ISM-0009 | System owners, in consultation with each system's authorising officer, identify any supple | 1 |
ISM-0027 | System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensit | 2 |
ISM-0039 | A cyber security strategy is developed, implemented and maintained. | 1 |
ISM-0041 | Systems have a system security plan that includes an overview of the system (covering the | 1 |
ISM-0042 | System administration processes, and supporting system administration procedures, are deve | 1 |
ISM-0043 | Systems have a cyber security incident response plan that covers the following: - guidelin | 3 |
ISM-0047 | Organisational-level cyber security documentation is approved by the chief information sec | 2 |
ISM-0072 | Security requirements associated with the confidentiality, integrity and availability of d | 3 |
ISM-0078 | Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under | 0 |
ISM-0100 | Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessm | 1 |
ISM-0109 | Event logs from workstations are analysed in a timely manner to detect cyber security even | 2 |
ISM-0120 | Cyber security personnel have access to sufficient data sources and tools to ensure that s | 2 |
ISM-0123 | Cyber security incidents are reported to the chief information security officer, or one of | 3 |
ISM-0125 | A cyber security incident register is developed, implemented and maintained. | 1 |
ISM-0133 | When a data spill occurs, data owners are advised and access to the data is restricted. | 1 |
ISM-0137 | Legal advice is sought before allowing intrusion activity to continue on a system for the | 1 |
ISM-0138 | The integrity of evidence gathered during an investigation is maintained by investigators: | 2 |
ISM-0140 | Cyber security incidents are reported to ASD as soon as possible after they occur or are d | 2 |
ISM-0141 | The requirement for service providers to report cyber security incidents to a designated p | 3 |
ISM-0142 | The compromise or suspected compromise of cryptographic equipment or associated keying mat | 1 |
ISM-0161 | IT equipment and media are secured when not in use. | 1 |
ISM-0164 | Unauthorised people are prevented from observing systems, in particular workstation displa | 2 |
ISM-0181 | Cabling infrastructure is installed in accordance with relevant Australian Standards, as d | 0 |
ISM-0187 | SECRET cables, when bundled together or run in conduit, are run exclusively in their own i | 0 |
ISM-0194 | In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit | 0 |
ISM-0195 | In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to | 0 |
ISM-0198 | When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Orga | 0 |
ISM-0201 | Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre | 0 |
ISM-0206 | Cable labelling processes, and supporting cable labelling procedures, are developed, imple | 1 |
ISM-0208 | A cable register contains the following for each cable: - cable identifier - cable colour | 0 |
ISM-0211 | A cable register is developed, implemented, maintained and verified on a regular basis. | 0 |
ISM-0213 | SECRET and TOP SECRET cables are terminated on their own individual patch panels. | 0 |
ISM-0216 | TOP SECRET patch panels are installed in individual TOP SECRET cabinets. | 0 |
ISM-0217 | Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabi | 1 |
ISM-0218 | If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wa | 1 |
ISM-0225 | Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas. | 1 |
ISM-0229 | Personnel are advised of the permitted sensitivity or classification of information that c | 0 |
ISM-0230 | Personnel are advised of security risks posed by non-secure telephone systems in areas whe | 0 |
ISM-0231 | When using cryptographic equipment to permit different levels of conversation for differen | 0 |
ISM-0232 | Telephone systems used for sensitive or classified conversations encrypt all traffic that | 0 |
ISM-0233 | Cordless telephone handsets and headsets are not used for sensitive or classified conversa | 0 |
ISM-0235 | Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone s | 1 |
ISM-0236 | Off-hook audio protection features are used on telephone systems in areas where background | 1 |
ISM-0240 | Paging, Multimedia Message Service, Short Message Service and messaging apps are not used | 1 |
ISM-0245 | MFDs are not connected to digital telephone systems. | 0 |
ISM-0246 | When an emanation security risk assessment is required, it is sought as early as possible | 0 |
ISM-0249 | System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployab | 0 |
ISM-0250 | IT equipment meets industry and government standards relating to electromagnetic interfere | 0 |
ISM-0252 | Cyber security awareness training is undertaken annually by all personnel and covers: - th | 3 |
ISM-0258 | A web usage policy is developed, implemented and maintained. | 0 |
ISM-0260 | All web access, including that by internal servers, is conducted through web proxies. | 2 |
