Services · Framework assessment
ASD ISM: Information Security Manual Assessment
The Information security manual (ISM) is the Australian Signals Directorate's cyber security framework: 49 principles and 1,143 controls, updated every quarter. We help you identify the ISM controls that apply to your systems, the controls and evidence you already have, and the gaps, in plain English.
What is the ISM?
The Information security manual (ISM) is produced by the Australian Signals Directorate (ASD). In ASD's words, it is "a cyber security framework that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats". ASD writes it for chief information security officers, chief information officers, cyber security professionals, and IT and OT managers.
The ISM has two layers. The current release, 2026.09.4, holds:
- 49 cyber security principles, "grouped into six functions: govern, identify, protect, detect, respond and recover". They are the strategic layer: ASD says an organisation "should be able to demonstrate that the cyber security principles are being adhered to".
- 1,143 controls in 23 chapters of cyber security guidelines, from cyber security roles to data transfers. They are the practical layer. Each control carries an applicability marking: NC for non-classified systems, government and non-government alike, then OS, P, S and TS for OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET systems.
ASD pairs the controls with a six-step risk management framework, drawn from NIST SP 800-37: define the system, select security controls, implement them, assess them, authorise the system, and monitor it. ASD also publishes the Essential Eight maturity levels as baselines drawn from ISM controls, so an Essential Eight program is ISM work.
ASD updates the ISM every quarter, in March, June, September and December.
What changed in the latest ISM release?
The September 2026 release, 2026.09.4, added 44 controls, amended 105 and withdrew two, and moved the sign-in, credential and session controls into a new chapter, Guidelines for system access. Most of it treats applications, workloads and AI agents as identities in their own right. Our plain-English summary, with six things a business can check this quarter and every new control in ASD's words: ISM September 2026: What Changed and What to Check.
We rewrite this section with every release.
Does the ISM apply to my business?
Not by law, unless something makes it so. ASD states that an organisation "is not required as a matter of law to comply with the ISM, unless legislation, or a direction given under legislation or by some other lawful authority, compels them to comply".
- Australian Government entities must apply it. The Protective Security Policy Framework (Release 2026) requires the ISM's cyber security principles to be "applied during all stages of the lifecycle of each system" (Requirement 0084), and its controls and guidelines to be "applied on a risk-based approach" (Requirement 0085).
- Suppliers to government meet it through their customer. For commercial providers delivering services to an organisation, ASD says the authorising officer is "the CISO of the supported organisation". If you host, manage or build systems for a government customer, their decision to accept your service rests on ISM controls.
- Everyone else can use it as a benchmark. The ISM is the most complete public statement of what ASD considers good cyber security. Most small businesses start with the Essential Eight and use the ISM to see where expectations are heading.
Is there an ISM certification?
No. The ISM has no certificate. ASD's process is an assessment of the controls, which "can be undertaken by an organisation's own assessors or Infosec Registered Assessors Program (IRAP) assessors" for systems up to SECRET, followed by a decision by the system's authorising officer to accept the remaining risk. IRAP is ASD's program of endorsed individual assessors. When a customer or contract asks for an IRAP assessment, only an endorsed IRAP assessor can do it. Our ISM assessment is not an IRAP assessment and does not replace one.
What does an ISM assessment involve?
Our ISM assessment is a review done with you and your IT provider. We help you identify the ISM controls that apply to your systems, the controls you already have and the evidence that can prove them. It is not a technical test of your systems.
- Scope the systems. We agree which systems are in scope and what information they handle. That sets which applicability markings, and so which controls, apply.
- Select the controls. We work through the ISM guidelines relevant to those systems and list the controls that apply, including the ones you inherit from a cloud or managed service.
- Map controls and evidence. For each control, we identify the tools, settings and processes that meet it, including what your existing licences provide, and the evidence that can prove it, and note where evidence is missing or is only a policy statement.
- Report the gaps. We walk you and your IT provider through what is covered, what is not, and what to fix first.
If a customer later asks for an IRAP assessment, you go into it with your controls and evidence already identified and in one place.
What you get
- The ISM controls that apply to your systems, chapter by chapter, and which are met and which are missing.
- The evidence that can prove each control, and where it is missing or weak.
- The gaps in priority order, with the practical fix for each.
- A plain-English summary for owners, and the detail your IT provider needs.
- Optional help to close the gaps: we can do the work, or source and deliver the products, quoted separately.
ISM controls explained in plain English
What individual controls require, why they matter and the evidence that shows they are met.
- ISM-1648: Disable Idle Admin Access After 45 Days →
ISM-1648 says privileged access is disabled after 45 days without use. What counts as inactive, how to automate it, the exceptions and evidence to keep.
- ISM-0428: Lock Idle Sessions After 15 Minutes →
ISM-0428 says online services lock after 15 idle minutes or 12 hours in all, and unlock only with every factor. What that means and the evidence to keep.
- ISM-2121: Security Skills for Software Developers →
ISM-2121 says developers without the security skills a task needs are not used for it. What that means for staff, contractors and AI, and the evidence.
- ISM-1685: Passwords for Admin and Service Accounts →
ISM-1685 says break glass, local admin and service account credentials must be long, unique, random and managed. What that means and the evidence to keep.
- ISM-2080: Why Password Complexity Rules Are Out →
ASD's ISM-2080 says not to impose password complexity rules. What it means, why length and banned-password checks work better, and the evidence to keep.
How much does an ISM assessment cost?
Each assessment is priced by individual quote, because the effort depends on how many systems and sites are in scope and what the assessment is for: a maturity target, a certification or a customer's requirement.
If you are not sure where you stand, start with the fixed-price IT Security Review ($399 inc GST). It gives you a prioritised action plan and tells you whether a full assessment is worth doing yet.
Ask for a quoteRelated
- ISM September 2026: What Changed and What to Check →
The latest release in plain English: six things to check this quarter and every new control in ASD's words.
- Sample coverage report →
Every ISM control we count, by identifier, in ASD's wording. This link opens at the new AI agent identity control.
- Free coverage check →
See which ISM and Essential Eight controls your existing licences already reach, in about three minutes.
- Free Cyber Security Self-Check for Small Business →
How the coverage check reads your licences against the ISM and the Essential Eight.
Other frameworks we assess against
- Essential Eight →
Essential Eight (Essential 8) assessment: we identify the controls and evidence that prove each strategy, and the gaps to your target maturity level.
Sources
- ASD, Information security manual - what the ISM is, who it is for, and the current release
- ASD, Information security manual (September 2026), Using the cyber security framework - the legal position, the principles' six functions, applicability markings, the risk management framework, assessors and authorising officers
- ASD, ISM OSCAL release v2026.09.4 - the counts of principles, chapters and controls, and the Essential Eight baselines
- ASD, Archived ISM releases - the quarterly release cycle
- Department of Home Affairs, Protective Security Policy Framework Release 2026 - Requirements 0084 and 0085
- ASD, Infosec Registered Assessors Program (IRAP) - endorsed individual assessors
Quoted ASD material © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au.