  • ISM-0974 ML2 ML3

    Multi-factor authentication is used to authenticate unprivileged human users of systems.

  • ISM-1055

    LAN Manager and NT LAN Manager authentication methods are disabled.

  • ISM-1173 ML2 ML3

    Multi-factor authentication is used to authenticate privileged human users of systems.

  • ISM-1227

    Credentials set for user accounts are randomly generated.

  • ISM-1401 ML1 ML2 ML3

    Multi-factor authentication uses either: something people have and something people know, or something people have that is unlocked by something people know or are.

  • ISM-1403

    User accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon attempts, with either indefinite or automated lockout durations.

  • ISM-1504 ML1 ML2 ML3

    Multi-factor authentication is used to authenticate human users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

  • ISM-1505 ML3

    Multi-factor authentication is used to authenticate human users of data repositories.

  • ISM-1546

    Users are authenticated before they are granted access to a system and its resources.

  • ISM-1558 Explained in the ISM-2080 guide →

    Passwords using a sequence of words for single-factor authentication are not constructed using:

    - a list of categorised words

    - a real sentence in a natural language

    - song lyrics, movie or television show quotes, literature, or any other publicly available material

    - less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.

  • ISM-1559 Explained in the ISM-2080 guide →

    Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.

  • ISM-1590

    Credentials for user accounts are changed if:

    - they are compromised or suspected of being compromised

    - they are discovered stored on systems in the clear

    - they are discovered being transferred across networks in the clear

    - membership of a shared user account changes.

  • ISM-1593

    Human users provide sufficient evidence to verify their identity when first requesting credentials, when requesting the reset of any credentials, when requesting the temporary disabling of any credentials, and when requesting the enrolment or re-enrolment of any credentials.

  • ISM-1594

    Credentials for human users are provided via a secure communications channel or, if not possible, split into two parts with one part provided to the human user and the other part provided to their supervisor.

  • ISM-1595

    Credentials provided to human users are changed on first use.

  • ISM-1596

    Credentials are not reused by users across different systems.

  • ISM-1597

    Credentials are obscured as they are entered into systems.

  • ISM-1603

    Authentication methods susceptible to replay attacks are disabled.

  • ISM-1610

    A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.

  • ISM-1611

    Break glass accounts are only used when normal authentication processes cannot be used.

  • ISM-1612

    Break glass accounts are only used for specific authorised activities.

  • ISM-1613

    Use of break glass accounts is centrally logged.

  • ISM-1614 Explained in the ISM-1685 guide →

    Break glass account credentials are changed by the account custodian after they are accessed by any other party.

  • ISM-1615 Explained in the ISM-1685 guide →

    Break glass accounts are tested after credentials are changed.

  • ISM-1679 ML1 ML2 ML3

    Multi-factor authentication is used to authenticate human users to third-party online services that process, store or communicate their organisation’s sensitive data.

  • ISM-1680 ML1 ML2 ML3

    Multi-factor authentication (where available) is used to authenticate human users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

  • ISM-1681 ML1 ML2 ML3

    Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

  • ISM-1682 ML2 ML3

    Multi-factor authentication used for authenticating human users of systems is phishing-resistant.

  • ISM-1685 Plain-English guide → ML2 ML3

    Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

  • ISM-1686 ML3

    Credential Guard functionality is enabled.

  • ISM-1749

    Cached credentials are limited to one previous logon.

  • ISM-1795 Explained in the ISM-1685 guide →

    Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.

  • ISM-1861 ML3

    Local Security Authority protection functionality is enabled.

  • ISM-1872 ML2 ML3

    Multi-factor authentication used for authenticating human users of online services is phishing-resistant.

  • ISM-1873 ML2

    Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.

  • ISM-1874 ML3

    Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.

  • ISM-1892 ML1 ML2 ML3

    Multi-factor authentication is used to authenticate human users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ISM-1893 ML1 ML2 ML3

    Multi-factor authentication is used to authenticate human users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ISM-1894 ML3

    Multi-factor authentication used for authenticating human users of data repositories is phishing-resistant.

  • ISM-1897 ML3

    Remote Credential Guard functionality is enabled.