ISM-0261 | The following details are centrally logged for websites accessed via web proxies: - web ad | 1 |
ISM-0263 | TLS traffic communicated through gateways is decrypted and inspected. | 0 |
ISM-0264 | An email usage policy is developed, implemented and maintained. | 0 |
ISM-0267 | Access to non-approved webmail services is blocked. | 0 |
ISM-0269 | Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To | 1 |
ISM-0270 | Protective markings are applied to emails and reflect the highest sensitivity or classific | 1 |
ISM-0271 | Protective marking tools do not automatically insert protective markings into emails. | 0 |
ISM-0272 | Protective marking tools do not allow users to select protective markings that a system ha | 0 |
ISM-0280 | If procuring an evaluated product, a product that has completed a PP-based evaluation, inc | 1 |
ISM-0285 | Evaluated products are delivered in a manner consistent with any delivery procedures defin | 0 |
ISM-0286 | When procuring high assurance information technology (IT) equipment, ASD is contacted for | 0 |
ISM-0289 | Evaluated products are installed, configured, administered and operated in an evaluated co | 0 |
ISM-0290 | High assurance IT equipment is installed, configured, administered and operated in an eval | 0 |
ISM-0293 | IT equipment is classified based on the highest sensitivity or classification of data that | 1 |
ISM-0294 | IT equipment, with the exception of high assurance IT equipment, is labelled with protecti | 1 |
ISM-0296 | ASD's approval is sought before applying labels to external surfaces of high assurance IT | 0 |
ISM-0298 | A centralised and managed approach that maintains the integrity of patches or updates, and | 1 |
ISM-0300 | Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equi | 0 |
ISM-0304 | Applications other than office productivity suites, web browsers and their extensions, ema | 2 |
ISM-0305 | Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared | 1 |
ISM-0306 | If an appropriately cleared technician is not used to undertake maintenance or repairs of | 1 |
ISM-0307 | If an appropriately cleared technician is not used to undertake maintenance or repairs of | 1 |
ISM-0310 | IT equipment maintained or repaired off site is done so at facilities approved for handlin | 1 |
ISM-0311 | IT equipment containing media is sanitised by removing the media from the IT equipment or | 1 |
ISM-0312 | IT equipment, including associated media, that is located overseas and has processed, stor | 1 |
ISM-0313 | IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, | 1 |
ISM-0315 | High assurance IT equipment is destroyed prior to its disposal. | 0 |
ISM-0316 | Following sanitisation, destruction or declassification, a formal administrative decision | 0 |
ISM-0317 | At least three pages of random text with no blank areas are printed on each colour printer | 0 |
ISM-0318 | When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per e | 0 |
ISM-0321 | When disposing of IT equipment that has been designed or modified to meet emanation securi | 0 |
ISM-0323 | Media is classified to the highest sensitivity or classification of data it stores, unless | 2 |
ISM-0325 | Any media connected to a system with a higher sensitivity or classification than the media | 1 |
ISM-0330 | Before reclassifying media to a lower sensitivity or classification, the media is sanitise | 0 |
ISM-0332 | Media, with the exception of internally mounted fixed media within information technology | 1 |
ISM-0336 | A networked IT equipment register is developed, implemented, maintained and verified on a | 3 |
ISM-0337 | Media is only used with systems that are authorised to process, store or communicate its s | 1 |
ISM-0341 | Automatic execution features for removable media are disabled. | 2 |
ISM-0343 | If there is no business requirement for writing to removable media and devices, such funct | 1 |
ISM-0345 | External communication interfaces that allow DMA are disabled. | 0 |
ISM-0347 | When transferring data manually between two systems belonging to different security domain | 1 |
ISM-0348 | Media sanitisation processes, and supporting media sanitisation procedures, are developed, | 2 |
ISM-0350 | The following media types are destroyed prior to their disposal: - microfiche and microfil | 1 |
ISM-0351 | Volatile media is sanitised by removing its power for at least 10 minutes. | 0 |
ISM-0352 | SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its e | 0 |
ISM-0354 | Non-volatile magnetic media is sanitised by overwriting it at least once (or three times i | 1 |
ISM-0356 | Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its clas | 0 |
ISM-0357 | Non-volatile EPROM media is sanitised by applying three times the manufacturer's specified | 1 |
ISM-0358 | Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains | 0 |
