[E1]
Security Overview
Australian Defence Projects

Building a secure
home for Defence
tender information.

This overview describes E1's security posture for Australian Defence tender information. Control positions are current assessments for review, not audited statements. PROTECTED information is not yet formally supported. Prepared July 2026. Commercial in confidence.

What you can store

What information can be used with E1?

E1 supports the markings that commercial Defence tender packages typically carry. The boundary below sets out what may and may not be placed on the platform.

Information markingE1 position
OFFICIAL✓Supported
OFFICIAL: Sensitive✓Supported, subject to customer and project requirements
PROTECTED✓Not yet universally supported; Subject to project requirements and risk assessment
SECRET✗Not supported
TOP SECRET✗Not supported
✓Met ✓Assessment required ✗Gap
Clarification
Platform security

How E1 protects tender information

E1 applies security controls across the platform. Access to each tender remains controlled by the customer and the permissions they assign.

✓

Access stays with the customer. Access to each tender is invite-only and strictly need-to-know. Customers assign and revoke permissions themselves, and every action is captured in a full audit trail, so you always know who has seen what.

✓

Strong authentication. Every user signs in with multifactor authentication, and access is limited to trusted, managed devices rather than passwords alone.

✓

Encryption in transit and at rest. Tender documents are encrypted throughout their lifecycle using strong, current algorithms, with managed and access-restricted keys.

✓

Australian data residency. E1 stores Australian document data in AWS's Sydney region, and these documents are not sent to overseas processors. Customers should confirm any additional residency, sovereignty or personnel-access requirements in their contract.

✓

Not used in public AI. Defence tender documents are never used to train or run public AI models.

✓

Restricted, monitored administration. Administrative access is least-privilege, separated from everyday accounts and granted only when needed. The platform is continuously monitored, with security event detection and alerting.

✓

Patched and recoverable. Vulnerabilities are tracked and patched across the platform. Backups are immutable and replicated to a separate, isolated store, with recovery tested on a defined cycle.

✓

Audited and governed. Access and activity are captured in full audit trails, under an information security management system aligned with ISO/IEC 27001.

The sections that follow set these controls out in depth, including E1's strong self-assessed alignment with the ACSC Essential Eight.

Sensitivity and security expectations

How E1 maps sensitivity to security maturity

Australian Government information markings indicate the potential harm that could result if information is compromised. As sensitivity increases, the systems handling that information will generally require stronger security controls, governance and assurance.

Essential Eight maturity levels do not formally map to information classifications as shown below. However, Australian Government policies, Defence requirements and contracts commonly use Essential Eight maturity assessments as a benchmark for cyber security. This provides a useful way to understand how closely an organisation’s security posture aligns with the increasing protection expected for more sensitive information.

E8 benchmarkInformation typeSecurity expectation
Maturity Level 1OFFICIALEstablishes foundational protections against common and opportunistic attacks. It reduces the likelihood that information will be exposed through unpatched systems, weak authentication, malicious documents, unsupported applications or basic ransomware.
Maturity Level 2OFFICIAL: SensitiveStrengthens controls against adversaries that deliberately target the organisation, use convincing phishing, steal credentials or attempt to bypass common security controls. It introduces tighter administrative access, stronger application control, faster remediation and greater resistance to account and endpoint compromise.
Maturity Level 3PROTECTEDProvides stronger resistance to adaptive and persistent adversaries that change techniques when initial attacks fail. It reduces reliance on standing privileges, extends preventative controls across more systems and requires more rigorous enforcement, making it harder for an attacker to establish access, move through the environment or reach sensitive information.
i

For PROTECTED information types, Essential Eight is only one part of the broader security framework. What is actually required will be determined by the contract requirements. E1 has assessed what is generally required to support PROTECTED contract types and our assessment is outlined on pages 10-11.

Essential Eight · At a glance

Essential Eight maturity summary

E1's self-assessed status at each maturity level, strategy by strategy. This is E1's own gap analysis, not a formal or independent assessment.

E8 strategy areaML1ML2ML3
Patch applications✓✓✓
Multi-factor authentication✓✓✓
Restrict administrative privileges✓✓✓
Application control✓✓✓
Restrict Office macros✓✓✓
User application hardening✓✓✓
Patch operating systems✓✓✓
Regular backups✓✓✓
✓Met (self-assessed) ✓In progress

The honest position

E1's controls already extend significantly beyond the requirements normally associated with OFFICIAL: Sensitive information. Most of the technical foundation for Essential Eight Maturity Level 3 is in place.

The remaining work is concentrated in evidence, formalisation and several specific control refinements, rather than the absence of fundamental security capabilities.

E1 self-assessment

E1's Essential Eight Maturity Level Analysis

E1 already meets or substantially meets most Maturity Level 2 and 3 requirements. The assessment below indicates the status of E1's self-assessed status for every requirement of Essential Eight across all maturity levels.

This is E1's own gap analysis

E1 is not yet formally certified or independently assessed against the Essential Eight. The positions shown are E1's own self-assessment, and will be confirmed by evidence and, where required, independent assessment.

1

Patch applications

ML1ML2ML3
  • ✓Formal, documented patch management processML1
  • ✓Applications continuously scanned for vulnerabilitiesML1
  • ✓Critical internet-facing vulnerabilities patched within 48 hoursML1
  • ✓Unsupported applications removedML1
  • ✓All applications patched within one month of releaseML2
  • ✓All applications scanned fortnightly or betterML2
  • ✓Critical patches for endpoints and common apps within 48 hoursML3
  • ✓Firmware kept current across devices and network equipmentML3
2

Multi-factor authentication

ML1ML2ML3
  • ✓MFA enforced for users of internet-facing services with sensitive dataML1
  • ✓MFA required for all users, across services and devicesML2
  • ✓Successful and unsuccessful authentication events centrally loggedML2
  • ✓Access requires a verified, approved device, defeating credential-only phishingML2
  • ✓MFA required for access to sensitive data repositoriesML3
  • ✓Authentication logs analysed across services and devicesML3
✓Met✓In progress✗Gap Self-assessed level completion · strategies 3 to 4 on page 7
Essential Eight · E1 gap analysis (continued)

Privilege and application control

3

Restrict administrative privileges

ML1ML2ML3
  • ✓Separate privileged and unprivileged accounts for administratorsML1
  • ✓Privileged accounts blocked from internet, email and web servicesML1
  • ✓Privileged access validated when first requestedML1
  • ✓Privileged access revalidated at least annuallyML2
  • ✓Privileged access events centrally loggedML2
  • ✓Privileged access automatically disabled after a period of inactivityML2
  • ✓Just-in-Time administration used to grant access only when neededML3
  • ✓Administrative tasks restricted to managed, controlled devicesML3
  • ✓Credentials protected against theft and reuseML3
4

Application control

ML1ML2ML3
  • ✓Execution control enforced on every deviceML1
  • ✓Application control enforced on internet-facing serversML2
  • ✓Allowed and blocked execution events centrally loggedML2
  • ✓Known-malicious applications blockedML2
  • ✓Execution ruleset reviewed at least annuallyML2
  • ✓Application control extended across all servers, including internalML3
  • ✓Execution of vulnerable drivers and kernel components blockedML3
✓Met✓In progress✗Gap Strategies 5 to 6 on page 8
Essential Eight · E1 gap analysis (continued)

Macros and application hardening

5

Restrict Office macros

ML1ML2ML3
  • ✓Macros from untrusted sources blockedML1
  • ✓Users cannot change macro security settingsML1
  • ✓Macro and file behaviour scanned before executionML1
  • ✓Macro calls to high-risk system interfaces blockedML2
  • ✓Macros only run from a trusted, controlled contextML3
6

User application hardening

ML1ML2ML3
  • ✓Web browsers block advertisements from the internetML1
  • ✓Web browsers block Java from the internetML1
  • ✓Endpoint command-line activity centrally loggedML2
  • ✓Legacy and unneeded browser components removedML2
  • ✓Productivity applications blocked from spawning malicious processesML2
  • ✓Legacy and high-risk scripting components removed or restrictedML3
✓Met✓In progress✗Gap Strategies 7 to 8 on page 9
Essential Eight · E1 gap analysis (continued)

Operating systems and backups

7

Patch operating systems

ML1ML2ML3
  • ✓Operating systems on all devices scanned for vulnerabilities continuouslyML1
  • ✓Critical operating-system vulnerabilities patched promptlyML1
  • ✓Only vendor-supported operating systems in useML1
  • ✓Server operating systems patched within one monthML2
  • ✓Fortnightly-or-better operating-system vulnerability scanningML2
  • ✓Critical operating-system patches within 48 hoursML3
  • ✓Firmware kept current across devices and network equipmentML3
8

Regular backups

ML1ML2ML3
  • ✓Regular backups of important data, software and configurationML1
  • ✓Backups retained in line with business continuity requirementsML1
  • ✓Restoration of backups tested on a defined cycleML1
  • ✓Unprivileged accounts cannot access, modify or delete backupsML1
  • ✓Privileged accounts, including administrators, cannot modify or delete backupsML2
  • ✓Backups immutable during the retention period, replicated to a separate storeML3
✓Met✓In progress✗Gap Consolidated summary on page 10
Formal PROTECTED support

What remains for formal PROTECTED support

Reaching and evidencing Essential Eight Maturity Level 3 is an important part of supporting PROTECTED information, but it is not the only requirement. E1 must also determine and implement the applicable ISM controls, prepare the required security documentation and complete an independent IRAP assessment.

✓

Already in place

  • ✓A strong platform foundation: onshore hosting, encryption, tight access control and monitoring
  • ✓Essential Eight controls operating and reaching into Maturity Level 3
  • ✓System architecture and data-flow documentation prepared
»

Remaining before formal PROTECTED support

  • Achieve DISP membership.
  • Reach and formally evidence Essential Eight Maturity Level 3
  • Logical separation of PROTECTED information from lower-sensitivity systems and data
  • Network segmentation and controlled gateways between security domains
  • Encryption using ASD Approved Cryptographic Algorithms and Protocols
  • Broader ISM controls across system administration, monitoring, secure development, data transfers, media handling and backups
  • Formal system authorisation: a documented security assessment with an authorising officer accepting the residual risk
  • An independent IRAP assessment at the PROTECTED classification (Stage 1 and Stage 2)
  • Australian hosting and control, addressing foreign ownership, legal control and personnel access
  • Security-cleared personnel for anyone with access, including cloud administrators and support staff
  • Need-to-know access with least privilege and controlled privileged access
  • AI use confined to an appropriately authorised environment
  • Approved handling and transfer processes that retain protective markings
  • Physical security appropriate to PROTECTED, including remote-work controls
  • Incident reporting through Defence and contractual security channels
  • Defence-specific obligations where imposed by contract (DISP membership, DSPF controls, nationality restrictions, security officers)
i

Informing a risk assessment. E1 has not completed an independent IRAP assessment. Customers should review their own requirements and use this document to inform a risk assessment before uploading PROTECTED information. E1 is close on the Essential Eight and has much of the underlying platform capability; formal PROTECTED support would still involve independent assessment.

ISM · Provisional self-assessment

ISM control alignment at a glance

A high-level view of E1's provisional alignment with the 22 guidelines of the ASD Information Security Manual (June 2026). Of 1101 controls, 989 are in scope for E1; the other 112 are not required (they apply only at SECRET or above, outside E1's cloud-SaaS scope). Across the in-scope set, E1 provisionally meets 737 (71 of these delivered by its cloud provider). Each row shows the position for one guideline; the control-by-control breakdown follows. These are internal estimates for review, not audited positions.

GuidelinePositionRequired controls met
Guidelines for cyber security roles✓
28/40 · 2 n/a
Guidelines for cyber security incidents✓
21/21
Guidelines for procurement and outsourcing✓
33/35 · 3 n/a
Guidelines for cyber security documentation✓
6/11 · 1 inherited
Guidelines for physical security✓
10/11 · 8 n/a
Guidelines for personnel security✓
35/49 · 1 inherited · 8 n/a
Guidelines for communications infrastructure✓
27/27 · 27 inherited · 26 n/a
Guidelines for communications systems✓
9/32 · 1 n/a
Guidelines for enterprise mobility✓
38/45 · 2 inherited · 6 n/a
Guidelines for evaluated products✓
1/3 · 1 inherited · 2 n/a
Guidelines for information technology equipment✓
23/29 · 2 inherited · 6 n/a
Guidelines for media✓
48/49 · 37 inherited · 7 n/a
Guidelines for system hardening✓
195/216 · 5 n/a
Guidelines for system management✓
43/56 · 1 n/a
Guidelines for security assurance✓
31/35
Guidelines for software development✓
65/108
Guidelines for database systems✓
13/13
Guidelines for email✓
15/25 · 1 n/a
Guidelines for networking✓
52/70 · 1 n/a
Guidelines for cryptography✓
26/59 · 13 n/a
Guidelines for gateways✓
17/47 · 16 n/a
Guidelines for data transfers✓
1/8 · 6 n/a
✓Met✓Provider-inherited (AWS)✓In progress✗Gap (needed for PROTECTED)–Not required
i

How to read this. Positions are E1's own provisional estimates, grounded in its ISMS policy set and Essential Eight self-assessment. Provider-inherited controls (physical cabling, emanation, facilities and drive destruction) are delivered by E1's cloud provider and count as met. Not required controls apply only at SECRET or TOP SECRET, above E1's cloud-SaaS scope, and are excluded from the totals. Gaps are in-scope items, including those needing clearances, IRAP or cross-domain gateways for PROTECTED. Confirm any specific control before relying on it.

ISM · Detailed control breakdown

ISM controls, guideline by guideline

Every ISM control with E1's provisional self-assessed position. Grouped by guideline, section and topic. Use the summary on the previous page for the high-level picture.

Guidelines for cyber security roles

28/40 met
Board of directors and executive committee
Embedding cyber security
  • ✓The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.ISM-1997
    • Document board-level cyber roles and responsibilities in a governance charter
    • Assign a named board member as accountable cyber security owner
  • ✓The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.ISM-1998
  • ✓The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.ISM-1999
    • Map cyber security strategy to business strategy in a board-approved document
    • Review alignment at least annually at board level, retain minutes
  • ✓The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.ISM-2000
Championing a positive cyber security culture
  • ✓The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.ISM-2001
    • Add a standing cyber security item to board meeting agendas
    • Have executives visibly complete the same security training as staff
Building cyber security expertise
  • ✓The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.ISM-2002
    • Schedule annual cyber literacy briefings for board members
    • Retain records of board cyber training completion
  • ✓The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.ISM-2003
    • Report cyber hiring, retention and skills-gap metrics to the board quarterly
  • ✓The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.ISM-2004
Identifying critical business assets
  • ✓The board of directors or executive committee understands the business criticality of their organisation’s systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.ISM-2005
    • Brief board on system register, data value, access and protections
    • Maintain criticality ratings for key systems, reviewed annually
Planning for major cyber security incidents
  • ✓The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.ISM-2006
    • Run an annual board-level incident tabletop exercise, retain records
    • Document board members' incident duties and notification obligations
Chief information security officer
Providing cyber security leadership and guidance
  • ✓A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).ISM-0714
Overseeing the cyber security program
  • ✓The CISO oversees their organisation’s cyber security program and ensures their organisation’s compliance with cyber security policy, standards, regulations and legislation.ISM-1478
  • ✓The CISO regularly reviews and updates their organisation’s cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.ISM-1617
  • ✓The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.ISM-1966
    • Build an authoritative system register from AWS Config and resource tags
    • Assign owners and review register quarterly, retain sign-off
  • ✓The CISO implements cyber security measurement metrics and key performance indicators for their organisation.ISM-0724
Coordinating cyber security
  • ✓The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.ISM-0725
    • Establish a cyber security steering committee with business and security execs
    • Hold quarterly meetings, retain agendas and minutes as evidence
  • ✓The CISO coordinates security risk management activities between cyber security and business teams.ISM-0726
Reporting on cyber security
  • ✓The CISO regularly reports directly to their organisation’s board of directors or executive committee on cyber security matters.ISM-0718
  • ✓The CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters.ISM-1918
Overseeing cyber security incident response activities
  • ✓The CISO is fully aware of all cyber security incidents within their organisation.ISM-0733
  • ✓The CISO oversees their organisation’s response to cyber security incidents.ISM-1618
Contributing to business continuity and disaster recovery planning
  • ✓The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.ISM-0734
Communicating a cyber security vision and strategy
  • ✓The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.ISM-0720
Working with suppliers
  • ✓The CISO oversees cyber supply chain risk management activities for their organisation.ISM-0731
Receiving and managing a dedicated cyber security budget
  • ✓The CISO receives and manages a dedicated cyber security budget for their organisation.ISM-0732
Overseeing cyber security personnel
  • ✓The CISO oversees the management of cyber security personnel within their organisation.ISM-0717
  • ✓The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.ISM-2020
Overseeing cyber security awareness training
  • ✓The CISO oversees the development, implementation and maintenance of their organisation’s cyber security awareness training program.ISM-0735
System owners
System ownership and oversight
  • ✓Each system has a designated system owner.ISM-1071
  • ✓System owners register each system with its authorising officer.ISM-1525
Protecting systems and their resources
  • ✓System owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.ISM-1633
  • ✓System owners, in consultation with each system’s authorising officer, conduct a threat and risk assessment for each system.ISM-1203
  • ✓System owners, in consultation with each system’s authorising officer, select controls for each system and tailor them to achieve desired security and resilience objectives.ISM-1634
    • Document per-system control selection and tailoring against the ISM baseline
    • Record authorising officer consultation and sign-off
  • ✓System owners, in consultation with each system’s authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation’s risk tolerances.ISM-0009
  • ✓System owners implement controls for each system and its operating environment.ISM-1635
  • ✗System owners, in consultation with each system’s authorising officer, ensure controls for each non- classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation’s own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.ISM-1636
  • –System owners, in consultation with each system’s authorising officer, ensure controls for each TOP SECRET system and its operating environment, including each sensitive compartmented information system and its operating environment, undergo a security assessment by ASD assessors (or their delegates) to determine if they have been implemented correctly and are operating as intended.ISM-1967
  • ✓System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.ISM-0027
    • Define an authorisation-to-operate process with a named authorising officer
    • Issue and retain a signed ATO for each in-scope system
  • –System owners obtain an authorisation to operate for each TOP SECRET system, including for each sensitive compartmented information system, from Director-General ASD (or their delegate).ISM-1968
  • ✓System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.ISM-1526
  • ✓System owners implement and maintain data minimisation practices for each of their systems.ISM-2021
Annual reporting of system security status
  • ✓System owners report the security status of each system to its authorising officer at least annually.ISM-1587

