Sample report. Generated from our live catalogue for a typical small-business stack — Microsoft 365 Business Premium + NinjaOne. Run your own free check →
TERESEC CYBERSECURITY CONSULTING Security Coverage Report

Prepared for

Sample Pty Ltd

Security coverage report — what your licences already cover

Prepared 2026-08-26 · Microsoft 365 Business Premium · NinjaOne Endpoint Management · NinjaOne Backup

3products selected
3licence tiers
32capabilities in scope
11frameworks assessed
15findings

Framework coverage

Requirements in our crosswalk reachable from the tiers you selected. Open each list to see them by name.

APAC Australia Essential 8 2024 — Maturity Level 1 31 / 48
APAC Australia Essential 8 2024 — Maturity Level 2 48 / 107
APAC Australia Essential 8 2024 — Maturity Level 3 58 / 149
APAC Australia ISM March 2026 123 / 1054
NIST CSF 2.0 12 / 106
ISO 27001 2022 0 / 122
ISO 27002 2022 15 / 96
CIS CSC 8.1 39 / 153
CIS CSC 8.1 IG1 20 / 56
CIS CSC 8.1 IG2 35 / 130
CIS CSC 8.1 IG3 39 / 153
AICPA TSC 2017:2022 (used for SOC 2) 11 / 69
PCI DSS 4.0.1 46 / 251

ISO 27001 2022 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

ISO 27002 2022 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

CIS CSC 8.1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

CIS CSC 8.1 IG1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

CIS CSC 8.1 IG2 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

CIS CSC 8.1 IG3 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

AICPA TSC 2017:2022 (used for SOC 2) appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

PCI DSS 4.0.1 appears in this report as counts only: it is a licensed standard and its requirement details cannot be redistributed here. We work through the specifics with you in a consultation.

The 31 APAC Australia Essential 8 2024 — Maturity Level 1 requirements your selection reaches

Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory

Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.

  • ML1-P1-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML1-P2-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML1-P1 Maturity Level 1 — Patch applications — broad support, not counted in coverage
  • ML1-P2 Maturity Level 1 — Patch operating systems — broad support, not counted in coverage

Backup Modification and/or Destruction via Backup access control

Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.

  • ML1-P8-ISM-1814

    Unprivileged user accounts are prevented from modifying and deleting backups.

  • ML1-P8 Maturity Level 1 — Regular backups — broad support, not counted in coverage

Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy

Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.

  • ML1-P5-ISM-0843

    Application control is implemented on workstations.

Data Backups via Backup job status

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  • ML1-P8-ISM-1511

    Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • ML1-P8-ISM-1810

    Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

  • ML1-P8-ISM-1811

    Backups of data, applications and settings are retained in a secure and resilient manner.

  • ML1-P8 Maturity Level 1 — Regular backups — broad support, not counted in coverage

Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting

Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.

  • ML1-P5-ISM-0843 — requirements listed above
  • ML1-P5 Maturity Level 1 — Application control — broad support, not counted in coverage

Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state

Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.

  • ML1-P3-ISM-1401

    Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

  • ML1-P3-ISM-1504

    Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

  • ML1-P3-ISM-1679

    Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.

  • ML1-P3-ISM-1680

    Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

  • ML1-P3-ISM-1681

    Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

  • ML1-P3-ISM-1892

    Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML1-P3-ISM-1893

    Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML1-P3 Maturity Level 1 — Multi-factor authentication — broad support, not counted in coverage

Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership

Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).

  • ML1-P4-ISM-0445

    Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

  • ML1-P4-ISM-1175

    Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

  • ML1-P4-ISM-1380

    Privileged users use separate privileged and unprivileged operating environments.

  • ML1-P4-ISM-1507

    Requests for privileged access to systems and their resources are validated when first requested.

  • ML1-P4-ISM-1688

    Unprivileged user accounts cannot logon to privileged operating environments.

  • ML1-P4-ISM-1689

    Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

  • ML1-P4 Maturity Level 1 — Restrict administrative privileges — broad support, not counted in coverage

Software & Firmware Patching via Patch deployment state

Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.

  • ML1-P1-ISM-1690

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML1-P1-ISM-1691

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

  • ML1-P1-ISM-1876

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML1-P2-ISM-1694

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML1-P2-ISM-1695

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

  • ML1-P2-ISM-1877

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML1-P1 Maturity Level 1 — Patch applications — broad support, not counted in coverage
  • ML1-P2 Maturity Level 1 — Patch operating systems — broad support, not counted in coverage

Testing for Reliability & Integrity via Backup integrity check

Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.

