Right Fit For Risk · ISM June 2026 · Statement of Applicability

Every control in the RFFR SoA — and what automates.

The RFFR Statement of Applicability is 996 controls: 7 program-deed obligations and all 989 Australian Government ISM controls that apply to Non-Classified and OFFICIAL: Sensitive information, across 22 guidelines. This is the whole list — filter it, and see which controls our Checkpoint console assesses automatically from your Microsoft 365 tenant.

989ISM controls
7RFFR deed obligations
86RFFR Core Expectations
126Essential Eight mapped
48auto-assessed today
~14%Microsoft-assessable

What Microsoft 365 assesses for you

Each read-only Microsoft Graph posture check maps to specific ISM controls. When Checkpoint scans your tenant, the live signal proposes an implementation status a practitioner confirms — no manual evidence gathering for the technical baseline. These 48 controls are assessed directly; adding the 126 Essential Eight-mapped controls (delivered through the bundled E8 module) brings the Microsoft-assessable share of the SoA to about 14%. The controls beyond that (governance, personnel, physical, documentation, procurement) stay practitioner-assessed by design; a manual result is never silently counted as a pass.

Microsoft posture checkISM controls assessedExample control IDs
Patching & vulnerability scanning 7 ISM-1876, ISM-1690, ISM-1691, ISM-1692 +3
MFA — all users (Conditional Access) 6 ISM-1504, ISM-1679, ISM-1892, ISM-1893 +2
Microsoft Office macro hardening 5 ISM-1671, ISM-1488, ISM-1672, ISM-1673 +1
Application control (WDAC) 5 ISM-0843, ISM-1490, ISM-1656, ISM-1870 +1
Centralised event logging 4 ISM-1405, ISM-1983, ISM-1985, ISM-1815
Backups & restoration testing 4 ISM-1511, ISM-1810, ISM-1811, ISM-1515
Privileged / admin account limits 3 ISM-1507, ISM-1508, ISM-1852
Managed / compliant devices (Intune) 3 ISM-1400, ISM-1482, ISM-1195
Protective markings & sensitivity labels 3 ISM-0271, ISM-1187, ISM-0272
Just-in-time privileged access (PIM) 2 ISM-1649, ISM-1647
Access re-validation & reviews 2 ISM-1647, ISM-1509
Encryption (ASD-approved cryptography) 2 ISM-1059, ISM-1781
Antivirus / malicious-code protection 2 ISM-1417, ISM-1288
MFA — privileged users 1 ISM-1173
14 checks48distinct ISM controls (~5% of the SoA)

The full control library

All 996 controls, grouped by guideline. Filter by guideline, or show only the RFFR Core Expectations, Essential Eight-mapped, or Microsoft-automated controls.

RFFR Obligations · 7 program-deed controls

RFFR-D1 RFFR Core

Prior to offering employment, and on-going requirements to maintain employment, the individual's identity is positively confirmed.

RFFR-D2 RFFR Core

Prior to offering employment, and on-going requirements to maintain employment, the competency of the individual is verified via qualifications, certifications and experience provided on their CV.

RFFR-D3 RFFR Core

Prior to offering employment, and on-going requirements to maintain employment, a police check and Working with Vulnerable People check are completed per requirements in each state and territory. https://aifs.gov.au/resources/resource-sheets/pre-employment-screening-working-children-checks-and-police-checks

RFFR-D4 RFFR Core

Prior to offering employment, and on-going requirements to maintain employment, it is confirmed that the individual has a valid right to work in Australia.

RFFR-D5 RFFR Core

In considering results of pre-employment checks (e.g. if a person has a criminal record), consideration will be limited to information that impacts on the person’s ability to perform the inherent requirements of the job, consistent with anti-discrimination legislation.

RFFR-D6 RFFR Core

IT Administrators are Australian citizens or permanent residents to give them sufficient connection with Australia.

RFFR-D7 RFFR Core

In accordance with privacy requirements of contracts held, data relating to the Services is not accessible from outside of Australia, and no data relating to the Services is transferred or stored outside of Australia, without prior written approval from the Department.

Cyber security roles · 40 controls · 0 Microsoft-assessed

ISM-1997 NCOS

The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.

Board of directors and executive committee › Embedding cyber security

ISM-1998 NCOS

The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.

Board of directors and executive committee › Embedding cyber security

ISM-1999 NCOS

The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.

Board of directors and executive committee › Embedding cyber security

ISM-2000 NCOS

The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.

Board of directors and executive committee › Embedding cyber security

ISM-2001 NCOS

The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.

Board of directors and executive committee › Championing a positive cyber security culture

ISM-2002 NCOS

The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.

Board of directors and executive committee › Building cyber security expertise

ISM-2003 NCOS

The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.

Board of directors and executive committee › Building cyber security expertise

ISM-2004 NCOS

The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.