  • ISM-1919

    When multi-factor authentication is used to authenticate human users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.

  • ISM-1920

    When multi-factor authentication is used to authenticate human users to online services, online customer services, systems or data repositories – that process, store or communicate their organisation’s sensitive data or sensitive customer data – human users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.

  • ISM-1954 Explained in the ISM-1685 guide →

    Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.

  • ISM-1980

    Credential hint functionality is not used for systems.

  • ISM-2011

    When phishing-resistant multi-factor authentication is used by human users, other non-phishing-resistant multi-factor authentication options are disabled for their user accounts.

  • ISM-2012 Explained in the ISM-0428 guide →

    Systems are configured with a screen lock that:

    - activates after a maximum of 15 minutes of human user inactivity, or when manually activated

    - conceals all content on the screen

    - ensures that the screen does not enter a power saving state before the screen lock is activated

    - requires re-authentication by human users using all authentication factors to unlock the system

    - denies human users the ability to disable the screen locking mechanism.

  • ISM-2076

    Security questions are not used for authentication purposes.

  • ISM-2077

    Email is not used for out-of-band authentication purposes.

  • ISM-2078 Explained in the ISM-2080 guide →

    Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.

  • ISM-2079 Explained in the ISM-2080 guide →

    Maximum length limits for passwords are not less than 64 characters.

  • ISM-2080 Plain-English guide →

    Password complexity requirements are not imposed for passwords.

  • ISM-2081 Explained in the ISM-2080 guide →

    All ASCII printable characters are supported for passwords.

  • ISM-2136

    Risk-based access decisions, informed by contextual signals, are enforced for access to systems and their resources.

  • ISM-2140

    The OAuth device code authentication flow is disabled unless required, and where required, is restricted to authorised user accounts and managed devices.

  • ISM-2147 Explained in the ISM-0428 guide →

    Authentication tokens, session cookies and refresh tokens are cryptographically bound to the device on which they were issued.

  • ISM-2148 Explained in the ISM-0428 guide →

    Active sessions, refresh tokens and other authentication artefacts are revoked when credentials are reset or re-enrolled, when credentials are compromised or suspected of being compromised, when a device no longer meets compliance requirements, or when high-risk sign-in activity is detected.

Not reached from your selection

  • ISM-0405

    Requests for unprivileged access to systems and their resources are validated when first requested.

  • ISM-0407

    A secure record is maintained for the life of systems and their resources that covers the following for each human user:

    - their unique identifier

    - their signed agreement to abide by system usage policies

    - who authorised their access

    - when their access was granted

    - the level of access they were granted

    - when their access, and their level of access, was last reviewed

    - when their level of access was changed, and to what extent (if applicable)

    - when their access was withdrawn (if applicable).

  • ISM-0414

    Users granted access to systems and their resources are uniquely identifiable.

  • ISM-0415

    The use of shared user accounts is strictly controlled, and users of such accounts are uniquely identifiable.

  • ISM-0418

    Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.

  • ISM-0430 Explained in the ISM-1648 guide →

    Access to systems and their resources are removed or suspended the same day users no longer have a legitimate requirement for access.

  • ISM-0432

    Access requirements for systems and their resources are documented in their system security plan.

  • ISM-0434

    Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.

  • ISM-0435

    Personnel receive any necessary briefings before being granted access to systems and their resources.

  • ISM-0441

    When personnel are granted temporary access to systems and their resources, effective security controls are put in place to restrict their access to only data required for them to undertake their duties or functions.

  • ISM-0445 Explained in the ISM-1648 guide → ML1 ML2 ML3

    Privileged human users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

  • ISM-1175 ML1 ML2 ML3

    Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

  • ISM-1263

    Unique privileged user accounts are used for administering individual server applications.

  • ISM-1402

    Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.

  • ISM-1404 Explained in the ISM-1648 guide →

    Unprivileged access to systems and their resources are disabled after 45 days of inactivity.

  • ISM-1507 Explained in the ISM-1648 guide → ML1 ML2 ML3

    Requests for privileged access to systems and their resources are validated when first requested.

  • ISM-1508 ML3

    Privileged access to systems and their resources is limited to only what is required for users to undertake their duties or functions.