Guidelines for cyber security incidents

21/21 met
Managing cyber security incidents
Cyber security incident management policy
  • ✓A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.ISM-0576
  • ✓The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.ISM-1784
Cyber security incident register
  • ✓A cyber security incident register is developed, implemented and maintained.ISM-0125
  • ✓A cyber security incident register contains the following for each cyber security incident: the date the cyber security incident occurred; the date the cyber security incident was discovered; a description of the cyber security incident; any actions taken in response to the cyber security incident; to whom the cyber security incident was reported.ISM-1803
Insider threat mitigation program
  • ✓An insider threat mitigation program is developed, implemented and maintained.ISM-1625
  • ✓Legal advice is sought regarding the development and implementation of an insider threat mitigation program.ISM-1626
Reporting cyber security incidents
  • ✓Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.ISM-0123
Reporting cyber security incidents to ASD
  • ✓Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.ISM-0140
Reporting cyber security incidents to customers and the public
  • ✓Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.ISM-1880
  • ✓Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.ISM-1881
Responding to cyber security incidents
Enacting cyber security incident response plans
  • ✓Following the identification of a cyber security incident, the cyber security incident response plan is enacted.ISM-1819
Handling and containing data spills
  • ✓When a data spill occurs, data owners are advised and access to the data is restricted.ISM-0133
Handling and containing malicious code infections
  • ✓When malicious code is detected, the following steps are taken to handle the infection: the infected systems are isolated; all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary antivirus applications are used to remove the infection from infected systems and media; if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.ISM-0917
  • ✓Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.ISM-1969
  • ✓Malicious code processing for cyber security incident response or research purposes is conducted in a dedicated analysis environment segregated from other systems.ISM-1970
Handling and containing intrusions
  • ✓Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.ISM-0137
  • ✓System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.ISM-1609
  • ✓Planning and coordination of intrusion remediation activities are conducted on a separate system to that which has been compromised.ISM-1731
  • ✓To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.ISM-1732
  • ✓Following intrusion remediation activities, full network traffic is captured for at least seven days and analysed to determine whether malicious actors have been successfully removed from the system.ISM-1213
Maintaining the integrity of evidence
  • ✓The integrity of evidence gathered during an investigation is maintained by investigators: recording all their actions; maintaining a proper chain of custody; following all instructions provided by relevant law enforcement agencies.ISM-0138

Guidelines for procurement and outsourcing

33/35 met
Cyber supply chain risk management
Cyber supply chain risk management activities
  • ✓Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.ISM-1631
  • ✓A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system’s security risk profile.ISM-1452
  • ✓Suppliers identified as high risk by a cyber supply chain risk assessment are not used.ISM-1567
  • ✓Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.ISM-1568
  • ✓Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.ISM-1882
  • ✓Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.ISM-1632
  • ✓A shared responsibility model is created, documented and shared between suppliers and their customers to articulate the security responsibilities of each party.ISM-1569
Supplier relationship management
  • ✓A supplier relationship management policy is developed, implemented and maintained.ISM-1785
  • ✓An approved supplier list is developed, implemented and maintained.ISM-1786
Sourcing operating systems, applications, IT equipment, OT equipment and services
  • ✓Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.ISM-1787
  • ✓Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.ISM-1788
  • ✓Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.ISM-1789
Delivery of operating systems, applications, IT equipment, OT equipment and services
  • ✓Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.ISM-1790
  • ✓The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.ISM-1791
  • ✓The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.ISM-1792
Managed services and cloud services
Managed services
  • ✓A managed service register is developed, implemented, maintained and regularly verified.ISM-1736
  • ✓A managed service register contains the following for each managed service: managed service provider’s name; managed service’s name; purpose for using the managed service; sensitivity or classification of data involved; due date for the next security assessment of the managed service; contractual arrangements for the managed service; point of contact for users of the managed service; 24/7 contact details for the managed service provider.ISM-1737
Assessment of managed service providers
  • ✗Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.ISM-1793
  • –Managed service providers and their TOP SECRET managed services, including sensitive compartmented information managed services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.ISM-1971
Outsourced cloud services
  • ✓An outsourced cloud service register is developed, implemented, maintained and regularly verified.ISM-1637
  • ✓An outsourced cloud service register contains the following for each outsourced cloud service: cloud service provider’s name; cloud service’s name; purpose for using the cloud service; sensitivity or classification of data involved; due date for the next security assessment of the cloud service; contractual arrangements for the cloud service; point of contact for users of the cloud service; 24/7 contact details for the cloud service provider.ISM-1638
  • –Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud services.ISM-1529
Assessment of outsourced cloud service providers
  • ✗Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.ISM-1570
  • –Outsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.ISM-1972
Contractual security requirements with service providers
  • ✓Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.ISM-1395
  • ✓Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.ISM-0072
  • ✓The right to verify compliance with security requirements is documented in contractual arrangements with service providers.ISM-1571
  • ✓The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.ISM-1738
  • ✓Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.ISM-1804
  • ✓The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.ISM-0141
  • ✓A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.ISM-1794
  • ✓Types of data and its ownership is documented in contractual arrangements with service providers.ISM-1451
  • ✓The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.ISM-1572
  • ✓Access to all logs relating to an organisation’s data and services is documented in contractual arrangements with service providers.ISM-1573
  • ✓The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.ISM-1574
  • ✓A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.ISM-1575
Access to systems by service providers
  • ✓An organisation’s systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.ISM-1073
  • ✓If an organisation’s systems are accessed or administered by a service provider in an unauthorised manner, the organisation is immediately notified.ISM-1576

Guidelines for cyber security documentation

6/11 met
Development and maintenance of cyber security documentation
Cyber security strategy
  • ✓A cyber security strategy is developed, implemented and maintained.ISM-0039
Approval of cyber security documentation
  • ✓Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system’s authorising officer.ISM-0047
    • Record CISO approval on org docs, authorising officer on system docs
    • Track document approvals and review dates in the ISMS register
  • ✓A system’s security architecture is approved prior to the development of the system.ISM-1739
Maintenance of cyber security documentation
  • ✓Cyber security documentation is reviewed at least annually and includes a ‘current as at [date]’ or equivalent statement.ISM-0888
Communication of cyber security documentation
  • ✓Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.ISM-1602
System-specific cyber security documentation
System security plan
  • ✓Systems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is managed) as well as an annex that covers applicable controls from this document and any additional controls that have been identified and implemented.ISM-0041
Cyber security incident response plan
  • ✓Systems have a cyber security incident response plan that covers the following: guidelines on what constitutes a cyber security incident; the types of cyber security incidents likely to be encountered and the expected response to each type; how to report cyber security incidents, internally to an organisation and externally to relevant authorities other parties that need to be informed in the event of a cyber security incident; the authority, or authorities, responsible for investigating and responding to cyber security incidents; the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority the steps necessary to ensure the integrity of evidence relating to a cyber security incident; system contingency measures or a reference to such details if they are in a separate document.ISM-0043
    • Expand IR plan with incident types, expected response and evidence-integrity steps
    • Add external reporting criteria for ASD and law enforcement
    • Reference contingency measures and responsible investigating authorities
Change and configuration management plan
  • ✓Systems have a change and configuration management plan that includes: the establishment and maintenance of authorised baseline configurations for systems; what constitutes routine and urgent changes to the configuration of systems; how changes to the configuration of systems will be requested, tracked and documented; who needs to be consulted prior to routine and urgent changes to the configuration of systems; who needs to approve routine and urgent changes to the configuration of systems; who needs to be notified of routine and urgent changes to the configuration of systems; what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.ISM-0912
    • Document baseline configurations and routine vs urgent change criteria
    • Define change request, approval, notification and tracking workflow
    • Link plan to IaC pipeline and AWS Config baseline drift detection
Continuous monitoring plan
  • ✓Systems have a continuous monitoring plan that includes: conducting security assessment activities to identify vulnerabilities; analysing identified vulnerabilities to determine their potential impact; implementing mitigations based on risk, effectiveness and cost.ISM-1163
Security assessment report
  • ✓At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: the scope of the security assessment; the system’s strengths and weaknesses; security risks associated with the operation of the system; the effectiveness of the implementation of controls; any recommended remediation actions.ISM-1563
    • Engage assessor to produce report covering scope, weaknesses, risks and controls
    • Include recommended remediation actions in the assessment report
Plan of action and milestones
  • ✓At the conclusion of a security assessment for a system, a plan of action and milestones is produced by the system owner.ISM-1564
    • Produce a plan of action and milestones from assessment findings
    • Assign owners and due dates, track POA&M to closure

Guidelines for physical security

10/11 met
Facilities and systems
Physical access to systems
  • ✓Non-classified systems are secured in suitably secure facilities.ISM-1973
  • ✓Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.ISM-0810
Physical access to servers, network devices and cryptographic equipment
  • ✓Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.ISM-1974
  • ✓Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.ISM-1053
  • ✓Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.ISM-1975
  • ✓Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.ISM-1530
  • ✓Server rooms, communications rooms and security containers are not left in unsecured states.ISM-0813
  • ✓Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.ISM-1074
Physical access to network devices in public areas
  • ✓Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.ISM-1296
Bringing radio frequency and infrared devices into facilities
  • –An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.ISM-1543
  • –Unauthorised RF and IR devices are not brought into SECRET and TOP SECRET areas.ISM-0225
  • –Security measures are used to detect and respond to unauthorised RF devices in SECRET and TOP SECRET areas.ISM-0829
Bringing photographic and video recording devices into facilities
  • –An authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.ISM-2069
  • –Unauthorised photographic and video recording devices are not brought into SECRET and TOP SECRET areas.ISM-2070
Bringing medical devices into facilities
  • –An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.ISM-2007
  • –Medical devices authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: are listed on the Australian Register of Therapeutic Goods; have been prescribed by a legally qualified medical practitioner; have been commercially purchased within Australia; do not have inbuilt cellular connectivity; can operate independently of mobile devices; where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas.ISM-2008
  • –Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.ISM-2009
Preventing observation by unauthorised people
  • ✓Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.ISM-0164
    • Enforce clean-desk and automatic screen-lock policy for staff workstations
    • Provide privacy screens for staff working in public spaces
IT equipment and media
Securing IT equipment and media
  • ✓IT equipment and media are secured when not in use.ISM-0161

Guidelines for personnel security

35/49 met
Cyber security awareness training
Providing cyber security awareness training
  • ✓Cyber security awareness training is undertaken annually by all personnel and covers: the purpose of the cyber security awareness training; security appointments and contacts; authorised use of systems and their resources; protection of systems and their resources; reporting of cyber security incidents and suspected compromises of systems and their resources.ISM-0252
  • ✓Tailored privileged user training is undertaken annually by all privileged users.ISM-1565
  • ✓A cyber security awareness training register is developed, implemented and maintained.ISM-2022
Managing and reporting suspicious changes to banking details or payment requests
  • ✓Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.ISM-1740
Managing and reporting suspicious requests to disclose or change user account details
  • ✓Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.ISM-2071
    • Add a social-engineering module to security awareness training
    • Publish a process to report suspicious account-change requests
Reporting suspicious contact via online services
  • ✓Personnel are advised of what suspicious contact via online services is and how to report it.ISM-0817
Posting work-related information on online services
  • ✓Personnel are advised not to post work-related information on unauthorised online services, and to report cases where such information is posted.ISM-0820
    • Add policy clause prohibiting posting work info on unauthorised services
    • Brief staff on how to report exposed work information
  • ✗Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted.ISM-2104
  • ✓Personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such information is posted.ISM-2105
  • ✓Personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases where such information is posted.ISM-2106
    • Advise staff to limit posting work skills and experience online
    • Include guidance in onboarding and annual awareness training
Posting personal information on online services
  • ✓Personnel are advised of security risks associated with posting personal information on online services.ISM-0821
  • ✓Personnel are advised to maintain separate personal user accounts from any work user accounts they use for online services.ISM-1146
  • ✓Personnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.ISM-2107
Sending and receiving files via online services
  • ✓Personnel are advised not to send or receive files via unauthorised online services.ISM-0824
Access to systems and their resources
System usage policy
  • ✓A system usage policy is developed, implemented and maintained.ISM-1864
General-purpose artificial intelligence usage policy
  • ✓A general-purpose AI usage policy is developed, implemented and maintained.ISM-2074
    • Develop and publish a general-purpose AI usage policy
    • Define approved tools and prohibited data types for AI use
Web usage policy
  • ✓A web usage policy is developed, implemented and maintained.ISM-0258
System access requirements
  • ✓Access requirements for systems and their resources are documented in their system security plan.ISM-0432
  • ✗Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.ISM-0434
  • ✓Personnel receive any necessary briefings before being granted access to systems and their resources.ISM-0435
  • ✓Personnel agree to abide by system usage policies before being granted access to systems and their resources.ISM-1865
User identification
  • ✓Personnel granted access to systems and their resources are uniquely identifiable.ISM-0414
    • Enforce individual named accounts via IAM Identity Center / SSO
    • Eliminate anonymous or generic logins across systems
  • ✓The use of shared user accounts is strictly controlled, and personnel using such accounts are uniquely identifiable.ISM-0415
    • Inventory and eliminate shared accounts where technically possible
    • For unavoidable shared accounts, attribute use individually via a PAM vault
  • ✓Personnel who are contractors are identified as such.ISM-1583
  • –Where systems process, store or communicate AUSTEO, AGAO or REL data, personnel who are foreign nationals are identified as such, including by their specific nationality.ISM-0420
Unprivileged access to systems
  • ✓Requests for unprivileged access to systems and their resources are validated when first requested.ISM-0405
  • ✓Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.ISM-1852
  • ✓Use of unprivileged access is centrally logged.ISM-1566
Unprivileged access to systems by foreign nationals
  • –Foreign nationals, including seconded foreign nationals, do not have access to systems that process, store or communicate AUSTEO or REL data unless effective controls are in place to ensure such data is not accessible to them.ISM-0409
  • –Foreign nationals, excluding seconded foreign nationals, do not have access to systems that process, store or communicate AGAO data unless effective controls are in place to ensure such data is not accessible to them.ISM-0411
Privileged access to systems
  • ✓Requests for privileged access to systems and their resources are validated when first requested.ISM-1507
  • ✓Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.ISM-1508
    • Right-size IAM policies using Access Analyzer least-privilege findings
    • Apply permission boundaries and remove unused privileged entitlements
  • ✓Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.ISM-1175
  • ✓Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.ISM-1883
  • ✓Just-in-time administration is used for the administration of systems and their resources.ISM-1649
    • Implement just-in-time elevation via IAM Identity Center temporary access
    • Require an approval workflow for time-bound privileged sessions
  • ✓Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.ISM-0445
  • ✓Unique privileged user accounts are used for administering individual server applications.ISM-1263
  • ✓Privileged access events are centrally logged.ISM-1509
  • ✓Privileged user account and security group management events are centrally logged.ISM-1650
Privileged access to systems by foreign nationals
  • –Foreign nationals, including seconded foreign nationals, do not have privileged access to systems that process, store or communicate AUSTEO or REL data.ISM-0446
  • –Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.ISM-0447
Suspension of access to systems
  • ✓Access to systems and their resources are removed or suspended the same day personnel no longer have a legitimate requirement for access.ISM-0430
  • ✓Access to systems and their resources are removed or suspended as soon as practicable when personnel are detected undertaking malicious activities.ISM-1591
  • ✓Unprivileged access to systems and their resources are disabled after 45 days of inactivity.ISM-1404
  • ✓Privileged access to systems and their resources are disabled after 45 days of inactivity.ISM-1648
  • ✓Privileged access to systems and their resources are disabled after 12 months unless revalidated.ISM-1647
Recording authorisation for personnel to access systems
  • ✓A secure record is maintained for the life of systems and their resources that covers the following for each user: their user identification; their signed agreement to abide by system usage policies; who authorised their access; when their access was granted; the level of access they were granted; when their access, and their level of access, was last reviewed; when their level of access was changed, and to what extent (if applicable); when their access was withdrawn (if applicable).ISM-0407
Temporary access to systems
  • ✓When personnel are granted temporary access to systems and their resources, effective controls are put in place to restrict their access to only data required for them to undertake their duties.ISM-0441
  • –Temporary access is not granted to systems that process, store or communicate caveated or sensitive compartmented information.ISM-0443
Emergency access to systems
  • ✓A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.ISM-1610
    • Document the emergency access and break-glass procedure
    • Test emergency access on implementation and after major infra changes
  • ✓Break glass accounts are only used when normal authentication processes cannot be used.ISM-1611
  • ✓Break glass accounts are only used for specific authorised activities.ISM-1612
    • Restrict break-glass accounts to defined authorised activities only
    • Alert on any break-glass use via CloudTrail and GuardDuty
  • ✓Break glass account credentials are changed by the account custodian after they are accessed by any other party.ISM-1614
    • Rotate break-glass credentials after each use via Secrets Manager
    • Assign a custodian responsible for credential reset and logging
  • ✗Break glass accounts are tested after credentials are changed.ISM-1615
  • ✓Use of break glass accounts is centrally logged.ISM-1613
Control of Australian systems
  • –Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under the control of an Australian national working for or on behalf of the Australian Government.ISM-0078
  • –AUSTEO and AGAO data can only be accessed from systems under the sole control of the Australian Government that are located within facilities authorised by the Australian Government.ISM-0854