  • ML1-P8-ISM-1515

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Vulnerability Scanning via Vulnerability findings

Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.

  • ML1-P1-ISM-1698

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

  • ML1-P1-ISM-1699

    A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ML1-P2-ISM-1701

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

  • ML1-P2-ISM-1702

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

  • ML1-P1 Maturity Level 1 — Patch applications — broad support, not counted in coverage
  • ML1-P2 Maturity Level 1 — Patch operating systems — broad support, not counted in coverage
The 48 APAC Australia Essential 8 2024 — Maturity Level 2 requirements your selection reaches

Anomalous Behavior via Endpoint detection and response

Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.

  • ML2-P5-ISM-1660

    Allowed and blocked application control events are centrally logged.

Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory

Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.

  • ML2-P1-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML2-P2-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML2-P1 Maturity Level 2 — Patch applications — broad support, not counted in coverage
  • ML2-P2 Maturity Level 2 — Patch operating systems — broad support, not counted in coverage

Backup Modification and/or Destruction via Backup access control

Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.

  • ML2-P8-ISM-1814

    Unprivileged user accounts are prevented from modifying and deleting backups.

  • ML2-P8 Maturity Level 2 — Regular backups — broad support, not counted in coverage

Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy

Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.

  • ML2-P5-ISM-0843

    Application control is implemented on workstations.

  • ML2-P5-ISM-1490

    Application control is implemented on internet-facing servers.

  • ML2-P5-ISM-1544

    Microsoft’s recommended application blocklist is implemented.

  • ML2-P5-ISM-1582

    Application control rulesets are validated on an annual or more frequent basis.

Content of Event Logs via Authentication events, Endpoint logging policy

Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.

  • ML2-P3 Maturity Level 2 — Multi-factor authentication — broad support, not counted in coverage
  • ML2-P5 Maturity Level 2 — Application control — broad support, not counted in coverage

Data Backups via Backup job status

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  • ML2-P8-ISM-1511

    Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • ML2-P8-ISM-1810

    Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

  • ML2-P8-ISM-1811

    Backups of data, applications and settings are retained in a secure and resilient manner.

  • ML2-P8 Maturity Level 2 — Regular backups — broad support, not counted in coverage

Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting

Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.

  • ML2-P5-ISM-0843 — requirements listed above
  • ML2-P5-ISM-1544 — requirements listed above
  • ML2-P5 Maturity Level 2 — Application control — broad support, not counted in coverage

Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state

Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.

  • ML2-P3-ISM-0974

    Multi-factor authentication is used to authenticate unprivileged users of systems.

  • ML2-P3-ISM-1173

    Multi-factor authentication is used to authenticate privileged users of systems.

  • ML2-P3-ISM-1401

    Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

  • ML2-P3-ISM-1504

    Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

  • ML2-P3-ISM-1679

    Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.

  • ML2-P3-ISM-1680

    Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

  • ML2-P3-ISM-1681

    Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

  • ML2-P3-ISM-1682

    Multi-factor authentication used for authenticating users of systems is phishing-resistant.

  • ML2-P3-ISM-1683

    Successful and unsuccessful multi-factor authentication events are centrally logged.

  • ML2-P3-ISM-1872

    Multi-factor authentication used for authenticating users of online services is phishing-resistant.

  • ML2-P3-ISM-1873

    Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.

  • ML2-P3-ISM-1892

    Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML2-P3-ISM-1893

    Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML2-P4-ISM-1685

    Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

  • ML2-P3 Maturity Level 2 — Multi-factor authentication — broad support, not counted in coverage

Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting

Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.

  • ML2-P5 Maturity Level 2 — Application control — broad support, not counted in coverage

Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership

Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).

  • ML2-P4-ISM-0445

    Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

  • ML2-P4-ISM-1175

    Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

  • ML2-P4-ISM-1380

    Privileged users use separate privileged and unprivileged operating environments.

  • ML2-P4-ISM-1507

    Requests for privileged access to systems and their resources are validated when first requested.

  • ML2-P4-ISM-1509

    Privileged access events are centrally logged.

  • ML2-P4-ISM-1648

    Privileged access to systems and their resources are disabled after 45 days of inactivity.