ISM-0359 | Non-volatile flash memory media is sanitised by overwriting it at least twice in its entir | 0 |
ISM-0360 | Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its | 0 |
ISM-0361 | Magnetic media is destroyed using a degausser with a suitable magnetic field strength and | 0 |
ISM-0362 | Product-specific directions provided by degausser manufacturers are followed. | 0 |
ISM-0363 | Media destruction processes, and supporting media destruction procedures, are developed, i | 0 |
ISM-0368 | Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results i | 0 |
ISM-0370 | The destruction of media is performed under the supervision of at least one cleared person | 0 |
ISM-0371 | Personnel supervising the destruction of media supervise its handling to the point of dest | 0 |
ISM-0372 | The destruction of media storing accountable material is performed under the supervision o | 0 |
ISM-0373 | Personnel supervising the destruction of media storing accountable material supervise its | 1 |
ISM-0374 | Media disposal processes, and supporting media disposal procedures, are developed, impleme | 1 |
ISM-0375 | Following sanitisation, destruction or declassification, a formal administrative decision | 0 |
ISM-0378 | Labels and markings indicating the owner, sensitivity, classification or any other marking | 0 |
ISM-0380 | Unneeded user accounts, components, services and functionality of operating systems are di | 1 |
ISM-0382 | Unprivileged users do not have the ability to uninstall or disable approved applications. | 0 |
ISM-0383 | Default user accounts or credentials for operating systems, including for any pre-configur | 1 |
ISM-0385 | Servers maintain effective functional separation with other servers allowing them to opera | 0 |
ISM-0393 | Databases and their contents are classified based on the sensitivity or classification of | 2 |
ISM-0400 | Development, testing, staging and production environments are segregated. | 3 |
ISM-0401 | Secure by Design principles and practices are followed throughout the software development | 3 |
ISM-0402 | Software is comprehensively tested for vulnerabilities, using SAST, DAST and SCA prior to | 3 |
ISM-0405 | Requests for unprivileged access to systems and their resources are validated when first r | 2 |
ISM-0407 | A secure record is maintained for the life of systems and their resources that covers the | 3 |
ISM-0408 | Systems have a logon banner that reminds users of their security responsibilities when acc | 0 |
ISM-0409 | Foreign nationals, including seconded foreign nationals, do not have access to systems tha | 1 |
ISM-0411 | Foreign nationals, excluding seconded foreign nationals, do not have access to systems tha | 1 |
ISM-0414 | Personnel granted access to systems and their resources are uniquely identifiable. | 2 |
ISM-0415 | The use of shared user accounts is strictly controlled, and personnel using such accounts | 1 |
ISM-0417 | When systems cannot support multi-factor authentication, single-factor authentication usin | 0 |
ISM-0418 | Physical credentials are kept separate from systems they are used to authenticate to, exce | 0 |
ISM-0420 | Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are fo | 0 |
ISM-0421 | Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and | 1 |
ISM-0422 | Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 | 0 |
ISM-0428 | Services are configured with a session lock that: - activates after a maximum of 15 minute | 1 |
ISM-0430 | Access to systems and their resources are removed or suspended the same day personnel no l | 3 |
ISM-0432 | Access requirements for systems and their resources are documented in their system securit | 2 |
ISM-0434 | Personnel undergo appropriate employment screening and, where necessary, hold an appropria | 2 |
ISM-0435 | Personnel receive any necessary briefings before being granted access to systems and their | 0 |
ISM-0441 | When personnel are granted temporary access to systems and their resources, effective cont | 0 |
ISM-0443 | Temporary access is not granted to systems that process, store or communicate caveated or | 0 |
ISM-0445 | Privileged users are assigned a dedicated privileged user account to be used solely for du | 3 |
ISM-0446 | Foreign nationals, including seconded foreign nationals, do not have privileged access to | 0 |
ISM-0447 | Foreign nationals, excluding seconded foreign nationals, do not have privileged access to | 0 |
ISM-0455 | Where practical, cryptographic equipment, applications and libraries provide a means of da | 1 |
ISM-0457 | Cryptographic equipment, applications or libraries that have completed a Common Criteria e | 1 |
ISM-0459 | Full disk encryption, or partial encryption where access controls will only allow writing | 2 |
ISM-0460 | HACE is used when encrypting media that contains SECRET or TOP SECRET data. | 0 |
ISM-0462 | When a user authenticates to the encryption functionality of IT equipment or media, it is | 1 |