Guidelines for communications infrastructure

27/27 met
Cabling infrastructure
Cabling infrastructure standards
  • ✓Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.ISM-0181
Use of fibre-optic cables
  • ✓Fibre-optic cables are used for cabling infrastructure instead of copper cables.ISM-1111
Cable register
  • ✓A cable register is developed, implemented, maintained and regularly verified.ISM-0211
  • ✓A cable register contains the following for each cable: cable identifier; cable colour; sensitivity/classification; source; destination; location; seal numbers (if applicable).ISM-0208
Floor plan diagrams
  • ✓Floor plan diagrams are developed, implemented, maintained and regularly verified.ISM-1645
  • ✓Floor plan diagrams contain the following: cable paths (including ingress and egress points between floors); cable reticulation system and conduit paths; floor concentration boxes; wall outlet boxes; network cabinets.ISM-1646
Cable labelling processes and procedures
  • ✓Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.ISM-0206
Labelling cables
  • ✓Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.ISM-1096
Labelling building management cables
  • ✓Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.ISM-1639
Labelling cables for foreign systems in Australian facilities
  • ✓Cables for foreign systems installed in Australian facilities are labelled at inspection points.ISM-1640
Cable colours
  • ✓Cables for individual systems use a consistent colour.ISM-1820
  • ✓Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.ISM-0926
  • –SECRET cables are coloured salmon pink.ISM-1718
  • –TOP SECRET cables are coloured red.ISM-1719
Cable colour non-conformance
  • –SECRET and TOP SECRET cables with non-conformant cable colouring are banded with the appropriate colour and labelled at inspection points.ISM-1216
Cable inspectability
  • ✓Cables in non-TOP SECRET areas are inspectable every five metres or less.ISM-1112
  • ✓Cables in TOP SECRET areas are fully inspectable for their entire length.ISM-1119
Common cable bundles and conduits
  • –SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.ISM-0187
  • –TOP SECRET cables, when bundled together or run in conduit, are run exclusively in their own individual cable bundle or conduit.ISM-1821
Common cable reticulation systems
  • ✓Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.ISM-1114
Enclosed cable reticulation systems
  • ✓In shared facilities, cables are run in an enclosed cable reticulation system.ISM-1130
Covers for enclosed cable reticulation systems
  • ✓In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.ISM-1164
Sealing cable reticulation systems and conduits
  • –In shared facilities, uniquely identifiable SCEC-approved tamper-evident seals are used to seal all removable covers on TOP SECRET cable reticulation systems.ISM-0195
  • –In shared facilities, a visible smear of conduit glue is used to seal all plastic conduit joints and TOP SECRET conduits connected by threaded lock nuts.ISM-0194
Labelling conduits
  • –Labels for TOP SECRET conduits are a minimum size of 2.5 cm x 1 cm, attached at five-metre intervals and marked as ‘TS RUN’.ISM-0201
Cables in walls
  • ✓Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.ISM-1115
Cables in party walls
  • –In shared facilities, TOP SECRET cables are not run in party walls.ISM-1133
Wall penetrations
  • –Where wall penetrations exit a TOP SECRET area into a lower classified area, TOP SECRET cables are encased in conduit with all gaps between the TOP SECRET conduit and the wall filled with an appropriate sealing compound.ISM-1122
Wall outlet boxes
  • –SECRET and TOP SECRET wall outlet boxes contain exclusively SECRET or TOP SECRET cables.ISM-1105
Labelling wall outlet boxes
  • ✓Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.ISM-1095
Wall outlet box colours
  • ✓Wall outlet boxes for individual systems use a consistent colour.ISM-1822
  • ✓Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.ISM-1107
  • –SECRET wall outlet boxes are coloured salmon pink.ISM-1720
  • –TOP SECRET wall outlet boxes are coloured red.ISM-1721
Wall outlet box covers
  • ✓Wall outlet box covers are clear plastic.ISM-1109
Fly lead installation
  • –If TOP SECRET fibre-optic fly leads exceeding five metres in length are used to connect wall outlet boxes to IT equipment, they are run in a protective and easily inspected pathway that is clearly labelled at the IT equipment end with the wall outlet box’s identifier.ISM-0218
Connecting cable reticulation systems to cabinets
  • ✓Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.ISM-1102
  • ✓In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.ISM-1101
  • ✓In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.ISM-1103
Terminating cables in cabinets
  • –SECRET cables are terminated in an individual cabinet; or for small systems, a cabinet with a division plate between any SECRET cables and non-SECRET cables.ISM-1098
  • –TOP SECRET cables are terminated in an individual TOP SECRET cabinet.ISM-1100
Terminating cables on patch panels
  • –SECRET and TOP SECRET cables are terminated on their own individual patch panels.ISM-0213
Physical separation of cabinets and patch panels
  • –TOP SECRET patch panels are installed in individual TOP SECRET cabinets.ISM-0216
  • –Where spatial constraints demand non-TOP SECRET patch panels be installed in the same cabinet as a TOP SECRET patch panel: a physical barrier in the cabinet is provided to separate patch panels; only personnel holding a Positive Vetting security clearance have access to the cabinet; approval from the TOP SECRET system’s authorising officer is obtained prior to installation.ISM-0217
  • –A visible gap exists between TOP SECRET cabinets and non-TOP SECRET cabinets.ISM-1116
Audio secure rooms
  • –When penetrating a TOP SECRET audio secure room, the Australian Security Intelligence Organisation is consulted and all directions provided are complied with.ISM-0198
Power reticulation
  • –A power distribution board with a feed from an Uninterruptible Power Supply is used to power all TOP SECRET IT equipment.ISM-1123
Emanation security
Electromagnetic interference/electromagnetic compatibility standards
  • ✓IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.ISM-0250
Emanation security doctrine
  • ✓Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.ISM-1884
Emanation security risk assessments
  • –System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security risk assessment.ISM-1137
  • –System owners deploying SECRET or TOP SECRET systems in mobile platforms, or as a deployable capability, contact ASD for an emanation security risk assessment.ISM-0249
  • –When an emanation security risk assessment is required, it is sought as early as possible in a system’s life cycle.ISM-0246
  • –Recommended actions contained within emanation security mitigation advice issued for systems are implemented by system owners.ISM-1885

Guidelines for communications systems

9/32 met
Telephone systems
Telephone system usage policy
  • ✓A telephone system usage policy is developed, implemented and maintained.ISM-1078
    • Develop and publish a VoIP/telephone system usage policy
Personnel awareness
  • ✓Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.ISM-0229
    • Advise staff on permitted data sensitivity for phone conversations
  • ✓Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.ISM-0230
    • Brief staff on risks of discussing sensitive info on non-secure phones
  • ✓When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.ISM-0231
    • Document as not applicable: no classified voice cryptographic equipment in use
Protecting conversations
  • ✓Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.ISM-0232
Cordless telephone systems
  • ✓Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted using ASD-approved cryptography.ISM-0233
Speakerphones
  • ✗Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.ISM-0235
Off-hook audio protection
  • ✓Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.ISM-0236
    • Document as not applicable: no secure telephony in sensitive-conversation areas
  • ✗In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off- hook audio protection requirements.ISM-0931
Video conferencing and Internet Protocol telephony
Video conferencing and Internet Protocol telephony infrastructure hardening
  • ✓Video conferencing and IP telephony infrastructure is hardened.ISM-1562
    • Harden VoIP and video conferencing config to CIS/vendor benchmarks
    • Restrict management interfaces and enforce TLS/SRTP encryption
Video-aware and voice-aware firewalls and proxies
  • ✓When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.ISM-0546
Protecting video conferencing and Internet Protocol telephony traffic
  • ✓Video conferencing and IP telephony calls are established using a secure session initiation protocol.ISM-0548
  • ✓Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.ISM-0547
Video conferencing unit and Internet Protocol phone authentication
  • ✓An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.ISM-0554
  • ✓Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.ISM-0553
    • Enforce SSO and MFA for conferencing admin actions and call setup
    • Restrict settings changes to authorised roles; retain access logs as evidence
  • ✓Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.ISM-0555
    • Require authenticated SSO for telephony admin, registration and voicemail access
    • Apply RBAC to telephony console and log all privileged actions
  • ✓IP telephony is configured such that: IP phones authenticate themselves to the call controller upon registration; auto-registration is disabled and only authorised devices are allowed to access the network; unauthorised devices are blocked by default; all unused and prohibited functionality is disabled.ISM-0551
  • –Individual logins are implemented for IP phones used for SECRET or TOP SECRET conversations.ISM-1014
Traffic separation
  • ✓Video conferencing and IP telephony traffic is physically or logically separated from other data traffic.ISM-0549
  • ✓Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses Virtual Local Area Networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.ISM-0556
Internet Protocol phones in public areas
  • ✓IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.ISM-0558
Microphones and webcams
  • ✓Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.ISM-0559
  • ✗Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.ISM-1450
Denial of service response plan
  • ✓A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.ISM-1019
  • ✓A denial of service response plan for video conferencing and IP telephony services contains the following: how to identify signs of a denial-of-service attack; how to identify the source of a denial-of-service attack; how capabilities can be maintained during a denial-of-service attack; what actions can be taken to respond to a denial-of-service attack.ISM-1805
Multifunction devices
Multifunction device usage policy
  • ✓An MFD usage policy is developed, implemented and maintained.ISM-0588
Connecting multifunction devices to digital telephone systems
  • ✓MFDs are not connected to digital telephone systems.ISM-0245
Authenticating to multifunction devices
  • ✓Users authenticate to MFDs before they can print, scan or copy documents.ISM-1854
  • ✓Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.ISM-0590
Scanning and copying documents on multifunction devices
  • ✓MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.ISM-0589
Logging multifunction device use
  • ✓Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.ISM-1855
Observing multifunction device use
  • ✓MFDs are placed in areas where their use can be observed.ISM-1036
Fax machines and services
Sending and receiving fax messages
  • ✓Fax machines, and online fax services, are not used for sending or receiving fax messages.ISM-2075

Guidelines for enterprise mobility

38/45 met
Enterprise mobility
Privately owned mobile devices and desktop computers
  • ✓Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.ISM-1297
    • Engage legal counsel on BYOD access to OFFICIAL: Sensitive data
    • Record legal advice outcome in the BYOD/mobility policy
  • ✓Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.ISM-1400
  • ✓Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately owned mobile devices and desktop computers.ISM-1866
  • ✓Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.ISM-2095
    • Add explicit ban on unapproved AI agents to BYOD policy
    • Enforce via MDM app controls and signed acceptable-use acknowledgement
  • –Privately owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data.ISM-0694
Organisation-owned mobile devices and desktop computers
  • ✓Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.ISM-1482
Mobile devices and desktop computers accessing the internet
  • ✓Mobile devices and desktop computers access the internet via an organisation’s internet gateway rather than via a direct connection to the internet.ISM-0874
    • Deploy a managed secure web gateway or cloud proxy for endpoints
    • Force gateway routing via MDM device configuration on all devices
  • ✓When accessing an organisation’s network via a VPN connection, split tunnelling is disabled.ISM-0705
Mobile device management
Mobile device management policy
  • ✓A mobile device management policy is developed, implemented and maintained.ISM-1533
  • ✓Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.ISM-1195
Approved mobile platforms
  • ✓Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.ISM-1867
  • –Mobile devices that access SECRET or TOP SECRET systems or data use mobile platforms that have been issued an Approval for Use by ASD and are operated in accordance with the latest version of their associated Australian Communications Security Instruction.ISM-0687
Encrypted storage
  • ✓Mobile devices encrypt their internal storage and any removable media using ASD-approved cryptography.ISM-0869
  • –SECRET and TOP SECRET mobile devices do not use removable media unless approved beforehand by ASD.ISM-1868
Encrypted communications
  • ✓Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.ISM-1085
  • ✓Mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.ISM-2108
Maintaining mobile device security
  • ✓Mobile devices are configured to operate in a supervised (or equivalent) mode.ISM-1886
  • ✓Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.ISM-2096
  • ✓Mobile devices are configured with always on VPN functionality.ISM-2097
  • ✓Mobile devices are configured with remote locate and wipe functionality.ISM-1887
  • ✓Mobile devices are configured with secure password-based lock screens.ISM-1888
  • ✓Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.ISM-2098
  • ✓Mobile devices prevent personnel from installing non-approved applications once provisioned.ISM-0863
  • ✓Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.ISM-0864
  • ✓Security updates are applied to mobile devices as soon as they become available.ISM-1366
Mobile device usage
Mobile device usage policy
  • ✓A mobile device usage policy is developed, implemented and maintained.ISM-1082
Personnel awareness
  • ✓Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.ISM-1083
  • ✓Personnel are advised to take the following precautions when using mobile devices: never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes never store credentials with mobile devices that they grant access to, such as in laptop computer bags; never lend mobile devices or removable media to untrusted people, even if briefly; never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging never connect mobile devices to designated charging stations or wall outlet charging ports; never use gifted or unauthorised peripherals, chargers or removable media with mobile devices; never use removable media for data transfers or backups that have not been checked for malicious code beforehand avoid reuse of removable media once used with other parties’ systems or mobile devices; avoid connecting mobile devices to open or untrusted Wi-Fi networks; consider disabling any communications capabilities of mobile devices when not in use, such as Wi-Fi, Bluetooth, Near Field Communication and ultra-wideband consider periodically rebooting mobile devices; consider using a VPN connection to encrypt all cellular and wireless communications; consider using encrypted email or messaging apps for all communications.ISM-1299
Using paging, message services and messaging apps
  • ✓Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.ISM-0240
Using Bluetooth functionality
  • ✓Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.ISM-1196
  • ✓Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.ISM-1200
  • ✓Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.ISM-1198
  • ✓Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.ISM-1199
  • –Bluetooth functionality is not enabled on SECRET and TOP SECRET mobile devices.ISM-0682
Connecting mobile devices to connected vehicles
  • ✓Mobile devices are not connected to the infotainment systems of connected vehicles.ISM-2099
Using mobile devices within or near connected vehicles
  • ✓Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.ISM-2100
  • ✓Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.ISM-2101
Using mobile devices in public spaces
  • ✓Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.ISM-0866
  • –Privacy filters are applied to the screens of SECRET and TOP SECRET mobile devices.ISM-1145
  • ✓Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.ISM-1644
Maintaining control of mobile devices
  • ✓Mobile devices are kept under continual direct supervision when being actively used.ISM-0871
  • ✓Mobile devices are carried or stored in a secured state when not being actively used.ISM-0870
  • ✓If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.ISM-1084
Mobile device emergency sanitisation processes and procedures
  • ✓Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.ISM-0701
  • –If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SECRET or TOP SECRET mobile device, the function is used as part of mobile device emergency sanitisation processes and procedures.ISM-0702
Before travelling overseas with mobile devices
  • ✓Personnel are advised of privacy and security risks when travelling overseas with mobile devices.ISM-1298
  • ✓If travelling overseas with mobile devices to high or extreme risk countries, personnel are: issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities advised on how to apply and inspect tamper seals to key areas of mobile devices; advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.ISM-1554
    • Establish dedicated travel-device pool with freshly provisioned accounts
    • Document tamper-seal apply/inspect procedure for high-risk travel
    • Add pre-travel security briefing to awareness process
  • ✓Before travelling overseas with mobile devices, personnel take the following actions: record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers update all operating systems and applications; remove all non-essential data, applications and user accounts; backup all remaining data, applications and settings.ISM-1555
While travelling overseas with mobile devices
  • ✓Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they: provide credentials to foreign government officials; decrypt mobile devices for foreign government officials; have mobile devices taken out of sight by foreign government officials; have mobile devices or removable media stolen, including if later returned; lose mobile devices or removable media, including if later found; observe unusual behaviour of mobile devices.ISM-1088
After travelling overseas with mobile devices
  • ✓Upon returning from travelling overseas with mobile devices, personnel take the following actions: sanitise and reset mobile devices, including all removable media; decommission any credentials that left their possession during their travel; report if significant doubt exists as to the integrity of any mobile devices or removable media.ISM-1300
  • ✓If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions: reset credentials used with mobile devices, including those used for remote access to their organisation’s systems monitor user accounts for any indicators of compromise, such as failed logon attempts.ISM-1556