  • ISM-1509 Explained in the ISM-1648 guide → ML2 ML3

    Privileged access events are centrally logged.

  • ISM-1566

    Use of unprivileged access is centrally logged.

  • ISM-1583

    Personnel who are contractors are identified as such.

  • ISM-1591 Explained in the ISM-1648 guide →

    Access to systems and their resources are removed or suspended as soon as practicable when users are detected undertaking malicious activities.

  • ISM-1619 Explained in the ISM-1685 guide →

    Service accounts are created as group Managed Service Accounts.

  • ISM-1647 Explained in the ISM-1648 guide → ML2 ML3

    Privileged access to systems and their resources are disabled after 12 months unless revalidated.

  • ISM-1648 Plain-English guide → ML2 ML3

    Privileged access to systems and their resources are disabled after 45 days of inactivity.

  • ISM-1649 ML3

    Just-in-time administration is used for the administration of systems and their resources.

  • ISM-1650 ML2 ML3

    Privileged user account and security group management events are centrally logged.

  • ISM-1683 ML2 ML3

    Successful and unsuccessful multi-factor authentication events are centrally logged.

  • ISM-1847

    Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past six months.

  • ISM-1852

    Unprivileged access to systems and their resources is limited to only what is required for users to undertake their duties or functions.

  • ISM-1864

    A system usage policy is developed, implemented and maintained.

  • ISM-1865

    Personnel agree to abide by system usage policies before being granted access to systems and their resources.

  • ISM-1875

    Systems are scanned at least monthly to identify any credentials that are being stored in the clear.

  • ISM-1883 ML1 ML2 ML3

    Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users to undertake their duties or functions.

  • ISM-1895

    Successful and unsuccessful single-factor authentication events are centrally logged.

  • ISM-1953 Explained in the ISM-1685 guide →

    Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.

  • ISM-1955

    Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.

  • ISM-1956

    Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.

  • ISM-1957

    Private keys for Microsoft AD CS certification authority servers are protected by a hardware security module.

  • ISM-2133

    Each AI agent is assigned a unique identity that is distinct from the user accounts of personnel and the identities of other AI agents.

  • ISM-2134

    An AI agent register is developed, implemented, maintained and regularly verified.

  • ISM-2135

    An AI agent register contains the following for each AI agent:

    - its unique identifier

    - its owner and business purpose

    - the identities assigned to it

    - any user accounts and credentials it uses

    - the tools, permissions and data repositories it can access.

  • ISM-2137

    Human users are prevented from granting consent to third-party OAuth applications, with such consent granted only by an authorised administrator.

  • ISM-2138

    OAuth application consents, including their granted permissions, are reviewed at least every six months, with unused applications and excessive permissions revoked.

  • ISM-2139

    Consent grants, token issuance and token use for third-party OAuth applications are centrally logged.

  • ISM-2141

    Applications and workloads use short-lived dynamically issued credentials in preference to long-lived static credentials.

  • ISM-2142

    Static credentials used by applications and workloads are centrally managed using a credential or secrets management solution.

  • ISM-2143

    Applications and workloads use unique credentials that are not shared with other applications or workloads, or across development, testing, staging and production environments.

  • ISM-2144

    Static credentials used by applications and workloads are changed if:

    - they are compromised or suspected of being compromised

    - they are discovered stored on systems in the clear

    - they are discovered being transferred across networks in the clear.

  • ISM-2145

    Credentials for user accounts are revoked when they are no longer required.

  • ISM-2146

    Static credentials used by applications and workloads are revoked when they are no longer required.

System hardening: 53 of 160 controls reached (58 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0341

    Automatic execution features for removable media are disabled.

  • ISM-0343

    If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

  • ISM-0345

    External communication interfaces that allow DMA are disabled.

  • ISM-0380

    Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.

  • ISM-0383

    Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

  • ISM-0843 ML1 ML2 ML3

    Application control is implemented on workstations.

  • ISM-0846

    Users cannot disable or bypass application control, and are not exempted from application control, except when using local administrator accounts or break glass accounts.

  • ISM-0955

    Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.

