Services · Framework assessment

ASD ISM: Information Security Manual Assessment

The Information security manual (ISM) is the Australian Signals Directorate's cyber security framework: 49 principles and 1,143 controls, updated every quarter. We help you identify the ISM controls that apply to your systems, the controls and evidence you already have, and the gaps, in plain English.

What is the ISM?

The Information security manual (ISM) is produced by the Australian Signals Directorate (ASD). In ASD's words, it is "a cyber security framework that an organisation can apply, using their risk management framework, to protect their information technology and operational technology systems from cyber threats". ASD writes it for chief information security officers, chief information officers, cyber security professionals, and IT and OT managers.

The ISM has two layers. The current release, 2026.09.4, holds:

  • 49 cyber security principles, "grouped into six functions: govern, identify, protect, detect, respond and recover". They are the strategic layer: ASD says an organisation "should be able to demonstrate that the cyber security principles are being adhered to".
  • 1,143 controls in 23 chapters of cyber security guidelines, from cyber security roles to data transfers. They are the practical layer. Each control carries an applicability marking: NC for non-classified systems, government and non-government alike, then OS, P, S and TS for OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET systems.

ASD pairs the controls with a six-step risk management framework, drawn from NIST SP 800-37: define the system, select security controls, implement them, assess them, authorise the system, and monitor it. ASD also publishes the Essential Eight maturity levels as baselines drawn from ISM controls, so an Essential Eight program is ISM work.

ASD updates the ISM every quarter, in March, June, September and December.

What changed in the latest ISM release?

The September 2026 release, 2026.09.4, added 44 controls, amended 105 and withdrew two, and moved the sign-in, credential and session controls into a new chapter, Guidelines for system access. Most of it treats applications, workloads and AI agents as identities in their own right. Our plain-English summary, with six things a business can check this quarter and every new control in ASD's words: ISM September 2026: What Changed and What to Check.

We rewrite this section with every release.

Does the ISM apply to my business?

Not by law, unless something makes it so. ASD states that an organisation "is not required as a matter of law to comply with the ISM, unless legislation, or a direction given under legislation or by some other lawful authority, compels them to comply".

  • Australian Government entities must apply it. The Protective Security Policy Framework (Release 2026) requires the ISM's cyber security principles to be "applied during all stages of the lifecycle of each system" (Requirement 0084), and its controls and guidelines to be "applied on a risk-based approach" (Requirement 0085).
  • Suppliers to government meet it through their customer. For commercial providers delivering services to an organisation, ASD says the authorising officer is "the CISO of the supported organisation". If you host, manage or build systems for a government customer, their decision to accept your service rests on ISM controls.
  • Everyone else can use it as a benchmark. The ISM is the most complete public statement of what ASD considers good cyber security. Most small businesses start with the Essential Eight and use the ISM to see where expectations are heading.

Is there an ISM certification?

No. The ISM has no certificate. ASD's process is an assessment of the controls, which "can be undertaken by an organisation's own assessors or Infosec Registered Assessors Program (IRAP) assessors" for systems up to SECRET, followed by a decision by the system's authorising officer to accept the remaining risk. IRAP is ASD's program of endorsed individual assessors. When a customer or contract asks for an IRAP assessment, only an endorsed IRAP assessor can do it. Our ISM assessment is not an IRAP assessment and does not replace one.

What does an ISM assessment involve?

Our ISM assessment is a review done with you and your IT provider. We help you identify the ISM controls that apply to your systems, the controls you already have and the evidence that can prove them. It is not a technical test of your systems.

  1. Scope the systems. We agree which systems are in scope and what information they handle. That sets which applicability markings, and so which controls, apply.
  2. Select the controls. We work through the ISM guidelines relevant to those systems and list the controls that apply, including the ones you inherit from a cloud or managed service.
  3. Map controls and evidence. For each control, we identify the tools, settings and processes that meet it, including what your existing licences provide, and the evidence that can prove it, and note where evidence is missing or is only a policy statement.
  4. Report the gaps. We walk you and your IT provider through what is covered, what is not, and what to fix first.

If a customer later asks for an IRAP assessment, you go into it with your controls and evidence already identified and in one place.

What you get

  • The ISM controls that apply to your systems, chapter by chapter, and which are met and which are missing.
  • The evidence that can prove each control, and where it is missing or weak.
  • The gaps in priority order, with the practical fix for each.
  • A plain-English summary for owners, and the detail your IT provider needs.
  • Optional help to close the gaps: we can do the work, or source and deliver the products, quoted separately.

ISM controls explained in plain English

What individual controls require, why they matter and the evidence that shows they are met.

All ISM guides →

How much does an ISM assessment cost?

Each assessment is priced by individual quote, because the effort depends on how many systems and sites are in scope and what the assessment is for: a maturity target, a certification or a customer's requirement.

If you are not sure where you stand, start with the fixed-price IT Security Review ($399 inc GST). It gives you a prioritised action plan and tells you whether a full assessment is worth doing yet.

Ask for a quote

Related

Other frameworks we assess against

  • Essential Eight →

    Essential Eight (Essential 8) assessment: we identify the controls and evidence that prove each strategy, and the gaps to your target maturity level.

Sources

Quoted ASD material © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au.