Board of directors and executive committee › Building cyber security expertise

ISM-2005 NCOS

The board of directors or executive committee understands the business criticality of their organisation’s systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.

Board of directors and executive committee › Identifying critical business assets

ISM-2006 NCOS

The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.

Board of directors and executive committee › Planning for major cyber security incidents

ISM-0714 NCOS

A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).

Chief information security officer › Providing cyber security leadership and guidance

ISM-1478 RFFR Core NCOS

The CISO oversees their organisation’s cyber security program and ensures their organisation’s compliance with cyber security policy, standards, regulations and legislation.

Chief information security officer › Overseeing the cyber security program

ISM-1617 NCOS

The CISO regularly reviews and updates their organisation’s cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.

Chief information security officer › Overseeing the cyber security program

ISM-1966 NCOS

The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.

Chief information security officer › Overseeing the cyber security program

ISM-0724 NCOS

The CISO implements cyber security measurement metrics and key performance indicators for their organisation.

Chief information security officer › Overseeing the cyber security program

ISM-0725 NCOS

The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.

Chief information security officer › Coordinating cyber security

ISM-0726 NCOS

The CISO coordinates security risk management activities between cyber security and business teams.

Chief information security officer › Coordinating cyber security

ISM-0718 NCOS

The CISO regularly reports directly to their organisation’s board of directors or executive committee on cyber security matters.

Chief information security officer › Reporting on cyber security

ISM-1918 NCOS

The CISO regularly reports directly to their organisation’s audit, risk and compliance committee (or equivalent) on cyber security matters.

Chief information security officer › Reporting on cyber security

ISM-0733 NCOS

The CISO is fully aware of all cyber security incidents within their organisation.

Chief information security officer › Overseeing cyber security incident response activities

ISM-1618 NCOS

The CISO oversees their organisation’s response to cyber security incidents.

Chief information security officer › Overseeing cyber security incident response activities

ISM-0734 RFFR Core NCOS

The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.

Chief information security officer › Contributing to business continuity and disaster recovery planning

ISM-0720 NCOS

The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.

Chief information security officer › Communicating a cyber security vision and strategy

ISM-0731 NCOS

The CISO oversees cyber supply chain risk management activities for their organisation.

Chief information security officer › Working with suppliers

ISM-0732 NCOS

The CISO receives and manages a dedicated cyber security budget for their organisation.

Chief information security officer › Receiving and managing a dedicated cyber security budget

ISM-0717 NCOS

The CISO oversees the management of cyber security personnel within their organisation.

Chief information security officer › Overseeing cyber security personnel

ISM-2020 NCOS

The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.

Chief information security officer › Overseeing cyber security personnel

ISM-0735 NCOS

The CISO oversees the development, implementation and maintenance of their organisation’s cyber security awareness training program.

Chief information security officer › Overseeing cyber security awareness training

ISM-1071 NCOS

Each system has a designated system owner.

System owners › System ownership and oversight

ISM-1525 NCOS

System owners register each system with its authorising officer.

System owners › System ownership and oversight

ISM-1633 NCOS

System owners, in consultation with each system’s authorising officer, determine the system boundary, business criticality, and security and resilience objectives for each system based on an assessment of the impact if it were to be compromised or attacked.

System owners › Protecting systems and their resources

ISM-1203 NCOS

System owners, in consultation with each system’s authorising officer, conduct a threat and risk assessment for each system.

System owners › Protecting systems and their resources

ISM-1634 NCOS

System owners, in consultation with each system’s authorising officer, select controls for each system and tailor them to achieve desired security and resilience objectives.

System owners › Protecting systems and their resources

ISM-0009 NCOS

System owners, in consultation with each system’s authorising officer, identify any supplementary controls required based upon the unique nature of each system, its operating environment and the organisation’s risk tolerances.

System owners › Protecting systems and their resources

ISM-1635 NCOS

System owners implement controls for each system and its operating environment.

System owners › Protecting systems and their resources

ISM-1636 NCOS

System owners, in consultation with each system’s authorising officer, ensure controls for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system and its operating environment undergo a security assessment by their organisation’s own assessors or Infosec Registered Assessor Program (IRAP) assessors to determine if they have been implemented correctly and are operating as intended.

System owners › Protecting systems and their resources

ISM-0027 NCOS

System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.

System owners › Protecting systems and their resources

ISM-1526 RFFR Core NCOS

System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.

System owners › Protecting systems and their resources

ISM-2021 NCOS

System owners implement and maintain data minimisation practices for each of their systems.

System owners › Protecting systems and their resources

ISM-1587 NCOS

System owners report the security status of each system to its authorising officer at least annually.

System owners › Annual reporting of system security status

Cyber security incidents · 21 controls · 0 Microsoft-assessed

ISM-0576 NCOS

A cyber security incident management policy, and associated cyber security incident response plan, is developed, implemented and maintained.

Managing cyber security incidents › Cyber security incident management policy

ISM-1784 NCOS

The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.