  • ISM-1245

    All temporary installation files created during server application installation processes are removed after server applications have been installed.

  • ISM-1246

    Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1247

    Unneeded user accounts, components, services and functionality of server applications are disabled or removed.

  • ISM-1249

    Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.

  • ISM-1250

    The user accounts under which server applications run have limited access to their underlying server’s file system.

  • ISM-1260

    Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

  • ISM-1392

    When implementing application control using path rules, only approved users can modify approved files and write to approved folders.

  • ISM-1406

    SOEs are used for workstations and servers.

  • ISM-1407 ML3

    The latest release, or the previous release, of operating systems are used.

  • ISM-1408

    64-bit versions of operating systems are used.

  • ISM-1409

    Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1416

    A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.

  • ISM-1418

    If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

  • ISM-1471

    When implementing application control using publisher certificate rules, publisher names and product names are used.

  • ISM-1490 ML2 ML3

    Application control is implemented on internet-facing servers.

  • ISM-1544 ML2 ML3

    Microsoft’s recommended application blocklist is implemented.

  • ISM-1582 ML2 ML3

    Application control rulesets are validated at least annually.

  • ISM-1588

    SOEs are reviewed and updated at least annually.

  • ISM-1592

    Unprivileged human users do not have the ability to install unapproved applications.

  • ISM-1604

    When using a software-based isolation mechanism that consumes shared physical computing resources, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.

  • ISM-1605

    When using a software-based isolation mechanism that consumes shared physical computing resources, the underlying operating system is hardened.

  • ISM-1606

    When using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.

  • ISM-1608

    SOEs provided by third parties are scanned for malicious code and configurations.

  • ISM-1654 ML1 ML2 ML3

    Internet Explorer 11 is disabled or removed.

  • ISM-1655 ML3

    .NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.

  • ISM-1656 ML3

    Application control is implemented on non-internet-facing servers.

  • ISM-1657 ML1 ML2 ML3

    Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.

  • ISM-1658 ML3

    Application control restricts the execution of drivers to an organisation-approved set.

  • ISM-1659 ML3

    Microsoft’s vulnerable driver blocklist is implemented.

  • ISM-1745

    Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.

  • ISM-1746

    When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.

  • ISM-1848

    When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.

  • ISM-1870 ML1 ML2 ML3

    Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.

  • ISM-1871 ML2 ML3

    Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.

  • ISM-1896 ML3

    Memory integrity functionality is enabled.

  • ISM-1914

    Approved configurations for operating systems are developed, implemented and maintained.

  • ISM-1916

    Approved configurations for server applications are developed, implemented and maintained.

  • ISM-1926

    Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.

  • ISM-1928

    Backups of Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.

  • ISM-1950

    Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.

  • ISM-1951

    Hard match takeover is disabled for Microsoft Entra Connect servers.

  • ISM-1952

    Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.

  • ISM-2115

    Extensions for server applications are restricted to an organisation-approved set.

  • ISM-2127

    Digital signature verification functionality for drivers is enforced before they are loaded.

  • ISM-2128

    The ability to install, load or modify kernel-mode code, including drivers, kernel modules and extensions, is limited to privileged users who require such abilities as part of their duties or functions.

Not reached from your selection

  • ISM-0382

    Unprivileged human users do not have the ability to uninstall or disable approved applications.

  • ISM-0582

    Security-relevant events for Microsoft Windows operating systems are centrally logged.

  • ISM-0938

    Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.

  • ISM-1034

    A HIPS or EDR solution is implemented on critical servers and high-value servers.

  • ISM-1235

    Extensions for user applications are restricted to an organisation-approved set.

  • ISM-1341

    A HIPS or EDR solution is implemented on workstations.

  • ISM-1412 ML2 ML3

    Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1417

    An antivirus application is implemented on workstations and servers with:

    - signature-based detection functionality enabled and set to a high level

    - heuristic-based detection functionality enabled and set to a high level

    - reputation rating functionality enabled

    - ransomware protection functionality enabled

    - detection signatures configured to update at least daily

    - regular scanning configured for all fixed disks and removable media.

  • ISM-1460

    When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.

  • ISM-1467

    The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are used.

