ISM: Australian Government Information Security Manual
The Australian Government Information Security Manual (ISM) is the comprehensive information security reference published by the Australian Signals Directorate (ASD). It provides a cybersecurity framework for Australian government entities and their contractors, covering everything from governance and personnel security to technical controls and cryptographic standards. The ISM is updated regularly to address emerging threats and incorporates the Essential Eight — ASD's prioritized list of mitigation strategies.
What the ISM Is and Who Issues It
The ISM is published by the Australian Signals Directorate (ASD), Australia's foreign signals intelligence and cybersecurity agency, operating under the Department of Defence. ASD has a dual role: collecting foreign intelligence and protecting Australian government systems and critical infrastructure. This intelligence-informed perspective gives the ISM a distinctive quality — its controls reflect real-world threat intelligence from ASD's visibility into adversary activity targeting Australian government and critical sector systems.
The ISM is a living document updated multiple times per year to reflect new threats, new technology, and revised guidance. The current version (March 2025) represents the latest iteration of a document that has evolved from its origins in 2010 into one of the most comprehensive government information security manuals in the world. ASD publishes the ISM on its website (asd.gov.au) as a freely accessible HTML document, organized by topic rather than issued as a traditional PDF standard.
The ISM operates within Australia's broader information security framework. The Protective Security Policy Framework (PSPF), issued by the Attorney-General's Department, sets the overarching government security requirements. The ISM provides the technical cybersecurity controls that implement PSPF requirements. Together, they form the mandatory framework for non-corporate Commonwealth entities, with adoption expected or mandated for state/territory governments and contractors.
The ISM is distinct from ACSC (Australian Cyber Security Centre) publications, though ACSC sits within ASD and its threat advisories and advisory materials complement the ISM. The Essential Eight Maturity Model — now formally part of the ISM framework — was developed by ACSC/ASD as a prioritized subset of ISM controls.
Who Needs ISM Compliance
Commonwealth government entities: All non-corporate Commonwealth entities (federal government departments and agencies) are required to comply with the ISM. Corporate Commonwealth entities (government business enterprises) are expected to consider and apply ISM principles. State and territory governments increasingly reference the ISM for their own entities.
Defense contractors and industry partners: Companies holding contracts with Defence or other security-sensitive agencies must demonstrate ISM compliance for the systems they operate on behalf of or in support of government. DISP (Defence Industry Security Program) membership requires alignment with ISM and related standards. Contractors handling PROTECTED or higher-classified information must meet the most stringent ISM requirements.
Critical infrastructure operators: Australia's Security of Critical Infrastructure Act 2018 (SOCI Act) applies to critical infrastructure sectors including energy, communications, water, transport, health, food, finance, data storage, and defense industry. The ISM is referenced in sector-specific security rules under SOCI, making it relevant for operators of systems of national significance.
Government service providers and cloud providers: Technology providers — including SaaS and cloud service providers — who want to sell to Australian government must be able to demonstrate alignment with relevant ISM controls. The ASD-certified cloud services list recognizes cloud providers that have been assessed against ISM controls.
Financial sector: While APRA CPS 234 is the primary framework for APRA-regulated entities, ISM alignment is increasingly referenced in government financial sector contracts and regulatory guidance, particularly for entities that interface with government systems.
The Essential Eight: Core Controls in Depth
At the heart of ISM compliance for most organizations are the Essential Eight — eight mitigation strategies that ASD identifies as the most effective countermeasures against common cyber attack patterns. The Essential Eight have a Maturity Model from Level Zero (not implemented or not effective) to Level Three (full implementation aligned with the ASD's recommended configuration).
1. Application Control Prevent execution of unapproved or malicious programs by maintaining an approved list of applications, scripts, and executables. At higher maturity levels, application control extends to scripts, libraries, and interpreted code. This control directly addresses drive-by downloads, phishing payloads, and malicious software execution.
2. Patch Applications Apply security patches for applications within defined timeframes. ASD guidance specifies patching within 2 weeks for internet-facing applications at Maturity Level 2, and within 48 hours for exploitable vulnerabilities at Maturity Level 3. Unpatched applications remain one of the most common initial access vectors.
3. Configure Microsoft Office Macro Settings Block macros from the internet; allow only digitally signed macros from trusted sources. Malicious macros embedded in Office documents distributed via email remain a persistent attack vector. This control substantially reduces the success rate of phishing-based attacks.