Managing cyber security incidents › Cyber security incident management policy

ISM-0125 RFFR Core NCOS

A cyber security incident register is developed, implemented and maintained.

Managing cyber security incidents › Cyber security incident register

ISM-1803 NCOS

A cyber security incident register contains the following for each cyber security incident: • the date the cyber security incident occurred • the date the cyber security incident was discovered • a description of the cyber security incident • any actions taken in response to the cyber security incident • to whom the cyber security incident was reported.

Managing cyber security incidents › Cyber security incident register

ISM-1625 NCOS

An insider threat mitigation program is developed, implemented and maintained.

Managing cyber security incidents › Insider threat mitigation program

ISM-1626 NCOS

Legal advice is sought regarding the development and implementation of an insider threat mitigation program.

Managing cyber security incidents › Insider threat mitigation program

ISM-0123 RFFR Core ML2 NCOS

Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.

Managing cyber security incidents › Reporting cyber security incidents

ISM-0140 ML2 NCOS

Cyber security incidents are reported to ASD as soon as possible after they occur or are discovered.

Managing cyber security incidents › Reporting cyber security incidents to ASD

ISM-1880 NCOS

Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

Managing cyber security incidents › Reporting cyber security incidents to customers and the public

ISM-1881 NCOS

Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.

Managing cyber security incidents › Reporting cyber security incidents to customers and the public

ISM-1819 ML2 NCOS

Following the identification of a cyber security incident, the cyber security incident response plan is enacted.

Responding to cyber security incidents › Enacting cyber security incident response plans

ISM-0133 RFFR Core NCOS

When a data spill occurs, data owners are advised and access to the data is restricted.

Responding to cyber security incidents › Handling and containing data spills

ISM-0917 NCOS

When malicious code is detected, the following steps are taken to handle the infection: • the infected systems are isolated • all previously connected media used in the period leading up to the infection are scanned for signs of infection and isolated if necessary • antivirus applications are used to remove the infection from infected systems and media • if the infection cannot be reliably removed, systems are restored from a known good backup or rebuilt.

Responding to cyber security incidents › Handling and containing malicious code infections

ISM-1969 NCOS

Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.

Responding to cyber security incidents › Handling and containing malicious code infections

ISM-1970 NCOS

Malicious code processing for cyber security incident response or research purposes is conducted in a dedicated analysis environment segregated from other systems.

Responding to cyber security incidents › Handling and containing malicious code infections

ISM-0137 NCOS

Legal advice is sought before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

Responding to cyber security incidents › Handling and containing intrusions

ISM-1609 NCOS

System owners are consulted before allowing intrusion activity to continue on a system for the purpose of collecting further data or evidence.

Responding to cyber security incidents › Handling and containing intrusions

ISM-1731 NCOS

Planning and coordination of intrusion remediation activities are conducted on a separate system to that which has been compromised.

Responding to cyber security incidents › Handling and containing intrusions

ISM-1732 NCOS

To the extent possible, all intrusion remediation activities are conducted in a coordinated manner during the same planned outage.

Responding to cyber security incidents › Handling and containing intrusions

ISM-1213 RFFR Core NCOS

Following intrusion remediation activities, full network traffic is captured for at least seven days and analysed to determine whether malicious actors have been successfully removed from the system.

Responding to cyber security incidents › Handling and containing intrusions

ISM-0138 NCOS

The integrity of evidence gathered during an investigation is maintained by investigators: • recording all their actions • maintaining a proper chain of custody • following all instructions provided by relevant law enforcement agencies.

Responding to cyber security incidents › Maintaining the integrity of evidence

Procurement and outsourcing · 35 controls · 0 Microsoft-assessed

ISM-1631 NCOS

Suppliers of operating systems, applications, IT equipment, OT equipment and services associated with systems are identified.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1452 RFFR Core NCOS

A supply chain risk assessment is performed for suppliers of operating systems, applications, IT equipment, OT equipment and services to assess the impact to a system’s security risk profile.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1567 NCOS

Suppliers identified as high risk by a cyber supply chain risk assessment are not used.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1568 NCOS

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to the security of their products and services.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1882 NCOS

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have demonstrated a commitment to transparency for their products and services.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1632 NCOS

Operating systems, applications, IT equipment, OT equipment and services are procured from suppliers that have a strong track record of maintaining the security of their own systems.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1569 NCOS

A shared responsibility model is created, documented and shared between suppliers and their customers to articulate the security responsibilities of each party.

Cyber supply chain risk management › Cyber supply chain risk management activities

ISM-1785 NCOS

A supplier relationship management policy is developed, implemented and maintained.

Cyber supply chain risk management › Supplier relationship management

ISM-1786 NCOS

An approved supplier list is developed, implemented and maintained.

Cyber supply chain risk management › Supplier relationship management

ISM-1787 NCOS

Operating systems, applications, IT equipment, OT equipment and services are sourced from approved suppliers.

Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services

ISM-1788 NCOS

Multiple potential suppliers are identified for sourcing critical operating systems, applications, IT equipment, OT equipment and services.

Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services

ISM-1789 NCOS

Sufficient spares of critical IT equipment and OT equipment are sourced and kept in reserve.

Cyber supply chain risk management › Sourcing operating systems, applications, IT equipment, OT equipment and services

ISM-1790 NCOS

Operating systems, applications, IT equipment, OT equipment and services are delivered in a manner that maintains their integrity.

Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services

ISM-1791 NCOS

The integrity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services

ISM-1792 NCOS

The authenticity of operating systems, applications, IT equipment, OT equipment and services are assessed as part of acceptance of products and services.

Cyber supply chain risk management › Delivery of operating systems, applications, IT equipment, OT equipment and services

ISM-1736 NCOS

A managed service register is developed, implemented, maintained and regularly verified.

Managed services and cloud services › Managed services

ISM-1737 NCOS

A managed service register contains the following for each managed service: • managed service provider’s name • managed service’s name • purpose for using the managed service • sensitivity or classification of data involved • due date for the next security assessment of the managed service • contractual arrangements for the managed service • point of contact for users of the managed service • 24/7 contact details for the managed service provider.

Managed services and cloud services › Managed services

ISM-1793 NCOS

Managed service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET managed services undergo an Infosec Registered Assessor Program (IRAP) assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Managed services and cloud services › Assessment of managed service providers

ISM-1637 NCOS

An outsourced cloud service register is developed, implemented, maintained and regularly verified.

Managed services and cloud services › Outsourced cloud services

ISM-1638 NCOS

An outsourced cloud service register contains the following for each outsourced cloud service: • cloud service provider’s name • cloud service’s name • purpose for using the cloud service • sensitivity or classification of data involved • due date for the next security assessment of the cloud service • contractual arrangements for the cloud service • point of contact for users of the cloud service • 24/7 contact details for the cloud service provider.

Managed services and cloud services › Outsourced cloud services

ISM-1570 NCOS

Outsourced cloud service providers and their non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET cloud services undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Managed services and cloud services › Assessment of outsourced cloud service providers

ISM-1395 RFFR Core NCOS

Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.

Managed services and cloud services › Contractual security requirements with service providers

ISM-0072 NCOS

Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1571 RFFR Core NCOS

The right to verify compliance with security requirements is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1738 RFFR Core NCOS

The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1804 NCOS

Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-0141 RFFR Core NCOS

The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1794 NCOS

A minimum notification period of one month by service providers for significant changes to their own service provider arrangements is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1451 NCOS

Types of data and its ownership is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1572 RFFR Core NCOS

The regions or availability zones where data will be processed, stored and communicated, as well as a minimum notification period for any configuration changes, is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1573 NCOS

Access to all logs relating to an organisation’s data and services is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1574 NCOS

The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1575 NCOS

A minimum notification period of one month for the cessation of any services by a service provider is documented in contractual arrangements with service providers.

Managed services and cloud services › Contractual security requirements with service providers

ISM-1073 NCOS

An organisation’s systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.

Managed services and cloud services › Access to systems by service providers

ISM-1576 NCOS

If an organisation’s systems are accessed or administered by a service provider in an unauthorised manner, the organisation is immediately notified.

Managed services and cloud services › Access to systems by service providers

Cyber security documentation · 11 controls · 0 Microsoft-assessed

ISM-0039 RFFR Core NCOS

A cyber security strategy is developed, implemented and maintained.

Development and maintenance of cyber security documentation › Cyber security strategy

ISM-0047 NCOS

Organisational-level cyber security documentation is approved by the chief information security officer while system-specific cyber security documentation is approved by the system’s authorising officer.

Development and maintenance of cyber security documentation › Approval of cyber security documentation

ISM-1739 NCOS

A system’s security architecture is approved prior to the development of the system.

Development and maintenance of cyber security documentation › Approval of cyber security documentation

ISM-0888 NCOS

Cyber security documentation is reviewed at least annually and includes a ‘current as at [date]’ or equivalent statement.

Development and maintenance of cyber security documentation › Maintenance of cyber security documentation

ISM-1602 NCOS

Cyber security documentation, including notification of subsequent changes, is communicated to all stakeholders.

Development and maintenance of cyber security documentation › Communication of cyber security documentation

ISM-0041 RFFR Core NCOS

Systems have a system security plan that includes an overview of the system (covering the system’s purpose, the system boundary and how the system is managed) as well as an annex that covers applicable controls from this document and any additional controls that have been identified and implemented.