  • ML2-P4-ISM-1650

    Privileged user account and security group management events are centrally logged.

  • ML2-P4-ISM-1687

    Privileged operating environments are not virtualised within unprivileged operating environments.

  • ML2-P4-ISM-1688

    Unprivileged user accounts cannot logon to privileged operating environments.

  • ML2-P4-ISM-1689

    Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

  • ML2-P4 Maturity Level 2 — Restrict administrative privileges — broad support, not counted in coverage

Software & Firmware Patching via Patch deployment state

Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.

  • ML2-P1-ISM-1690

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML2-P1-ISM-1691

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

  • ML2-P1-ISM-1693

    Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

  • ML2-P1-ISM-1876

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML2-P2-ISM-1694

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML2-P2-ISM-1695

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

  • ML2-P2-ISM-1877

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML2-P1 Maturity Level 2 — Patch applications — broad support, not counted in coverage
  • ML2-P2 Maturity Level 2 — Patch operating systems — broad support, not counted in coverage

Testing for Reliability & Integrity via Backup integrity check

Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.

  • ML2-P8-ISM-1515

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Vulnerability Scanning via Vulnerability findings

Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.

  • ML2-P1-ISM-1698

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

  • ML2-P1-ISM-1699

    A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ML2-P1-ISM-1700

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ML2-P2-ISM-1701

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

  • ML2-P2-ISM-1702

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

  • ML2-P1 Maturity Level 2 — Patch applications — broad support, not counted in coverage
  • ML2-P2 Maturity Level 2 — Patch operating systems — broad support, not counted in coverage
The 58 APAC Australia Essential 8 2024 — Maturity Level 3 requirements your selection reaches

Anomalous Behavior via Endpoint detection and response

Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.

  • ML3-P5-ISM-1660

    Allowed and blocked application control events are centrally logged.

Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory

Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.

  • ML3-P1-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML3-P2-ISM-1807

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ML3-P1 Maturity Level 3 — Patch applications — broad support, not counted in coverage
  • ML3-P2 Maturity Level 3 — Patch operating systems — broad support, not counted in coverage

Backup Modification and/or Destruction via Backup access control

Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.

  • ML3-P8-ISM-1814

    Unprivileged user accounts are prevented from modifying and deleting backups.

  • ML3-P8 Maturity Level 3 — Regular backups — broad support, not counted in coverage

Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy

Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.

  • ML3-P5-ISM-0843

    Application control is implemented on workstations.

  • ML3-P5-ISM-1490

    Application control is implemented on internet-facing servers.

  • ML3-P5-ISM-1544

    Microsoft’s recommended application blocklist is implemented.

  • ML3-P5-ISM-1582

    Application control rulesets are validated on an annual or more frequent basis.

Content of Event Logs via Authentication events, Endpoint logging policy

Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.

  • ML3-P3 Maturity Level 3 — Multi-factor authentication — broad support, not counted in coverage
  • ML3-P5 Maturity Level 3 — Application control — broad support, not counted in coverage

Data Backups via Backup job status

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  • ML3-P8-ISM-1511

    Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • ML3-P8-ISM-1810

    Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

  • ML3-P8-ISM-1811

    Backups of data, applications and settings are retained in a secure and resilient manner.

  • ML3-P8 Maturity Level 3 — Regular backups — broad support, not counted in coverage

Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting

Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.

  • ML3-P5-ISM-0843 — requirements listed above
  • ML3-P5-ISM-1544 — requirements listed above
  • ML3-P5 Maturity Level 3 — Application control — broad support, not counted in coverage

Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state

Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.

  • ML3-P3-ISM-0974

    Multi-factor authentication is used to authenticate unprivileged users of systems.

  • ML3-P3-ISM-1173

    Multi-factor authentication is used to authenticate privileged users of systems.

  • ML3-P3-ISM-1401

    Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

  • ML3-P3-ISM-1504

    Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

  • ML3-P3-ISM-1505

    Multi-factor authentication is used to authenticate users of data repositories.

  • ML3-P3-ISM-1679

    Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.

  • ML3-P3-ISM-1680

    Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

  • ML3-P3-ISM-1681

    Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

  • ML3-P3-ISM-1682

    Multi-factor authentication used for authenticating users of systems is phishing-resistant.

  • ML3-P3-ISM-1683

    Successful and unsuccessful multi-factor authentication events are centrally logged.

  • ML3-P3-ISM-1872

    Multi-factor authentication used for authenticating users of online services is phishing-resistant.