Guidelines for evaluated products

1/3 met
Evaluated product procurement
Evaluated product selection
  • ✓If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.ISM-0280
Delivery of evaluated products
  • ✓Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.ISM-0285
    • Procure evaluated products via approved channels and verify delivery integrity
  • –When procuring high assurance information technology (IT) equipment, ASD is contacted for any equipment-specific delivery procedures.ISM-0286
Evaluated product usage
Using evaluated products
  • ✓Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.ISM-0289
    • Configure evaluated products to ASD/vendor evaluated-configuration guidance
    • Audit deployed configuration against the evaluated baseline periodically
  • –High assurance IT equipment is installed, configured, administered and operated in an evaluated configuration and in accordance with ASD guidance.ISM-0290

Guidelines for information technology equipment

23/29 met
IT equipment usage
IT equipment management policy
  • ✓An IT equipment management policy is developed, implemented and maintained.ISM-1551
Hardening IT equipment configurations
  • ✓Approved configurations for IT equipment are developed, implemented and maintained.ISM-1913
  • ✓IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1858
IT equipment registers
  • ✓A networked IT equipment register is developed, implemented, maintained and regularly verified.ISM-0336
  • ✓A non-networked IT equipment register is developed, implemented, maintained and regularly verified.ISM-1869
Labelling IT equipment
  • ✓IT equipment, except for high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.ISM-0294
Labelling high assurance IT equipment
  • –ASD’s approval is sought before applying labels to external surfaces of high assurance IT equipment.ISM-0296
Classifying IT equipment
  • ✓IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.ISM-0293
Handling IT equipment
  • ✓IT equipment is handled in a manner suitable for its sensitivity or classification.ISM-1599
IT equipment maintenance or repairs
Maintenance or repairs of high assurance IT equipment
  • –ASD’s approval is sought before undertaking any maintenance or repairs to high assurance IT equipment.ISM-1079
On-site maintenance or repairs
  • ✓Maintenance or repairs of IT equipment are carried out on site by an appropriately cleared technician.ISM-0305
  • ✓If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the IT equipment and associated media are sanitised before maintenance or repairs.ISM-0307
  • ✓If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: has the authority to direct the technician; is appropriately cleared and briefed; is sufficiently familiar with the IT equipment to understand the work being undertaken; takes all responsible measures to ensure the integrity of the IT equipment; takes due care to ensure that data is not disclosed.ISM-0306
Off-site maintenance or repairs
  • ✓IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.ISM-0310
Inspection of IT equipment following maintenance or repairs
  • ✓Following maintenance or repairs to IT equipment, it is inspected to confirm that it retains its approved configuration and that no unauthorised modifications have been made.ISM-1598
IT equipment sanitisation and destruction
IT equipment sanitisation processes and procedures
  • ✓IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.ISM-0313
IT equipment destruction processes and procedures
  • ✓IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.ISM-1741
Sanitising IT equipment
  • ✓IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.ISM-0311
  • ✓IT equipment that cannot be sanitised is destroyed.ISM-1742
Sanitising highly sensitive IT equipment
  • –IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data, is sanitised in situ.ISM-1218
  • –IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data that cannot be sanitised in situ, is returned to Australia for destruction.ISM-0312
Destroying high assurance IT equipment
  • –High assurance IT equipment is destroyed prior to its disposal.ISM-0315
Sanitising printers and multifunction devices
  • ✓At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.ISM-0317
  • ✓MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner that cannot be removed or a print is visible on the image transfer roller.ISM-1219
  • ✓Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.ISM-1220
  • ✓Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.ISM-1221
  • ✓When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.ISM-0318
  • ✓Printer ribbons in printers and MFDs are removed and destroyed.ISM-1534
Sanitising televisions and computer monitors
  • ✓Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period.ISM-1076
  • ✓Televisions and computer monitors that cannot be sanitised are destroyed.ISM-1222
Sanitising network devices
  • ✓Memory in network devices is sanitised using the following processes, in order of preference: following device-specific guidance provided in evaluation documentation; following vendor sanitisation guidance; loading a dummy configuration file, performing a factory reset and then reinstalling firmware.ISM-1223
IT equipment disposal
IT equipment disposal processes and procedures
  • ✓IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.ISM-1550
Disposal of IT equipment
  • ✓Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.ISM-1217
  • –When disposing of IT equipment that has been designed or modified to meet emanation security standards, ASD is contacted for requirements relating to its disposal.ISM-0321
  • ✗Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.ISM-0316

Guidelines for media

48/49 met
Media usage
Media management policy
  • ✓A media management policy is developed, implemented and maintained.ISM-1549
Removable media usage policy
  • ✓A removable media usage policy is developed, implemented and maintained.ISM-1359
Removable media register
  • ✓A removable media register is developed, implemented, maintained and regularly verified.ISM-1713
Labelling media
  • ✓Media, except for internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.ISM-0332
Classifying media
  • ✓Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.ISM-0323
  • ✓Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.ISM-0337
Reclassifying media
  • ✓Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.ISM-0325
  • ✓Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.ISM-0330
Encrypting media
  • ✓All data stored on media is encrypted using ASD-approved cryptography.ISM-1059
  • ✓Full disk encryption, or partial encryption where access controls only allow writing to encrypted partitions or volumes, is implemented when encrypting media.ISM-0459
  • ✓Pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.ISM-2109
Handling media
  • ✓Media is handled in a manner suitable for its sensitivity or classification.ISM-0831
Sanitising media before first use
  • ✓Media is sanitised before it is used for the first time.ISM-1600
  • ✓Media is sanitised before it is reused in a different security domain.ISM-1642
Using media for data transfers
  • ✓When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.ISM-0347
  • ✓When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.ISM-0947
Media sanitisation
Media sanitisation processes and procedures
  • ✓Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.ISM-0348
Volatile media sanitisation
  • ✓Volatile media is sanitised by removing its power for at least 10 minutes.ISM-0351
  • –SECRET and TOP SECRET volatile media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.ISM-0352
Treatment of volatile media following sanitisation
  • –Following sanitisation, TOP SECRET volatile media retains its classification if it stored static data for an extended period, or had data repeatedly stored on or written to the same memory location for an extended period.ISM-0835
Non-volatile magnetic media sanitisation
  • ✓Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.ISM-0354
  • ✓The host-protected area and device configuration overlay table are reset prior to the sanitisation of non- volatile magnetic hard drives.ISM-1065
  • ✓The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.ISM-1067
Treatment of non-volatile magnetic media following sanitisation
  • –Following sanitisation, SECRET and TOP SECRET non-volatile magnetic media retains its classification.ISM-0356
Non-volatile erasable programmable read-only memory media sanitisation
  • ✓Non-volatile EPROM media is sanitised by applying three times the manufacturer’s specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.ISM-0357
Non-volatile electrically erasable programmable read-only memory media sanitisation
  • ✓Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.ISM-0836
Treatment of non-volatile erasable and electrically erasable programmable read-only memory media following sanitisation
  • –Following sanitisation, SECRET and TOP SECRET non-volatile EPROM and EEPROM media retains its classification.ISM-0358
Non-volatile flash memory media sanitisation
  • ✓Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.ISM-0359
Treatment of non-volatile flash memory media following sanitisation
  • –Following sanitisation, SECRET and TOP SECRET non-volatile flash memory media retains its classification.ISM-0360
Media that cannot be successfully sanitised
  • ✓Media that cannot be successfully sanitised is destroyed prior to its disposal.ISM-1735
Media destruction
Media destruction processes and procedures
  • ✓Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.ISM-0363
Media that cannot be sanitised
  • ✓The following media types are destroyed prior to their disposal: microfiche and microfilm; optical discs; programmable read-only memory; read-only memory; other types of media that cannot be sanitised.ISM-0350
Media destruction equipment
  • ✓Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.ISM-1361
  • ✓If using degaussers to destroy media, degaussers evaluated by the United States’ National Security Agency are used.ISM-1160
Media destruction methods
  • ✓Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.ISM-1517
  • ✓Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.ISM-1722
  • ✓Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.ISM-1723
  • ✓Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.ISM-1724
  • ✓Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.ISM-1725
  • ✓Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.ISM-1726
  • ✓Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.ISM-1727
  • ✓Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.ISM-0368
Treatment of media waste particles
  • –The resulting media waste particles from the destruction of SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, PROTECTED if greater than 3 mm and less than or equal to 6 mm, or SECRET if greater than 6 mm and less than or equal to 9 mm.ISM-1728
  • –The resulting media waste particles from the destruction of TOP SECRET media is stored and handled as OFFICIAL if less than or equal to 3 mm, or SECRET if greater than 3 mm and less than or equal to 9 mm.ISM-1729
Degaussing magnetic media
  • ✓Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.ISM-0361
  • ✓Product-specific directions provided by degausser manufacturers are followed.ISM-0362
  • ✓Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.ISM-1641
Supervision of destruction
  • ✓The destruction of media is performed under the supervision of at least one cleared person.ISM-0370
  • ✓Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.ISM-0371
Supervision of accountable material destruction
  • ✓The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.ISM-0372
  • ✓Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.ISM-0373
Outsourcing media destruction
  • ✓The destruction of media storing accountable material is not outsourced.ISM-0839
  • ✓When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO’s Protective Security Circular-167, is used.ISM-0840
Media disposal
Media disposal processes and procedures
  • ✓Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.ISM-0374
Disposal of media
  • ✓Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.ISM-0378
  • ✓Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.ISM-0375