System-specific cyber security documentation › System security plan

ISM-0043 RFFR Core NCOS

Systems have a cyber security incident response plan that covers the following: • guidelines on what constitutes a cyber security incident • the types of cyber security incidents likely to be encountered and the expected response to each type • how to report cyber security incidents, internally to an organisation and externally to relevant authorities • other parties that need to be informed in the event of a cyber security incident • the authority, or authorities, responsible for investigating and responding to cyber security incidents • the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority • the steps necessary to ensure the integrity of evidence relating to a cyber security incident • system contingency measures or a reference to such details if they are in a separate document.

System-specific cyber security documentation › Cyber security incident response plan

ISM-0912 NCOS

Systems have a change and configuration management plan that includes: • the establishment and maintenance of authorised baseline configurations for systems • what constitutes routine and urgent changes to the configuration of systems • how changes to the configuration of systems will be requested, tracked and documented • who needs to be consulted prior to routine and urgent changes to the configuration of systems • who needs to approve routine and urgent changes to the configuration of systems • who needs to be notified of routine and urgent changes to the configuration of systems • what additional change management and configuration management processes and procedures need to be followed before, during and after routine and urgent changes to the configuration of systems.

System-specific cyber security documentation › Change and configuration management plan

ISM-1163 RFFR Core NCOS

Systems have a continuous monitoring plan that includes: • conducting security assessment activities to identify vulnerabilities • analysing identified vulnerabilities to determine their potential impact • implementing mitigations based on risk, effectiveness and cost.

System-specific cyber security documentation › Continuous monitoring plan

ISM-1563 RFFR Core NCOS

At the conclusion of a security assessment for a system, a security assessment report is produced by the assessor and covers: • the scope of the security assessment • the system’s strengths and weaknesses • security risks associated with the operation of the system • the effectiveness of the implementation of controls • any recommended remediation actions.

System-specific cyber security documentation › Security assessment report

ISM-1564 RFFR Core NCOS

At the conclusion of a security assessment for a system, a plan of action and milestones is produced by the system owner.

System-specific cyber security documentation › Plan of action and milestones

Physical security · 11 controls · 0 Microsoft-assessed

ISM-1973 NC

Non-classified systems are secured in suitably secure facilities.

Facilities and systems › Physical access to systems

ISM-0810 OS

Classified systems are secured in facilities that meet the requirements for a security zone suitable for their classification.

Facilities and systems › Physical access to systems

ISM-1974 NC

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-1053 OS

Classified servers, network devices and cryptographic equipment are secured in server rooms or communications rooms that meet the requirements for a security zone suitable for their classification.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-1975 NC

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure security containers.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-1530 OS

Classified servers, network devices and cryptographic equipment are secured in security containers suitable for their classification taking into account the combination of security zones they reside in.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-0813 NCOS

Server rooms, communications rooms and security containers are not left in unsecured states.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-1074 NCOS

Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.

Facilities and systems › Physical access to servers, network devices and cryptographic equipment

ISM-1296 RFFR Core NCOS

Physical security is implemented to protect network devices in public areas from physical damage or unauthorised access.

Facilities and systems › Physical access to network devices in public areas

ISM-0164 NCOS

Unauthorised people are prevented from observing systems, in particular workstation displays and keyboards, within facilities.

Facilities and systems › Preventing observation by unauthorised people

ISM-0161 NCOS

IT equipment and media are secured when not in use.

IT equipment and media › Securing IT equipment and media

Personnel security · 49 controls · 6 Microsoft-assessed

ISM-0252 RFFR Core NCOS

Cyber security awareness training is undertaken annually by all personnel and covers: • the purpose of the cyber security awareness training • security appointments and contacts • authorised use of systems and their resources • protection of systems and their resources • reporting of cyber security incidents and suspected compromises of systems and their resources.

Cyber security awareness training › Providing cyber security awareness training

ISM-1565 NCOS

Tailored privileged user training is undertaken annually by all privileged users.

Cyber security awareness training › Providing cyber security awareness training

ISM-2022 NCOS

A cyber security awareness training register is developed, implemented and maintained.

Cyber security awareness training › Providing cyber security awareness training

ISM-1740 RFFR Core NCOS

Personnel dealing with banking details and payment requests are advised of what business email compromise is and how to manage and report it.

Cyber security awareness training › Managing and reporting suspicious changes to banking details or payment requests

ISM-2071 NCOS

Personnel dealing with user account details are advised of what social engineering attacks are, how to manage such situations and how to report them.

Cyber security awareness training › Managing and reporting suspicious requests to disclose or change user account details

ISM-0817 NCOS

Personnel are advised of what suspicious contact via online services is and how to report it.

Cyber security awareness training › Reporting suspicious contact via online services

ISM-0820 NCOS

Personnel are advised not to post work information on unauthorised online services, and to report cases where such information is posted.

Cyber security awareness training › Posting work-related information on online services

ISM-2104 NCOS

Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted.

Cyber security awareness training › Posting work-related information on online services

ISM-2105 NCOS

Personnel are advised to limit posting information about their work-related duties on unauthorised online services, and to report cases where such information is posted.

