Australia · Australian Signals Directorate (ASD) / ACSC · ISM

Information Security Manual

The ASD's cybersecurity framework used by Australian Government agencies to protect their information and systems.

What it is

The Information Security Manual (ISM) is the ASD's risk-based framework for protecting government information and systems from cyber threats, applied through each entity's own risk-management approach. It is structured around cyber-security principles and associated controls. Agencies apply controls relative to the classification of the data being protected, from OFFICIAL through to TOP SECRET. For IRAP assessments, the ISM is the authoritative control catalogue.

Who it applies to

Non-corporate Commonwealth entities (mandatorily, via the PSPF) and corporate Commonwealth entities under the Archives Act. Widely adopted by state and territory governments and by suppliers handling government data.

Requirements

Govern

Identify and manage security risks, roles, accountabilities and reporting - tied to the agency risk framework.

Protect

Implement security controls to reduce security risks, across personnel, information, cyber, physical, ICT and supply chain.

Detect

Detect and understand cybersecurity events, including monitoring of systems and analysis of event data.

Respond

Respond to and recover from cybersecurity incidents through planning, exercises and post-incident review.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.