  • ML3-P3-ISM-1874

    Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.

  • ML3-P3-ISM-1892

    Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML3-P3-ISM-1893

    Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ML3-P3-ISM-1894

    Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.

  • ML3-P4-ISM-1685

    Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

  • ML3-P3 Maturity Level 3 — Multi-factor authentication — broad support, not counted in coverage

Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting

Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.

  • ML3-P5 Maturity Level 3 — Application control — broad support, not counted in coverage

Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership

Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).

  • ML3-P4-ISM-0445

    Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

  • ML3-P4-ISM-1175

    Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

  • ML3-P4-ISM-1380

    Privileged users use separate privileged and unprivileged operating environments.

  • ML3-P4-ISM-1507

    Requests for privileged access to systems and their resources are validated when first requested.

  • ML3-P4-ISM-1508

    Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

  • ML3-P4-ISM-1509

    Privileged access events are centrally logged.

  • ML3-P4-ISM-1648

    Privileged access to systems and their resources are disabled after 45 days of inactivity.

  • ML3-P4-ISM-1649

    Just-in-time administration is used for the administration of systems and their resources.

  • ML3-P4-ISM-1650

    Privileged user account and security group management events are centrally logged.

  • ML3-P4-ISM-1687

    Privileged operating environments are not virtualised within unprivileged operating environments.

  • ML3-P4-ISM-1688

    Unprivileged user accounts cannot logon to privileged operating environments.

  • ML3-P4-ISM-1689

    Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

  • ML3-P4 Maturity Level 3 — Restrict administrative privileges — broad support, not counted in coverage

Security Event Monitoring via Endpoint detection and response

Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.

  • ML3-P3-ISM-0109

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

  • ML3-P4-ISM-0109

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

  • ML3-P5-ISM-0109

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

  • ML3-P7-ISM-0109

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

Software & Firmware Patching via Patch deployment state

Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.

  • ML3-P1-ISM-1690

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML3-P1-ISM-1692

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML3-P1-ISM-1693

    Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

  • ML3-P1-ISM-1876

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML3-P1-ISM-1901

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML3-P2-ISM-1694

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ML3-P2-ISM-1696

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML3-P2-ISM-1877

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ML3-P1 Maturity Level 3 — Patch applications — broad support, not counted in coverage
  • ML3-P2 Maturity Level 3 — Patch operating systems — broad support, not counted in coverage

Testing for Reliability & Integrity via Backup integrity check

Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.

  • ML3-P8-ISM-1515

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Vulnerability Scanning via Vulnerability findings

Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.

  • ML3-P1-ISM-1698

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

  • ML3-P1-ISM-1699

    A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ML3-P1-ISM-1700

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ML3-P2-ISM-1701

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

  • ML3-P2-ISM-1702

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

  • ML3-P2-ISM-1703

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.

  • ML3-P1 Maturity Level 3 — Patch applications — broad support, not counted in coverage
  • ML3-P2 Maturity Level 3 — Patch operating systems — broad support, not counted in coverage
The 123 APAC Australia ISM March 2026 requirements your selection reaches

Anomalous Behavior via Endpoint detection and response

Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.

  • ism-1660 Application control

    Allowed and blocked application control events are centrally logged.

Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory

Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.

  • ism-0336 IT equipment registers

    A networked IT equipment register is developed, implemented, maintained and verified on a regular basis.

  • ism-1643 Software register

    Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.

  • ism-1807 Scanning for unmitigated vulnerabilities

    An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

  • ism-1966 Overseeing the cyber security program

    The CISO develops, implements, maintains and verifies on a regular basis a register of systems used by their organisation.

Backup Modification and/or Destruction via Backup access control

Mechanisms exist to restrict access to modify and/or delete backups to privileged users with assigned data backup and recovery operations roles.

  • ism-1814 Backup modification and deletion

    Unprivileged user accounts are prevented from modifying and deleting backups.

Centralized Management of Flaw Remediation Processes via Patch deployment state

Mechanisms exist to centrally-manage the flaw remediation process.

  • ism-0298 Patch management processes and procedures

    A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.

  • ism-0300 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.

Configuration Enforcement via Application hardening policy, Attack surface reduction rules, Exploit protection, Macro hardening policy

Automated mechanisms exist to monitor, enforce and report on configurations for endpoint devices.

  • ism-0843 Application control

    Application control is implemented on workstations.