  • ISM-1470

    Unneeded user accounts, components, services and functionality of user applications are disabled or removed.

  • ISM-1483

    The latest release of internet-facing server applications is used.

  • ISM-1485 ML1 ML2 ML3

    Web browsers do not process web advertisements from the internet.

  • ISM-1486 ML1 ML2 ML3

    Web browsers do not process Java from the internet.

  • ISM-1487 ML3

    Only privileged human users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.

  • ISM-1488 ML1 ML2 ML3

    Microsoft Office macros in files originating from the internet are blocked.

  • ISM-1489 ML1 ML2 ML3

    Microsoft Office macro security settings cannot be changed by human users.

  • ISM-1491

    Unprivileged human users are prevented from running script execution engines, including:

    - Windows Script Host (cscript.exe and wscript.exe)

    - PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe)

    - Command Prompt (cmd.exe)

    - Windows Management Instrumentation (wmic.exe)

    - Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).

  • ISM-1492

    Operating system exploit protection functionality is enabled.

  • ISM-1542 ML2 ML3

    Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.

  • ISM-1584

    Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.

  • ISM-1585 ML1 ML2 ML3

    Web browser security settings cannot be changed by human users.

  • ISM-1601

    Microsoft’s attack surface reduction rules are implemented.

  • ISM-1607

    When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.

  • ISM-1620

    Privileged user accounts are members of the Protected Users security group.

  • ISM-1621 ML3

    Windows PowerShell 2.0 is disabled or removed.

  • ISM-1622 ML3

    PowerShell is configured to use Constrained Language Mode.

  • ISM-1623 ML2 ML3

    PowerShell module logging, script block logging and transcription events are centrally logged.

  • ISM-1624

    PowerShell script block logs are protected by Protected Event Logging functionality.

  • ISM-1660 ML2 ML3

    Allowed and blocked application control events are centrally logged.

  • ISM-1667 ML2 ML3

    Microsoft Office is blocked from creating child processes.

  • ISM-1668 ML2 ML3

    Microsoft Office is blocked from creating executable content.

  • ISM-1669 ML2 ML3

    Microsoft Office is blocked from injecting code into other processes.

  • ISM-1670 ML2 ML3

    PDF applications are blocked from creating child processes.

  • ISM-1671 ML1 ML2 ML3

    Microsoft Office macros are disabled for human users that do not have a demonstrated business requirement.

  • ISM-1672 ML1 ML2 ML3

    Microsoft Office macro antivirus scanning is enabled.

  • ISM-1673 ML2 ML3

    Microsoft Office macros are blocked from making Win32 API calls.

  • ISM-1674 ML3

    Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.

  • ISM-1675 ML3

    Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.

  • ISM-1676 ML3

    Microsoft Office’s list of trusted publishers is validated at least annually.

  • ISM-1743

    Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.

  • ISM-1748

    Email client security settings cannot be changed by human users.

  • ISM-1806

    Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

  • ISM-1823 ML2 ML3

    Office productivity suite security settings cannot be changed by human users.

  • ISM-1824 ML2 ML3

    PDF application security settings cannot be changed by human users.

  • ISM-1825

    Security product security settings cannot be changed by human users.

  • ISM-1826

    Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.

  • ISM-1827

    Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.

  • ISM-1828

    The Print Spooler service is disabled on Microsoft AD DS domain controllers.

  • ISM-1829

    Passwords are not stored in Group Policy Preferences.

  • ISM-1830

    Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.

  • ISM-1832

    Only service accounts and computer accounts are configured with Service Principal Names (SPNs).

  • ISM-1833

    User accounts are provisioned with the minimum privileges required.

  • ISM-1834

    Duplicate SPNs do not exist within the domain.

  • ISM-1835

    Privileged user accounts are configured as sensitive and cannot be delegated.

  • ISM-1836

    User accounts require Kerberos pre-authentication.

  • ISM-1838

    The UserPassword attribute for user accounts is not used.

  • ISM-1839

    Account properties accessible by unprivileged users are not used to store passwords.

  • ISM-1840

    User account passwords do not use reversible encryption.

  • ISM-1841

    Unprivileged user accounts cannot add machines to the domain.