ISM-0465 | Cryptographic equipment, applications or libraries that have completed a Common Criteria e | 1 |
ISM-0467 | HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently s | 0 |
ISM-0469 | An ASD-Approved Cryptographic Protocol (AACP) or high assurance cryptographic protocol is | 2 |
ISM-0471 | Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, | 2 |
ISM-0472 | When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is | 0 |
ISM-0474 | When using ECDH for agreeing on encryption session keys, a base point order and key size o | 0 |
ISM-0475 | When using ECDSA for digital signatures, a base point order and key size of at least 224 b | 0 |
ISM-0476 | When using RSA for digital signatures, and transporting encryption session keys (and simil | 0 |
ISM-0477 | When using RSA for digital signatures, and for transporting encryption session keys (and s | 0 |
ISM-0479 | Symmetric cryptographic algorithms are not used in Electronic Codebook Mode. | 0 |
ISM-0481 | Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, | 1 |
ISM-0484 | The SSH daemon is configured to: - only listen on the required interfaces (ListenAddress x | 1 |
ISM-0485 | Public key-based authentication is used for SSH connections. | 0 |
ISM-0487 | When using logins without a password for SSH connections, the following are disabled: - ac | 1 |
ISM-0488 | If using remote access without the use of a password for SSH connections, the 'forced comm | 0 |
ISM-0489 | When SSH-agent or similar key caching applications are used, it is limited to workstations | 0 |
ISM-0490 | Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections. | 0 |
ISM-0494 | Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel | 0 |
ISM-0496 | The ESP protocol is used for authentication and encryption of IPsec connections. | 0 |
ISM-0498 | A security association lifetime of less than four hours (14400 seconds) is used for IPsec | 0 |
ISM-0499 | Communications security doctrine and policy produced by ASD for the management and operati | 0 |
ISM-0501 | Keyed cryptographic equipment is transported based on the sensitivity or classification of | 0 |
ISM-0507 | Cryptographic key management processes, and supporting cryptographic key management proced | 1 |
ISM-0516 | Network documentation includes high-level network diagrams showing all connections into ne | 2 |
ISM-0518 | Network documentation is developed, implemented and maintained. | 3 |
ISM-0520 | Network access controls are implemented on networks to prevent the connection of unauthori | 3 |
ISM-0521 | IPv6 functionality is disabled in dual-stack network devices unless it is being used. | 0 |
ISM-0529 | VLANs are not used to separate network traffic between networks belonging to different sec | 0 |
ISM-0530 | Network devices managing VLANs are administered from the most trusted security domain. | 0 |
ISM-0534 | Unused physical ports on network devices are disabled. | 0 |
ISM-0535 | Network devices managing VLANs belonging to different security domains do not share VLAN t | 0 |
ISM-0536 | Public wireless networks provided for general public use are segregated from all other org | 1 |
ISM-0546 | When video conferencing or IP telephony traffic passes through a gateway containing a fire | 0 |
ISM-0547 | Video conferencing and IP telephony calls are conducted using a secure real-time transport | 0 |
ISM-0548 | Video conferencing and IP telephony calls are established using a secure session initiatio | 0 |
ISM-0549 | Video conferencing and IP telephony traffic is separated physically or logically from othe | 0 |
ISM-0551 | IP telephony is configured such that: - IP phones authenticate themselves to the call cont | 1 |
ISM-0553 | Authentication and authorisation is used for all actions on a video conferencing network, | 0 |
ISM-0554 | An encrypted and non-replayable two-way authentication scheme is used for call authenticat | 0 |
ISM-0555 | Authentication and authorisation is used for all actions on an IP telephony network, inclu | 0 |
ISM-0556 | Workstations are not connected to video conferencing units or IP phones unless the worksta | 1 |
ISM-0558 | IP phones used in public areas do not have the ability to access data networks, voicemail | 0 |
ISM-0559 | Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET | 1 |
ISM-0565 | Email servers are configured to block, log and report emails with inappropriate protective | 2 |
ISM-0567 | Email servers only relay emails destined for or originating from their domains (including | 0 |
ISM-0569 | Emails are routed via centralised email gateways. | 0 |
ISM-0570 | Where backup or alternative email gateways are in place, they are maintained at the same s | 1 |
ISM-0571 | When users send or receive emails, an authenticated and encrypted channel is used to route | 0 |
ISM-0572 | Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing em | 0 |
ISM-0574 | SPF is used to specify authorised email servers (or lack thereof) for an organisation's do | 1 |