Guidelines for system hardening

195/216 met
Operating system hardening
Operating system selection
  • ✓Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.ISM-1743
Operating system releases and versions
  • ✓The latest release, or the previous release, of operating systems are used.ISM-1407
    • Set baseline requiring supported OS releases on EC2 and endpoints
    • Track OS end-of-life and schedule upgrades before support ends
    • Report version compliance via Systems Manager Inventory
  • ✓Where supported, 64-bit versions of operating systems are used.ISM-1408
Standard Operating Environments
  • ✓SOEs are used for workstations and servers.ISM-1406
  • ✓SOEs provided by third parties are scanned for malicious code and configurations.ISM-1608
  • ✓SOEs are reviewed and updated at least annually.ISM-1588
Hardening operating system configurations
  • ✓Approved configurations for operating systems are developed, implemented and maintained.ISM-1914
  • ✓Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1409
  • ✓Microsoft’s attack surface reduction rules are implemented.ISM-1601
  • ✓Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.ISM-0383
  • ✓Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.ISM-0380
  • ✓Automatic execution features for removable media are disabled.ISM-0341
  • ✓Internet Explorer 11 is disabled or removed.ISM-1654
  • ✓.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.ISM-1655
  • ✓Operating system exploit protection functionality is enabled.ISM-1492
  • ✓Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.ISM-1745
  • ✓Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.ISM-1584
  • ✓Unprivileged users are prevented from running script execution engines, including: Windows Script Host (cscript.exe and wscript.exe); PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe); Command Prompt (cmd.exe); Windows Management Instrumentation (wmic.exe); Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).ISM-1491
Application management
  • ✓Unprivileged users do not have the ability to install unapproved applications.ISM-1592
  • ✓Unprivileged users do not have the ability to uninstall or disable approved applications.ISM-0382
Application control
  • ✓Application control is implemented on workstations.ISM-0843
  • ✓Application control is implemented on internet-facing servers.ISM-1490
  • ✓Application control is implemented on non-internet-facing servers.ISM-1656
    • Implement application allowlisting on internal EC2 servers via SELinux/AppArmor
    • Define approved-binary baseline and alert on out-of-baseline execution
    • Surface violations in Security Hub for review
  • ✓Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.ISM-1870
  • ✓Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.ISM-1871
  • ✓Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.ISM-1657
  • ✓Application control restricts the execution of drivers to an organisation-approved set.ISM-1658
  • ✓Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.ISM-0955
  • ✓When implementing application control using publisher certificate rules, publisher names and product names are used.ISM-1471
  • ✓When implementing application control using path rules, only approved users can modify approved files and write to approved folders.ISM-1392
  • ✓When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.ISM-1746
  • ✓Microsoft’s recommended application blocklist is implemented.ISM-1544
  • ✓Microsoft’s vulnerable driver blocklist is implemented.ISM-1659
  • ✓Application control rulesets are validated at least annually.ISM-1582
  • ✓All users, except for local administrator accounts and break glass accounts, cannot disable, bypass or be exempted from application control.ISM-0846
  • ✓Allowed and blocked application control events are centrally logged.ISM-1660
Command Shell
  • ✓Command line process creation events are centrally logged.ISM-1889
PowerShell
  • ✓Windows PowerShell 2.0 is disabled or removed.ISM-1621
  • ✓PowerShell is configured to use Constrained Language Mode.ISM-1622
  • ✓PowerShell module logging, script block logging and transcription events are centrally logged.ISM-1623
  • ✓PowerShell script block logs are protected by Protected Event Logging functionality.ISM-1624
Host-based intrusion detection and response solution
  • ✓A HIPS or EDR solution is implemented on workstations.ISM-1341
  • ✓A HIPS or EDR solution is implemented on critical servers and high-value servers.ISM-1034
Software firewall
  • ✓A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.ISM-1416
Antivirus application
  • ✓An antivirus application is implemented on workstations and servers with: signature-based detection functionality enabled and set to a high level; heuristic-based detection functionality enabled and set to a high level; reputation rating functionality enabled; ransomware protection functionality enabled; detection signatures configured to update at least daily; regular scanning configured for all fixed disks and removable media.ISM-1417
Device access control
  • ✓If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.ISM-1418
  • ✓If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.ISM-0343
  • ✓External communication interfaces that allow DMA are disabled.ISM-0345
Operating system event logging
  • ✓Security-relevant events for Apple macOS operating systems are centrally logged.ISM-1976
  • ✓Security-relevant events for Linux operating systems are centrally logged.ISM-1977
  • ✓Security-relevant events for Microsoft Windows operating systems are centrally logged.ISM-0582
User application hardening
User application selection
  • ✓Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.ISM-0938
User application releases
  • ✓The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are used.ISM-1467
Hardening user application configurations
  • ✓Approved configurations for user applications are developed, implemented and maintained.ISM-1915
  • ✓User applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-2110
  • ✓Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.ISM-1806
  • ✓Unneeded user accounts, components, services and functionality of user applications are disabled or removed.ISM-1470
  • ✓Extensions for user applications are restricted to an organisation-approved set.ISM-1235
  • ✓All temporary installation files created during user application installation processes are removed after user applications have been installed.ISM-2111
Artificial intelligence applications
  • ✓AI applications that process classified data have their ability to directly access external public data sources disabled.ISM-2112
  • ✓AI applications are configured to flag organisationally defined risky actions for human approval prior to their execution.ISM-2113
  • ✓Baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.ISM-2114
Email clients
  • ✓Email client security settings cannot be changed by users.ISM-1748
Office productivity suites
  • ✓Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1859
  • ✓Microsoft Office is blocked from creating child processes.ISM-1667
  • ✓Microsoft Office is blocked from creating executable content.ISM-1668
  • ✓Microsoft Office is blocked from injecting code into other processes.ISM-1669
  • ✓Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.ISM-1542
  • ✓Office productivity suite security settings cannot be changed by users.ISM-1823
  • ✓Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.ISM-1671
  • ✓Microsoft Office macros in files originating from the internet are blocked.ISM-1488
  • ✓Microsoft Office macro antivirus scanning is enabled.ISM-1672
  • ✓Microsoft Office macros are blocked from making Win32 API calls.ISM-1673
  • ✓Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.ISM-1674
    • Configure macro policy via Intune to allow only signed/Trusted Location macros
    • Block all other Office macros by default across the workstation fleet
  • ✓Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.ISM-1890
    • Establish a process to scan macros for malicious code before signing
    • Record reviewer sign-off before adding any macro to Trusted Locations
  • ✓Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.ISM-1487
    • Restrict write/modify on Trusted Locations to designated privileged reviewers
    • Enforce via NTFS ACLs and Intune-managed folder permissions
  • ✓Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.ISM-1675
  • ✓Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.ISM-1891
  • ✓Microsoft Office’s list of trusted publishers is validated at least annually.ISM-1676
    • Add annual trusted-publisher list review to the compliance calendar
    • Retain signed evidence of each annual validation
  • ✓Microsoft Office macro security settings cannot be changed by users.ISM-1489
Portable Document Format applications
  • ✓PDF applications are blocked from creating child processes.ISM-1670
  • ✓PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1860
  • ✓PDF application security settings cannot be changed by users.ISM-1824
Security products
  • ✓Security product security settings cannot be changed by users.ISM-1825
Web browsers
  • ✓Web browsers do not process Java from the internet.ISM-1486
  • ✓Web browsers do not process web advertisements from the internet.ISM-1485
  • ✓Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1412
  • ✓Web browser security settings cannot be changed by users.ISM-1585
Server application hardening
Server application selection
  • ✓Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.ISM-1826
Server application releases
  • ✓The latest release of internet-facing server applications is used.ISM-1483
Hardening server application configurations
  • ✓Approved configurations for server applications are developed, implemented and maintained.ISM-1916
  • ✓Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.ISM-1246
  • ✓Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.ISM-1260
  • ✓Unneeded user accounts, components, services and functionality of server applications are disabled or removed.ISM-1247
  • ✓Extensions for server applications are restricted to an organisation-approved set.ISM-2115
  • ✓All temporary installation files created during server application installation processes are removed after server applications have been installed.ISM-1245
Restricting privileges for server applications
  • ✓Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.ISM-1249
  • ✓The user accounts under which server applications run have limited access to their underlying server’s file system.ISM-1250
Microsoft Active Directory services
  • ✓Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.ISM-1926
  • ✓Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.ISM-1927
  • ✓Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.ISM-1928
  • ✓Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.ISM-1830
Microsoft Active Directory Domain Services domain controllers
  • ✓Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.ISM-1827
  • ✓Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.ISM-1929
  • ✓The Print Spooler service is disabled on Microsoft AD DS domain controllers.ISM-1828
  • ✓Passwords are not stored in Group Policy Preferences.ISM-1829
  • ✓Passwords are prevented from being stored in Group Policy Preferences.ISM-1930
  • ✓SID Filtering is enabled for domain and forest trusts.ISM-1931
Microsoft Active Directory Domain Services account hardening
  • ✓Only service accounts and computer accounts are configured with Service Principal Names (SPNs).ISM-1832
  • ✓The number of service accounts configured with an SPN is minimised.ISM-1932
  • ✓Service accounts configured with an SPN do not have DCSync permissions.ISM-1933
  • ✓Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.ISM-2010
  • ✓Duplicate SPNs do not exist within the domain.ISM-1834
  • ✓User accounts are provisioned with the minimum privileges required.ISM-1833
  • ✓User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.ISM-1934
  • ✓Privileged user accounts are configured as sensitive and cannot be delegated.ISM-1835
  • ✓Computer accounts are not configured for unconstrained delegation.ISM-1935
  • ✓User accounts require Kerberos pre-authentication.ISM-1836
  • ✓The UserPassword attribute for user accounts is not used.ISM-1838
  • ✓The sIDHistory attribute for user accounts is not used.ISM-1936
  • ✓User accounts are checked at least weekly for the presence of the sIDHistory attribute.ISM-1937
  • ✓Account properties accessible by unprivileged users are not used to store passwords.ISM-1839
  • ✓User account passwords do not use reversible encryption.ISM-1840
  • ✓Unprivileged user accounts cannot add machines to the domain.ISM-1841
  • ✓Dedicated privileged service accounts are used to add machines to the domain.ISM-1842
  • ✓User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.ISM-1843
  • ✓Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.ISM-1844
  • ✓The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.ISM-1938
Microsoft Active Directory Domain Services security group memberships
  • ✓Privileged user accounts are members of the Protected Users security group.ISM-1620
  • ✓The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly privileged security groups is minimised.ISM-1939
  • ✓Service accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.ISM-1940
  • ✓Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.ISM-1941
  • ✓The Domain Computers security group is not a member of any privileged or highly privileged security groups.ISM-1942
  • ✓When a user account is disabled, it is removed from all security group memberships.ISM-1845
  • ✓The Pre-Windows 2000 Compatible Access security group does not contain user accounts.ISM-1846
Microsoft Active Directory Certificate Services
  • ✓Strong mapping between certificates and users is enforced.ISM-1943
  • ✓The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.ISM-1944
  • ✓The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.ISM-1945
  • ✓Unprivileged user accounts do not have write access to certificate templates.ISM-1946
  • ✓Extended Key Usages that enable user authentication are removed.ISM-1947
  • ✓CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.ISM-1948
Microsoft Active Directory Federation Services
  • ✓Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.ISM-1949
Microsoft Entra Connect
  • ✓Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.ISM-1950
  • ✓Hard match takeover is disabled for Microsoft Entra Connect servers.ISM-1951
  • ✓Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.ISM-1952
Server application event logging
  • ✓Security-relevant events for server applications on internet-facing servers are centrally logged.ISM-1978
  • ✓Security-relevant events for server applications on non-internet-facing servers are centrally logged.ISM-1979
Authentication hardening
Authenticating to systems
  • ✓Users are authenticated before they are granted access to a system and its resources.ISM-1546
Insecure authentication methods
  • ✓Authentication methods susceptible to replay attacks are disabled.ISM-1603
  • ✓LAN Manager and NT LAN Manager authentication methods are disabled.ISM-1055
  • ✓Security questions are not used for authentication purposes.ISM-2076
  • ✓Email is not used for out-of-band authentication purposes.ISM-2077
Multi-factor authentication
  • ✓Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.ISM-1504
  • ✓Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.ISM-1679
  • ✓Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.ISM-1680
  • ✓Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.ISM-1892
  • ✓Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.ISM-1893
  • ✓Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.ISM-1681
  • ✓When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.ISM-1919
  • ✓Multi-factor authentication is used to authenticate privileged users of systems.ISM-1173
  • ✓Multi-factor authentication is used to authenticate unprivileged users of systems.ISM-0974
  • ✓Multi-factor authentication is used to authenticate users of data repositories.ISM-1505
    • Enforce IdP MFA on all admin access to data stores (RDS, S3)
    • Require MFA on any console or app path reaching data repositories
  • ✓Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.ISM-1401
  • ✓Multi-factor authentication used for authenticating users of online services is phishing-resistant.ISM-1872
  • ✓Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.ISM-1873
  • ✓Multi-factor authentication used for authenticating customers of online customer services is phishing- resistant.ISM-1874
    • Add FIDO2/WebAuthn passkey support to customer authentication
    • Deprecate SMS/TOTP as primary customer MFA over time
  • ✓Multi-factor authentication used for authenticating users of systems is phishing-resistant.ISM-1682
  • ✓Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.ISM-1894
    • Issue FIDO2 security keys for staff accessing data repositories
    • Enforce phishing-resistant MFA in the IdP for those roles
  • ✓When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.ISM-2011
  • ✓When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that process, store or communicate their organisation’s sensitive data or sensitive customer data – users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.ISM-1920
  • ✓Successful and unsuccessful multi-factor authentication events are centrally logged.ISM-1683
Single-factor authentication
  • ✓When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.ISM-0417
  • ✓Successful and unsuccessful single-factor authentication events are centrally logged.ISM-1895
Password strength
  • ✓Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.ISM-1559
  • –Passwords used for multi-factor authentication on SECRET systems are a minimum of 8 characters.ISM-1560
  • –Passwords used for multi-factor authentication on TOP SECRET systems are a minimum of 10 characters.ISM-1561
  • ✓Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.ISM-0421
  • –Passwords used for single-factor authentication on SECRET systems are a minimum of 17 characters.ISM-1557
  • –Passwords used for single-factor authentication on TOP SECRET systems are a minimum of 20 characters.ISM-0422
  • ✗Passwords using a sequence of words for single-factor authentication are not constructed using: a list of categorised words; a real sentence in a natural language; song lyrics, movie or television show quotes, literature, or any other publicly available material; less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.ISM-1558
  • ✓Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.ISM-2078
  • ✓Maximum length limits for passwords are not less than 64 characters.ISM-2079
  • ✓Password complexity requirements are not imposed for passwords.ISM-2080
  • ✓All ASCII printable characters are supported for passwords.ISM-2081
Setting credentials for user accounts
  • ✓Users provide sufficient evidence to verify their identity when requesting new credentials.ISM-1593
  • ✓Credentials set for user accounts are randomly generated.ISM-1227
  • ✓Credentials are provided to users via a secure communications channel or, if not possible, split into two parts with one part provided to users and the other part provided to supervisors.ISM-1594
  • ✓Credentials provided to users are changed on first use.ISM-1595
  • ✓Credentials are not reused by users across different systems.ISM-1596
Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
  • ✓Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.ISM-1953
  • ✓Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.ISM-1685
  • ✓Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.ISM-1795
  • ✓Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.ISM-1954
  • ✓Service accounts are created as group Managed Service Accounts.ISM-1619
Changing credentials
  • ✓Credentials for user accounts are changed if: they are compromised; they are suspected of being compromised; they are discovered stored on networks in the clear; they are discovered being transferred across networks in the clear; membership of a shared user account changes.ISM-1590
  • ✓Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.ISM-1955
  • ✓Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.ISM-1847
  • ✓Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.ISM-1956
Protecting credentials
  • ✓Credentials are obscured as they are entered into systems.ISM-1597
  • ✓Credential hint functionality is not used for systems.ISM-1980
  • ✓Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.ISM-0418
  • ✓Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.ISM-1402
  • ✓Private keys for Microsoft AD CS CA servers are protected by a hardware security module.ISM-1957
  • ✓Memory integrity functionality is enabled.ISM-1896
  • ✓Local Security Authority protection functionality is enabled.ISM-1861
  • ✓Credential Guard functionality is enabled.ISM-1686
  • ✓Remote Credential Guard functionality is enabled.ISM-1897
  • ✓Cached credentials are limited to one previous logon.ISM-1749
  • ✓Networks are scanned at least monthly to identify any credentials that are being stored in the clear.ISM-1875
User account lockouts
  • ✓User accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon attempts, with either indefinite or automated lockout durations.ISM-1403
Session termination
  • ✓User sessions are terminated and workstations are restarted at least daily.ISM-0853
Session locking
  • ✓Services are configured with a session lock that: activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users blocks access to all session content; requires users to re-authenticate using all authentication factors to unlock the session; denies users the ability to disable the session locking mechanism.ISM-0428
Screen locking
  • ✓Systems are configured with a screen lock that: activates after a maximum of 15 minutes of user inactivity, or when manually activated by users; conceals all content on the screen; ensures that the screen does not enter a power saving state before the screen lock is activated; requires users to re-authenticate using all authentication factors to unlock the system; denies users the ability to disable the screen locking mechanism.ISM-2012
Logon banner
  • ✓Systems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.ISM-0408
Virtualisation hardening
Functional separation between operating environments
  • ✓When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.ISM-1460
  • ✓When using a software-based isolation mechanism that consumes shared physical computing resources, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.ISM-1604
  • ✓When using a software-based isolation mechanism that consumes shared physical computing resources, the underlying operating system is hardened.ISM-1605
  • ✓When using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.ISM-1606
  • ✓When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.ISM-1848
  • ✓When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.ISM-1607
  • –When using a software-based isolation mechanism that consumes shared physical computing resources for SECRET or TOP SECRET operating environments, the physical server and all operating environments are of the same classification and belong to the same security domain.ISM-1461

Guidelines for system management

43/56 met
System administration
System administration processes and procedures
  • ✓System administration processes, and supporting system administration procedures, are developed, implemented and maintained.ISM-0042
  • ✓System administrators perform system administration activities in accordance with the system’s change and configuration management plan.ISM-1211
Separate privileged operating environments
  • ✓Secure Admin Workstations are used in the performance of administrative activities.ISM-1898
    • Provision dedicated hardened admin workstations (PAW) for privileged AWS/infra tasks
    • Restrict AWS console and production access to those devices by policy
  • ✓Privileged users use separate privileged and unprivileged operating environments.ISM-1380
  • ✓Privileged operating environments are not virtualised within unprivileged operating environments.ISM-1687
  • ✓Unprivileged user accounts cannot logon to privileged operating environments.ISM-1688
  • ✓Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.ISM-1689
  • ✓User accounts with DCSync permissions cannot logon to unprivileged operating environments.ISM-1958
Administrative infrastructure
  • ✓Administrative infrastructure is segregated from the wider network and the internet.ISM-1385
  • ✓Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.ISM-1750
  • ✓Network management traffic can only originate from administrative infrastructure.ISM-1386
  • ✓Administrative activities are conducted through jump servers.ISM-1387
  • ✓Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.ISM-1899
Software registers
  • ✓Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.ISM-1493
  • ✓Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.ISM-1643
System maintenance
Patch management processes and procedures
  • ✓Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.ISM-1143
  • ✓A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.ISM-0298
Mitigating known vulnerabilities
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1876
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1690
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.ISM-1691
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1692
    • Configure Intune to auto-deploy critical app patches within 48 hours
    • Track critical CVE advisories against a 48-hour remediation SLA
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1901
    • Set a 2-week Intune deployment ring for non-critical app updates
    • Report patch compliance against the fortnightly SLA
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.ISM-1693
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1877
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1694
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non- internet-facing servers and non-internet-facing network devices are applied within one month of release.ISM-1695
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non- internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1696
    • Use SSM Patch Manager for critical EC2 OS patches within 48 hours
    • Deploy critical workstation OS patches via Intune within 48 hours
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non- internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1902
    • Configure SSM Patch Manager and Intune monthly rings for non-critical OS patches
    • Report compliance against the one-month SLA
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1878
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1751
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1879
    • Enable Intune Windows driver updates with expedited critical deployment
    • Track critical driver advisories against a 48-hour SLA
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1697
    • Set Intune driver update policy to deploy within one month
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.ISM-1903
    • Enable Intune/vendor firmware updates for critical fixes within 48 hours
    • Subscribe to hardware vendor firmware advisories
  • ✓Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.ISM-1904
    • Configure firmware update deployment within one month via Intune/vendor tooling
  • –Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.ISM-0300
Cessation of support
  • ✓Online services that are no longer supported by vendors are removed.ISM-1905
  • ✓Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.ISM-1704
  • ✓Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.ISM-0304
    • Inventory installed apps via Intune and flag EOL/unsupported software
    • Remove or replace unsupported apps and block reinstallation
  • ✓Operating systems that are no longer supported by vendors are replaced.ISM-1501
  • ✓Internet-facing network devices that are no longer supported by vendors are replaced.ISM-1753
  • ✓Non-internet-facing network devices that are no longer supported by vendors are replaced.ISM-1981
  • ✓Networked IT equipment that is no longer supported by vendors is replaced.ISM-1982
  • ✓When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.ISM-1809
Data backup and restoration
Digital preservation policy
  • ✓A digital preservation policy is developed, implemented and maintained.ISM-1510
Data backup and restoration processes and procedures
  • ✓Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.ISM-1547
  • ✓Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.ISM-1548
Performing and retaining backups
  • ✓Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.ISM-1511
  • ✓Backups of data, applications and settings are synchronised to enable restoration to a common point in time.ISM-1810
  • ✓Backups of data, applications and settings are retained in a secure and resilient manner.ISM-1811
Backup access
  • ✓Unprivileged user accounts cannot access backups belonging to other user accounts.ISM-1812
  • ✓Unprivileged user accounts cannot access their own backups.ISM-1813
    • Deny end-user IAM/app access to AWS Backup vaults and S3 backup buckets
    • Separate backup storage account/vault from user-accessible resources
  • ✓Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.ISM-1705
  • ✓Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.ISM-1706
    • Restrict backup vault access to a dedicated backup administrator role
    • Remove backup read/restore rights from general privileged IAM roles
Backup modification and deletion
  • ✓Unprivileged user accounts are prevented from modifying and deleting backups.ISM-1814
  • ✓Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.ISM-1707
  • ✓Backup administrator accounts are prevented from modifying and deleting backups during their retention period.ISM-1708
    • Enable AWS Backup Vault Lock in compliance mode for the retention period
    • Apply S3 Object Lock (compliance mode) to backup objects
Testing restoration of backups
  • ✓Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.ISM-1515