Cyber security awareness training › Posting work-related information on online services

ISM-2106 NCOS

Personnel are advised to limit posting information about their work-related skills and experience on unauthorised online services, and to report cases where such information is posted.

Cyber security awareness training › Posting work-related information on online services

ISM-0821 NCOS

Personnel are advised of security risks associated with posting personal information on online services.

Cyber security awareness training › Posting personal information on online services

ISM-1146 NCOS

Personnel are advised to maintain separate personal user accounts from any work user accounts they use for online services.

Cyber security awareness training › Posting personal information on online services

ISM-2107 NCOS

Personnel are encouraged to use any available privacy settings to restrict who can view personal information they post on online services.

Cyber security awareness training › Posting personal information on online services

ISM-0824 NCOS

Personnel are advised not to send or receive files via unauthorised online services.

Cyber security awareness training › Sending and receiving files via online services

ISM-1864 NCOS

A system usage policy is developed, implemented and maintained.

Access to systems and their resources › System usage policy

ISM-2074 NCOS

A general-purpose AI usage policy is developed, implemented and maintained.

Access to systems and their resources › General-purpose artificial intelligence usage policy

ISM-0258 NCOS

A web usage policy is developed, implemented and maintained.

Access to systems and their resources › Web usage policy

ISM-0432 NCOS

Access requirements for systems and their resources are documented in their system security plan.

Access to systems and their resources › System access requirements

ISM-0434 RFFR Core NCOS

Personnel undergo appropriate employment screening and, where necessary, hold an appropriate security clearance before being granted access to systems and their resources.

Access to systems and their resources › System access requirements

ISM-0435 NCOS

Personnel receive any necessary briefings before being granted access to systems and their resources.

Access to systems and their resources › System access requirements

ISM-1865 NCOS

Personnel agree to abide by system usage policies before being granted access to systems and their resources.

Access to systems and their resources › System access requirements

ISM-0414 NCOS

Personnel granted access to systems and their resources are uniquely identifiable.

Access to systems and their resources › User identification

ISM-0415 NCOS

The use of shared user accounts is strictly controlled, and personnel using such accounts are uniquely identifiable.

Access to systems and their resources › User identification

ISM-1583 NCOS

Personnel who are contractors are identified as such.

Access to systems and their resources › User identification

ISM-0405 NCOS

Requests for unprivileged access to systems and their resources are validated when first requested.

Access to systems and their resources › Unprivileged access to systems

ISM-1852 Microsoft-assessed NCOS

Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

Access to systems and their resources › Unprivileged access to systems

ISM-1566 NCOS

Use of unprivileged access is centrally logged.

Access to systems and their resources › Unprivileged access to systems

ISM-1507 RFFR Core ML1 Microsoft-assessed NCOS

Requests for privileged access to systems and their resources are validated when first requested.

Access to systems and their resources › Privileged access to systems

ISM-1508 ML3 Microsoft-assessed NCOS

Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.

Access to systems and their resources › Privileged access to systems

ISM-1175 RFFR Core ML1 NCOS

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.

Access to systems and their resources › Privileged access to systems

ISM-1883 RFFR Core ML1 NCOS

Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.

Access to systems and their resources › Privileged access to systems

ISM-1649 ML3 Microsoft-assessed NCOS

Just-in-time administration is used for the administration of systems and their resources.

Access to systems and their resources › Privileged access to systems

ISM-0445 RFFR Core ML1 NCOS

Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.

Access to systems and their resources › Privileged access to systems

ISM-1263 NCOS

Unique privileged user accounts are used for administering individual server applications.

Access to systems and their resources › Privileged access to systems

ISM-1509 RFFR Core ML2 Microsoft-assessed NCOS

Privileged access events are centrally logged.

Access to systems and their resources › Privileged access to systems

ISM-1650 RFFR Core ML2 NCOS

Privileged user account and security group management events are centrally logged.

Access to systems and their resources › Privileged access to systems

ISM-0430 NCOS

Access to systems and their resources are removed or suspended the same day personnel no longer have a legitimate requirement for access.

Access to systems and their resources › Suspension of access to systems

ISM-1591 NCOS

Access to systems and their resources are removed or suspended as soon as practicable when personnel are detected undertaking malicious activities.

Access to systems and their resources › Suspension of access to systems

ISM-1404 NCOS

Unprivileged access to systems and their resources are disabled after 45 days of inactivity.

Access to systems and their resources › Suspension of access to systems

ISM-1648 ML2 NCOS

Privileged access to systems and their resources are disabled after 45 days of inactivity.

Access to systems and their resources › Suspension of access to systems

ISM-1647 ML2 Microsoft-assessed NCOS

Privileged access to systems and their resources are disabled after 12 months unless revalidated.