ISM-0576 | A cyber security incident management policy, and associated cyber security incident respon | 3 |
ISM-0580 | An event logging policy is developed, implemented and maintained. | 2 |
ISM-0582 | Security-relevant events for Microsoft Windows operating systems are centrally logged. | 1 |
ISM-0585 | For each event logged, the date and time of the event, the relevant user or process, the r | 3 |
ISM-0588 | An MFD usage policy is developed, implemented and maintained. | 0 |
ISM-0589 | MFDs are not used to scan or copy documents above the sensitivity or classification of net | 0 |
ISM-0590 | Authentication measures for MFDs are the same strength as those used for workstations on n | 0 |
ISM-0591 | Evaluated peripheral switches are used when sharing peripherals between systems. | 0 |
ISM-0597 | When planning, designing, implementing or introducing additional connectivity to CDSs, ASD | 1 |
ISM-0610 | Users are trained on the secure use of CDSs before access is granted. | 0 |
ISM-0611 | System administrators for gateways are assigned the minimum privileges required to perform | 0 |
ISM-0612 | System administrators for gateways are formally trained on the operation and management of | 2 |
ISM-0613 | System administrators for gateways that connect to Australian Eyes Only or Releasable To n | 0 |
ISM-0616 | Separation of duties is implemented in performing administrative activities for gateways. | 1 |
ISM-0619 | Users authenticate to other networks accessed via gateways. | 0 |
ISM-0622 | IT equipment authenticates to other networks accessed via gateways. | 1 |
ISM-0626 | CDSs are implemented between SECRET or TOP SECRET networks and any other networks belongin | 0 |
ISM-0628 | Gateways are implemented between networks belonging to different security domains. | 0 |
ISM-0629 | For gateways between networks belonging to different security domains, any shared componen | 1 |
ISM-0631 | Gateways only allow explicitly authorised data flows. | 2 |
ISM-0634 | Security-relevant events for gateways are centrally logged, including: - data packets and | 1 |
ISM-0635 | CDSs implement isolated upward and downward network paths. | 0 |
ISM-0637 | Gateways implement a demilitarised zone if external parties require access to an organisat | 0 |
ISM-0639 | Evaluated firewalls are used between networks belonging to different security domains. | 0 |
ISM-0643 | Evaluated diodes are used for controlling the data flow of unidirectional gateways between | 0 |
ISM-0645 | Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC | 0 |
ISM-0649 | Files imported or exported via gateways or CDSs are filtered for allowed file types. | 1 |
ISM-0651 | Files identified by content filtering checks as malicious, or that cannot be inspected, ar | 0 |
ISM-0652 | Files identified by content filtering checks as suspicious are quarantined until reviewed | 0 |
ISM-0657 | When manually importing data to systems, the data is scanned for malicious and active cont | 0 |
ISM-0659 | Files imported or exported via gateways or CDSs undergo content filtering checks. | 0 |
ISM-0660 | Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly. | 0 |
ISM-0661 | Users transferring data to and from systems are held accountable for data transfers they p | 0 |
ISM-0663 | Data transfer processes, and supporting data transfer procedures, are developed, implement | 1 |
ISM-0664 | Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustwort | 0 |
ISM-0665 | Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services t | 0 |
ISM-0669 | When manually exporting data from SECRET and TOP SECRET systems, digital signatures are va | 0 |
ISM-0670 | Security-relevant events for CDSs are centrally logged. | 0 |
ISM-0675 | Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a tru | 0 |
ISM-0677 | Files imported or exported via gateways or CDSs that have a digital signature or cryptogra | 0 |
ISM-0682 | Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices. | 0 |
ISM-0687 | Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that | 1 |
ISM-0694 | Privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET s | 0 |
ISM-0701 | Mobile device emergency sanitisation processes, and supporting mobile device emergency san | 0 |
ISM-0702 | If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SE | 1 |
ISM-0705 | When accessing an organisation's network via a VPN connection, split tunnelling is disable | 2 |
ISM-0714 | A CISO is appointed to provide cyber security leadership and guidance for their organisati | 2 |
ISM-0717 | The CISO oversees the management of cyber security personnel within their organisation. | 0 |
ISM-0718 | The CISO regularly reports directly to their organisation's board of directors or executiv | 1 |
ISM-0720 | The CISO oversees the development, implementation and maintenance of a cyber security comm | 1 |