Guidelines for security assurance

31/35 met
Security monitoring
Security monitoring policy
  • ✓A security monitoring policy is developed, implemented and maintained.ISM-0580
Centralised event logging facility
  • ✓A centralised event logging facility is implemented.ISM-1405
  • ✓Event logs sent to a centralised event logging facility are sent as soon as possible after they occur.ISM-1983
  • ✓Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.ISM-1984
  • ✓Event logs are protected from unauthorised access.ISM-1985
  • ✓Event logs are protected from unauthorised modification and deletion.ISM-1815
  • ✓An accurate and consistent time source is used for event logging.ISM-0988
Event log details
  • ✓For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.ISM-0585
  • ✓To the extent possible, event logs are captured and stored in a consistent and structured format.ISM-1959
Event log monitoring
  • ✓Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.ISM-0120
  • ✓Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.ISM-2116
  • ✓Suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.ISM-2117
  • ✓Event logs from critical servers are analysed in a timely manner to detect cyber security events.ISM-1986
  • ✓Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.ISM-1906
  • ✓Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.ISM-1907
    • Ship backend EC2/server logs to CloudWatch/SIEM with detection rules
    • Alert on security events and review within a defined timeframe
  • ✓Event logs from workstations are analysed in a timely manner to detect cyber security events.ISM-0109
    • Forward workstation and EDR logs to the central SIEM
    • Create detection rules and triage alerts promptly
  • ✓Event logs from security products are analysed in a timely manner to detect cyber security events.ISM-1987
  • ✓Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.ISM-1960
  • ✓Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.ISM-1961
  • ✓Cyber security events are analysed in a timely manner to identify cyber security incidents.ISM-1228
Event log retention
  • ✓Event logs are retained in a searchable manner for at least 12 months.ISM-1988
  • ✓Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.ISM-1989
Security assessments
Vulnerability scanning
  • ✓An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.ISM-1807
  • ✓A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.ISM-1808
  • ✓A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.ISM-1698
  • ✓A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.ISM-1699
  • ✓A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.ISM-1700
  • ✓A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.ISM-1701
  • ✓A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.ISM-1702
  • ✓A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.ISM-1752
  • ✓A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.ISM-1703
    • Run fortnightly vulnerability scans reporting missing driver updates
    • Feed results into patch remediation tracking
  • ✓A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.ISM-1900
    • Run fortnightly scans identifying outdated firmware
    • Track firmware findings through to remediation
  • ✓The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.ISM-1921
Vulnerability assessments and penetration tests
  • ✓Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least annually thereafter.ISM-2118
  • ✓Suitable AI models are used to augment vulnerability assessments and penetration tests.ISM-2119

Guidelines for software development

65/108 met
Software development fundamentals
Development, testing, staging and production environments
  • ✓Development, testing, staging and production environments are segregated.ISM-0400
  • ✓Development and modification of software only take place in development environments.ISM-1419
  • ✓Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.ISM-1420
Authoritative source for software
  • ✓An authoritative source for software is established and maintained.ISM-2023
  • ✓The authoritative source for software is used for all software development activities.ISM-2024
  • ✓Unauthorised access to the authoritative source for software is prevented.ISM-1422
    • Enforce SSO+MFA and least-privilege on GitHub/CodeArtifact/ECR
    • Audit and remove stale repo/registry access regularly
  • ✓Unauthorised modification of the authoritative source for software is prevented.ISM-1816
    • Enable branch protection, required reviews, and restricted push on repos
    • Require signed commits and protect artifact registries from direct writes
Issue tracking
  • ✓An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.ISM-2025
Software artefacts
  • ✓All software artefacts are scanned for malicious content before being imported into the authoritative source for software.ISM-2026
    • Run malware/dependency scanning in CI before publishing to CodeArtifact/ECR
    • Enable ECR image scanning and block promotion on findings
  • ✓All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.ISM-2027
    • Verify checksums or digital signatures of third-party artefacts in CI
    • Adopt cosign/sigstore verification before accepting artefacts
  • ✓All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.ISM-2028
  • ✓Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.ISM-2102
    • Integrate SAST, SCA and DAST into CI pipelines
    • Schedule recurring scans of existing artefacts and use Inspector for images
  • ✓The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.ISM-2029
    • Route all dependency installs through a private CodeArtifact repository with upstream allowlists
    • Enforce provenance/signature checks on packages in CI before build proceeds
  • ✓Scanning is used during commits to identify plain text or encoded secrets and keys, which are then blocked from being stored in the authoritative source for software.ISM-2030
    • Enable pre-commit secret scanning (git-secrets/gitleaks) plus GitHub push protection
    • Fail CI on detected secrets and rotate any keys already committed
Build solution
  • ✓Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.ISM-2031
  • ✓The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.ISM-2032
Secure software development
  • ✓A secure software development policy is developed, implemented and maintained.ISM-2120
  • ✓All software security requirements are documented, stored securely and maintained throughout the software development life cycle.ISM-2033
  • ✓Security design decisions are documented and reviewed throughout the software development cycle.ISM-2034
  • ✓Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.ISM-2035
  • ✓Security responsibilities for software developers are identified and documented.ISM-2036
  • ✓Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.ISM-2121
  • ✓Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.ISM-2037
  • ✓A software developer cyber security knowledge and skills register is implemented and maintained.ISM-2038
  • ✓Secure by Design principles and practices are followed throughout the software development life cycle.ISM-0401
  • ✓Threat modelling is used in support of the software development life cycle.ISM-1238
  • ✓The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.ISM-2039
  • ✓Secure programming practices for the chosen programming language are used for software development.ISM-2040
  • ✓Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.ISM-2041
  • ✓Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.ISM-2042
  • ✓SecDevOps practices are used for software development.ISM-1780
  • ✓Software is architected and structured to support readability and maintainability.ISM-2043
  • ✓Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.ISM-1796
    • Provision a code-signing certificate with a trusted CA chain
    • Sign downloadable executables/artefacts in CI and publish the signatures
  • ✓Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.ISM-1797
    • Generate SHA-256 checksums for all released installers and patches
    • Publish checksums/signatures alongside downloads and document verification steps
  • ✓Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.ISM-2044
  • ✓Application backwards compatibility does not compromise any security measures or features.ISM-2045
  • ✓Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.ISM-2046
  • ✓Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.ISM-2047
    • Send email and SMS alerts on password/MFA reset via SES/SNS
    • Ensure the notification uses a channel distinct from the reset request
  • ✓Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.ISM-2048
  • ✓When user permissions or credentials are changed, software forces all impacted users to re-authenticate.ISM-2049
  • ✓When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.ISM-2050
    • Add CRL and OCSP revocation checks to certificate validation logic
    • Reject signatures whose chain fails to resolve to a trusted root
  • ✓Software generates sufficient event logs to support the detection of cyber security events.ISM-2051
  • ✓Event logs produced by software ensure that any sensitive data is protected.ISM-2052
  • ✓Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.ISM-1798
  • ✓End of life procedures for software, including procedures for software removal and the archival or destruction of user accounts and data, are produced and made available to consumers.ISM-2053
    • Write an end-of-life runbook covering account and data destruction
    • Publish EOL/offboarding data-export and deletion procedures to customers
Software bill of materials
  • ✓If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.ISM-2054
  • ✓A software bill of materials is produced and made available to consumers of software.ISM-1730
    • Generate a CycloneDX/SPDX SBOM in CI for each release
    • Make SBOMs available to customers on request or via portal
Cryptographic bill of materials
  • ✓If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.ISM-2082
    • Ingest CBOMs from third-party components during dependency review
    • Verify listed algorithms match ASD-approved standardised implementations
  • ✓A cryptographic bill of materials is produced and made available to consumers of software.ISM-2083
    • Produce a cryptographic bill of materials cataloguing algorithms and key sizes
    • Publish the CBOM to consumers alongside the SBOM
Software build provenance
  • ✓If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.ISM-2055
  • ✓A software build provenance is produced and made available to consumers of software.ISM-2056
    • Adopt SLSA build provenance with signed attestations in the CI pipeline
    • Publish provenance metadata so consumers can verify build origin
Network application programming interfaces
  • ✓Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.ISM-1818
    • Enforce Cognito/JWT authorizers on all internet-facing data-modifying API Gateway routes
    • Apply least-privilege authorisation checks per endpoint and log denials
  • ✓Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.ISM-2013
    • Require IAM/service-token authentication on internal data-modifying APIs
    • Restrict internal API access via VPC security groups and authorizers
  • ✓Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.ISM-1817
    • Require authenticated sessions before serving non-public data over internet APIs
    • Enforce per-object authorisation so users only access permitted records
  • ✓Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.ISM-2014
    • Authenticate service-to-service calls to internal non-public data APIs
    • Enforce authorisation and network isolation via security groups
  • ✓Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.ISM-1910
    • Enable access logging on ALB/API Gateway and WAF for internet APIs
    • Centralise logs to CloudWatch/S3 with CloudTrail data events retained
  • ✓Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.ISM-2015
    • Emit structured request logs from internal APIs to CloudWatch
    • Aggregate internal API logs centrally with defined retention
Software input handling
  • ✓Validation and sanitisation are performed on all input received over the internet by software.ISM-1240
    • Deploy AWS WAF managed rules in front of ALB/API Gateway
    • Enforce server-side schema validation and output encoding on all inputs
  • ✓Validation and sanitisation are performed on all input received over a local network by software.ISM-2016
  • ✓All input validation rules are documented, implemented in code, and tested using both positive and negative unit tests and integration tests.ISM-2057
  • ✓Data sources and serialised data inputs are validated before being deserialised.ISM-2058
  • ✓File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.ISM-2059
Software interaction with databases
  • ✓All queries to databases from software are filtered for legitimate content and correct syntax.ISM-1275
    • Convert all database access to parameterised queries/prepared statements
    • Add static analysis to flag string-concatenated SQL in CI
  • ✓Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.ISM-1276
  • ✓Software is designed or configured to provide as little error information as possible about the structure of databases.ISM-1278
  • ✓All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.ISM-1536
Software security testing
  • ✓Peer reviews are conducted on all critical and security-related software components.ISM-2061
  • ✓Code reviews are utilised to ensure software components meets Secure by Design principles and practices as well as secure programming practices.ISM-2060
  • ✓Unit testing and integration testing, covering both positive and negative use cases, are used for software components to ensure code quality and correctness.ISM-2062
  • ✓Software is comprehensively tested for vulnerabilities using SAST, DAST and SCA prior to its initial release, any subsequent release, and periodically to help identify any previously unidentified vulnerabilities.ISM-0402
  • ✓Suitable AI models are used to augment software security testing.ISM-2122
Vulnerability disclosure program
  • ✓A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.ISM-1616
  • ✓A vulnerability disclosure policy is developed, implemented and maintained.ISM-1755
    • Draft, approve and publish a vulnerability disclosure policy
    • Define intake, triage and researcher-communication process with SLAs
  • ✓Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.ISM-1756
  • ✓A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.ISM-1717
Reporting and resolving vulnerabilities
  • ✓Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.ISM-1908
    • Publish advisories for fixed vulnerabilities with CWE and CPE identifiers
    • Assign CVEs and coordinate timing with affected customers
  • ✓Vulnerabilities identified in software are resolved in a timely manner.ISM-1754
    • Set severity-based remediation SLAs and track via Jira/Security Hub
    • Report overdue vulnerabilities in a recurring remediation review
  • ✓In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.ISM-1909
    • Perform documented root cause analysis on each significant vulnerability
    • Add lint/SAST rules or framework fixes to kill the whole class
Software event logging
  • ✓Security-relevant usage, error messages and crashes for software are centrally logged.ISM-1911
Artificial intelligence application development
Secure artificial intelligence application development
  • ✓AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.ISM-2084
    • Author AI model and system cards documenting architecture, use cases, risks
    • Store cards in the ISMS repository and review each release
  • ✓AI models are stored in a non-executable file format that does not allow arbitrary code execution.ISM-2072
    • Store AI models in safetensors or equivalent non-executable format
    • Block loading of pickle-based model files in code
  • ✓The exposure of exact AI model confidence scores in API outputs or user interfaces is prevented.ISM-2085
    • Round or bucket confidence scores before returning them in API responses
    • Remove raw model probabilities from user-facing outputs
Data collection, retention and use
  • ✓Organisational data generated, collected or processed by AI applications is not used for training, fine-tuning or improving AI models unless informed and explicit consent has been obtained from data owners in advance.ISM-2103
    • Disable vendor training on data via API/enterprise settings
    • Capture explicit data-owner consent before any model fine-tuning
  • ✓All prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.ISM-2123
    • Hard-delete stored prompts and outputs when a chat session is removed
    • Confirm deletion propagates to backups and vector stores
Artificial intelligence model poisoning
  • ✓The source and integrity of AI models, structures and weights are verified.ISM-2086
    • Verify checksums/signatures of model weights against a trusted source
    • Pin model versions and store them in an integrity-checked S3 bucket
  • ✓The source and integrity of training data for AI models is verified.ISM-2087
    • Validate provenance and integrity hashes of training datasets
    • Restrict and log write access to training-data buckets
  • ✓Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by AI models.ISM-2088
Unbounded consumption
  • ✓AI model performance metrics are monitored and anomalies are investigated.ISM-2089
    • Emit AI latency, accuracy and drift metrics to CloudWatch
    • Alarm on metric anomalies and route to on-call for investigation
  • ✓Rate limiting is applied to inference queries for AI models.ISM-2090
  • ✓Resource limits are enforced for AI models.ISM-2091
    • Enforce token, request-rate and timeout limits per AI request
    • Apply API Gateway throttling and per-tenant quotas on AI endpoints
Excessive agency
  • ✓Access control policies are implemented to enforce fine-grained permissions for AI applications.ISM-2092
  • ✓Role-based access controls are implemented for AI applications to restrict access to sensitive data.ISM-2093
Prompt injection
  • ✓Generative AI applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.ISM-1924
Sensitive data exposure and improper output
  • ✓Content filtering is implemented by AI applications to detect and block sensitive data exposure and improper output.ISM-2094
    • Add input/output content filtering (Bedrock Guardrails or equivalent)
    • Block or redact sensitive-data leakage in AI responses
Mobile application development
Secure mobile application development
  • ✓The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.ISM-1922
Web application development
Secure web application design and development
  • ✓Robust web application frameworks are used in the development of web applications.ISM-1239
  • ✓The OWASP Application Security Verification Standard is used in the development of web applications.ISM-0971
  • ✓The OWASP Top 10 Proactive Controls are used in the development of web applications.ISM-1849
  • ✓The OWASP Top 10 are mitigated in the development of web applications.ISM-1850
  • ✓If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.ISM-2063
  • ✓Web application session cookies contain only digitally signed opaque bearer tokens.ISM-2064
    • Issue opaque, server-signed session tokens instead of embedding data in cookies
    • Set HttpOnly/Secure/SameSite and validate signatures server-side
  • ✓Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.ISM-2065
    • Generate session tokens with a CSPRNG providing at least 256 bits entropy
    • Audit existing token generation for sequential or low-entropy identifiers
  • ✓Web application sessions are centrally managed server side.ISM-2066
  • ✓Web applications that support Single Sign On equally support Single Logout.ISM-2067
Web security policy response headers
  • ✓Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.ISM-1424
    • Define and deploy a Content-Security-Policy via CloudFront/ALB or app headers
    • Set HSTS with long max-age and includeSubDomains; add X-Frame-Options DENY
    • Roll CSP out in report-only mode before enforcing
Web application interactions
  • ✓All web application content is offered exclusively using HTTPS.ISM-1552
Web application programming interfaces
  • ✓The OWASP API Security Top 10 are mitigated in the development of web APIs.ISM-1851
Web application output encoding
  • ✓Output encoding is performed on all output produced by web applications.ISM-1241
    • Apply context-aware output encoding in the framework/templating layer for all responses
    • Add SAST and automated tests to catch unencoded output paths