  • ism-0846 Application control

    All users (with the exception of local administrator accounts and break glass accounts) cannot disable, bypass or be exempted from application control.

  • ism-0955 Application control

    Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.

  • ism-1392 Application control

    When implementing application control using path rules, only approved users can modify approved files and write to approved folders.

  • ism-1471 Application control

    When implementing application control using publisher certificate rules, publisher names and product names are used.

  • ism-1490 Application control

    Application control is implemented on internet-facing servers.

  • ism-1544 Application control

    Microsoft’s recommended application blocklist is implemented.

  • ism-1582 Application control

    Application control rulesets are validated on an annual or more frequent basis.

Content of Event Logs via Authentication events, Endpoint logging policy

Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.

  • ism-0582 Operating system event logging

    Security-relevant events for Microsoft Windows operating systems are centrally logged.

  • ism-0585 Event log details

    For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.

  • ism-1536 Software interaction with databases

    All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.

  • ism-1537 Database event logging

    Security-relevant events for databases are centrally logged, including:

    - access or modification of particularly important content

    - addition of new users, especially privileged users

    - changes to user roles or privileges

    - attempts to elevate user privileges

    - queries containing comments

    - queries containing multiple embedded queries

    - database and query alerts or failures

    - database structure changes

    - database administrator actions

    - use of executable commands

    - database logons and logoffs.

  • ism-1895 Single-factor authentication

    Successful and unsuccessful single-factor authentication events are centrally logged.

  • ism-2051 Secure software development

    Software generates sufficient event logs to support the detection of cyber security events.

Data & Asset Classification via Data classification and labelling

Mechanisms exist to ensure data and assets are categorized in accordance with applicable statutory, regulatory and contractual requirements.

  • ism-0270 Protective markings for emails

    Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.

  • ism-0271 Protective marking tools

    Protective marking tools do not automatically insert protective markings into emails.

  • ism-0272 Protective marking tools

    Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.

  • ism-0294 Labelling IT equipment

    IT equipment, with the exception of high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.

  • ism-0296 Labelling high assurance IT equipment

    ASD’s approval is sought before applying labels to external surfaces of high assurance IT equipment.

  • ism-0323 Classifying media

    Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.

  • ism-0393 Protecting database contents

    Databases and their contents are classified based on the sensitivity or classification of data that they contain.

Data Backups via Backup job status

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  • ism-1511 Performing and retaining backups

    Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

  • ism-1547 Data backup and restoration processes and procedures

    Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.

  • ism-1548 Data backup and restoration processes and procedures

    Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.

  • ism-1810 Performing and retaining backups

    Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

  • ism-1811 Performing and retaining backups

    Backups of data, applications and settings are retained in a secure and resilient manner.

Explicitly Allow / Deny Applications via Executable allowlisting, Executable blocklisting

Mechanisms exist to explicitly allow (allowlist / whitelist) and/or block (denylist / blacklist) applications that are authorized to execute on systems.

  • ism-0843 Application control — requirements listed above
  • ism-0846 Application control — requirements listed above
  • ism-1235 Hardening user application configurations

    Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clients, PDF applications and security products are restricted to an organisation-approved set.

  • ism-1544 Application control — requirements listed above

Heuristic / Nonsignature-Based Detection via Anti-malware protection

Mechanisms exist to utilize heuristic / nonsignature-based antimalware detection capabilities.

  • ism-1284 Content validation

    Files imported or exported via gateways or CDSs undergo content validation.

  • ism-1286 Content conversion

    Files imported or exported via gateways or CDSs undergo content conversion.

  • ism-1288 Antivirus scanning

    Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.

  • ism-1289 Archive files

    Archive files imported or exported via gateways or CDSs are unpacked in order to undergo content filtering checks.

  • ism-1293 Encrypted files

    Encrypted files imported or exported via gateways or CDSs are decrypted in order to undergo content filtering checks.

  • ism-1417 Antivirus application

    An antivirus application is implemented on workstations and servers with:

    - signature-based detection functionality enabled and set to a high level

    - heuristic-based detection functionality enabled and set to a high level

    - reputation rating functionality enabled

    - ransomware protection functionality enabled

    - detection signatures configured to update on at least a daily basis

    - regular scanning configured for all fixed disks and removable media.

  • ism-1608 Standard Operating Environments

    SOEs provided by third parties are scanned for malicious code and configurations.