ISM-0724 | The CISO implements cyber security measurement metrics and key performance indicators for | 1 |
ISM-0725 | The CISO coordinates cyber security and business alignment through a cyber security steeri | 1 |
ISM-0726 | The CISO coordinates security risk management activities between cyber security and busine | 1 |
ISM-0731 | The CISO oversees cyber supply chain risk management activities for their organisation. | 2 |
ISM-0732 | The CISO receives and manages a dedicated cyber security budget for their organisation. | 1 |
ISM-0733 | The CISO is fully aware of all cyber security incidents within their organisation. | 1 |
ISM-0734 | The CISO contributes to the development, implementation and maintenance of business contin | 2 |
ISM-0735 | The CISO oversees the development, implementation and maintenance of their organisation's | 2 |
ISM-0810 | Classified systems are secured in facilities that meet the requirements for a security zon | 2 |
ISM-0813 | Server rooms, communications rooms and security containers are not left in unsecured state | 1 |
ISM-0817 | Personnel are advised of what suspicious contact via online services is and how to report | 2 |
ISM-0820 | Personnel are advised to not post work information to unauthorised online services and to | 1 |
ISM-0821 | Personnel are advised of security risks associated with posting personal information to on | 1 |
ISM-0824 | Personnel are advised not to send or receive files via unauthorised online services. | 1 |
ISM-0829 | Security measures are used to detect and respond to unauthorised RF devices in SECRET and | 1 |
ISM-0831 | Media is handled in a manner suitable for its sensitivity or classification. | 1 |
ISM-0835 | Following sanitisation, TOP SECRET volatile media retains its classification if it stored | 1 |
ISM-0836 | Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety wit | 0 |
ISM-0839 | The destruction of media storing accountable material is not outsourced. | 0 |
ISM-0840 | When outsourcing the destruction of media storing non-accountable material, a National Ass | 1 |
ISM-0843 | Application control is implemented on workstations. | 4 |
ISM-0846 | All users (with the exception of local administrator accounts and break glass accounts) ca | 0 |
ISM-0853 | On a daily basis, outside of business hours and after an appropriate period of inactivity, | 0 |
ISM-0854 | AUSTEO and AGAO data can only be accessed from systems under the sole control of the Austr | 0 |
ISM-0861 | DKIM signing is enabled on emails originating from an organisation's domains (including su | 1 |
ISM-0863 | Mobile devices prevent personnel from installing non-approved applications once provisione | 1 |
ISM-0864 | Mobile devices prevent personnel from disabling or modifying security functionality once p | 0 |
ISM-0866 | Sensitive or classified data is not viewed on mobile devices in public locations unless ca | 1 |
ISM-0869 | Mobile devices encrypt their internal storage and any removable media. | 3 |
ISM-0870 | Mobile devices are carried or stored in a secured state when not being actively used. | 1 |
ISM-0871 | Mobile devices are kept under continual direct supervision when being actively used. | 1 |
ISM-0874 | Mobile devices and desktop computers access the internet via an organisation's internet ga | 1 |
ISM-0888 | Cyber security documentation is reviewed at least annually and includes a 'current as at \ | 2 |
ISM-0912 | Systems have a change and configuration management plan that includes: - the establishment | 2 |
ISM-0917 | When malicious code is detected, the following steps are taken to handle the infection: - | 2 |
ISM-0926 | Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink | 0 |
ISM-0931 | In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to | 0 |
ISM-0938 | Vendors that have demonstrated a commitment to Secure by Design and Secure by Default prin | 1 |
ISM-0947 | When transferring data manually between two systems belonging to different security domain | 0 |
ISM-0955 | Application control is implemented using cryptographic hash rules, publisher certificate r | 0 |
ISM-0958 | An organisation-approved list of domain names, or list of website categories, is implement | 2 |
ISM-0961 | Client-side active content is restricted by web content filters to an organisation-approve | 0 |
ISM-0963 | Web content filtering is implemented to filter potentially harmful web-based content. | 2 |
ISM-0971 | The OWASP Application Security Verification Standard is used in the development of web app | 1 |
ISM-0974 | Multi-factor authentication is used to authenticate unprivileged users of systems. | 4 |
ISM-0988 | An accurate and consistent time source is used for event logging. | 3 |
ISM-0994 | ECDH is used in preference to DH. | 0 |
ISM-0998 | AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with | 0 |
ISM-0999 | DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random E | 0 |
ISM-1000 | PFS is used for IPsec connections. | 0 |