Guidelines for database systems

13/13 met
Database servers
Functional separation between database servers and web servers
  • ✓Database servers and web servers are functionally separated.ISM-1269
Communications between database servers and web servers
  • ✓Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.ISM-1277
Network environment
  • ✓Database servers are placed on a different network segment to user workstations.ISM-1270
  • ✓Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.ISM-1271
  • ✓If only local access to a database is required, networking functionality of database management system applications is disabled or directed to listen solely to the localhost interface.ISM-1272
Segregation of development, testing, staging and production database servers
  • ✓Database servers for development, testing, staging and production environments are segregated.ISM-1273
Databases
Database register
  • ✓A database register is developed, implemented, maintained and regularly verified.ISM-1243
Protecting databases
  • ✓File-based access controls are applied to database files.ISM-1256
Protecting database contents
  • ✓Databases and their contents are classified based on the sensitivity or classification of data that they contain.ISM-0393
  • ✓Database users’ ability to access, insert, modify and remove database contents is restricted based on their work duties.ISM-1255
  • ✓The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.ISM-1268
Segregation of development, testing, staging and production databases
  • ✓Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.ISM-1274
Database event logging
  • ✓Security-relevant events for databases are centrally logged, including: access or modification of particularly important content; addition of new users, especially privileged users; changes to user roles or privileges; attempts to elevate user privileges; queries containing comments; queries containing multiple embedded queries; database and query alerts or failures; database structure changes; database administrator actions; use of executable commands; database logons and logoffs.ISM-1537

Guidelines for email

15/25 met
Email usage
Email usage policy
  • ✓An email usage policy is developed, implemented and maintained.ISM-0264
Webmail services
  • ✓Access to non-approved webmail services is blocked.ISM-0267
Protective markings for emails
  • ✓Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.ISM-0270
    • Deploy an email protective-marking add-in for staff outbound mail
    • Configure markings to reflect highest sensitivity of body and attachments
Protective marking tools
  • ✓Protective marking tools do not automatically insert protective markings into emails.ISM-0271
  • ✓Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.ISM-0272
  • ✓Protective marking tools do not allow users replying to or forwarding emails to select protective markings lower than previously used.ISM-1089
Handling emails with inappropriate, invalid or missing protective markings
  • ✓Email servers are configured to block, log and report emails with inappropriate protective markings.ISM-0565
    • Configure the mail gateway to block, log and report invalid protective markings
    • Route marking violations to the security team via SIEM/CloudWatch alerts
  • ✓The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.ISM-1023
    • Enable notifications to recipients of blocked inbound and senders of blocked outbound mail
Email distribution lists
  • –Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To data are not sent to email distribution lists unless the nationality of all members of email distribution lists can be confirmed.ISM-0269
Email gateways and servers
Centralised email gateways
  • ✓Emails are routed via centralised email gateways.ISM-0569
  • ✓When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.ISM-0571
Email gateway maintenance activities
  • ✓Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.ISM-0570
Open relay email servers
  • ✓Email servers only relay emails destined for or originating from their domains (including subdomains).ISM-0567
Email server transport encryption
  • ✓Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.ISM-0572
  • ✓MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.ISM-1589
Sender Policy Framework
  • ✓SPF is used to specify authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).ISM-0574
    • Inventory all sending sources (SES, Workspace, marketing tools) then publish an SPF record
  • ✓A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).ISM-1183
  • ✓SPF is used to verify the authenticity of incoming emails.ISM-1151
DomainKeys Identified Mail
  • ✓DKIM signing is enabled on emails originating from an organisation’s domains (including subdomains).ISM-0861
  • ✓DKIM signatures on incoming emails are verified.ISM-1026
  • ✓Email distribution list applications used by external senders is configured such that it does not break the validity of the sender’s DKIM signature.ISM-1027
Domain-based Message Authentication, Reporting and Conformance
  • ✓DMARC records are configured for an organisation’s domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.ISM-1540
    • Deploy DMARC at p=none, monitor aggregate reports, then ramp to p=reject
    • Confirm SPF and DKIM alignment before enforcing reject
  • ✓Incoming emails are rejected if they do not pass DMARC checks.ISM-1799
    • Enable inbound DMARC enforcement on the gateway to reject failing mail
Email content filtering
  • ✓Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.ISM-1234
Blocking suspicious emails
  • ✓Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.ISM-1502
Notifications of undeliverable emails
  • ✓Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.ISM-1024
    • Configure the mail server to send NDRs only to SPF-verified senders

Guidelines for networking

52/70 met
Network design and configuration
Network documentation
  • ✓Network documentation is developed, implemented and maintained.ISM-0518
  • ✓Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.ISM-0516
  • ✓Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.ISM-1912
  • ✓Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.ISM-1178
Network segmentation and segregation
  • ✓Networks are segregated into multiple network zones according to the criticality of servers, services and data.ISM-1181
  • ✓An organisation’s networks are segregated from their service providers’ networks.ISM-1577
Using Virtual Local Area Networks
  • ✓VLANs are not used to separate network traffic between an organisation’s networks and public network infrastructure.ISM-1532
  • ✓VLANs are not used to separate network traffic between networks belonging to different security domains.ISM-0529
  • ✓Network devices managing VLANs are administered from the most trusted security domain.ISM-0530
  • ✓Network devices managing VLANs belonging to different security domains do not share VLAN trunks.ISM-0535
  • ✓Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.ISM-1364
Functional separation between networked devices and the internet
  • ✓Internet connectivity for networked devices is strictly limited to those that require access.ISM-2068
Networked management interfaces
  • ✓Networked management interfaces for IT equipment are not directly exposed to the internet.ISM-1863
Functional separation between servers
  • ✓Servers maintain effective functional separation from each other.ISM-0385
  • ✓Servers minimise communications with other servers at the network and file system level.ISM-1479
Network encryption
  • ✓All data communicated over network infrastructure is encrypted using ASD-approved cryptography.ISM-1781
    • Enforce TLS on all internal service-to-service traffic and load balancers
    • Enable in-transit encryption for RDS, ElastiCache and internal APIs
Using Internet Protocol version 6
  • ✓IPv6 functionality is disabled in dual-stack network devices unless it is being used.ISM-0521
  • ✓IPv6 capable network security appliances are used on IPv6 and dual-stack networks.ISM-1186
  • ✓Unless explicitly required, IPv6 tunnelling is disabled on all network devices.ISM-1428
  • ✓IPv6 tunnelling is blocked by network security appliances at externally connected network boundaries.ISM-1429
  • ✓Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.ISM-1430
Network access controls
  • ✓Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.ISM-0520
  • ✓Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.ISM-1182
Network management traffic
  • ✓Security measures are implemented to prevent unauthorised access to network management traffic.ISM-1006
Using the Server Message Block protocol
  • ✓SMB version 1 is not used on networks.ISM-1962
Using the Simple Network Management Protocol
  • ✓SNMP version 1 and SNMP version 2 are not used on networks.ISM-1311
  • ✓All default SNMP community strings on network devices are changed and write access is disabled.ISM-1312
Using Network-based Intrusion Detection and Prevention Systems
  • ✓A NIDS or NIPS is deployed in gateways between an organisation’s networks and other networks they do not manage.ISM-1028
  • ✓A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.ISM-1030
Blocking anonymity network traffic
  • ✓Inbound network connections from anonymity networks are blocked.ISM-1627
  • ✓Outbound network connections to anonymity networks are blocked.ISM-1628
Encrypted Domain Name System Services
  • ✓DNS traffic is encrypted by clients and servers using ASD-approved cryptography.ISM-2017
    • Enable encrypted DNS (DoH/DoT) on endpoints and via Route 53 Resolver
Protective Domain Name System Services
  • ✓A protective DNS service is used to block access to known malicious domain names.ISM-1782
Flashing network devices with trusted firmware before first use
  • ✓Network devices are flashed with trusted firmware before they are used for the first time.ISM-1800
Default user accounts and credentials for network devices
  • ✓Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.ISM-1304
Disabling unused physical ports on network devices
  • ✓Unused physical ports on network devices are disabled.ISM-0534
Regularly restarting network devices
  • ✓Network devices are restarted at least monthly.ISM-1801
Network device event logging
  • ✓Security-relevant events for internet-facing network devices are centrally logged.ISM-1963
  • ✓Security-relevant events for non-internet-facing network devices are centrally logged.ISM-1964
Wireless networks
Choosing wireless devices
  • ✓All wireless devices are Wi-Fi Alliance certified.ISM-1314
    • Procure only Wi-Fi Alliance certified access points and update the asset register
Public wireless networks
  • ✓Public wireless networks provided for public use are segregated from all other organisation networks.ISM-0536
Administrative interfaces for wireless access points
  • ✓The administrative interface on wireless access points is disabled for wireless network connections.ISM-1315
Default settings
  • ✓Settings for wireless access points are hardened.ISM-1710
  • ✓Default SSIDs of wireless access points are changed.ISM-1316
  • ✓SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.ISM-1317
  • ✓SSID broadcasting is not disabled on wireless access points.ISM-1318
Media Access Control address filtering
  • ✓MAC address filtering is not used to restrict which devices can connect to wireless networks.ISM-1320
Static addressing
  • ✓Static addressing is not used for assigning IP addresses on wireless networks.ISM-1319
Confidentiality and integrity of wireless network traffic
  • ✓WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.ISM-1332
802.1X authentication
  • ✓802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.ISM-1321
    • Deploy 802.1X with EAP-TLS and X.509 certificates on corporate WiFi
    • Disable all non-EAP-TLS methods on supplicants and RADIUS servers
  • ✓User identity confidentiality is used if available with EAP-TLS implementations.ISM-1711
Evaluation of 802.1X authentication implementation
  • ✓Evaluated supplicants, authenticators, wireless access points and authentication servers are used in wireless networks.ISM-1322
    • Select ASD-evaluated APs, supplicants and RADIUS servers; record in procurement
Generating and issuing certificates for authentication
  • ✓Certificates are generated using an evaluated certificate authority or hardware security module.ISM-1324
  • ✓Certificates are required for devices and users accessing wireless networks.ISM-1323
    • Issue device and user certificates via an internal PKI for wireless access
  • ✓Certificates are protected by logical and physical access controls, encryption, and user authentication.ISM-1327
    • Store certificate private keys in an HSM/Secrets Manager with access controls and encryption
Caching 802.1X authentication outcomes
  • ✓The PMK caching period is not set to greater than 1440 minutes (24 hours).ISM-1330
Fast Basic Service Set Transition
  • ✓The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.ISM-1712
Remote Authentication Dial-In User Service authentication
  • ✓Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.ISM-1454
    • Implement RadSec (RADIUS over TLS) or IPsec between authenticators and the RADIUS server
Interference between wireless networks
  • ✓Wireless networks implement sufficient frequency separation from other wireless networks.ISM-1334
Protecting management frames on wireless networks
  • ✓Wireless access points enable the use of the 802.11w amendment to protect management frames.ISM-1335
Wireless network footprint
  • ✓Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.ISM-1338
  • –The effective range of wireless communications outside an organisation’s area of control is limited by implementing RF shielding on facilities in which SECRET or TOP SECRET wireless networks are used.ISM-1013
Service continuity for online services
Cloud-based hosting of online services
  • ✓Cloud service providers are used for hosting online services.ISM-1437
Capacity and availability planning and monitoring for online services
  • ✓Cloud service providers’ ability to scale resources dynamically in response to genuine spikes in demand is discussed and verified as part of capacity and availability planning for online services.ISM-1579
    • Document verified AWS dynamic-scaling capability within capacity planning records
  • ✓Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.ISM-1580
    • Architect critical services across multiple AZs with automatic failover
    • Test AZ failover (ASG, Multi-AZ RDS, ALB) and retain results
  • ✓Continuous real-time monitoring of the capacity and availability of online services is performed.ISM-1581
Using content delivery networks
  • ✓Where a high availability requirement exists for website hosting, CDNs that cache websites are used.ISM-1438
    • Deploy CloudFront CDN caching in front of high-availability websites
  • ✓If using CDNs, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.ISM-1439
Denial-of-service attack mitigation strategies
  • ✓Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: their capacity to withstand denial-of-service attacks; costs likely to be incurred as a result of denial-of-service attacks; availability monitoring and thresholds for notification of denial-of-service attacks; thresholds for turning off any online services or functionality during denial-of-service attacks; pre-approved actions that can be undertaken during denial-of-service attacks; any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.ISM-1431
    • Document DoS discussions with AWS: capacity, costs, thresholds and pre-approved actions
    • Configure AWS Shield/WAF alarms and upstream mitigation arrangements
  • ✓Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.ISM-1436
    • Segregate critical services from higher-risk services into separate accounts/VPCs
  • ✓Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.ISM-1432

Guidelines for cryptography

26/59 met
Cryptographic fundamentals
Communications security doctrine
  • –Communications security doctrine and policy produced by ASD for the management and operation of HACE is complied with.ISM-0499
High Assurance Cryptographic Equipment
  • –HACE are issued an Approval for Use by ASD and operated in accordance with the latest version of their associated Australian Communications Security Instructions.ISM-1802
Cryptographic key management processes and procedures
  • ✓Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.ISM-0507
Cryptographic implementation assurance
  • ✓Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.ISM-0457
    • Use FIPS 140-validated modules (AWS KMS) for encrypting data at rest
  • –HACE is used when encrypting media that contains SECRET or TOP SECRET data.ISM-0460
  • ✓Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.ISM-0465
    • Enforce FIPS-validated TLS (ACM/KMS) for data traversing public networks
  • –HACE is used to protect SECRET and TOP SECRET data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.ISM-0467
Data recovery
  • ✓Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.ISM-0455
    • Enable KMS key backup and document a recovery process for unavailable keys
Handling encrypted IT equipment and media
  • ✓When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.ISM-0462
Transporting cryptographic equipment
  • ✓Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.ISM-0501
    • Record AWS KMS/CloudHSM as sole cryptographic equipment in ISMS asset register
    • Document that key material never leaves KMS and is never physically transported
Reporting cryptographic-related cyber security incidents
  • ✓The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.ISM-0142
  • ✓Keying material is changed when compromised or suspected of being compromised.ISM-1091
    • Enable annual automatic key rotation on all KMS customer-managed keys
    • Add key compromise revocation and re-key procedure to incident response runbook
    • Rotate affected Secrets Manager secrets immediately on suspected compromise
Cryptographic algorithms
Using cryptographic algorithms
  • ✓An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.ISM-1080
  • ✓Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.ISM-0471
    • Inventory crypto algorithms across ELB, CloudFront, RDS, S3, KMS and app libraries
    • Replace any non-AACA algorithms found and enforce approved set in coding standards
    • Add cipher/algorithm scanning to CI and periodic config compliance checks
Asymmetric cryptographic algorithms
  • ✓ECDH is used in preference to DH.ISM-0994
Using Diffie-Hellman
  • ✓When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.ISM-0472
  • –When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is used, preferably 3072 bits.ISM-1759
  • ✓When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.ISM-1629
Using Elliptic Curve Cryptography
  • ✓When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.ISM-1446
Using Elliptic Curve Diffie-Hellman
  • ✓When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.ISM-0474
  • –When using ECDH for agreeing on encryption session keys, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P-384 curve.ISM-1761
  • –When using ECDH for agreeing on encryption session keys, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.ISM-1762
Using the Elliptic Curve Digital Signature Algorithm
  • ✓When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.ISM-0475
  • –When using ECDSA for digital signatures, NIST P-256, P-384 or P-521 curves are used, preferably the NIST P- 384 curve.ISM-1763
  • –When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.ISM-1764
Using post-quantum cryptographic algorithms
  • ✓When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.ISM-1990
    • Select FIPS 140-3 validated crypto modules when adopting ML-DSA or ML-KEM
    • Track FIPS validation status of AWS and third-party crypto in procurement
Using the Module-Lattice-Based Digital Signature Algorithm
  • ✓When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.ISM-1991
  • ✓When using ML-DSA for digital signatures, the hedged variant is used whenever possible.ISM-1992
  • ✓Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.ISM-1993
  • ✓When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.ISM-1994
Using the Module-Lattice-Based Key Encapsulation Mechanism
  • ✓When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM- 1024 is used, preferably ML-KEM-1024.ISM-1995
Using Rivest-Shamir-Adleman
  • ✓When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.ISM-0476
  • –When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 3072 bits is used, preferably 3072 bits.ISM-1765
  • ✓When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.ISM-0477
    • Provision separate KMS key pairs for signing versus encryption and key-wrapping
    • Audit application certificates so signing keys are not reused for key transport
Using Secure Hashing Algorithms
  • ✓When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.ISM-1766
  • –When using SHA-2 for hashing, an output size of at least 256 bits is used, preferably SHA-384 or SHA-512.ISM-1767
  • –When using SHA-2 for hashing, an output size of at least 384 bits is used, preferably SHA-384 or SHA-512.ISM-1768
Using symmetric cryptographic algorithms
  • ✓When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.ISM-1769
  • –When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.ISM-1770
  • ✓Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.ISM-0479
Transitioning to post-quantum cryptography
  • ✓A post-quantum cryptography transition plan is developed, implemented and maintained.ISM-2073
  • ✓The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.ISM-1917
    • Build PQC migration roadmap targeting ML-DSA-87, ML-KEM-1024 and AES-256 before 2030
    • Add PQC support as a mandatory requirement in new crypto procurement
    • Inventory quantum-vulnerable algorithms in use to prioritise migration
Post-quantum traditional hybrid schemes
  • ✓When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.ISM-1996
Cryptographic protocols
Using cryptographic protocols
  • ✓An AACP or high assurance cryptographic protocol is used when encrypting data in transit.ISM-0469
  • ✓Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.ISM-0481
    • Enforce TLS 1.2+ predefined security policies on all ALB, CloudFront and API Gateway
    • Scan for and disable legacy protocols (SSLv3, TLS 1.0/1.1) across all endpoints
Transport Layer Security
Configuring Transport Layer Security
  • ✓Only the latest version of TLS is used for TLS connections.ISM-1139
  • ✓AES-GCM is used for encryption of TLS connections.ISM-1369
  • ✓Only server-initiated secure renegotiation is used for TLS connections.ISM-1370
  • ✓DH or ECDH is used for key establishment of TLS connections.ISM-1372
  • ✓When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.ISM-1448
  • ✓Anonymous DH is not used for TLS connections.ISM-1373
  • ✓SHA-2-based certificates are used for TLS connections.ISM-1374
  • ✓SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.ISM-1375
  • ✓TLS compression is disabled for TLS connections.ISM-1553
  • ✓Perfect Forward Secrecy (PFS) is used for TLS connections.ISM-1453
Secure Shell
Configuring Secure Shell
  • ✓The use of SSH version 1 is disabled for SSH connections.ISM-1506
  • ✓The SSH daemon is configured to: only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx); have a suitable login banner (Banner x); have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60); disable host-based authentication (HostbasedAuthentication no); disable rhosts-based authentication (IgnoreRhosts yes); disable the ability to log in directly as root (PermitRootLogin no); disable empty passwords (PermitEmptyPasswords no); disable connection forwarding (AllowTCPForwarding no); disable gateway ports (GatewayPorts no); disable X11 forwarding (X11Forwarding no).ISM-0484
Authentication mechanisms
  • ✓Public key-based authentication is used for SSH connections.ISM-0485
  • ✓SSH private keys are protected with a password or a key encryption key.ISM-1449
Automated remote access
  • ✓When using logins without a password for SSH connections, the following are disabled: access from IP addresses that do not require access; port forwarding; agent credential forwarding; X11 forwarding; console access.ISM-0487
    • Restrict SSH key access to bastion source IPs via security groups
    • Set sshd AllowTcpForwarding no, X11Forwarding no and disable agent forwarding
    • Prefer SSM Session Manager over SSH to remove key-based console access
  • ✓If using remote access without the use of a password for SSH connections, the ‘forced command’ option is used to specify what command is executed and parameter checking is enabled.ISM-0488
SSH-agent
  • ✓When SSH-agent or similar key caching applications are used, it is limited to workstations and servers with screen locks and key caches that are set to expire within four hours of inactivity.ISM-0489
Secure/Multipurpose Internet Mail Extension
Configuring Secure/Multipurpose Internet Mail Extension
  • ✓Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.ISM-0490
Internet Protocol Security
Mode of operation
  • ✓Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.ISM-0494
Protocol selection
  • ✓The ESP protocol is used for authentication and encryption of IPsec connections.ISM-0496
Key exchange
  • ✓IKE version 2 is used for key exchange when establishing IPsec connections.ISM-1233
Encryption algorithms
  • ✓AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.ISM-1771
Pseudorandom function
  • ✓PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.ISM-1772
Integrity algorithms
  • ✓AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.ISM-0998
Diffie-Hellman groups
  • ✓DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072- bit MODP Group or 4096-bit MODP Group.ISM-0999
Security association lifetimes
  • ✓A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.ISM-0498
Perfect Forward Secrecy
  • ✓PFS is used for IPsec connections.ISM-1000