  • ism-1782 Protective Domain Name System Services

    A protective DNS service is used to block access to known malicious domain names.

Host Intrusion Detection and Prevention Systems (HIDS / HIPS) via Endpoint detection and response

Mechanisms exist to utilize Host-based Intrusion Detection / Prevention Systems (HIDS / HIPS), or similar technologies, to monitor for and protect against anomalous host activity, including lateral movement across the network.

  • ism-1034 Host-based intrusion detection and response solution

    A HIPS or EDR solution is implemented on critical servers and high-value servers.

  • ism-1341 Host-based intrusion detection and response solution

    A HIPS or EDR solution is implemented on workstations.

  • ism-1418 Device access control

    If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Malicious Code Protection (Anti-Malware) via Anti-malware protection

Mechanisms exist to utilize antimalware technologies to detect and eradicate malicious code.

  • ism-1284 Content validation — requirements listed above
  • ism-1286 Content conversion — requirements listed above
  • ism-1288 Antivirus scanning — requirements listed above
  • ism-1289 Archive files — requirements listed above
  • ism-1290 Archive files

    Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.

  • ism-1293 Encrypted files — requirements listed above
  • ism-1417 Antivirus application — requirements listed above
  • ism-1608 Standard Operating Environments — requirements listed above
  • ism-1969 Handling and containing malicious code infections

    Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.

Media Marking via Data classification and labelling

Mechanisms exist to mark media in accordance with data protection requirements so that personnel are alerted to distribution limitations, handling caveats and applicable security requirements.

  • ism-0201 Labelling conduits

    Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre intervals and marked as ‘TS RUN’.

  • ism-0270 Protective markings for emails — requirements listed above
  • ism-0272 Protective marking tools — requirements listed above
  • ism-0294 Labelling IT equipment — requirements listed above
  • ism-0296 Labelling high assurance IT equipment — requirements listed above
  • ism-0332 Labelling media

    Media, with the exception of internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.

  • ism-0356 Treatment of non-volatile magnetic media following sanitisation

    Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its classification.

  • ism-0358 Treatment of non-volatile erasable and electrically erasable programmable read-only memory media following sanitisation

    Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains its classification.

  • ism-0360 Treatment of non-volatile flash memory media following sanitisation

    Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its classification.

Media Use via Removable media control

Mechanisms exist to restrict the use of types of digital media on systems or system components.

  • ism-0341 Hardening operating system configurations

    Automatic execution features for removable media are disabled.

  • ism-0343 Device access control

    If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Monitoring for Indicators of Compromise (IOC) via Endpoint detection and response

Automated mechanisms exist to identify and alert on Indicators of Compromise (IoC).

  • ism-0120 Access to sufficient data sources and tools

    Cyber security personnel have access to sufficient data sources and tools to ensure that systems can be monitored for key indicators of compromise.

  • ism-1091 Reporting cryptographic-related cyber security incidents

    Keying material is changed when compromised or suspected of being compromised.

Multi-Factor Authentication (MFA) via MFA enforcement scope, MFA method strength, Multi-factor authentication state

Automated mechanisms exist to enforce Multi-Factor Authentication (MFA) for: (1) Remote network access; (2) Third-party Technology Assets, Applications and/or Services (TAAS); and/ or (3) Non-console access to critical TAAS that store, transmit and/or process sensitive and/or regulated data.

  • ism-0974 Multi-factor authentication

    Multi-factor authentication is used to authenticate unprivileged users of systems.

  • ism-1173 Multi-factor authentication

    Multi-factor authentication is used to authenticate privileged users of systems.

  • ism-1401 Multi-factor authentication

    Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

  • ism-1504 Multi-factor authentication

    Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

  • ism-1505 Multi-factor authentication

    Multi-factor authentication is used to authenticate users of data repositories.

  • ism-1559 Password strength

    Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.

  • ism-1560 Password strength

    Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.

  • ism-1561 Password strength

    Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.

  • ism-1679 Multi-factor authentication

    Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.

  • ism-1680 Multi-factor authentication

    Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

  • ism-1681 Multi-factor authentication

    Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

  • ism-1682 Multi-factor authentication

    Multi-factor authentication used for authenticating users of systems is phishing-resistant.

  • ism-1683 Multi-factor authentication

    Successful and unsuccessful multi-factor authentication events are centrally logged.