ISM-1006 | Security measures are implemented to prevent unauthorised access to network management tra | 2 |
ISM-1013 | The effective range of wireless communications outside an organisation's area of control i | 1 |
ISM-1014 | Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversation | 0 |
ISM-1019 | A denial of service response plan for video conferencing and IP telephony services is deve | 0 |
ISM-1023 | The intended recipients of blocked inbound emails, and the senders of blocked outbound ema | 0 |
ISM-1024 | Notifications of undeliverable emails are only sent to senders that can be verified via SP | 0 |
ISM-1026 | DKIM signatures on incoming emails are verified. | 0 |
ISM-1027 | Email distribution list applications used by external senders is configured such that it d | 0 |
ISM-1028 | A NIDS or NIPS is deployed in gateways between an organisation's networks and other networ | 3 |
ISM-1030 | A NIDS or NIPS is located immediately inside the outermost firewall for gateways and confi | 2 |
ISM-1034 | A HIPS or EDR solution is implemented on critical servers and high-value servers. | 3 |
ISM-1036 | MFDs are located in areas where their use can be observed. | 1 |
ISM-1037 | Gateways undergo testing following configuration changes, and at regular intervals no more | 2 |
ISM-1053 | Classified servers, network devices and cryptographic equipment are secured in server room | 2 |
ISM-1055 | LAN Manager and NT LAN Manager authentication methods are disabled. | 0 |
ISM-1059 | All data stored on media is encrypted. | 2 |
ISM-1065 | The host-protected area and device configuration overlay table are reset prior to the sani | 0 |
ISM-1067 | The ATA secure erase command is used, in addition to block overwriting software, to ensure | 0 |
ISM-1071 | Each system has a designated system owner. | 2 |
ISM-1073 | An organisation's systems are not accessed or administered by a service provider unless a | 0 |
ISM-1074 | Keys or equivalent access mechanisms to server rooms, communications rooms and security co | 2 |
ISM-1076 | Televisions and computer monitors with minor burn-in or image persistence are sanitised by | 0 |
ISM-1078 | A telephone system usage policy is developed, implemented and maintained. | 0 |
ISM-1079 | ASD's approval is sought before undertaking any maintenance or repairs to high assurance I | 0 |
ISM-1080 | An ASD-Approved Cryptographic Algorithm (AACA) or high assurance cryptographic algorithm i | 1 |
ISM-1082 | A mobile device usage policy is developed, implemented and maintained. | 0 |
ISM-1083 | Personnel are advised of the sensitivity or classification permitted for voice and data co | 0 |
ISM-1084 | If unable to carry or store mobile devices in a secured state, they are physically transfe | 1 |
ISM-1085 | Mobile devices encrypt all sensitive or classified data communicated over public network i | 0 |
ISM-1088 | Personnel report the potential compromise of mobile devices, removable media or credential | 2 |
ISM-1089 | Protective marking tools do not allow users replying to or forwarding emails to select pro | 0 |
ISM-1091 | Keying material is changed when compromised or suspected of being compromised. | 1 |
ISM-1095 | Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier. | 0 |
ISM-1096 | Cables are labelled at each end with sufficient source and destination details to enable t | 1 |
ISM-1098 | SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet wit | 0 |
ISM-1100 | TOP SECRET cables are terminated in an individual TOP SECRET cabinet. | 0 |
ISM-1101 | In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or c | 0 |
ISM-1102 | Cable reticulation systems leading into cabinets are terminated as close as possible to th | 0 |
ISM-1103 | In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms | 0 |
ISM-1105 | SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables. | 0 |
ISM-1107 | Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither s | 0 |
ISM-1109 | Wall outlet box covers are clear plastic. | 0 |
ISM-1111 | Fibre-optic cables are used for cabling infrastructure instead of copper cables. | 0 |
ISM-1112 | Cables in non-TOP SECRET areas are inspectable every five metres or less. | 0 |
ISM-1114 | Cable bundles or conduits sharing a common cable reticulation system have a dividing parti | 1 |
ISM-1115 | Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit. | 0 |
ISM-1116 | A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets. | 0 |
ISM-1119 | Cables in TOP SECRET areas are fully inspectable for their entire length. | 0 |
ISM-1122 | Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET ca | 1 |
ISM-1123 | A power distribution board with a feed from an Uninterruptible Power Supply is used to pow | 2 |
ISM-1130 | In shared facilities, cables are run in an enclosed cable reticulation system. | 1 |
ISM-1133 | In shared facilities, TOP SECRET cables are not run in party walls. | 0 |