Access to systems and their resources › Suspension of access to systems

ISM-0407 NCOS

A secure record is maintained for the life of systems and their resources that covers the following for each user: • their user identification • their signed agreement to abide by system usage policies • who authorised their access • when their access was granted • the level of access they were granted • when their access, and their level of access, was last reviewed • when their level of access was changed, and to what extent (if applicable) • when their access was withdrawn (if applicable).

Access to systems and their resources › Recording authorisation for personnel to access systems

ISM-0441 NCOS

When personnel are granted temporary access to systems and their resources, effective controls are put in place to restrict their access to only data required for them to undertake their duties.

Access to systems and their resources › Temporary access to systems

ISM-1610 NCOS

A method of emergency access to systems and their resources is documented and tested at least once when initially implemented and each time fundamental information technology infrastructure changes occur.

Access to systems and their resources › Emergency access to systems

ISM-1611 NCOS

Break glass accounts are only used when normal authentication processes cannot be used.

Access to systems and their resources › Emergency access to systems

ISM-1612 NCOS

Break glass accounts are only used for specific authorised activities.

Access to systems and their resources › Emergency access to systems

ISM-1614 NCOS

Break glass account credentials are changed by the account custodian after they are accessed by any other party.

Access to systems and their resources › Emergency access to systems

ISM-1615 NCOS

Break glass accounts are tested after credentials are changed.

Access to systems and their resources › Emergency access to systems

ISM-1613 NCOS

Use of break glass accounts is centrally logged.

Access to systems and their resources › Emergency access to systems

Communications infrastructure · 27 controls · 0 Microsoft-assessed

ISM-0181 NCOS

Cabling infrastructure is installed in accordance with relevant Australian Standards, as directed by the Australian Communications and Media Authority.

Cabling infrastructure › Cabling infrastructure standards

ISM-1111 NCOS

Fibre-optic cables are used for cabling infrastructure instead of copper cables.

Cabling infrastructure › Use of fibre-optic cables

ISM-0211 NCOS

A cable register is developed, implemented, maintained and regularly verified.

Cabling infrastructure › Cable register

ISM-0208 NCOS

A cable register contains the following for each cable: • cable identifier • cable colour • sensitivity/classification • source • destination • location • seal numbers (if applicable).

Cabling infrastructure › Cable register

ISM-1645 NCOS

Floor plan diagrams are developed, implemented, maintained and regularly verified.

Cabling infrastructure › Floor plan diagrams

ISM-1646 NCOS

Floor plan diagrams contain the following: • cable paths (including ingress and egress points between floors) • cable reticulation system and conduit paths • floor concentration boxes • wall outlet boxes • network cabinets.

Cabling infrastructure › Floor plan diagrams

ISM-0206 NCOS

Cable labelling processes, and supporting cable labelling procedures, are developed, implemented and maintained.

Cabling infrastructure › Cable labelling processes and procedures

ISM-1096 NCOS

Cables are labelled at each end with sufficient source and destination details to enable the physical identification and inspection of the cable.

Cabling infrastructure › Labelling cables

ISM-1639 NCOS

Building management cables are labelled with their purpose in black writing on a yellow background, with a minimum size of 2.5 cm x 1 cm, and attached at five-metre intervals.

Cabling infrastructure › Labelling building management cables

ISM-1640 NCOS

Cables for foreign systems installed in Australian facilities are labelled at inspection points.

Cabling infrastructure › Labelling cables for foreign systems in Australian facilities

ISM-1820 NCOS

Cables for individual systems use a consistent colour.

Cabling infrastructure › Cable colours

ISM-0926 NCOS

Non-classified, OFFICIAL: Sensitive and PROTECTED cables are coloured neither salmon pink nor red.

Cabling infrastructure › Cable colours

ISM-1112 NCOS

Cables in non-TOP SECRET areas are inspectable every five metres or less.

Cabling infrastructure › Cable inspectability

ISM-1119 NCOS

Cables in TOP SECRET areas are fully inspectable for their entire length.

Cabling infrastructure › Cable inspectability

ISM-1114 NCOS

Cable bundles or conduits sharing a common cable reticulation system have a dividing partition or visible gap between each cable bundle and conduit.

Cabling infrastructure › Common cable reticulation systems

ISM-1130 NCOS

In shared facilities, cables are run in an enclosed cable reticulation system.

Cabling infrastructure › Enclosed cable reticulation systems

ISM-1164 NCOS

In shared facilities, conduits or the front covers of ducts, cable trays in floors and ceilings, and associated fittings are clear plastic.

Cabling infrastructure › Covers for enclosed cable reticulation systems

ISM-1115 NCOS

Cables from cable trays to wall outlet boxes are run in flexible or plastic conduit.

Cabling infrastructure › Cables in walls

ISM-1095 NCOS

Wall outlet boxes denote the systems, cable identifiers and wall outlet box identifier.

Cabling infrastructure › Labelling wall outlet boxes

ISM-1822 NCOS

Wall outlet boxes for individual systems use a consistent colour.