  • ism-1685 Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

    Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

  • ism-1872 Multi-factor authentication

    Multi-factor authentication used for authenticating users of online services is phishing-resistant.

  • ism-1873 Multi-factor authentication

    Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.

  • ism-1874 Multi-factor authentication

    Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.

  • ism-1892 Multi-factor authentication

    Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ism-1893 Multi-factor authentication

    Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

  • ism-1894 Multi-factor authentication

    Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.

  • ism-2011 Multi-factor authentication

    When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.

Privileged Account Management (PAM) via Privileged logon restriction, Privileged role membership

Mechanisms exist to restrict and control privileged access rights for users and Technology Assets, Applications and/or Services (TAAS).

  • ism-0445 Privileged access to systems

    Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

  • ism-0446 Privileged access to systems by foreign nationals

    Foreign nationals, including seconded foreign nationals, do not have privileged access to systems that process, store or communicate AUSTEO or REL data.

  • ism-0447 Privileged access to systems by foreign nationals

    Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.

  • ism-1175 Privileged access to systems

    Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

  • ism-1380 Separate privileged operating environments

    Privileged users use separate privileged and unprivileged operating environments.

  • ism-1507 Privileged access to systems

    Requests for privileged access to systems and their resources are validated when first requested.

  • ism-1508 Privileged access to systems

    Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

  • ism-1509 Privileged access to systems

    Privileged access events are centrally logged.

  • ism-1620 Microsoft Active Directory Domain Services security group memberships

    Privileged user accounts are members of the Protected Users security group.

  • ism-1648 Suspension of access to systems

    Privileged access to systems and their resources are disabled after 45 days of inactivity.

  • ism-1649 Privileged access to systems

    Just-in-time administration is used for the administration of systems and their resources.

  • ism-1650 Privileged access to systems

    Privileged user account and security group management events are centrally logged.

  • ism-1687 Separate privileged operating environments

    Privileged operating environments are not virtualised within unprivileged operating environments.

  • ism-1688 Separate privileged operating environments

    Unprivileged user accounts cannot logon to privileged operating environments.

  • ism-1689 Separate privileged operating environments

    Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

  • ism-1835 Microsoft Active Directory Domain Services account hardening

    Privileged user accounts are configured as sensitive and cannot be delegated.

  • ism-1939 Microsoft Active Directory Domain Services security group memberships

    The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly-privileged security groups is minimised.

Removable Media Security via Removable media control

Mechanisms exist to restrict removable media in accordance with data handling and acceptable usage parameters.

  • ism-1359 Removable media usage policy

    A removable media usage policy is developed, implemented and maintained.

  • ism-1713 Removable media register

    A removable media register is developed, implemented, maintained and verified on a regular basis.

Security Event Monitoring via Endpoint detection and response

Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.

  • ism-0109 Event log monitoring

    Event logs from workstations are analysed in a timely manner to detect cyber security events.

Software & Firmware Patching via Patch deployment state

Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.

  • ism-1143 Patch management processes and procedures

    Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.

  • ism-1493 Software register

    Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and verified on a regular basis.

  • ism-1690 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ism-1691 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

  • ism-1692 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ism-1693 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

  • ism-1694 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ism-1695 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

  • ism-1696 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ism-1751 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

  • ism-1876 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ism-1877 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ism-1878 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

  • ism-1901 Mitigating known vulnerabilities

    Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

Software Firewall via Host firewall management

Mechanisms exist to utilize host-based firewall software, or a similar technology, on all endpoint devices, where technically feasible.

  • ism-1416 Software firewall

    A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.

Testing for Reliability & Integrity via Backup integrity check

Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.

  • ism-1515 Testing restoration of backups

    Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Vulnerability Scanning via Vulnerability findings

Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.

  • ism-1163 Continuous monitoring plan

    Systems have a continuous monitoring plan that includes:

    - conducting vulnerability scans for systems at least fortnightly

    - conducting vulnerability assessments and penetration tests for systems prior to deployment, including prior to deployment of significant changes, and at least annually thereafter

    - analysing identified vulnerabilities to determine their potential impact

    - implementing mitigations based on risk, effectiveness and cost.

  • ism-1698 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

  • ism-1699 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ism-1700 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

  • ism-1701 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

  • ism-1702 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

  • ism-1703 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.

  • ism-1752 Scanning for unmitigated vulnerabilities

    A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.

  • ism-1875 Protecting credentials

    Networks are scanned at least monthly to identify any credentials that are being stored in the clear.