ISM-1137 | System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD f | 0 |
ISM-1139 | Only the latest version of TLS is used for TLS connections. | 0 |
ISM-1143 | Patch management processes, and supporting patch management procedures, are developed, imp | 3 |
ISM-1145 | Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices. | 0 |
ISM-1146 | Personnel are advised to maintain separate work and personal user accounts for online serv | 1 |
ISM-1151 | SPF is used to verify the authenticity of incoming emails. | 0 |
ISM-1157 | Evaluated diodes are used for controlling the data flow of unidirectional gateways between | 0 |
ISM-1158 | Evaluated diodes used for controlling the data flow of unidirectional gateways between SEC | 0 |
ISM-1160 | If using degaussers to destroy media, degaussers evaluated by the United States' National | 0 |
ISM-1163 | Systems have a continuous monitoring plan that includes: - conducting vulnerability scans | 3 |
ISM-1164 | In shared facilities, conduits or the front covers of ducts, cable trays in floors and cei | 0 |
ISM-1171 | Attempts to access websites through their IP addresses instead of their domain names are b | 0 |
ISM-1173 | Multi-factor authentication is used to authenticate privileged users of systems. | 4 |
ISM-1175 | Privileged user accounts (excluding those explicitly authorised to access online services) | 2 |
ISM-1178 | Network documentation provided to a third party, or published in public tender documentati | 0 |
ISM-1181 | Networks are segregated into multiple network zones according to the criticality of server | 2 |
ISM-1182 | Network access controls are implemented to limit the flow of network traffic within and be | 3 |
ISM-1183 | A hard fail SPF record is used when specifying authorised email servers (or lack thereof) | 0 |
ISM-1186 | IPv6 capable network security appliances are used on IPv6 and dual-stack networks. | 0 |
ISM-1187 | When manually exporting data from systems, the data is checked for unsuitable protective m | 1 |
ISM-1192 | Gateways inspect and filter data flows at the transport and above network layers. | 1 |
ISM-1195 | Mobile Device Management solutions that have completed a Common Criteria evaluation agains | 1 |
ISM-1196 | Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain | 0 |
ISM-1198 | Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is | 0 |
ISM-1199 | Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices ar | 0 |
ISM-1200 | Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is | 0 |
ISM-1203 | System owners, in consultation with each system's authorising officer, conduct a threat an | 2 |
ISM-1211 | System administrators perform system administration activities in accordance with the syst | 2 |
ISM-1213 | Following intrusion remediation activities, full network traffic is captured for at least | 2 |
ISM-1216 | SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appro | 0 |
ISM-1217 | Labels and markings indicating the owner, sensitivity, classification or any other marking | 0 |
ISM-1218 | IT equipment, including associated media, that is located overseas and has processed, stor | 0 |
ISM-1219 | MFD print drums and image transfer rollers are inspected and destroyed if there is remnant | 0 |
ISM-1220 | Printer and MFD platens are inspected and destroyed if any text or images are retained on | 0 |
ISM-1221 | Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a pa | 0 |
ISM-1222 | Televisions and computer monitors that cannot be sanitised are destroyed. | 0 |
ISM-1223 | Memory in network devices is sanitised using the following processes, in order of preferen | 1 |
ISM-1227 | Credentials set for user accounts are randomly generated. | 0 |
ISM-1228 | Cyber security events are analysed in a timely manner to identify cyber security incidents | 3 |
ISM-1233 | IKE version 2 is used for key exchange when establishing IPsec connections. | 0 |
ISM-1234 | Email content filtering is implemented to filter potentially harmful content in email bodi | 2 |
ISM-1235 | Add-ons, extensions and plug-ins for office productivity suites, web browsers, email clien | 2 |
ISM-1236 | Malicious domain names, dynamic domain names and domain names that can be registered anony | 2 |
ISM-1237 | Web content filtering is applied to outbound web traffic where appropriate. | 1 |
ISM-1238 | Threat modelling is used in support of the software development life cycle. | 3 |
ISM-1239 | Robust web application frameworks are used in the development of web applications. | 1 |
ISM-1240 | Validation and sanitisation are performed on all input received over the internet by softw | 2 |
ISM-1241 | Output encoding is performed on all output produced by web applications. | 0 |
ISM-1243 | A database register is developed, implemented, maintained and verified on a regular basis. | 2 |
ISM-1245 | All temporary installation files and logs created during server application installation p | 0 |