4. User Application Hardening Configure web browsers and PDF viewers to disable flash (now effectively universal), Java from the internet, and other unnecessary browser plugins and extensions. Block web advertisements that could contain malicious code. This reduces the attack surface presented by client-side applications.
5. Restrict Administrative Privileges Limit administrator accounts to specific administrative tasks; prohibit use of privileged accounts for email, web browsing, and daily work. Implement just-in-time and just-enough access for administrative functions. Restricting privileges contains the blast radius of credential compromise and lateral movement.
6. Patch Operating Systems Apply operating system security patches within defined timeframes — within 2 weeks at Maturity Level 2, within 48 hours for exploitable vulnerabilities at Maturity Level 3. End-of-life operating systems with no vendor support must be replaced or isolated. OS patching closes the vulnerability classes most commonly exploited in ransomware attacks.
7. Multi-Factor Authentication Require MFA for remote access, privileged accounts, and user access to important data repositories. At higher maturity levels, MFA covers all user accounts and all internet-facing services. MFA is among the most effective controls against identity-based attacks; ASD data suggests MFA alone prevents the majority of identity-based compromises observed in Australian incidents.
8. Regular Backups Maintain offline, encrypted, tested backups of important data and systems. Backups must be tested periodically to verify restoration capability. Offline copies (not accessible from production systems) protect against ransomware that targets backup systems to prevent recovery.
The Essential Eight Maturity Model
Each of the Essential Eight has defined requirements at four maturity levels:
Maturity Level Zero: Controls not implemented or not effective against commodity threats.
Maturity Level One: Controls implemented to reduce exposure to targeted attacks, adversaries using commodity techniques. This is the minimum recommended starting point for most organizations.
Maturity Level Two: Controls implemented to reduce exposure to adversaries operating with more sophisticated techniques, willing to invest more time and effort. Most non-corporate Commonwealth entities are expected to achieve Maturity Level Two across all eight strategies.
Maturity Level Three: Controls aligned with intent, targeting sophisticated adversaries using advanced techniques. Required for entities handling PROTECTED or higher-classified information, or those identified as having significant exposure to advanced persistent threats (APTs).
Achieving all eight strategies at the same maturity level is recommended — an organization at Maturity Level Three in seven strategies but Level Zero in one has a significant gap that adversaries can exploit.
Broader ISM Controls Beyond the Essential Eight
While the Essential Eight get the most attention, the ISM contains over 800 controls covering the complete security landscape for government information systems:
Security governance: Risk management, security plans, security policies, security awareness and training, personnel security including background checks and clearances.
Physical security: Secure facilities, server room controls, visitor management, clean desk policies, physical media handling.
Information classification and handling: Australia's government classification system (OFFICIAL, OFFICIAL: Sensitive, PROTECTED, SECRET, TOP SECRET) with specific handling rules for each level. Higher-classified systems face significantly more stringent control requirements.
Cryptographic security: Use of Australian Signals Directorate-approved cryptographic algorithms and products. High-assurance cryptography requirements for PROTECTED and above.
Network security: Gateway security requirements, network segmentation, protective monitoring, and event logging requirements.
System authorization: Formal authorization-to-operate processes for government systems, including security risk assessment, security documentation, and ongoing monitoring obligations.
Assessment and Authorization Process
Unlike ISO 27001, which uses third-party certification bodies, ISM compliance uses a government-specific authorization model:
Security Risk Assessment: The system owner (agency or contractor) conducts a security risk assessment covering all relevant ISM controls, identifying residual risks after controls are implemented.
Security Documentation: Systems above OFFICIAL require formal security documentation including a System Security Plan (SSP), Security Risk Management Plan, and supporting evidence.
Independent Security Assessment: For PROTECTED and above systems, an independent assessment by an ASD-approved assessor or the Australian Signals Directorate itself validates the security documentation and control implementation.
Authorization to Operate (ATO): The authorizing official (typically a senior agency executive) reviews the security risk assessment and accepts residual risks, granting an ATO. The ATO is a formal risk acceptance decision, not a certification that all risks are eliminated.
Continuous Monitoring: Post-authorization, systems must be monitored continuously. Changes to systems, threat environments, or risk profiles trigger reassessment.
Costs and Timeline
| Activity | Typical Cost (AUD equiv.) | Timeline |
|---|---|---|
| Essential Eight gap assessment | $15,000 – $40,000 | 2–4 weeks |
| Essential Eight implementation (Level 2) | $30,000 – $150,000 | 2–4 months |
| Essential Eight implementation (Level 3) | $80,000 – $250,000 | 4–8 months |
| Full ISM compliance (OFFICIAL) | $30,000 – $100,000 | 3–6 months |
| Full ISM compliance (PROTECTED) | $150,000 – $500,000+ | 6–18 months |
| Security documentation and SSP | $15,000 – $50,000 | 4–8 weeks |
| Independent security assessment | $30,000 – $100,000 | 4–8 weeks |
Comparison with Related Frameworks
ISO 27001 (55% overlap): ISO 27001 and the ISM share significant control overlap but serve different purposes. ISO 27001 is internationally recognized and certification is available through commercial certification bodies. ISM compliance is required for Australian government systems. Organizations holding ISO 27001 have a strong foundation for ISM compliance but must address ISM-specific requirements — particularly around classification, cryptographic standards, and the Essential Eight's specific configuration requirements.
NIST SP 800-53 (65% overlap): NIST SP 800-53 is the US government's comprehensive control catalogue. The ISM draws on similar principles with similar control coverage. Organizations familiar with NIST SP 800-53 from US government work will find ISM structure recognizable. The Essential Eight maps broadly to NIST SP 800-53 control families but with different implementation specifications.
Essential Eight (80% overlap): The Essential Eight is a subset of the ISM. Full ISM compliance encompasses the Essential Eight plus the broader control set. Organizations mandated to comply with the ISM must address the Essential Eight, but cannot claim ISM compliance by implementing only the Essential Eight.
How Automation Helps
Managing ISM compliance — tracking Essential Eight maturity levels, monitoring control implementation, collecting evidence for authorization documentation, and maintaining current posture as the ISM is updated — benefits significantly from compliance automation. LowerPlane supports Australian government compliance frameworks including ISM and the Essential Eight across its 50+ framework library, with evidence management and maturity tracking. Starting at $4,000 per year with a free tier, it is rated 9.4/10 by AuditXYZ users. See best compliance automation platforms for a full comparison.
Frequently Asked Questions
Is the Essential Eight sufficient for ISM compliance? No. The Essential Eight represents a prioritized subset of ISM controls targeting the most common attack vectors. Full ISM compliance requires addressing the complete set of applicable controls for the system's classification level. For systems handling OFFICIAL information with no particularly sensitive content, the Essential Eight provides a strong baseline but does not cover all ISM requirements (governance, personnel security, physical security, etc.).
How does the PSPF relate to the ISM? The Protective Security Policy Framework (PSPF) is the overarching Australian government security policy. It covers personnel security, physical security, and information security. The ISM provides the technical cybersecurity controls that implement the PSPF's information security requirements. Both are mandatory for non-corporate Commonwealth entities. Contractors and service providers to government must meet requirements from both frameworks as specified in their contracts.
What is ASD certification for cloud services and how does it relate to ISM? ASD operates a cloud services certification programme — the Certified Cloud Services List (CCSL) — that assesses cloud providers against ISM controls relevant to cloud hosting. Government agencies are encouraged to use CCSL-listed services for systems up to the relevant classification level. Cloud providers wanting to serve the Australian government should pursue CCSL assessment, which requires comprehensive documentation of controls and an independent assessment against ISM requirements.
Can Maturity Level Three of the Essential Eight be maintained with automated tools? Yes, and automation is effectively necessary at Level Three given the stringent requirements. Maturity Level Three requires application control covering scripts and interpreted code (not just executables), patching within 48 hours of exploitable vulnerability disclosure, and MFA for all user accounts including non-privileged accounts. Manual processes cannot reliably meet 48-hour patching timelines at scale — automated patch deployment and vulnerability scanning are required. Compliance automation and configuration management tools are standard at this maturity level.
How frequently is the ISM updated and how should organizations manage changes? ASD updates the ISM multiple times per year — typically with quarterly or more frequent updates. Changes may add new controls, modify existing requirements, or remove outdated guidance. Organizations must monitor ISM updates and assess the impact on their compliance posture. Subscribing to ASD update notifications and including ISM version review in change management processes is best practice. Compliance automation platforms that maintain current framework content help organizations track changes without manual monitoring.