  • ISM-1842

    Dedicated privileged service accounts are used to add machines to the domain.

  • ISM-1843

    User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.

  • ISM-1844

    Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.

  • ISM-1845

    When a user account is disabled, it is removed from all security group memberships.

  • ISM-1846

    The Pre-Windows 2000 Compatible Access security group does not contain user accounts.

  • ISM-1859 ML2 ML3

    Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1860 ML2 ML3

    PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-1889 ML2 ML3

    Command line process creation events are centrally logged.

  • ISM-1890 ML3

    Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.

  • ISM-1891 ML3

    Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.

  • ISM-1915

    Approved configurations for user applications are developed, implemented and maintained.

  • ISM-1927

    Access to Microsoft AD DS domain controllers, Microsoft AD CS servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.

  • ISM-1929

    Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.

  • ISM-1930

    Passwords are prevented from being stored in Group Policy Preferences.

  • ISM-1931

    SID Filtering is enabled for domain and forest trusts.

  • ISM-1932

    The number of service accounts configured with an SPN is minimised.

  • ISM-1933

    Service accounts configured with an SPN do not have DCSync permissions.

  • ISM-1934

    User accounts with DCSync permissions are reviewed at least every six months, and those without an ongoing requirement for the permissions have them removed.

  • ISM-1935

    Computer accounts are not configured for unconstrained delegation.

  • ISM-1936

    The sIDHistory attribute for user accounts is not used.

  • ISM-1937

    User accounts are checked at least weekly for the presence of the sIDHistory attribute.

  • ISM-1938

    The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.

  • ISM-1939

    The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly privileged security groups is minimised.

  • ISM-1940

    Service accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.

  • ISM-1941

    Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.

  • ISM-1942

    The Domain Computers security group is not a member of any privileged or highly privileged security groups.

  • ISM-1943

    Strong mapping between certificates and users is enforced.

  • ISM-1944

    The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS certification authority configurations.

  • ISM-1945

    The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.

  • ISM-1946

    Unprivileged user accounts do not have write access to certificate templates.

  • ISM-1947

    Extended Key Usages that enable user authentication are removed.

  • ISM-1948

    Certificate manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.

  • ISM-1949

    Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.

  • ISM-1976

    Security-relevant events for Apple macOS operating systems are centrally logged.

  • ISM-1977

    Security-relevant events for Linux operating systems are centrally logged.

  • ISM-1978

    Security-relevant events for server applications on internet-facing servers are centrally logged.

  • ISM-1979

    Security-relevant events for server applications on non-internet-facing servers are centrally logged.

  • ISM-2010

    Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.

  • ISM-2110

    User applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

  • ISM-2111

    All temporary installation files created during user application installation processes are removed after user applications have been installed.

  • ISM-2112

    AI applications that process classified data have their ability to directly access external public data sources disabled.

  • ISM-2113

    AI applications are configured to require human approval before executing sensitive or high-impact actions.

  • ISM-2114

    Baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.

  • ISM-2129

    WMI activity, including the creation of permanent event subscriptions, is centrally logged.

  • ISM-2130

    Web-based enrolment interfaces for Microsoft AD CS servers are disabled unless required, and where enabled, are configured to require HTTPS and Extended Protection for Authentication.

  • ISM-2131

    Certificate templates are reviewed at least every three months to identify and remediate misconfigurations that could enable privilege escalation or unauthorised certificate enrolment.

  • ISM-2132

    Certificate enrolment events, including successful and unsuccessful requests and changes to certificate templates or Microsoft AD CS configurations, are centrally logged.

System management: 36 of 60 controls reached (21 more reachable via our wider catalogue)

Reached from your selection

  • ISM-0298

    A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.

  • ISM-1143

    Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.

  • ISM-1380 ML1 ML2 ML3

    Privileged human users use separate privileged and unprivileged operating environments.

  • ISM-1501 ML1 ML2 ML3

    Operating systems that are no longer supported by vendors are replaced.

  • ISM-1511 ML1 ML2 ML3

    Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • ISM-1547

    Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.

  • ISM-1548

    Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.

  • ISM-1687 ML2 ML3

    Privileged operating environments are not virtualised within unprivileged operating environments.

  • ISM-1688 ML1 ML2 ML3

    Unprivileged user accounts cannot be used to log on to privileged operating environments.

  • ISM-1689 ML1 ML2 ML3

    Privileged user accounts (excluding local administrator accounts) cannot be used to log on to unprivileged operating environments.

  • ISM-1694 ML1 ML2 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1695 ML1 ML2

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

  • ISM-1696 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1697 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1705 ML2 ML3

    Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.

  • ISM-1706 ML3

    Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.

  • ISM-1707 ML2 ML3

    Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

  • ISM-1708 ML3

    Backup administrator accounts are prevented from modifying and deleting backups during their retention period.

  • ISM-1750

    Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.

  • ISM-1751

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1810 ML1 ML2 ML3

    Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

  • ISM-1811 ML1 ML2 ML3

    Backups of data, applications and settings are retained in a secure and resilient manner.

  • ISM-1812 ML1 ML2 ML3

    Unprivileged user accounts cannot access backups belonging to other user accounts.

  • ISM-1813 ML3

    Unprivileged user accounts cannot access their own backups.

  • ISM-1814 ML1 ML2 ML3

    Unprivileged user accounts are prevented from modifying and deleting backups.

  • ISM-1877 ML1 ML2 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1878

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1879 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1898 ML3

    Secure Admin Workstations are used in the performance of administrative activities.

  • ISM-1902 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1903 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1904 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1958

    User accounts with DCSync permissions cannot be used to log on to unprivileged operating environments.

  • ISM-2149

    A list of authorised RMM tools and remote access tools is developed, enforced and maintained.

  • ISM-2151

    Backups are stored using a technically enforced immutability mechanism that prevents their modification or deletion for the duration of their retention period.

  • ISM-2152

    Backup infrastructure, including backup servers, repositories and management consoles, is segregated from production environments and uses a separate authentication mechanism for administrative access.

Not reached from your selection

  • ISM-0042

    System administration processes, and supporting system administration procedures, are developed, implemented and maintained.

  • ISM-0304 ML3

    Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

  • ISM-1211

    System administration activities are performed in accordance with the system’s change and configuration management plan.

  • ISM-1385

    Administrative infrastructure is segregated from the wider network and the internet.

  • ISM-1386

    Network management traffic can only originate from administrative infrastructure.

  • ISM-1387 ML2 ML3

    Administrative activities are conducted through jump servers.

  • ISM-1493

    Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.

  • ISM-1510

    A digital preservation policy is developed, implemented and maintained.

  • ISM-1515 ML1 ML2 ML3

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

  • ISM-1643

    Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.

  • ISM-1690 ML1 ML2 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1691 ML1 ML2

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

  • ISM-1692 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1693 ML2 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

  • ISM-1704 ML1 ML2 ML3

    Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

  • ISM-1753

    Internet-facing network devices that are no longer supported by vendors are replaced.

  • ISM-1809

    When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating security controls are implemented until such time that they can be removed or replaced.

  • ISM-1876 ML1 ML2 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ISM-1899

    Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.

  • ISM-1901 ML3

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ISM-1905 ML1 ML2 ML3

    Online services that are no longer supported by vendors are removed.

  • ISM-1981

    Non-internet-facing network devices that are no longer supported by vendors are replaced.

  • ISM-1982

    Networked IT equipment that is no longer supported by vendors is replaced.

  • ISM-2150

    Network connections for unauthorised RMM tools and remote access tools are blocked at gateways.

Entitled but switched off

Your licences include these, and you told us they are not in use. Turning them on costs nothing further.

Worth confirming

Your licences include these and you were not sure they are in use. Check before buying anything that would duplicate them.

Running, but unattended

These are switched on, but your answers suggest nobody runs them or would notice them failing. Usually fixed with a process, not a purchase.

Provided by more than one of your products

You are paying more than once for this evidence. Overlap is not automatically waste, but it should be a decision rather than an accident.

Not reached by your selection

For the products you selected: ISM controls in our count that our catalogue does not reach.

See where your own products stand: free, about 3 minutes.

Check your coverage →