Guidelines for gateways

17/47 met
Gateways
Implementing gateways
  • ✓Gateways are implemented between networks belonging to different security domains.ISM-0628
  • ✓Gateways implement a demilitarised zone if external parties require access to an organisation’s services.ISM-0637
  • ✓Gateways only allow explicitly authorised data flows.ISM-0631
  • ✓Gateways inspect and filter data flows at the transport and above network layers.ISM-1192
  • ✓Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.ISM-1427
System administrators for gateways
  • ✗System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.ISM-1520
  • –System administrators for gateways that connect to Australian Eyes Only or Releasable To networks are Australian nationals.ISM-0613
  • –System administrators for gateways that connect to Australian Government Access Only networks are Australian nationals or seconded foreign nationals.ISM-1773
  • ✓System administrators for gateways are assigned the minimum privileges required to perform their duties.ISM-0611
    • Scope IAM roles for WAF, ALB and network admins to least privilege
    • Review with IAM Access Analyzer to remove unused gateway permissions
  • ✓Separation of duties is implemented in performing administrative activities for gateways.ISM-0616
    • Separate gateway change authoring from approval using distinct IAM roles
    • Require peer-reviewed IaC pull requests for all gateway and WAF changes
  • ✓System administrators for gateways are formally trained on the operation and management of gateways.ISM-0612
    • Deliver formal training on gateway and WAF operation; retain completion records
    • Add gateway admin training to onboarding and annual refresher schedule
System administration of gateways
  • ✓Gateways are managed via a secure path isolated from all connected networks.ISM-1774
  • ✓For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.ISM-0629
    • Define which party administers shared gateway components at PROTECTED boundaries
    • Document admin responsibilities in the gateway interconnect agreement
Authenticating to networks accessed via gateways
  • ✓Users authenticate to other networks accessed via gateways.ISM-0619
  • ✓IT equipment authenticates to other networks accessed via gateways.ISM-0622
    • Require mutual TLS or IAM authentication for services crossing gateway boundaries
    • Authenticate site-to-site VPN and Direct Connect peers with strong credentials
Border Gateway Protocol routing security
  • ✓Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.ISM-1783
  • ✓Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.ISM-2018
    • Publish RPKI ROAs for E1-owned prefixes advertised via Direct Connect
    • Confirm AWS or upstream performs RPKI origin validation and rejects invalid routes
Gateway event logging
  • ✓Security-relevant events for gateways are centrally logged, including: data packets and data flows permitted through gateways; data packets and data flows attempting to leave gateways; real-time alerts for attempted intrusions.ISM-0634
Assessment of gateways
  • ✓Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate that they conform to expected security configurations.ISM-1037
    • Add semi-annual gateway config validation to security calendar
    • Codify expected configs as AWS Config rules and Network Firewall policy baselines
    • Re-run validation and pen test after any gateway/WAF/firewall change
    • Retain dated test reports and remediation tickets as evidence
  • ✗Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.ISM-0100
  • –TOP SECRET gateways undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the assessment (or a subsequent release), at least every 24 months.ISM-2019
Cross Domain Solutions
Implementing Cross Domain Solutions
  • –CDSs are implemented between SECRET or TOP SECRET networks and any other networks belonging to different security domains.ISM-0626
Consultation on Cross Domain Solutions
  • –When planning, designing, implementing or introducing additional connectivity to CDSs, ASD is consulted and any directions provided by ASD are complied with.ISM-0597
Separation of data flows
  • –CDSs implement isolated upward and downward network paths.ISM-0635
  • –CDSs implement independent security-enforcing functions for upward and downward network paths.ISM-1522
  • –CDSs implement protocol breaks at each network layer.ISM-1521
Cross Domain Solution event logging
  • –Security-relevant events for CDSs are centrally logged.ISM-0670
  • –A sample of security-relevant events relating to data transfer policies are taken at least every three months and assessed against security policies for CDSs to identify any operational failures.ISM-1523
User training
  • –Users are trained on the secure use of CDSs before access is granted.ISM-0610
Firewalls
Using firewalls
  • ✓Evaluated firewalls are used between an organisation’s networks and public network infrastructure.ISM-1528
  • ✓Evaluated firewalls are used between networks belonging to different security domains.ISM-0639
    • Deploy AWS Network Firewall between VPCs of differing trust levels
    • Document security domains and enforce segmentation via NACLs and security groups
    • Select firewall products with recognised evaluation/certification for PROTECTED path
Web application firewalls
Using web application firewalls
  • ✓If using a WAF, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.ISM-1862
Diodes
Using diodes
  • ✓Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation’s networks and public network infrastructure.ISM-0643
  • –Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and public network infrastructure complete a high assurance evaluation.ISM-0645
  • ✓Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.ISM-1157
    • Confirm whether any unidirectional data flows exist in the architecture
    • If none, document diode control as not applicable with justification
    • If required for PROTECTED, source an evaluated hardware data diode
  • –Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and any other networks complete a high assurance evaluation.ISM-1158
Web proxies
Using web proxies
  • ✓All web access, including that by internal servers, is conducted through web proxies.ISM-0260
Web proxy event logging
  • ✓The following details are centrally logged for websites accessed via web proxies: web address; date and time; user; amount of data uploaded and downloaded; internal and external IP addresses.ISM-0261
    • Route all workload/staff egress through AWS Network Firewall or Squid proxy
    • Log web address, timestamp, user, bytes up/down, src/dst IP
    • Ship proxy logs centrally to CloudWatch Logs or the SIEM
Web content filters
Using web content filters
  • ✓Web content filtering is implemented to filter potentially harmful web-based content.ISM-0963
  • ✓Client-side active content is restricted by web content filters to an organisation-approved list of domain names.ISM-0961
    • Enforce egress domain allowlist for active content via Network Firewall FQDN rules
    • Maintain and review the approved-domains list under change control
  • ✓Web content filtering is applied to outbound web traffic where appropriate.ISM-1237
Transport Layer Security filtering
  • ✓TLS traffic communicated through gateways is decrypted and inspected.ISM-0263
    • Enable TLS inspection on AWS Network Firewall with a managed CA
    • Define decrypt/bypass rules and exclude sensitive categories per policy
    • Feed decrypted traffic into content and malware inspection
Allowing and blocking access to domain names
  • ✓An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.ISM-0958
  • ✓Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.ISM-1236
  • ✓Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.ISM-1171
    • Add Network Firewall rules blocking HTTP/HTTPS to bare IP hosts
    • Force resolution through DNS allowlist so IP-literal requests fail
Content filtering
Performing content filtering
  • ✓Files imported or exported via gateways or CDSs undergo content filtering checks.ISM-0659
    • Trigger a Lambda content-filtering scan on every S3 file upload
    • Apply the same filtering pipeline to files exported/downloaded from the platform
    • Log filter verdicts centrally for audit
  • ✓Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.ISM-0651
    • Block and delete files flagged malicious or that cannot be inspected
    • Return an upload error and alert security on block events
  • ✓Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.ISM-0652
    • Move suspicious files to a locked quarantine S3 bucket
    • Require analyst review before release or deletion
    • Track quarantine decisions with approver and timestamp
  • –Content filters used by CDSs undergo rigorous security testing to ensure they perform as expected and cannot be bypassed.ISM-1524
Encrypted files
  • ✓Encrypted files imported or exported via gateways or CDSs are decrypted to undergo content filtering checks.ISM-1293
    • Attempt decryption of encrypted uploads before content filtering
    • Block files that cannot be decrypted for inspection
Archive files
  • ✓Archive files imported or exported via gateways or CDSs are unpacked to undergo content filtering checks.ISM-1289
    • Unpack archive uploads in the scanning Lambda before filtering
    • Recursively scan nested archive contents
  • ✓Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.ISM-1290
    • Cap archive recursion depth, entry count, and decompressed size
    • Reject zip bombs and time-out oversized unpacking to protect availability
Antivirus scanning
  • ✓Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.ISM-1288
    • Integrate two independent AV engines in the upload scanning pipeline
    • Block files any engine flags; keep signatures auto-updated
Automated dynamic analysis
  • ✓Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.ISM-1389
    • Detonate uploaded executables in a sandbox before release
    • Wire in a sandbox service and block on suspicious behaviour verdicts
Allowing specific content types
  • ✓Files imported or exported via gateways or CDSs are filtered for allowed file types.ISM-0649
    • Enforce a file-type allowlist at the upload API before storing in S3
    • Validate magic-byte signatures, not just extensions
Content validation
  • ✓Files imported or exported via gateways or CDSs undergo content validation.ISM-1284
    • Validate that file structure conforms to its declared type spec
    • Reject files failing structural validation
Content checking
  • ✓Files imported or exported via gateways or CDSs undergo content checking.ISM-1965
    • Scan file contents for keywords and unsuitable data patterns
    • Log and act on content-check hits
Content conversion
  • ✓Files imported or exported via gateways or CDSs undergo content conversion.ISM-1286
    • Convert risky formats to safer representations on import where feasible
    • Document conversion mappings and exceptions
Content sanitisation
  • ✓Files imported or exported via gateways or CDSs undergo content sanitisation.ISM-1287
    • Apply content disarm and reconstruction to strip active content from documents
    • Integrate a CDR engine into the upload pipeline
Validating file integrity
  • ✓Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.ISM-0677
    • Verify digital signatures or checksums on files that carry them
    • Block or flag files that fail integrity validation
Peripheral switches
Using peripheral switches
  • ✓Evaluated peripheral switches are used when sharing peripherals between systems.ISM-0591
    • Document control as not applicable: cloud-only, no shared physical peripherals
    • Record justification in the SSP applicability register
  • –Evaluated peripheral switches used for sharing peripherals between SECRET and TOP SECRET systems, or between SECRET or TOP SECRET systems belonging to different security domains, preferably complete a high assurance evaluation.ISM-1457
  • –Evaluated peripheral switches used for sharing peripherals between SECRET or TOP SECRET systems and any non-SECRET or TOP SECRET systems complete a high assurance evaluation.ISM-1480

Guidelines for data transfers

1/8 met
Data transfers
Data transfer processes and procedures
  • ✓Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.ISM-0663
  • –Processes, and supporting procedures, are developed, implemented and maintained to prevent AUSTEO, AGAO and REL data in textual and non-textual formats from being exported to unsuitable foreign systems.ISM-1535
User responsibilities
  • ✓Users transferring data to and from systems are held accountable for data transfers they perform.ISM-0661
    • Attribute every upload/download to an authenticated user in logs
    • Require signed AUP acknowledging data-transfer accountability
    • Surface transfer activity in user-attributable audit reports
Manual import of data
  • ✓When manually importing data to systems, the data is scanned for malicious and active content.ISM-0657
    • Scan all manually imported data for malware and active content on ingest
    • Block active content unless explicitly approved
  • ✓When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.ISM-1778
    • Quarantine imports failing security checks in a locked bucket
    • Require review and explicit approval before release
Authorising export of data
  • –Data exported from SECRET and TOP SECRET systems is reviewed and authorised by a trustworthy source beforehand.ISM-0664
  • –Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a trustworthy source.ISM-0675
  • –Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services that have been verified and authorised as such by the chief information security officer.ISM-0665
Manual export of data
  • ✓When manually exporting data from systems, the data is checked for unsuitable protective markings.ISM-1187
    • Check exported data for unsuitable or missing protective markings
    • Block exports whose markings exceed the destination's authorised level
  • –When manually exporting data from SECRET and TOP SECRET systems, digital signatures are validated and keyword checks are performed within all textual data.ISM-0669
  • ✓When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.ISM-1779
    • Quarantine exports failing security checks pending review
    • Record approve/deny decisions with approver identity
Monitoring data import and export
  • ✓Data transfer logs are used to record all data imports and exports from systems.ISM-1586
    • Log every data import and export with user, file, and timestamp
    • Centralise transfer logs in CloudWatch/SIEM with retention
  • ✓Data transfer logs for systems are partially verified at least monthly.ISM-1294
    • Schedule monthly partial review of data transfer logs
    • Retain signed review records as evidence
    • Alert on anomalous transfer volumes between reviews
  • –Data transfer logs for SECRET and TOP SECRET systems are fully verified at least monthly.ISM-0660
Shared responsibility

Shared responsibility

E1 secures the platform. Customers remain responsible for how they classify, share and manage their own information.

  • Classify information correctly before uploading it
  • Restrict tender access to authorised recipients
  • Remove access when it is no longer required
  • Follow any project-specific handling instructions
  • Confirm contractual DISP, residency, personnel and clearance requirements
i

Where a tender, contract or security instruction expressly requires DISP membership, an accredited system, Australian-based personnel, security clearances or another specific control, customers should confirm those requirements with their Defence contract manager or legal adviser before uploading the information.

In summary

E1 supports OFFICIAL: Sensitive today. Its platform already implements strong security controls, including near-complete alignment with Essential Eight Maturity Level 3. This provides a substantial foundation for future PROTECTED support, although further evidence, ISM alignment and independent assessment are still required.

This statement describes E1's standard platform scope. It is not a determination that every Defence project or contract permits the use of E1.