Cabling infrastructure › Wall outlet box colours

ISM-1107 NCOS

Non-classified, OFFICIAL: Sensitive and PROTECTED wall outlet boxes are coloured neither salmon pink nor red.

Cabling infrastructure › Wall outlet box colours

ISM-1109 NCOS

Wall outlet box covers are clear plastic.

Cabling infrastructure › Wall outlet box covers

ISM-1102 NCOS

Cable reticulation systems leading into cabinets are terminated as close as possible to the cabinet.

Cabling infrastructure › Connecting cable reticulation systems to cabinets

ISM-1101 NCOS

In TOP SECRET areas, cable reticulation systems leading into cabinets in server rooms or communications rooms are terminated as close as possible to the cabinet.

Cabling infrastructure › Connecting cable reticulation systems to cabinets

ISM-1103 NCOS

In TOP SECRET areas, cable reticulation systems leading into cabinets not in server rooms or communications rooms are terminated at the boundary of the cabinet.

Cabling infrastructure › Connecting cable reticulation systems to cabinets

ISM-0250 NCOS

IT equipment meets industry and government standards relating to electromagnetic interference/electromagnetic compatibility.

Emanation security › Electromagnetic interference/electromagnetic compatibility standards

ISM-1884 OS

Emanation security doctrine produced by ASD for the management of emanation security matters is complied with.

Emanation security › Emanation security doctrine

Communications systems · 32 controls · 0 Microsoft-assessed

ISM-1078 NCOS

A telephone system usage policy is developed, implemented and maintained.

Telephone systems › Telephone system usage policy

ISM-0229 NCOS

Personnel are advised of the permitted sensitivity or classification of information that can be discussed over internal and external telephone systems.

Telephone systems › Personnel awareness

ISM-0230 NCOS

Personnel are advised of security risks posed by non-secure telephone systems in areas where sensitive or classified conversations can occur.

Telephone systems › Personnel awareness

ISM-0231 NCOS

When using cryptographic equipment to permit different levels of conversation for different kinds of connections, telephone systems give a visual indication of what kind of connection has been made.

Telephone systems › Personnel awareness

ISM-0232 NCOS

Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.

Telephone systems › Protecting conversations

ISM-0233 NCOS

Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted using ASD-approved cryptography.

Telephone systems › Cordless telephone systems

ISM-0235 NCOS

Speakerphones are not used on telephone systems in TOP SECRET areas unless the telephone system is located in an audio secure room, the room is audio secure during conversations and only personnel involved in conversations are present in the room.

Telephone systems › Speakerphones

ISM-0236 NCOS

Off-hook audio protection features are used on telephone systems in areas where background conversations may exceed the sensitivity or classification that the telephone system is authorised for communicating.

Telephone systems › Off-hook audio protection

ISM-0931 NCOS

In SECRET and TOP SECRET areas, push-to-talk handsets or push-to-talk headsets are used to meet any off-hook audio protection requirements.

Telephone systems › Off-hook audio protection

ISM-1562 NCOS

Video conferencing and IP telephony infrastructure is hardened.

Video conferencing and Internet Protocol telephony › Video conferencing and Internet Protocol telephony infrastructure hardening

ISM-0546 NCOS

When video conferencing or IP telephony traffic passes through a gateway containing a firewall or proxy, a video-aware or voice-aware firewall or proxy is used.

Video conferencing and Internet Protocol telephony › Video-aware and voice-aware firewalls and proxies

ISM-0548 NCOS

Video conferencing and IP telephony calls are established using a secure session initiation protocol.

Video conferencing and Internet Protocol telephony › Protecting video conferencing and Internet Protocol telephony traffic

ISM-0547 NCOS

Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.

Video conferencing and Internet Protocol telephony › Protecting video conferencing and Internet Protocol telephony traffic

ISM-0554 NCOS

An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.

Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication

ISM-0553 NCOS

Authentication and authorisation is used for all actions on a video conferencing network, including call setup and changing settings.

Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication

ISM-0555 NCOS

Authentication and authorisation is used for all actions on an IP telephony network, including registering a new IP phone, changing phone users, changing settings and accessing voicemail.

Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication

ISM-0551 NCOS

IP telephony is configured such that: • IP phones authenticate themselves to the call controller upon registration • auto-registration is disabled and only authorised devices are allowed to access the network • unauthorised devices are blocked by default • all unused and prohibited functionality is disabled.

Video conferencing and Internet Protocol telephony › Video conferencing unit and Internet Protocol phone authentication

ISM-0549 NCOS

Video conferencing and IP telephony traffic is physically or logically separated from other data traffic.

Video conferencing and Internet Protocol telephony › Traffic separation

ISM-0556 NCOS

Workstations are not connected to video conferencing units or IP phones unless the workstation or the device uses Virtual Local Area Networks or similar mechanisms to maintain separation between video conferencing, IP telephony and other data traffic.

Video conferencing and Internet Protocol telephony › