Right Fit For Risk · ISM June 2026 · Statement of Applicability
The RFFR Statement of Applicability is 996 controls: 7 program-deed obligations and all 989 Australian Government ISM controls that apply to Non-Classified and OFFICIAL: Sensitive information, across 22 guidelines. This is the whole list — filter it, and see which controls our Checkpoint console assesses automatically from your Microsoft 365 tenant.
Each read-only Microsoft Graph posture check maps to specific ISM controls. When Checkpoint scans your tenant, the live signal proposes an implementation status a practitioner confirms — no manual evidence gathering for the technical baseline. These 48 controls are assessed directly; adding the 126 Essential Eight-mapped controls (delivered through the bundled E8 module) brings the Microsoft-assessable share of the SoA to about 14%. The controls beyond that (governance, personnel, physical, documentation, procurement) stay practitioner-assessed by design; a manual result is never silently counted as a pass.
| Microsoft posture check | ISM controls assessed | Example control IDs |
|---|---|---|
| Patching & vulnerability scanning | 7 | ISM-1876, ISM-1690, ISM-1691, ISM-1692 +3 |
| MFA — all users (Conditional Access) | 6 | ISM-1504, ISM-1679, ISM-1892, ISM-1893 +2 |
| Microsoft Office macro hardening | 5 | ISM-1671, ISM-1488, ISM-1672, ISM-1673 +1 |
| Application control (WDAC) | 5 | ISM-0843, ISM-1490, ISM-1656, ISM-1870 +1 |
| Centralised event logging | 4 | ISM-1405, ISM-1983, ISM-1985, ISM-1815 |
| Backups & restoration testing | 4 | ISM-1511, ISM-1810, ISM-1811, ISM-1515 |
| Privileged / admin account limits | 3 | ISM-1507, ISM-1508, ISM-1852 |
| Managed / compliant devices (Intune) | 3 | ISM-1400, ISM-1482, ISM-1195 |
| Protective markings & sensitivity labels | 3 | ISM-0271, ISM-1187, ISM-0272 |
| Just-in-time privileged access (PIM) | 2 | ISM-1649, ISM-1647 |
| Access re-validation & reviews | 2 | ISM-1647, ISM-1509 |
| Encryption (ASD-approved cryptography) | 2 | ISM-1059, ISM-1781 |
| Antivirus / malicious-code protection | 2 | ISM-1417, ISM-1288 |
| MFA — privileged users | 1 | ISM-1173 |
| 14 checks | 48 | distinct ISM controls (~5% of the SoA) |
All 996 controls, grouped by guideline. Filter by guideline, or show only the RFFR Core Expectations, Essential Eight-mapped, or Microsoft-automated controls.
Prior to offering employment, and on-going requirements to maintain employment, the individual's identity is positively confirmed.
Prior to offering employment, and on-going requirements to maintain employment, the competency of the individual is verified via qualifications, certifications and experience provided on their CV.
Prior to offering employment, and on-going requirements to maintain employment, a police check and Working with Vulnerable People check are completed per requirements in each state and territory. https://aifs.gov.au/resources/resource-sheets/pre-employment-screening-working-children-checks-and-police-checks
Prior to offering employment, and on-going requirements to maintain employment, it is confirmed that the individual has a valid right to work in Australia.
In considering results of pre-employment checks (e.g. if a person has a criminal record), consideration will be limited to information that impacts on the person’s ability to perform the inherent requirements of the job, consistent with anti-discrimination legislation.
IT Administrators are Australian citizens or permanent residents to give them sufficient connection with Australia.
In accordance with privacy requirements of contracts held, data relating to the Services is not accessible from outside of Australia, and no data relating to the Services is transferred or stored outside of Australia, without prior written approval from the Department.
The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.
Board of directors and executive committee › Embedding cyber security
The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.
Board of directors and executive committee › Embedding cyber security
The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.
Board of directors and executive committee › Embedding cyber security
The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.
Board of directors and executive committee › Embedding cyber security
The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.
Board of directors and executive committee › Championing a positive cyber security culture
The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.
Board of directors and executive committee › Building cyber security expertise
The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.
Board of directors and executive committee › Building cyber security expertise
The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.
Board of directors and executive committee › Building cyber security expertise
The board of directors or executive committee understands the business criticality of their organisation’s systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.
Board of directors and executive committee › Identifying critical business assets
The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.
Board of directors and executive committee › Planning for major cyber security incidents
A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).
Chief information security officer › Providing cyber security leadership and guidance
The CISO oversees their organisation’s cyber security program and ensures their organisation’s compliance with cyber security policy, standards, regulations and legislation.
Chief information security officer › Overseeing the cyber security program
The CISO regularly reviews and updates their organisation’s cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.
Chief information security officer › Overseeing the cyber security program
The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.
Chief information security officer › Overseeing the cyber security program
The CISO implements cyber security measurement metrics and key performance indicators for their organisation.
Chief information security officer › Overseeing the cyber security program
The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.
Chief information security officer › Coordinating cyber security
The CISO coordinates security risk management activities between cyber security and business teams.
Chief information security officer › Coordinating cyber security
The CISO regularly reports directly to their organisation’s board of directors or executive committee on cyber security matters.
Chief information security officer › Reporting on cyber security
The CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters.
Chief information security officer › Reporting on cyber security
The CISO is fully aware of all cyber security incidents within their organisation.
Chief information security officer › Overseeing cyber security incident response activities
The CISO oversees their organisation’s response to cyber security incidents.
Chief information security officer › Overseeing cyber security incident response activities
The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.
Chief information security officer › Contributing to business continuity and disaster recovery planning
The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.
Chief information security officer › Communicating a cyber security vision and strategy
The CISO oversees cyber supply chain risk management activities for their organisation.
Chief information security officer › Working with suppliers
The CISO receives and manages a dedicated cyber security budget for their organisation.
Chief information security officer › Receiving and managing a dedicated cyber security budget
The CISO oversees the management of cyber security personnel within their organisation.
Chief information security officer › Overseeing cyber security personnel
The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.
Chief information security officer › Overseeing cyber security personnel
The CISO oversees the development, implementation and maintenance of their organisation’s cyber security awareness training program.
Chief information security officer › Overseeing cyber security awareness training
Each system has a designated system owner.
System owners › System ownership and oversight
System owners register each system with its authorising officer.
System owners › System ownership and oversight
System owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.
System owners › Protecting systems and their resources
System owners, in consultation with each system’s authorising officer, conduct a threat and risk assessment for each system.
System owners › Protecting systems and their resources
System owners, in consultation with each system’s authorising officer, select controls for each system and tailor them to achieve desired security and resilience objectives.
System owners › Protecting systems and their resources
System owners, in consultation with each system’s authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation’s risk tolerances.
System owners › Protecting systems and their resources
System owners implement controls for each system and its operating environment.
System owners › Protecting systems and their resources
System owners, in consultation with each system’s authorising officer, ensure controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation’s own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.
System owners › Protecting systems and their resources
System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.
System owners › Protecting systems and their resources
System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.
System owners › Protecting systems and their resources
System owners implement and maintain data minimisation practices for each of their systems.
System owners › Protecting systems and their resources
System owners report the security status of each system to its authorising officer at least annually.
System owners › Annual reporting of system security status
A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.
Managing cyber security incidents › Cyber security incident management policy
The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.
Managing cyber security incidents › Cyber security incident management policy
A cyber security incident register is developed, implemented and maintained.
Managing cyber security incidents › Cyber security incident register
A cyber security incident register contains the following for each cyber security incident: • the date the cyber security incident occurred • the date the cyber security incident was discovered • a description of the cyber security incident • any actions taken in response to the cyber security incident • to whom the cyber security incident was reported.
Managing cyber security incidents › Cyber security incident register
An insider threat mitigation program is developed, implemented and maintained.
Managing cyber security incidents › Insider threat mitigation program
Legal advice is sought regarding the development and implementation of an insider threat mitigation program.
Managing cyber security incidents › Insider threat mitigation program
Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.
Managing cyber security incidents › Reporting cyber security incidents
Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.
Managing cyber security incidents › Reporting cyber security incidents to ASD
Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
Managing cyber security incidents › Reporting cyber security incidents to customers and the public
Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
Managing cyber security incidents › Reporting cyber security incidents to customers and the public
Following the identification of a cyber security incident, the cyber security incident response plan is enacted.
Responding to cyber security incidents › Enacting cyber security incident response plans
When a data spill occurs, data owners are advised and access to the data is restricted.
Responding to cyber security incidents › Handling and containing data spills
When malicious code is detected, the following steps are taken to handle the infection: • the infected systems are isolated • all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary • antivirus applications are used to remove the infection from infected systems and media • if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.
Responding to cyber security incidents › Handling and containing malicious code infections
Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
Responding to cyber security incidents › Handling and containing malicious code infections
Malicious code processing for cyber security incident response or research purposes is conducted in a dedicated analysis environment segregated from other systems.
Responding to cyber security incidents › Handling and containing malicious code infections
Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.
Responding to cyber security incidents › Handling and containing intrusions
System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.
Responding to cyber security incidents › Handling and containing intrusions
Planning and coordination of intrusion remediation activities are conducted on a separate system to that which has been compromised.
Responding to cyber security incidents › Handling and containing intrusions
To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.
Responding to cyber security incidents › Handling and containing intrusions
Following intrusion remediation activities, full network traffic is captured for at least seven days and analysed to determine whether malicious actors have been successfully removed from the system.
Responding to cyber security incidents › Handling and containing intrusions
The integrity of evidence gathered during an investigation is maintained by investigators: • recording all their actions • maintaining a proper chain of custody • following all instructions provided by relevant law enforcement agencies.
Responding to cyber security incidents › Maintaining the integrity of evidence
Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.
Cyber supply chain risk management › Cyber supply chain risk management activities
A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system’s security risk profile.
Cyber supply chain risk management › Cyber supply chain risk management activities
Suppliers identified as high risk by a cyber supply chain risk assessment are not used.
Cyber supply chain risk management › Cyber supply chain risk management activities
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.
Cyber supply chain risk management › Cyber supply chain risk management activities
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.
Cyber supply chain risk management › Cyber supply chain risk management activities
Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.
Cyber supply chain risk management › Cyber supply chain risk management activities
A shared responsibility model is created, documented and shared between suppliers and their customers to articulate the security responsibilities of each party.
Cyber supply chain risk management › Cyber supply chain risk management activities
A supplier relationship management policy is developed, implemented and maintained.
Cyber supply chain risk management › Supplier relationship management
An approved supplier list is developed, implemented and maintained.
Cyber supply chain risk management › Supplier relationship management
Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.
Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services
Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.
Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services
Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.
Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services
Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.
Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services
The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.
Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services
The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.
Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services
A managed service register is developed, implemented, maintained and regularly verified.
Managed services and cloud services › Managed services
A managed service register contains the following for each managed service: • managed service provider’s name • managed service’s name • purpose for using the managed service • sensitivity or classification of data involved • due date for the next security assessment of the managed service • contractual arrangements for the managed service • point of contact for users of the managed service • 24/7 contact details for the managed service provider.
Managed services and cloud services › Managed services
Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
Managed services and cloud services › Assessment of managed service providers
An outsourced cloud service register is developed, implemented, maintained and regularly verified.
Managed services and cloud services › Outsourced cloud services
An outsourced cloud service register contains the following for each outsourced cloud service: • cloud service provider’s name • cloud service’s name • purpose for using the cloud service • sensitivity or classification of data involved • due date for the next security assessment of the cloud service • contractual arrangements for the cloud service • point of contact for users of the cloud service • 24/7 contact details for the cloud service provider.
Managed services and cloud services › Outsourced cloud services
Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
Managed services and cloud services › Assessment of outsourced cloud service providers
Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.
Managed services and cloud services › Contractual security requirements with service providers
Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.
Managed services and cloud services › Contractual security requirements with service providers
The right to verify compliance with security requirements is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.
Managed services and cloud services › Contractual security requirements with service providers
Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
Types of data and its ownership is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
Access to all logs relating to an organisation’s data and services is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.
Managed services and cloud services › Contractual security requirements with service providers
An organisation’s systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.
Managed services and cloud services › Access to systems by service providers
If an organisation’s systems are accessed or administered by a service provider in an unauthorised manner, the organisation is immediately notified.
Managed services and cloud services › Access to systems by service providers
A cyber security strategy is developed, implemented and maintained.
Development and maintenance of cyber security documentation › Cyber security strategy
Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system’s authorising officer.
Development and maintenance of cyber security documentation › Approval of cyber security documentation
A system’s security architecture is approved prior to the development of the system.
Development and maintenance of cyber security documentation › Approval of cyber security documentation
Cyber security documentation is reviewed at least annually and includes a ‘current as at [date]’ or equivalent statement.
Development and maintenance of cyber security documentation › Maintenance of cyber security documentation
Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.
Development and maintenance of cyber security documentation › Communication of cyber security documentation
Systems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is managed) as well as an annex that covers applicable controls from this document and any additional controls that have been identified and implemented.
System-specific cyber security documentation › System security plan
Systems have a cyber security incident response plan that covers the following: • guidelines on what constitutes a cyber security incident • the types of cyber security incidents likely to be encountered and the expected response to each type • how to report cyber security incidents, internally to an organisation and externally to relevant authorities • other parties that need to be informed in the event of a cyber security incident • the authority, or authorities, responsible for investigating and responding to cyber security incidents • the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority • the steps necessary to ensure the integrity of evidence relating to a cyber security incident • system contingency measures or a reference to such details if they are in a separate document.
System-specific cyber security documentation › Cyber security incident response plan
Systems have a change and configuration management plan that includes: • the establishment and maintenance of authorised baseline configurations for systems • what constitutes routine and urgent changes to the configuration of systems • how changes to the configuration of systems will be requested, tracked and documented • who needs to be consulted prior to routine and urgent changes to the configuration of systems • who needs to approve routine and urgent changes to the configuration of systems • who needs to be notified of routine and urgent changes to the configuration of systems • what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.
System-specific cyber security documentation › Change and configuration management plan
Systems have a continuous monitoring plan that includes: • conducting security assessment activities to identify vulnerabilities • analysing identified vulnerabilities to determine their potential impact • implementing mitigations based on risk, effectiveness and cost.
System-specific cyber security documentation › Continuous monitoring plan
At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: • the scope of the security assessment • the system’s strengths and weaknesses • security risks associated with the operation of the system • the effectiveness of the implementation of controls • any recommended remediation actions.
System-specific cyber security documentation › Security assessment report
At the conclusion of a security assessment for a system, a plan of action and milestones is produced by the system owner.
System-specific cyber security documentation › Plan of action and milestones
Non-classified systems are secured in suitably secure facilities.
Facilities and systems › Physical access to systems
Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.
Facilities and systems › Physical access to systems
Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Server rooms, communications rooms and security containers are not left in unsecured states.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.
Facilities and systems › Physical access to servers, network devices and cryptographic equipment
Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.
Facilities and systems › Physical access to network devices in public areas
Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.
Facilities and systems › Preventing observation by unauthorised people
IT equipment and media are secured when not in use.
IT equipment and media › Securing IT equipment and media
Cyber security awareness training is undertaken annually by all personnel and covers: • the purpose of the cyber security awareness training • security appointments and contacts • authorised use of systems and their resources • protection of systems and their resources • reporting of cyber security incidents and suspected compromises of systems and their resources.
Cyber security awareness training › Providing cyber security awareness training
Tailored privileged user training is undertaken annually by all privileged users.
Cyber security awareness training › Providing cyber security awareness training
A cyber security awareness training register is developed, implemented and maintained.
Cyber security awareness training › Providing cyber security awareness training
Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.
Cyber security awareness training › Managing and reporting suspicious changes to banking details or payment requests
Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.
Cyber security awareness training › Managing and reporting suspicious requests to disclose or change user account details
Personnel are advised of what suspicious contact via online services is and how to report it.
Cyber security awareness training › Reporting suspicious contact via online services
Personnel are advised not to post work information on unauthorised online services, and to report cases where such information is posted.
Cyber security awareness training › Posting work-related information on online services
Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted.
Cyber security awareness training › Posting work-related information on online services
Personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such information is posted.
Cyber security awareness training › Posting work-related information on online services
Personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases where such information is posted.
Cyber security awareness training › Posting work-related information on online services
Personnel are advised of security risks associated with posting personal information on online services.
Cyber security awareness training › Posting personal information on online services
Personnel are advised to maintain separate personal user accounts from any work user accounts they use for online services.
Cyber security awareness training › Posting personal information on online services
Personnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.
Cyber security awareness training › Posting personal information on online services
Personnel are advised not to send or receive files via unauthorised online services.
Cyber security awareness training › Sending and receiving files via online services
A system usage policy is developed, implemented and maintained.
Access to systems and their resources › System usage policy
A general-purpose AI usage policy is developed, implemented and maintained.
Access to systems and their resources › General-purpose artificial intelligence usage policy
A web usage policy is developed, implemented and maintained.
Access to systems and their resources › Web usage policy
Access requirements for systems and their resources are documented in their system security plan.
Access to systems and their resources › System access requirements
Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.
Access to systems and their resources › System access requirements
Personnel receive any necessary briefings before being granted access to systems and their resources.
Access to systems and their resources › System access requirements
Personnel agree to abide by system usage policies before being granted access to systems and their resources.
Access to systems and their resources › System access requirements
Personnel granted access to systems and their resources are uniquely identifiable.
Access to systems and their resources › User identification
The use of shared user accounts is strictly controlled, and personnel using such accounts are uniquely identifiable.
Access to systems and their resources › User identification
Personnel who are contractors are identified as such.
Access to systems and their resources › User identification
Requests for unprivileged access to systems and their resources are validated when first requested.
Access to systems and their resources › Unprivileged access to systems
Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
Access to systems and their resources › Unprivileged access to systems
Use of unprivileged access is centrally logged.
Access to systems and their resources › Unprivileged access to systems
Requests for privileged access to systems and their resources are validated when first requested.
Access to systems and their resources › Privileged access to systems
Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
Access to systems and their resources › Privileged access to systems
Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
Access to systems and their resources › Privileged access to systems
Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
Access to systems and their resources › Privileged access to systems
Just-in-time administration is used for the administration of systems and their resources.
Access to systems and their resources › Privileged access to systems
Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
Access to systems and their resources › Privileged access to systems
Unique privileged user accounts are used for administering individual server applications.
Access to systems and their resources › Privileged access to systems
Privileged access events are centrally logged.
Access to systems and their resources › Privileged access to systems
Privileged user account and security group management events are centrally logged.
Access to systems and their resources › Privileged access to systems
Access to systems and their resources are removed or suspended the same day personnel no longer have a legitimate requirement for access.
Access to systems and their resources › Suspension of access to systems
Access to systems and their resources are removed or suspended as soon as practicable when personnel are detected undertaking malicious activities.
Access to systems and their resources › Suspension of access to systems
Unprivileged access to systems and their resources are disabled after 45 days of inactivity.
Access to systems and their resources › Suspension of access to systems
Privileged access to systems and their resources are disabled after 45 days of inactivity.
Access to systems and their resources › Suspension of access to systems
Privileged access to systems and their resources are disabled after 12 months unless revalidated.
Access to systems and their resources › Suspension of access to systems
A secure record is maintained for the life of systems and their resources that covers the following for each user: • their user identification • their signed agreement to abide by system usage policies • who authorised their access • when their access was granted • the level of access they were granted • when their access, and their level of access, was last reviewed • when their level of access was changed, and to what extent (if applicable) • when their access was withdrawn (if applicable).
Access to systems and their resources › Recording authorisation for personnel to access systems
When personnel are granted temporary access to systems and their resources, effective controls are put in place to restrict their access to only data required for them to undertake their duties.
Access to systems and their resources › Temporary access to systems
A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.
Access to systems and their resources › Emergency access to systems
Break glass accounts are only used when normal authentication processes cannot be used.
Access to systems and their resources › Emergency access to systems
Break glass accounts are only used for specific authorised activities.
Access to systems and their resources › Emergency access to systems
Break glass account credentials are changed by the account custodian after they are accessed by any other party.
Access to systems and their resources › Emergency access to systems
Break glass accounts are tested after credentials are changed.
Access to systems and their resources › Emergency access to systems
Use of break glass accounts is centrally logged.
Access to systems and their resources › Emergency access to systems
Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.
Cabling infrastructure › Cabling infrastructure standards
Fibre-optic cables are used for cabling infrastructure instead of copper cables.
Cabling infrastructure › Use of fibre-optic cables
A cable register is developed, implemented, maintained and regularly verified.
Cabling infrastructure › Cable register
A cable register contains the following for each cable: • cable identifier • cable colour • sensitivity/classification • source • destination • location • seal numbers (if applicable).
Cabling infrastructure › Cable register
Floor plan diagrams are developed, implemented, maintained and regularly verified.
Cabling infrastructure › Floor plan diagrams
Floor plan diagrams contain the following: • cable paths (including ingress and egress points between floors) • cable reticulation system and conduit paths • floor concentration boxes • wall outlet boxes • network cabinets.
Cabling infrastructure › Floor plan diagrams
Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.
Cabling infrastructure › Cable labelling processes and procedures
Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.
Cabling infrastructure › Labelling cables
Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.
Cabling infrastructure › Labelling building management cables
Cables for foreign systems installed in Australian facilities are labelled at inspection points.
Cabling infrastructure › Labelling cables for foreign systems in Australian facilities
Cables for individual systems use a consistent colour.
Cabling infrastructure › Cable colours
Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.
Cabling infrastructure › Cable colours
Cables in non-TOP SECRET areas are inspectable every five metres or less.
Cabling infrastructure › Cable inspectability
Cables in TOP SECRET areas are fully inspectable for their entire length.
Cabling infrastructure › Cable inspectability
Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.
Cabling infrastructure › Common cable reticulation systems
In shared facilities, cables are run in an enclosed cable reticulation system.
Cabling infrastructure › Enclosed cable reticulation systems
In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.
Cabling infrastructure › Covers for enclosed cable reticulation systems
Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.
Cabling infrastructure › Cables in walls
Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.
Cabling infrastructure › Labelling wall outlet boxes
Wall outlet boxes for individual systems use a consistent colour.
Cabling infrastructure › Wall outlet box colours
Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.
Cabling infrastructure › Wall outlet box colours
Wall outlet box covers are clear plastic.
Cabling infrastructure › Wall outlet box covers
Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.
Cabling infrastructure › Connecting cable reticulation systems to cabinets
In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.
Cabling infrastructure › Connecting cable reticulation systems to cabinets
In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.
Cabling infrastructure › Connecting cable reticulation systems to cabinets
IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.
Emanation security › Electromagnetic interference/electromagnetic compatibility standards
Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.
Emanation security › Emanation security doctrine
A telephone system usage policy is developed, implemented and maintained.
Telephone systems › Telephone system usage policy
Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.
Telephone systems › Personnel awareness
Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.
Telephone systems › Personnel awareness
When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.
Telephone systems › Personnel awareness
Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.
Telephone systems › Protecting conversations
Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted using ASD-approved cryptography.
Telephone systems › Cordless telephone systems
Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.
Telephone systems › Speakerphones
Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.
Telephone systems › Off-hook audio protection
In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements.
Telephone systems › Off-hook audio protection
Video conferencing and IP telephony infrastructure is hardened.
Video conferencing and Internet Protocol telephony › Video conferencing and Internet Protocol telephony infrastructure hardening
When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.
Video conferencing and Internet Protocol telephony › Video-aware and voice-aware firewalls and proxies
Video conferencing and IP telephony calls are established using a secure session initiation protocol.
Video conferencing and Internet Protocol telephony › Protecting video conferencing and Internet Protocol telephony traffic
Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.
Video conferencing and Internet Protocol telephony › Protecting video conferencing and Internet Protocol telephony traffic
An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.
Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication
Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.
Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication
Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.
Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication
IP telephony is configured such that: • IP phones authenticate themselves to the call controller upon registration • auto-registration is disabled and only authorised devices are allowed to access the network • unauthorised devices are blocked by default • all unused and prohibited functionality is disabled.
Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication
Video conferencing and IP telephony traffic is physically or logically separated from other data traffic.
Video conferencing and Internet Protocol telephony › Traffic separation
Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses Virtual Local Area Networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.
Video conferencing and Internet Protocol telephony › Traffic separation
IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.
Video conferencing and Internet Protocol telephony › Internet Protocol phones in public areas
Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.
Video conferencing and Internet Protocol telephony › Microphones and webcams
Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.
Video conferencing and Internet Protocol telephony › Microphones and webcams
A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.
Video conferencing and Internet Protocol telephony › Denial of service response plan
A denial of service response plan for video conferencing and IP telephony services contains the following: • how to identify signs of a denial-of-service attack • how to identify the source of a denial-of-service attack • how capabilities can be maintained during a denial-of-service attack • what actions can be taken to respond to a denial-of-service attack.
Video conferencing and Internet Protocol telephony › Denial of service response plan
An MFD usage policy is developed, implemented and maintained.
Multifunction devices › Multifunction device usage policy
MFDs are not connected to digital telephone systems.
Multifunction devices › Connecting multifunction devices to digital telephone systems
Users authenticate to MFDs before they can print, scan or copy documents.
Multifunction devices › Authenticating to multifunction devices
Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.
Multifunction devices › Authenticating to multifunction devices
MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.
Multifunction devices › Scanning and copying documents on multifunction devices
Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.
Multifunction devices › Logging multifunction device use
MFDs are placed in areas where their use can be observed.
Multifunction devices › Observing multifunction device use
Fax machines, and online fax services, are not used for sending or receiving fax messages.
Fax machines and services › Sending and receiving fax messages
Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.
Enterprise mobility › Privately owned mobile devices and desktop computers
Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.
Enterprise mobility › Privately owned mobile devices and desktop computers
Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately owned mobile devices and desktop computers.
Enterprise mobility › Privately owned mobile devices and desktop computers
Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.
Enterprise mobility › Privately owned mobile devices and desktop computers
Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.
Enterprise mobility › Organisation-owned mobile devices and desktop computers
Mobile devices and desktop computers access the internet via an organisation’s internet gateway rather than via a direct connection to the internet.
Enterprise mobility › Mobile devices and desktop computers accessing the internet
When accessing an organisation’s network via a VPN connection, split tunnelling is disabled.
Enterprise mobility › Mobile devices and desktop computers accessing the internet
A mobile device management policy is developed, implemented and maintained.
Mobile device management › Mobile device management policy
Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.
Mobile device management › Mobile device management policy
Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.
Mobile device management › Approved mobile platforms
Mobile devices encrypt their internal storage and any removable media using ASD-approved cryptography.
Mobile device management › Encrypted storage
Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
Mobile device management › Encrypted communications
Mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
Mobile device management › Encrypted communications
Mobile devices are configured to operate in a supervised (or equivalent) mode.
Mobile device management › Maintaining mobile device security
Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.
Mobile device management › Maintaining mobile device security
Mobile devices are configured with always on VPN functionality.
Mobile device management › Maintaining mobile device security
Mobile devices are configured with remote locate and wipe functionality.
Mobile device management › Maintaining mobile device security
Mobile devices are configured with secure password-based lock screens.
Mobile device management › Maintaining mobile device security
Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.
Mobile device management › Maintaining mobile device security
Mobile devices prevent personnel from installing non-approved applications once provisioned.
Mobile device management › Maintaining mobile device security
Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.
Mobile device management › Maintaining mobile device security
Security updates are applied to mobile devices as soon as they become available.
Mobile device management › Maintaining mobile device security
A mobile device usage policy is developed, implemented and maintained.
Mobile device usage › Mobile device usage policy
Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.
Mobile device usage › Personnel awareness
Personnel are advised to take the following precautions when using mobile devices: • never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes • never store credentials with mobile devices that they grant access to, such as in laptop computer bags • never lend mobile devices or removable media to untrusted people, even if briefly • never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging • never connect mobile devices to designated charging stations or wall outlet charging ports • never use gifted or unauthorised peripherals, chargers or removable media with mobile devices • never use removable media for data transfers or backups that have not been checked for malicious code beforehand • avoid reuse of removable media once used with other parties’ systems or mobile devices • avoid connecting mobile devices to open or untrusted Wi-Fi networks • consider disabling any communications capabilities of mobile devices when not in use, such as Wi-Fi, Bluetooth, Near Field Communication and ultra-wideband • consider periodically rebooting mobile devices • consider using a VPN connection to encrypt all cellular and wireless communications • consider using encrypted email or messaging apps for all communications.
Mobile device usage › Personnel awareness
Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.
Mobile device usage › Using paging, message services and messaging apps
Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.
Mobile device usage › Using Bluetooth functionality
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.
Mobile device usage › Using Bluetooth functionality
Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.
Mobile device usage › Using Bluetooth functionality
Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.
Mobile device usage › Using Bluetooth functionality
Mobile devices are not connected to the infotainment systems of connected vehicles.
Mobile device usage › Connecting mobile devices to connected vehicles
Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.
Mobile device usage › Using mobile devices within or near connected vehicles
Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.
Mobile device usage › Using mobile devices within or near connected vehicles
Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.
Mobile device usage › Using mobile devices in public spaces
Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.
Mobile device usage › Using mobile devices in public spaces
Mobile devices are kept under continual direct supervision when being actively used.
Mobile device usage › Maintaining control of mobile devices
Mobile devices are carried or stored in a secured state when not being actively used.
Mobile device usage › Maintaining control of mobile devices
If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.
Mobile device usage › Maintaining control of mobile devices
Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.
Mobile device usage › Mobile device emergency sanitisation processes and procedures
Personnel are advised of privacy and security risks when travelling overseas with mobile devices.
Mobile device usage › Before travelling overseas with mobile devices
If travelling overseas with mobile devices to high or extreme risk countries, personnel are: • issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities • advised on how to apply and inspect tamper seals to key areas of mobile devices • advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.
Mobile device usage › Before travelling overseas with mobile devices
Before travelling overseas with mobile devices, personnel take the following actions: • record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers • update all operating systems and applications • remove all non-essential data, applications and user accounts • backup all remaining data, applications and settings.
Mobile device usage › Before travelling overseas with mobile devices
Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they: • provide credentials to foreign government officials • decrypt mobile devices for foreign government officials • have mobile devices taken out of sight by foreign government officials • have mobile devices or removable media stolen, including if later returned • lose mobile devices or removable media, including if later found • observe unusual behaviour of mobile devices.
Mobile device usage › While travelling overseas with mobile devices
Upon returning from travelling overseas with mobile devices, personnel take the following actions: • sanitise and reset mobile devices, including all removable media • decommission any credentials that left their possession during their travel • report if significant doubt exists as to the integrity of any mobile devices or removable media.
Mobile device usage › After travelling overseas with mobile devices
If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions: • reset credentials used with mobile devices, including those used for remote access to their organisation’s systems • monitor user accounts for any indicators of compromise, such as failed logon attempts.
Mobile device usage › After travelling overseas with mobile devices
If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.
Evaluated product procurement › Evaluated product selection
Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.
Evaluated product procurement › Delivery of evaluated products
Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.
Evaluated product usage › Using evaluated products
An IT equipment management policy is developed, implemented and maintained.
IT equipment usage › IT equipment management policy
Approved configurations for IT equipment are developed, implemented and maintained.
IT equipment usage › Hardening IT equipment configurations
IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
IT equipment usage › Hardening IT equipment configurations
A networked IT equipment register is developed, implemented, maintained and regularly verified.
IT equipment usage › IT equipment registers
A non-networked IT equipment register is developed, implemented, maintained and regularly verified.
IT equipment usage › IT equipment registers
IT equipment, except for high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.
IT equipment usage › Labelling IT equipment
IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.
IT equipment usage › Classifying IT equipment
IT equipment is handled in a manner suitable for its sensitivity or classification.
IT equipment usage › Handling IT equipment
Maintenance or repairs of IT equipment are carried out on site by an appropriately cleared technician.
IT equipment maintenance or repairs › On-site maintenance or repairs
If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the IT equipment and associated media are sanitised before maintenance or repairs.
IT equipment maintenance or repairs › On-site maintenance or repairs
If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: • has the authority to direct the technician • is appropriately cleared and briefed • is sufficiently familiar with the IT equipment to understand the work being undertaken • takes all responsible measures to ensure the integrity of the IT equipment • takes due care to ensure that data is not disclosed.
IT equipment maintenance or repairs › On-site maintenance or repairs
IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.
IT equipment maintenance or repairs › Off-site maintenance or repairs
Following maintenance or repairs to IT equipment, it is inspected to confirm that it retains its approved configuration and that no unauthorised modifications have been made.
IT equipment maintenance or repairs › Inspection of IT equipment following maintenance or repairs
IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.
IT equipment sanitisation and destruction › IT equipment sanitisation processes and procedures
IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.
IT equipment sanitisation and destruction › IT equipment destruction processes and procedures
IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.
IT equipment sanitisation and destruction › Sanitising IT equipment
IT equipment that cannot be sanitised is destroyed.
IT equipment sanitisation and destruction › Sanitising IT equipment
At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner that cannot be removed or a print is visible on the image transfer roller.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
Printer ribbons in printers and MFDs are removed and destroyed.
IT equipment sanitisation and destruction › Sanitising printers and multifunction devices
Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period.
IT equipment sanitisation and destruction › Sanitising televisions and computer monitors
Televisions and computer monitors that cannot be sanitised are destroyed.
IT equipment sanitisation and destruction › Sanitising televisions and computer monitors
Memory in network devices is sanitised using the following processes, in order of preference: • following device-specific guidance provided in evaluation documentation • following vendor sanitisation guidance • loading a dummy configuration file, performing a factory reset and then reinstalling firmware.
IT equipment sanitisation and destruction › Sanitising network devices
IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.
IT equipment disposal › IT equipment disposal processes and procedures
Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.
IT equipment disposal › Disposal of IT equipment
Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.
IT equipment disposal › Disposal of IT equipment
A media management policy is developed, implemented and maintained.
Media usage › Media management policy
A removable media usage policy is developed, implemented and maintained.
Media usage › Removable media usage policy
A removable media register is developed, implemented, maintained and regularly verified.
Media usage › Removable media register
Media, except for internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.
Media usage › Labelling media
Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.
Media usage › Classifying media
Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.
Media usage › Classifying media
Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.
Media usage › Reclassifying media
Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.
Media usage › Reclassifying media
All data stored on media is encrypted using ASD-approved cryptography.
Media usage › Encrypting media
Full disk encryption, or partial encryption where access controls only allow writing to encrypted partitions or volumes, is implemented when encrypting media.
Media usage › Encrypting media
Pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.
Media usage › Encrypting media
Media is handled in a manner suitable for its sensitivity or classification.
Media usage › Handling media
Media is sanitised before it is used for the first time.
Media usage › Sanitising media before first use
Media is sanitised before it is reused in a different security domain.
Media usage › Sanitising media before first use
When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.
Media usage › Using media for data transfers
When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.
Media usage › Using media for data transfers
Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.
Media sanitisation › Media sanitisation processes and procedures
Volatile media is sanitised by removing its power for at least 10 minutes.
Media sanitisation › Volatile media sanitisation
Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.
Media sanitisation › Non-volatile magnetic media sanitisation
The host-protected area and device configuration overlay table are reset prior to the sanitisation of non-volatile magnetic hard drives.
Media sanitisation › Non-volatile magnetic media sanitisation
The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.
Media sanitisation › Non-volatile magnetic media sanitisation
Non-volatile EPROM media is sanitised by applying three times the manufacturer’s specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
Media sanitisation › Non-volatile erasable programmable read-only memory media sanitisation
Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.
Media sanitisation › Non-volatile electrically erasable programmable read-only memory media sanitisation
Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.
Media sanitisation › Non-volatile flash memory media sanitisation
Media that cannot be successfully sanitised is destroyed prior to its disposal.
Media sanitisation › Media that cannot be successfully sanitised
Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.
Media destruction › Media destruction processes and procedures
The following media types are destroyed prior to their disposal: • microfiche and microfilm • optical discs • programmable read-only memory • read-only memory • other types of media that cannot be sanitised.
Media destruction › Media that cannot be sanitised
Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.
Media destruction › Media destruction equipment
If using degaussers to destroy media, degaussers evaluated by the United States’ National Security Agency are used.
Media destruction › Media destruction equipment
Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.
Media destruction › Media destruction methods
Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.
Media destruction › Media destruction methods
Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.
Media destruction › Media destruction methods
Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.
Media destruction › Media destruction methods
Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.
Media destruction › Media destruction methods
Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.
Media destruction › Media destruction methods
Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.
Media destruction › Media destruction methods
Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.
Media destruction › Media destruction methods
Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.
Media destruction › Degaussing magnetic media
Product-specific directions provided by degausser manufacturers are followed.
Media destruction › Degaussing magnetic media
Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.
Media destruction › Degaussing magnetic media
The destruction of media is performed under the supervision of at least one cleared person.
Media destruction › Supervision of destruction
Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.
Media destruction › Supervision of destruction
The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.
Media destruction › Supervision of accountable material destruction
Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.
Media destruction › Supervision of accountable material destruction
The destruction of media storing accountable material is not outsourced.
Media destruction › Outsourcing media destruction
When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO’s Protective Security Circular-167, is used.
Media destruction › Outsourcing media destruction
Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.
Media disposal › Media disposal processes and procedures
Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.
Media disposal › Disposal of media
Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.
Media disposal › Disposal of media
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.
Operating system hardening › Operating system selection
The latest release, or the previous release, of operating systems are used.
Operating system hardening › Operating system releases and versions
Where supported, 64-bit versions of operating systems are used.
Operating system hardening › Operating system releases and versions
SOEs are used for workstations and servers.
Operating system hardening › Standard Operating Environments
SOEs provided by third parties are scanned for malicious code and configurations.
Operating system hardening › Standard Operating Environments
SOEs are reviewed and updated at least annually.
Operating system hardening › Standard Operating Environments
Approved configurations for operating systems are developed, implemented and maintained.
Operating system hardening › Hardening operating system configurations
Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
Operating system hardening › Hardening operating system configurations
Microsoft’s attack surface reduction rules are implemented.
Operating system hardening › Hardening operating system configurations
Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
Operating system hardening › Hardening operating system configurations
Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.
Operating system hardening › Hardening operating system configurations
Automatic execution features for removable media are disabled.
Operating system hardening › Hardening operating system configurations
Internet Explorer 11 is disabled or removed.
Operating system hardening › Hardening operating system configurations
.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
Operating system hardening › Hardening operating system configurations
Operating system exploit protection functionality is enabled.
Operating system hardening › Hardening operating system configurations
Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.
Operating system hardening › Hardening operating system configurations
Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.
Operating system hardening › Hardening operating system configurations
Unprivileged users are prevented from running script execution engines, including: • Windows Script Host (cscript.exe and wscript.exe) • PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe) • Command Prompt (cmd.exe) • Windows Management Instrumentation (wmic.exe) • Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).
Operating system hardening › Hardening operating system configurations
Unprivileged users do not have the ability to install unapproved applications.
Operating system hardening › Application management
Unprivileged users do not have the ability to uninstall or disable approved applications.
Operating system hardening › Application management
Application control is implemented on workstations.
Operating system hardening › Application control
Application control is implemented on internet-facing servers.
Operating system hardening › Application control
Application control is implemented on non-internet-facing servers.
Operating system hardening › Application control
Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.
Operating system hardening › Application control
Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.
Operating system hardening › Application control
Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.
Operating system hardening › Application control
Application control restricts the execution of drivers to an organisation-approved set.
Operating system hardening › Application control
Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.
Operating system hardening › Application control
When implementing application control using publisher certificate rules, publisher names and product names are used.
Operating system hardening › Application control
When implementing application control using path rules, only approved users can modify approved files and write to approved folders.
Operating system hardening › Application control
When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.
Operating system hardening › Application control
Microsoft’s recommended application blocklist is implemented.
Operating system hardening › Application control
Microsoft’s vulnerable driver blocklist is implemented.
Operating system hardening › Application control
Application control rulesets are validated at least annually.
Operating system hardening › Application control
All users, except for local administrator accounts and break glass accounts, cannot disable, bypass or be exempted from application control.
Operating system hardening › Application control
Allowed and blocked application control events are centrally logged.
Operating system hardening › Application control
Command line process creation events are centrally logged.
Operating system hardening › Command Shell
Windows PowerShell 2.0 is disabled or removed.
Operating system hardening › PowerShell
PowerShell is configured to use Constrained Language Mode.
Operating system hardening › PowerShell
PowerShell module logging, script block logging and transcription events are centrally logged.
Operating system hardening › PowerShell
PowerShell script block logs are protected by Protected Event Logging functionality.
Operating system hardening › PowerShell
A HIPS or EDR solution is implemented on workstations.
Operating system hardening › Host-based intrusion detection and response solution
A HIPS or EDR solution is implemented on critical servers and high-value servers.
Operating system hardening › Host-based intrusion detection and response solution
A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.
Operating system hardening › Software firewall
An antivirus application is implemented on workstations and servers with: • signature-based detection functionality enabled and set to a high level • heuristic-based detection functionality enabled and set to a high level • reputation rating functionality enabled • ransomware protection functionality enabled • detection signatures configured to update at least daily • regular scanning configured for all fixed disks and removable media.
Operating system hardening › Antivirus application
If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
Operating system hardening › Device access control
If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.
Operating system hardening › Device access control
External communication interfaces that allow DMA are disabled.
Operating system hardening › Device access control
Security-relevant events for Apple macOS operating systems are centrally logged.
Operating system hardening › Operating system event logging
Security-relevant events for Linux operating systems are centrally logged.
Operating system hardening › Operating system event logging
Security-relevant events for Microsoft Windows operating systems are centrally logged.
Operating system hardening › Operating system event logging
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.
User application hardening › User application selection
The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are used.
User application hardening › User application releases
Approved configurations for user applications are developed, implemented and maintained.
User application hardening › Hardening user application configurations
User applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
User application hardening › Hardening user application configurations
Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
User application hardening › Hardening user application configurations
Unneeded user accounts, components, services and functionality of user applications are disabled or removed.
User application hardening › Hardening user application configurations
Extensions for user applications are restricted to an organisation-approved set.
User application hardening › Hardening user application configurations
All temporary installation files created during user application installation processes are removed after user applications have been installed.
User application hardening › Hardening user application configurations
AI applications that process classified data have their ability to directly access external public data sources disabled.
User application hardening › Artificial intelligence applications
AI applications are configured to flag organisationally defined risky actions for human approval prior to their execution.
User application hardening › Artificial intelligence applications
Baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.
User application hardening › Artificial intelligence applications
Email client security settings cannot be changed by users.
User application hardening › Email clients
Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
User application hardening › Office productivity suites
Microsoft Office is blocked from creating child processes.
User application hardening › Office productivity suites
Microsoft Office is blocked from creating executable content.
User application hardening › Office productivity suites
Microsoft Office is blocked from injecting code into other processes.
User application hardening › Office productivity suites
Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.
User application hardening › Office productivity suites
Office productivity suite security settings cannot be changed by users.
User application hardening › Office productivity suites
Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.
User application hardening › Office productivity suites
Microsoft Office macros in files originating from the internet are blocked.
User application hardening › Office productivity suites
Microsoft Office macro antivirus scanning is enabled.
User application hardening › Office productivity suites
Microsoft Office macros are blocked from making Win32 API calls.
User application hardening › Office productivity suites
Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.
User application hardening › Office productivity suites
Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.
User application hardening › Office productivity suites
Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.
User application hardening › Office productivity suites
Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.
User application hardening › Office productivity suites
Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.
User application hardening › Office productivity suites
Microsoft Office’s list of trusted publishers is validated at least annually.
User application hardening › Office productivity suites
Microsoft Office macro security settings cannot be changed by users.
User application hardening › Office productivity suites
PDF applications are blocked from creating child processes.
User application hardening › Portable Document Format applications
PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
User application hardening › Portable Document Format applications
PDF application security settings cannot be changed by users.
User application hardening › Portable Document Format applications
Security product security settings cannot be changed by users.
User application hardening › Security products
Web browsers do not process Java from the internet.
User application hardening › Web browsers
Web browsers do not process web advertisements from the internet.
User application hardening › Web browsers
Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
User application hardening › Web browsers
Web browser security settings cannot be changed by users.
User application hardening › Web browsers
Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.
Server application hardening › Server application selection
The latest release of internet-facing server applications is used.
Server application hardening › Server application releases
Approved configurations for server applications are developed, implemented and maintained.
Server application hardening › Hardening server application configurations
Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
Server application hardening › Hardening server application configurations
Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
Server application hardening › Hardening server application configurations
Unneeded user accounts, components, services and functionality of server applications are disabled or removed.
Server application hardening › Hardening server application configurations
Extensions for server applications are restricted to an organisation-approved set.
Server application hardening › Hardening server application configurations
All temporary installation files created during server application installation processes are removed after server applications have been installed.
Server application hardening › Hardening server application configurations
Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.
Server application hardening › Restricting privileges for server applications
The user accounts under which server applications run have limited access to their underlying server’s file system.
Server application hardening › Restricting privileges for server applications
Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.
Server application hardening › Microsoft Active Directory services
Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.
Server application hardening › Microsoft Active Directory services
Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.
Server application hardening › Microsoft Active Directory services
Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.
Server application hardening › Microsoft Active Directory services
Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
The Print Spooler service is disabled on Microsoft AD DS domain controllers.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
Passwords are not stored in Group Policy Preferences.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
Passwords are prevented from being stored in Group Policy Preferences.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
SID Filtering is enabled for domain and forest trusts.
Server application hardening › Microsoft Active Directory Domain Services domain controllers
Only service accounts and computer accounts are configured with Service Principal Names (SPNs).
Server application hardening › Microsoft Active Directory Domain Services account hardening
The number of service accounts configured with an SPN is minimised.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Service accounts configured with an SPN do not have DCSync permissions.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Duplicate SPNs do not exist within the domain.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User accounts are provisioned with the minimum privileges required.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Privileged user accounts are configured as sensitive and cannot be delegated.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Computer accounts are not configured for unconstrained delegation.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User accounts require Kerberos pre-authentication.
Server application hardening › Microsoft Active Directory Domain Services account hardening
The UserPassword attribute for user accounts is not used.
Server application hardening › Microsoft Active Directory Domain Services account hardening
The sIDHistory attribute for user accounts is not used.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User accounts are checked at least weekly for the presence of the sIDHistory attribute.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Account properties accessible by unprivileged users are not used to store passwords.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User account passwords do not use reversible encryption.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Unprivileged user accounts cannot add machines to the domain.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Dedicated privileged service accounts are used to add machines to the domain.
Server application hardening › Microsoft Active Directory Domain Services account hardening
User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.
Server application hardening › Microsoft Active Directory Domain Services account hardening
The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.
Server application hardening › Microsoft Active Directory Domain Services account hardening
Privileged user accounts are members of the Protected Users security group.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly privileged security groups is minimised.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
Service accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
The Domain Computers security group is not a member of any privileged or highly privileged security groups.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
When a user account is disabled, it is removed from all security group memberships.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
The Pre-Windows 2000 Compatible Access security group does not contain user accounts.
Server application hardening › Microsoft Active Directory Domain Services security group memberships
Strong mapping between certificates and users is enforced.
Server application hardening › Microsoft Active Directory Certificate Services
The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.
Server application hardening › Microsoft Active Directory Certificate Services
The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
Server application hardening › Microsoft Active Directory Certificate Services
Unprivileged user accounts do not have write access to certificate templates.
Server application hardening › Microsoft Active Directory Certificate Services
Extended Key Usages that enable user authentication are removed.
Server application hardening › Microsoft Active Directory Certificate Services
CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.
Server application hardening › Microsoft Active Directory Certificate Services
Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.
Server application hardening › Microsoft Active Directory Federation Services
Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.
Server application hardening › Microsoft Entra Connect
Hard match takeover is disabled for Microsoft Entra Connect servers.
Server application hardening › Microsoft Entra Connect
Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.
Server application hardening › Microsoft Entra Connect
Security-relevant events for server applications on internet-facing servers are centrally logged.
Server application hardening › Server application event logging
Security-relevant events for server applications on non-internet-facing servers are centrally logged.
Server application hardening › Server application event logging
Users are authenticated before they are granted access to a system and its resources.
Authentication hardening › Authenticating to systems
Authentication methods susceptible to replay attacks are disabled.
Authentication hardening › Insecure authentication methods
LAN Manager and NT LAN Manager authentication methods are disabled.
Authentication hardening › Insecure authentication methods
Security questions are not used for authentication purposes.
Authentication hardening › Insecure authentication methods
Email is not used for out-of-band authentication purposes.
Authentication hardening › Insecure authentication methods
Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.
Authentication hardening › Multi-factor authentication
Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.
Authentication hardening › Multi-factor authentication
When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate privileged users of systems.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate unprivileged users of systems.
Authentication hardening › Multi-factor authentication
Multi-factor authentication is used to authenticate users of data repositories.
Authentication hardening › Multi-factor authentication
Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.
Authentication hardening › Multi-factor authentication
Multi-factor authentication used for authenticating users of online services is phishing-resistant.
Authentication hardening › Multi-factor authentication
Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.
Authentication hardening › Multi-factor authentication
Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.
Authentication hardening › Multi-factor authentication
Multi-factor authentication used for authenticating users of systems is phishing-resistant.
Authentication hardening › Multi-factor authentication
Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.
Authentication hardening › Multi-factor authentication
When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.
Authentication hardening › Multi-factor authentication
When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that process, store or communicate their organisation’s sensitive data or sensitive customer data – users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.
Authentication hardening › Multi-factor authentication
Successful and unsuccessful multi-factor authentication events are centrally logged.
Authentication hardening › Multi-factor authentication
When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.
Authentication hardening › Single-factor authentication
Successful and unsuccessful single-factor authentication events are centrally logged.
Authentication hardening › Single-factor authentication
Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.
Authentication hardening › Password strength
Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.
Authentication hardening › Password strength
Passwords using a sequence of words for single-factor authentication are not constructed using: • a list of categorised words • a real sentence in a natural language • song lyrics, movie or television show quotes, literature, or any other publicly available material • less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.
Authentication hardening › Password strength
Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.
Authentication hardening › Password strength
Maximum length limits for passwords are not less than 64 characters.
Authentication hardening › Password strength
Password complexity requirements are not imposed for passwords.
Authentication hardening › Password strength
All ASCII printable characters are supported for passwords.
Authentication hardening › Password strength
Users provide sufficient evidence to verify their identity when requesting new credentials.
Authentication hardening › Setting credentials for user accounts
Credentials set for user accounts are randomly generated.
Authentication hardening › Setting credentials for user accounts
Credentials are provided to users via a secure communications channel or, if not possible, split into two parts with one part provided to users and the other part provided to supervisors.
Authentication hardening › Setting credentials for user accounts
Credentials provided to users are changed on first use.
Authentication hardening › Setting credentials for user accounts
Credentials are not reused by users across different systems.
Authentication hardening › Setting credentials for user accounts
Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.
Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.
Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.
Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.
Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
Service accounts are created as group Managed Service Accounts.
Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts
Credentials for user accounts are changed if: • they are compromised • they are suspected of being compromised • they are discovered stored on networks in the clear • they are discovered being transferred across networks in the clear • membership of a shared user account changes.
Authentication hardening › Changing credentials
Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.
Authentication hardening › Changing credentials
Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.
Authentication hardening › Changing credentials
Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.
Authentication hardening › Changing credentials
Credentials are obscured as they are entered into systems.
Authentication hardening › Protecting credentials
Credential hint functionality is not used for systems.
Authentication hardening › Protecting credentials
Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.
Authentication hardening › Protecting credentials
Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.
Authentication hardening › Protecting credentials
Private keys for Microsoft AD CS CA servers are protected by a hardware security module.
Authentication hardening › Protecting credentials
Memory integrity functionality is enabled.
Authentication hardening › Protecting credentials
Local Security Authority protection functionality is enabled.
Authentication hardening › Protecting credentials
Credential Guard functionality is enabled.
Authentication hardening › Protecting credentials
Remote Credential Guard functionality is enabled.
Authentication hardening › Protecting credentials
Cached credentials are limited to one previous logon.
Authentication hardening › Protecting credentials
Networks are scanned at least monthly to identify any credentials that are being stored in the clear.
Authentication hardening › Protecting credentials
User accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon attempts, with either indefinite or automated lockout durations.
Authentication hardening › User account lockouts
User sessions are terminated and workstations are restarted at least daily.
Authentication hardening › Session termination
Services are configured with a session lock that: • activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users • blocks access to all session content • requires users to re-authenticate using all authentication factors to unlock the session • denies users the ability to disable the session locking mechanism.
Authentication hardening › Session locking
Systems are configured with a screen lock that: • activates after a maximum of 15 minutes of user inactivity, or when manually activated by users • conceals all content on the screen • ensures that the screen does not enter a power saving state before the screen lock is activated • requires users to re-authenticate using all authentication factors to unlock the system • denies users the ability to disable the screen locking mechanism.
Authentication hardening › Screen locking
Systems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.
Authentication hardening › Logon banner
When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.
Virtualisation hardening › Functional separation between operating environments
When using a software-based isolation mechanism that consumes shared physical computing resources, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.
Virtualisation hardening › Functional separation between operating environments
When using a software-based isolation mechanism that consumes shared physical computing resources, the underlying operating system is hardened.
Virtualisation hardening › Functional separation between operating environments
When using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.
Virtualisation hardening › Functional separation between operating environments
When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.
Virtualisation hardening › Functional separation between operating environments
When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.
Virtualisation hardening › Functional separation between operating environments
System administration processes, and supporting system administration procedures, are developed, implemented and maintained.
System administration › System administration processes and procedures
System administrators perform system administration activities in accordance with the system’s change and configuration management plan.
System administration › System administration processes and procedures
Secure Admin Workstations are used in the performance of administrative activities.
System administration › Separate privileged operating environments
Privileged users use separate privileged and unprivileged operating environments.
System administration › Separate privileged operating environments
Privileged operating environments are not virtualised within unprivileged operating environments.
System administration › Separate privileged operating environments
Unprivileged user accounts cannot logon to privileged operating environments.
System administration › Separate privileged operating environments
Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.
System administration › Separate privileged operating environments
User accounts with DCSync permissions cannot logon to unprivileged operating environments.
System administration › Separate privileged operating environments
Administrative infrastructure is segregated from the wider network and the internet.
System administration › Administrative infrastructure
Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.
System administration › Administrative infrastructure
Network management traffic can only originate from administrative infrastructure.
System administration › Administrative infrastructure
Administrative activities are conducted through jump servers.
System administration › Administrative infrastructure
Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.
System administration › Administrative infrastructure
Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.
System administration › Software registers
Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.
System administration › Software registers
Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.
System maintenance › Patch management processes and procedures
A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.
System maintenance › Patch management processes and procedures
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
System maintenance › Mitigating known vulnerabilities
Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
System maintenance › Mitigating known vulnerabilities
Online services that are no longer supported by vendors are removed.
System maintenance › Cessation of support
Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
System maintenance › Cessation of support
Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
System maintenance › Cessation of support
Operating systems that are no longer supported by vendors are replaced.
System maintenance › Cessation of support
Internet-facing network devices that are no longer supported by vendors are replaced.
System maintenance › Cessation of support
Non-internet-facing network devices that are no longer supported by vendors are replaced.
System maintenance › Cessation of support
Networked IT equipment that is no longer supported by vendors is replaced.
System maintenance › Cessation of support
When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.
System maintenance › Cessation of support
A digital preservation policy is developed, implemented and maintained.
Data backup and restoration › Digital preservation policy
Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.
Data backup and restoration › Data backup and restoration processes and procedures
Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.
Data backup and restoration › Data backup and restoration processes and procedures
Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.
Data backup and restoration › Performing and retaining backups
Backups of data, applications and settings are synchronised to enable restoration to a common point in time.
Data backup and restoration › Performing and retaining backups
Backups of data, applications and settings are retained in a secure and resilient manner.
Data backup and restoration › Performing and retaining backups
Unprivileged user accounts cannot access backups belonging to other user accounts.
Data backup and restoration › Backup access
Unprivileged user accounts cannot access their own backups.
Data backup and restoration › Backup access
Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.
Data backup and restoration › Backup access
Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.
Data backup and restoration › Backup access
Unprivileged user accounts are prevented from modifying and deleting backups.
Data backup and restoration › Backup modification and deletion
Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.
Data backup and restoration › Backup modification and deletion
Backup administrator accounts are prevented from modifying and deleting backups during their retention period.
Data backup and restoration › Backup modification and deletion
Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
Data backup and restoration › Testing restoration of backups
A security monitoring policy is developed, implemented and maintained.
Security monitoring › Security monitoring policy
A centralised event logging facility is implemented.
Security monitoring › Centralised event logging facility
Event logs sent to a centralised event logging facility are sent as soon as possible after they occur.
Security monitoring › Centralised event logging facility
Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.
Security monitoring › Centralised event logging facility
Event logs are protected from unauthorised access.
Security monitoring › Centralised event logging facility
Event logs are protected from unauthorised modification and deletion.
Security monitoring › Centralised event logging facility
An accurate and consistent time source is used for event logging.
Security monitoring › Centralised event logging facility
For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.
Security monitoring › Event log details
To the extent possible, event logs are captured and stored in a consistent and structured format.
Security monitoring › Event log details
Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.
Security monitoring › Event log monitoring
Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.
Security monitoring › Event log monitoring
Suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.
Security monitoring › Event log monitoring
Event logs from critical servers are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from workstations are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from security products are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.
Security monitoring › Event log monitoring
Cyber security events are analysed in a timely manner to identify cyber security incidents.
Security monitoring › Event log monitoring
Event logs are retained in a searchable manner for at least 12 months.
Security monitoring › Event log retention
Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.
Security monitoring › Event log retention
An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.
Security assessments › Vulnerability scanning
A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.
Security assessments › Vulnerability scanning
A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
Security assessments › Vulnerability scanning
The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.
Security assessments › Vulnerability scanning
Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least annually thereafter.
Security assessments › Vulnerability assessments and penetration tests
Suitable AI models are used to augment vulnerability assessments and penetration tests.
Security assessments › Vulnerability assessments and penetration tests
Development, testing, staging and production environments are segregated.
Software development fundamentals › Development, testing, staging and production environments
Development and modification of software only take place in development environments.
Software development fundamentals › Development, testing, staging and production environments
Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
Software development fundamentals › Development, testing, staging and production environments
An authoritative source for software is established and maintained.
Software development fundamentals › Authoritative source for software
The authoritative source for software is used for all software development activities.
Software development fundamentals › Authoritative source for software
Unauthorised access to the authoritative source for software is prevented.
Software development fundamentals › Authoritative source for software
Unauthorised modification of the authoritative source for software is prevented.
Software development fundamentals › Authoritative source for software
An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.
Software development fundamentals › Issue tracking
All software artefacts are scanned for malicious content before being imported into the authoritative source for software.
Software development fundamentals › Software artefacts
All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.
Software development fundamentals › Software artefacts
All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.
Software development fundamentals › Software artefacts
Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.
Software development fundamentals › Software artefacts
The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.
Software development fundamentals › Software artefacts
Scanning is used during commits to identify plain text or encoded secrets and keys, which are then blocked from being stored in the authoritative source for software.
Software development fundamentals › Software artefacts
Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.
Software development fundamentals › Build solution
The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.
Software development fundamentals › Build solution
A secure software development policy is developed, implemented and maintained.
Software development fundamentals › Secure software development
All software security requirements are documented, stored securely and maintained throughout the software development life cycle.
Software development fundamentals › Secure software development
Security design decisions are documented and reviewed throughout the software development cycle.
Software development fundamentals › Secure software development
Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.
Software development fundamentals › Secure software development
Security responsibilities for software developers are identified and documented.
Software development fundamentals › Secure software development
Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.
Software development fundamentals › Secure software development
Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.
Software development fundamentals › Secure software development
A software developer cyber security knowledge and skills register is implemented and maintained.
Software development fundamentals › Secure software development
Secure by Design principles and practices are followed throughout the software development life cycle.
Software development fundamentals › Secure software development
Threat modelling is used in support of the software development life cycle.
Software development fundamentals › Secure software development
The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.
Software development fundamentals › Secure software development
Secure programming practices for the chosen programming language are used for software development.
Software development fundamentals › Secure software development
Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.
Software development fundamentals › Secure software development
Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.
Software development fundamentals › Secure software development
SecDevOps practices are used for software development.
Software development fundamentals › Secure software development
Software is architected and structured to support readability and maintainability.
Software development fundamentals › Secure software development
Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.
Software development fundamentals › Secure software development
Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.
Software development fundamentals › Secure software development
Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.
Software development fundamentals › Secure software development
Application backwards compatibility does not compromise any security measures or features.
Software development fundamentals › Secure software development
Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.
Software development fundamentals › Secure software development
Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.
Software development fundamentals › Secure software development
Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.
Software development fundamentals › Secure software development
When user permissions or credentials are changed, software forces all impacted users to re-authenticate.
Software development fundamentals › Secure software development
When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.
Software development fundamentals › Secure software development
Software generates sufficient event logs to support the detection of cyber security events.
Software development fundamentals › Secure software development
Event logs produced by software ensure that any sensitive data is protected.
Software development fundamentals › Secure software development
Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.
Software development fundamentals › Secure software development
End of life procedures for software, including procedures for software removal and the archival or destruction of user accounts and data, are produced and made available to consumers.
Software development fundamentals › Secure software development
If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.
Software development fundamentals › Software bill of materials
A software bill of materials is produced and made available to consumers of software.
Software development fundamentals › Software bill of materials
If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.
Software development fundamentals › Cryptographic bill of materials
A cryptographic bill of materials is produced and made available to consumers of software.
Software development fundamentals › Cryptographic bill of materials
If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.
Software development fundamentals › Software build provenance
A software build provenance is produced and made available to consumers of software.
Software development fundamentals › Software build provenance
Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.
Software development fundamentals › Network application programming interfaces
Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.
Software development fundamentals › Network application programming interfaces
Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.
Software development fundamentals › Network application programming interfaces
Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.
Software development fundamentals › Network application programming interfaces
Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.
Software development fundamentals › Network application programming interfaces
Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.
Software development fundamentals › Network application programming interfaces
Validation and sanitisation are performed on all input received over the internet by software.
Software development fundamentals › Software input handling
Validation and sanitisation are performed on all input received over a local network by software.
Software development fundamentals › Software input handling
All input validation rules are documented, implemented in code, and tested using both positive and negative unit tests and integration tests.
Software development fundamentals › Software input handling
Data sources and serialised data inputs are validated before being deserialised.
Software development fundamentals › Software input handling
File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.
Software development fundamentals › Software input handling
All queries to databases from software are filtered for legitimate content and correct syntax.
Software development fundamentals › Software interaction with databases
Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.
Software development fundamentals › Software interaction with databases
Software is designed or configured to provide as little error information as possible about the structure of databases.
Software development fundamentals › Software interaction with databases
All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.
Software development fundamentals › Software interaction with databases
Peer reviews are conducted on all critical and security-related software components.
Software development fundamentals › Software security testing
Code reviews are utilised to ensure software components meets Secure by Design principles and practices as well as secure programming practices.
Software development fundamentals › Software security testing
Unit testing and integration testing, covering both positive and negative use cases, are used for software components to ensure code quality and correctness.
Software development fundamentals › Software security testing
Software is comprehensively tested for vulnerabilities using SAST, DAST and SCA prior to its initial release, any subsequent release, and periodically to help identify any previously unidentified vulnerabilities.
Software development fundamentals › Software security testing
Suitable AI models are used to augment software security testing.
Software development fundamentals › Software security testing
A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.
Software development fundamentals › Vulnerability disclosure program
A vulnerability disclosure policy is developed, implemented and maintained.
Software development fundamentals › Vulnerability disclosure program
Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.
Software development fundamentals › Vulnerability disclosure program
A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.
Software development fundamentals › Vulnerability disclosure program
Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.
Software development fundamentals › Reporting and resolving vulnerabilities
Vulnerabilities identified in software are resolved in a timely manner.
Software development fundamentals › Reporting and resolving vulnerabilities
In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.
Software development fundamentals › Reporting and resolving vulnerabilities
Security-relevant usage, error messages and crashes for software are centrally logged.
Software development fundamentals › Software event logging
AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.
Artificial intelligence application development › Secure artificial intelligence application development
AI models are stored in a non-executable file format that does not allow arbitrary code execution.
Artificial intelligence application development › Secure artificial intelligence application development
The exposure of exact AI model confidence scores in API outputs or user interfaces is prevented.
Artificial intelligence application development › Secure artificial intelligence application development
Organisational data generated, collected or processed by AI applications is not used for training, fine-tuning or improving AI models unless informed and explicit consent has been obtained from data owners in advance.
Artificial intelligence application development › Data collection, retention and use
All prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.
Artificial intelligence application development › Data collection, retention and use
The source and integrity of AI models, structures and weights are verified.
Artificial intelligence application development › Artificial intelligence model poisoning
The source and integrity of training data for AI models is verified.
Artificial intelligence application development › Artificial intelligence model poisoning
Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by AI models.
Artificial intelligence application development › Artificial intelligence model poisoning
AI model performance metrics are monitored and anomalies are investigated.
Artificial intelligence application development › Unbounded consumption
Rate limiting is applied to inference queries for AI models.
Artificial intelligence application development › Unbounded consumption
Resource limits are enforced for AI models.
Artificial intelligence application development › Unbounded consumption
Access control policies are implemented to enforce fine-grained permissions for AI applications.
Artificial intelligence application development › Excessive agency
Role-based access controls are implemented for AI applications to restrict access to sensitive data.
Artificial intelligence application development › Excessive agency
Generative AI applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.
Artificial intelligence application development › Prompt injection
Content filtering is implemented by AI applications to detect and block sensitive data exposure and improper output.
Artificial intelligence application development › Sensitive data exposure and improper output
The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.
Mobile application development › Secure mobile application development
Robust web application frameworks are used in the development of web applications.
Web application development › Secure web application design and development
The OWASP Application Security Verification Standard is used in the development of web applications.
Web application development › Secure web application design and development
The OWASP Top 10 Proactive Controls are used in the development of web applications.
Web application development › Secure web application design and development
The OWASP Top 10 are mitigated in the development of web applications.
Web application development › Secure web application design and development
If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.
Web application development › Secure web application design and development
Web application session cookies contain only digitally signed opaque bearer tokens.
Web application development › Secure web application design and development
Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.
Web application development › Secure web application design and development
Web application sessions are centrally managed server side.
Web application development › Secure web application design and development
Web applications that support Single Sign On equally support Single Logout.
Web application development › Secure web application design and development
Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.
Web application development › Web security policy response headers
All web application content is offered exclusively using HTTPS.
Web application development › Web application interactions
The OWASP API Security Top 10 are mitigated in the development of web APIs.
Web application development › Web application programming interfaces
Output encoding is performed on all output produced by web applications.
Web application development › Web application output encoding
Database servers and web servers are functionally separated.
Database servers › Functional separation between database servers and web servers
Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.
Database servers › Communications between database servers and web servers
Database servers are placed on a different network segment to user workstations.
Database servers › Network environment
Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.
Database servers › Network environment
If only local access to a database is required, networking functionality of database management system applications is disabled or directed to listen solely to the localhost interface.
Database servers › Network environment
Database servers for development, testing, staging and production environments are segregated.
Database servers › Segregation of development, testing, staging and production database servers
A database register is developed, implemented, maintained and regularly verified.
Databases › Database register
File-based access controls are applied to database files.
Databases › Protecting databases
Databases and their contents are classified based on the sensitivity or classification of data that they contain.
Databases › Protecting database contents
Database users’ ability to access, insert, modify and remove database contents is restricted based on their work duties.
Databases › Protecting database contents
The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.
Databases › Protecting database contents
Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
Databases › Segregation of development, testing, staging and production databases
Security-relevant events for databases are centrally logged, including: • access or modification of particularly important content • addition of new users, especially privileged users • changes to user roles or privileges • attempts to elevate user privileges • queries containing comments • queries containing multiple embedded queries • database and query alerts or failures • database structure changes • database administrator actions • use of executable commands • database logons and logoffs.
Databases › Database event logging
An email usage policy is developed, implemented and maintained.
Email usage › Email usage policy
Access to non-approved webmail services is blocked.
Email usage › Webmail services
Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.
Email usage › Protective markings for emails
Protective marking tools do not automatically insert protective markings into emails.
Email usage › Protective marking tools
Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.
Email usage › Protective marking tools
Protective marking tools do not allow users replying to or forwarding emails to select protective markings lower than previously used.
Email usage › Protective marking tools
Email servers are configured to block, log and report emails with inappropriate protective markings.
Email usage › Handling emails with inappropriate, invalid or missing protective markings
The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.
Email usage › Handling emails with inappropriate, invalid or missing protective markings
Emails are routed via centralised email gateways.
Email gateways and servers › Centralised email gateways
When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.
Email gateways and servers › Centralised email gateways
Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.
Email gateways and servers › Email gateway maintenance activities
Email servers only relay emails destined for or originating from their domains (including subdomains).
Email gateways and servers › Open relay email servers
Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.
Email gateways and servers › Email server transport encryption
MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.
Email gateways and servers › Email server transport encryption
SPF is used to specify authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).
Email gateways and servers › Sender Policy Framework
A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).
Email gateways and servers › Sender Policy Framework
SPF is used to verify the authenticity of incoming emails.
Email gateways and servers › Sender Policy Framework
DKIM signing is enabled on emails originating from an organisation’s domains (including subdomains).
Email gateways and servers › DomainKeys Identified Mail
DKIM signatures on incoming emails are verified.
Email gateways and servers › DomainKeys Identified Mail
Email distribution list applications used by external senders is configured such that it does not break the validity of the sender’s DKIM signature.
Email gateways and servers › DomainKeys Identified Mail
DMARC records are configured for an organisation’s domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.
Email gateways and servers › Domain-based Message Authentication, Reporting and Conformance
Incoming emails are rejected if they do not pass DMARC checks.
Email gateways and servers › Domain-based Message Authentication, Reporting and Conformance
Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.
Email gateways and servers › Email content filtering
Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.
Email gateways and servers › Blocking suspicious emails
Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.
Email gateways and servers › Notifications of undeliverable emails
Network documentation is developed, implemented and maintained.
Network design and configuration › Network documentation
Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.
Network design and configuration › Network documentation
Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.
Network design and configuration › Network documentation
Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.
Network design and configuration › Network documentation
Networks are segregated into multiple network zones according to the criticality of servers, services and data.
Network design and configuration › Network segmentation and segregation
An organisation’s networks are segregated from their service providers’ networks.
Network design and configuration › Network segmentation and segregation
VLANs are not used to separate network traffic between an organisation’s networks and public network infrastructure.
Network design and configuration › Using Virtual Local Area Networks
VLANs are not used to separate network traffic between networks belonging to different security domains.
Network design and configuration › Using Virtual Local Area Networks
Network devices managing VLANs are administered from the most trusted security domain.
Network design and configuration › Using Virtual Local Area Networks
Network devices managing VLANs belonging to different security domains do not share VLAN trunks.
Network design and configuration › Using Virtual Local Area Networks
Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.
Network design and configuration › Using Virtual Local Area Networks
Internet connectivity for networked devices is strictly limited to those that require access.
Network design and configuration › Functional separation between networked devices and the internet
Networked management interfaces for IT equipment are not directly exposed to the internet.
Network design and configuration › Networked management interfaces
Servers maintain effective functional separation from each other.
Network design and configuration › Functional separation between servers
Servers minimise communications with other servers at the network and file system level.
Network design and configuration › Functional separation between servers
All data communicated over network infrastructure is encrypted using ASD-approved cryptography.
Network design and configuration › Network encryption
IPv6 functionality is disabled in dual-stack network devices unless it is being used.
Network design and configuration › Using Internet Protocol version 6
IPv6 capable network security appliances are used on IPv6 and dual-stack networks.
Network design and configuration › Using Internet Protocol version 6
Unless explicitly required, IPv6 tunnelling is disabled on all network devices.
Network design and configuration › Using Internet Protocol version 6
IPv6 tunnelling is blocked by network security appliances at externally connected network boundaries.
Network design and configuration › Using Internet Protocol version 6
Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.
Network design and configuration › Using Internet Protocol version 6
Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.
Network design and configuration › Network access controls
Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.
Network design and configuration › Network access controls
Security measures are implemented to prevent unauthorised access to network management traffic.
Network design and configuration › Network management traffic
SMB version 1 is not used on networks.
Network design and configuration › Using the Server Message Block protocol
SNMP version 1 and SNMP version 2 are not used on networks.
Network design and configuration › Using the Simple Network Management Protocol
All default SNMP community strings on network devices are changed and write access is disabled.
Network design and configuration › Using the Simple Network Management Protocol
A NIDS or NIPS is deployed in gateways between an organisation’s networks and other networks they do not manage.
Network design and configuration › Using Network-based Intrusion Detection and Prevention Systems
A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.
Network design and configuration › Using Network-based Intrusion Detection and Prevention Systems
Inbound network connections from anonymity networks are blocked.
Network design and configuration › Blocking anonymity network traffic
Outbound network connections to anonymity networks are blocked.
Network design and configuration › Blocking anonymity network traffic
DNS traffic is encrypted by clients and servers using ASD-approved cryptography.
Network design and configuration › Encrypted Domain Name System Services
A protective DNS service is used to block access to known malicious domain names.
Network design and configuration › Protective Domain Name System Services
Network devices are flashed with trusted firmware before they are used for the first time.
Network design and configuration › Flashing network devices with trusted firmware before first use
Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
Network design and configuration › Default user accounts and credentials for network devices
Unused physical ports on network devices are disabled.
Network design and configuration › Disabling unused physical ports on network devices
Network devices are restarted at least monthly.
Network design and configuration › Regularly restarting network devices
Security-relevant events for internet-facing network devices are centrally logged.
Network design and configuration › Network device event logging
Security-relevant events for non-internet-facing network devices are centrally logged.
Network design and configuration › Network device event logging
All wireless devices are Wi-Fi Alliance certified.
Wireless networks › Choosing wireless devices
Public wireless networks provided for public use are segregated from all other organisation networks.
Wireless networks › Public wireless networks
The administrative interface on wireless access points is disabled for wireless network connections.
Wireless networks › Administrative interfaces for wireless access points
Settings for wireless access points are hardened.
Wireless networks › Default settings
Default SSIDs of wireless access points are changed.
Wireless networks › Default settings
SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.
Wireless networks › Default settings
SSID broadcasting is not disabled on wireless access points.
Wireless networks › Default settings
MAC address filtering is not used to restrict which devices can connect to wireless networks.
Wireless networks › Media Access Control address filtering
Static addressing is not used for assigning IP addresses on wireless networks.
Wireless networks › Static addressing
WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.
Wireless networks › Confidentiality and integrity of wireless network traffic
802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.
Wireless networks › 802.1X authentication
User identity confidentiality is used if available with EAP-TLS implementations.
Wireless networks › 802.1X authentication
Evaluated supplicants, authenticators, wireless access points and authentication servers are used in wireless networks.
Wireless networks › Evaluation of 802.1X authentication implementation
Certificates are generated using an evaluated certificate authority or hardware security module.
Wireless networks › Generating and issuing certificates for authentication
Certificates are required for devices and users accessing wireless networks.
Wireless networks › Generating and issuing certificates for authentication
Certificates are protected by logical and physical access controls, encryption, and user authentication.
Wireless networks › Generating and issuing certificates for authentication
The PMK caching period is not set to greater than 1440 minutes (24 hours).
Wireless networks › Caching 802.1X authentication outcomes
The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.
Wireless networks › Fast Basic Service Set Transition
Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.
Wireless networks › Remote Authentication Dial-In User Service authentication
Wireless networks implement sufficient frequency separation from other wireless networks.
Wireless networks › Interference between wireless networks
Wireless access points enable the use of the 802.11w amendment to protect management frames.
Wireless networks › Protecting management frames on wireless networks
Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.
Wireless networks › Wireless network footprint
Cloud service providers are used for hosting online services.
Service continuity for online services › Cloud-based hosting of online services
Cloud service providers’ ability to scale resources dynamically in response to genuine spikes in demand is discussed and verified as part of capacity and availability planning for online services.
Service continuity for online services › Capacity and availability planning and monitoring for online services
Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.
Service continuity for online services › Capacity and availability planning and monitoring for online services
Continuous real-time monitoring of the capacity and availability of online services is performed.
Service continuity for online services › Capacity and availability planning and monitoring for online services
Where a high availability requirement exists for website hosting, CDNs that cache websites are used.
Service continuity for online services › Using content delivery networks
If using CDNs, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.
Service continuity for online services › Using content delivery networks
Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: • their capacity to withstand denial-of-service attacks • costs likely to be incurred as a result of denial-of-service attacks • availability monitoring and thresholds for notification of denial-of-service attacks • thresholds for turning off any online services or functionality during denial-of-service attacks • pre-approved actions that can be undertaken during denial-of-service attacks • any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.
Service continuity for online services › Denial-of-service attack mitigation strategies
Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.
Service continuity for online services › Denial-of-service attack mitigation strategies
Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.
Service continuity for online services › Denial-of-service attack mitigation strategies
Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.
Cryptographic fundamentals › Cryptographic key management processes and procedures
Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.
Cryptographic fundamentals › Cryptographic implementation assurance
Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.
Cryptographic fundamentals › Cryptographic implementation assurance
Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.
Cryptographic fundamentals › Data recovery
When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.
Cryptographic fundamentals › Handling encrypted IT equipment and media
Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.
Cryptographic fundamentals › Transporting cryptographic equipment
The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.
Cryptographic fundamentals › Reporting cryptographic-related cyber security incidents
Keying material is changed when compromised or suspected of being compromised.
Cryptographic fundamentals › Reporting cryptographic-related cyber security incidents
An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.
Cryptographic algorithms › Using cryptographic algorithms
Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.
Cryptographic algorithms › Using cryptographic algorithms
ECDH is used in preference to DH.
Cryptographic algorithms › Asymmetric cryptographic algorithms
When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.
Cryptographic algorithms › Using Diffie-Hellman
When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.
Cryptographic algorithms › Using Diffie-Hellman
When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.
Cryptographic algorithms › Using Elliptic Curve Cryptography
When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.
Cryptographic algorithms › Using Elliptic Curve Diffie-Hellman
When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.
Cryptographic algorithms › Using the Elliptic Curve Digital Signature Algorithm
When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.
Cryptographic algorithms › Using post-quantum cryptographic algorithms
When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.
Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm
When using ML-DSA for digital signatures, the hedged variant is used whenever possible.
Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm
Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.
Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm
When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.
Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm
When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.
Cryptographic algorithms › Using the Module-Lattice-Based Key Encapsulation Mechanism
When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.
Cryptographic algorithms › Using Rivest-Shamir-Adleman
When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.
Cryptographic algorithms › Using Rivest-Shamir-Adleman
When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.
Cryptographic algorithms › Using Secure Hashing Algorithms
When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.
Cryptographic algorithms › Using symmetric cryptographic algorithms
Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.
Cryptographic algorithms › Using symmetric cryptographic algorithms
A post-quantum cryptography transition plan is developed, implemented and maintained.
Cryptographic algorithms › Transitioning to post-quantum cryptography
The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.
Cryptographic algorithms › Transitioning to post-quantum cryptography
When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.
Cryptographic algorithms › Post-quantum traditional hybrid schemes
An AACP or high assurance cryptographic protocol is used when encrypting data in transit.
Cryptographic protocols › Using cryptographic protocols
Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.
Cryptographic protocols › Using cryptographic protocols
Only the latest version of TLS is used for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
AES-GCM is used for encryption of TLS connections.
Transport Layer Security › Configuring Transport Layer Security
Only server-initiated secure renegotiation is used for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
DH or ECDH is used for key establishment of TLS connections.
Transport Layer Security › Configuring Transport Layer Security
When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.
Transport Layer Security › Configuring Transport Layer Security
Anonymous DH is not used for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
SHA-2-based certificates are used for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
TLS compression is disabled for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
Perfect Forward Secrecy (PFS) is used for TLS connections.
Transport Layer Security › Configuring Transport Layer Security
The use of SSH version 1 is disabled for SSH connections.
Secure Shell › Configuring Secure Shell
The SSH daemon is configured to: • only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx) • have a suitable login banner (Banner x) • have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60) • disable host-based authentication (HostbasedAuthentication no) • disable rhosts-based authentication (IgnoreRhosts yes) • disable the ability to log in directly as root (PermitRootLogin no) • disable empty passwords (PermitEmptyPasswords no) • disable connection forwarding (AllowTCPForwarding no) • disable gateway ports (GatewayPorts no) • disable X11 forwarding (X11Forwarding no).
Secure Shell › Configuring Secure Shell
Public key-based authentication is used for SSH connections.
Secure Shell › Authentication mechanisms
SSH private keys are protected with a password or a key encryption key.
Secure Shell › Authentication mechanisms
When using logins without a password for SSH connections, the following are disabled: • access from IP addresses that do not require access • port forwarding • agent credential forwarding • X11 forwarding • console access.
Secure Shell › Automated remote access
If using remote access without the use of a password for SSH connections, the ‘forced command’ option is used to specify what command is executed and parameter checking is enabled.
Secure Shell › Automated remote access
When SSH-agent or similar key caching applications are used, it is limited to workstations and servers with screen locks and key caches that are set to expire within four hours of inactivity.
Secure Shell › SSH-agent
Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.
Secure/Multipurpose Internet Mail Extension › Configuring Secure/Multipurpose Internet Mail Extension
Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.
Internet Protocol Security › Mode of operation
The ESP protocol is used for authentication and encryption of IPsec connections.
Internet Protocol Security › Protocol selection
IKE version 2 is used for key exchange when establishing IPsec connections.
Internet Protocol Security › Key exchange
AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.
Internet Protocol Security › Encryption algorithms
PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.
Internet Protocol Security › Pseudorandom function
AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.
Internet Protocol Security › Integrity algorithms
DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072-bit MODP Group or 4096-bit MODP Group.
Internet Protocol Security › Diffie-Hellman groups
A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.
Internet Protocol Security › Security association lifetimes
PFS is used for IPsec connections.
Internet Protocol Security › Perfect Forward Secrecy
Gateways are implemented between networks belonging to different security domains.
Gateways › Implementing gateways
Gateways implement a demilitarised zone if external parties require access to an organisation’s services.
Gateways › Implementing gateways
Gateways only allow explicitly authorised data flows.
Gateways › Implementing gateways
Gateways inspect and filter data flows at the transport and above network layers.
Gateways › Implementing gateways
Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.
Gateways › Implementing gateways
System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.
Gateways › System administrators for gateways
System administrators for gateways are assigned the minimum privileges required to perform their duties.
Gateways › System administrators for gateways
Separation of duties is implemented in performing administrative activities for gateways.
Gateways › System administrators for gateways
System administrators for gateways are formally trained on the operation and management of gateways.
Gateways › System administrators for gateways
Gateways are managed via a secure path isolated from all connected networks.
Gateways › System administration of gateways
For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.
Gateways › System administration of gateways
Users authenticate to other networks accessed via gateways.
Gateways › Authenticating to networks accessed via gateways
IT equipment authenticates to other networks accessed via gateways.
Gateways › Authenticating to networks accessed via gateways
Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.
Gateways › Border Gateway Protocol routing security
Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.
Gateways › Border Gateway Protocol routing security
Security-relevant events for gateways are centrally logged, including: • data packets and data flows permitted through gateways • data packets and data flows attempting to leave gateways • real-time alerts for attempted intrusions.
Gateways › Gateway event logging
Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate that they conform to expected security configurations.
Gateways › Assessment of gateways
Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.
Gateways › Assessment of gateways
Evaluated firewalls are used between an organisation’s networks and public network infrastructure.
Firewalls › Using firewalls
Evaluated firewalls are used between networks belonging to different security domains.
Firewalls › Using firewalls
If using a WAF, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.
Web application firewalls › Using web application firewalls
Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation’s networks and public network infrastructure.
Diodes › Using diodes
Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.
Diodes › Using diodes
All web access, including that by internal servers, is conducted through web proxies.
Web proxies › Using web proxies
The following details are centrally logged for websites accessed via web proxies: • web address • date and time • user • amount of data uploaded and downloaded • internal and external IP addresses.
Web proxies › Web proxy event logging
Web content filtering is implemented to filter potentially harmful web-based content.
Web content filters › Using web content filters
Client-side active content is restricted by web content filters to an organisation-approved list of domain names.
Web content filters › Using web content filters
Web content filtering is applied to outbound web traffic where appropriate.
Web content filters › Using web content filters
TLS traffic communicated through gateways is decrypted and inspected.
Web content filters › Transport Layer Security filtering
An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.
Web content filters › Allowing and blocking access to domain names
Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.
Web content filters › Allowing and blocking access to domain names
Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.
Web content filters › Allowing and blocking access to domain names
Files imported or exported via gateways or CDSs undergo content filtering checks.
Content filtering › Performing content filtering
Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.
Content filtering › Performing content filtering
Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.
Content filtering › Performing content filtering
Encrypted files imported or exported via gateways or CDSs are decrypted to undergo content filtering checks.
Content filtering › Encrypted files
Archive files imported or exported via gateways or CDSs are unpacked to undergo content filtering checks.
Content filtering › Archive files
Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.
Content filtering › Archive files
Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.
Content filtering › Antivirus scanning
Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.
Content filtering › Automated dynamic analysis
Files imported or exported via gateways or CDSs are filtered for allowed file types.
Content filtering › Allowing specific content types
Files imported or exported via gateways or CDSs undergo content validation.
Content filtering › Content validation
Files imported or exported via gateways or CDSs undergo content checking.
Content filtering › Content checking
Files imported or exported via gateways or CDSs undergo content conversion.
Content filtering › Content conversion
Files imported or exported via gateways or CDSs undergo content sanitisation.
Content filtering › Content sanitisation
Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.
Content filtering › Validating file integrity
Evaluated peripheral switches are used when sharing peripherals between systems.
Peripheral switches › Using peripheral switches
Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.
Data transfers › Data transfer processes and procedures
Users transferring data to and from systems are held accountable for data transfers they perform.
Data transfers › User responsibilities
When manually importing data to systems, the data is scanned for malicious and active content.
Data transfers › Manual import of data
When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.
Data transfers › Manual import of data
When manually exporting data from systems, the data is checked for unsuitable protective markings.
Data transfers › Manual export of data
When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.
Data transfers › Manual export of data
Data transfer logs are used to record all data imports and exports from systems.
Data transfers › Monitoring data import and export
Data transfer logs for systems are partially verified at least monthly.
Data transfers › Monitoring data import and export
Control text is reproduced from the Australian Government Information Security Manual (June 2026), published by the Australian Signals Directorate, and the DEWR RFFR Statement of Applicability template. This library is provided as a reference; always work from the department's current SoA template and the latest ISM. "Microsoft-assessed" indicates a control our Checkpoint console can propose a status for from a live Microsoft Graph signal — every proposed status is confirmed by a practitioner before it enters the SoA.
We load this entire SoA into your own Microsoft 365 tenant, assess the technical baseline automatically, and drive the gaps to closure on an ISO 27001 ISMS backbone.
Hi! I’m the Compliance365 AI. I can help you work out which security or privacy framework you need, explain what’s involved, and answer questions about ISO 27001, SOC 2, Essential Eight, and more.
What can I help you with today?
Messages are sent to our AI assistant (Claude, by Anthropic) to generate a reply — not stored as part of your account and not used to train AI models.