The 12 NIST CSF 2.0 requirements your selection reaches

Anomalous Behavior via Endpoint detection and response

Mechanisms exist to utilize User & Entity Behavior Analytics (UEBA) and/or User Activity Monitoring (UAM) solutions to detect and respond to anomalous behavior that could indicate account compromise or other malicious activities.

  • DE.CM-03

    Personnel activity and technology usage are monitored to find potentially adverse events

  • DE.CM Continuous Monitoring — broad support, not counted in coverage

Asset Inventories via Active asset discovery, Asset last seen, Operating system fingerprint, Software inventory

Mechanisms exist to perform inventories of Technology Assets, Applications, Services and/or Data (TAASD) that: (1) Accurately reflects the current TAASD in use; (2) Identifies authorized software products, including business justification details; (3) Is at the level of granularity deemed necessary for tracking and reporting; (4) Includes organization-defined information deemed necessary to achieve effective property accountability; and (5) Is available for review and audit by designated organizational personnel.

  • ID.AM-01

    Inventories of hardware managed by the organization are maintained

  • ID.AM-02

    Inventories of software, services, and systems managed by the organization are maintained

  • ID.AM Asset Management — broad support, not counted in coverage

Content of Event Logs via Authentication events, Endpoint logging policy

Mechanisms exist to configure Technology Assets, Applications and/or Services (TAAS) to produce event logs that contain sufficient information to, at a minimum: (1) Establish what type of event occurred; (2) When (date and time) the event occurred; (3) Where the event occurred; (4) The source of the event; (5) The outcome (success or failure) of the event; and (6) The identity of any user/subject associated with the event.

  • PR.PS-04

    Log records are generated and made available for continuous monitoring

Data & Asset Classification via Data classification and labelling

Mechanisms exist to ensure data and assets are categorized in accordance with applicable statutory, regulatory and contractual requirements.

  • ID.AM-05

    Assets are prioritized based on classification, criticality, resources, and impact on the mission

  • PR.DS Data Security — broad support, not counted in coverage

Data Backups via Backup job status

Mechanisms exist to create recurring backups of data, software and/or system images, as well as verify the integrity of these backups, to ensure the availability of the data to satisfy Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).

  • PR.DS-11

    Backups of data are created, protected, maintained, and tested

Malicious Code Protection (Anti-Malware) via Anti-malware protection

Mechanisms exist to utilize antimalware technologies to detect and eradicate malicious code.

  • DE.CM-09

    Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

Monitoring for Indicators of Compromise (IOC) via Endpoint detection and response

Automated mechanisms exist to identify and alert on Indicators of Compromise (IoC).

  • DE.CM Continuous Monitoring — broad support, not counted in coverage

Prevent Unauthorized Software Execution via Driver allowlisting, Executable allowlisting

Mechanisms exist to configure systems to prevent the execution of unauthorized software programs.

  • PR.PS-05

    Installation and execution of unauthorized software are prevented

Security Event Monitoring via Endpoint detection and response

Mechanisms exist to review event logs on an ongoing basis and escalate incidents in accordance with established timelines and procedures.

  • DE.AE-06

    Information on adverse events is provided to authorized staff and tools

  • DE.CM-01

    Networks and network services are monitored to find potentially adverse events

  • DE.AE Adverse Event Analysis — broad support, not counted in coverage

Software & Firmware Patching via Patch deployment state

Mechanisms exist to conduct software patching for all deployed Technology Assets, Applications and/or Services (TAAS), including firmware.

  • PR.PS-02

    Software is maintained, replaced, and removed commensurate with risk

Testing for Reliability & Integrity via Backup integrity check

Mechanisms exist to routinely test backups that verify the reliability of the backup process, as well as the integrity and availability of the data.

  • PR.DS-11 — requirements listed above

Vulnerability Scanning via Vulnerability findings

Mechanisms exist to detect vulnerabilities and configuration errors by routine vulnerability scanning of systems and applications.

  • ID.RA-01

    Vulnerabilities in assets are identified, validated, and recorded

Provided by more than one of your products

You are paying more than once for this evidence. Overlap is not automatically waste, but it should be a decision rather than an accident.

Not reached by your selection

For the products you selected: requirements in our crosswalk that no capability in our catalogue reaches.

See where your own products stand — free, about 3 minutes.

Check your coverage →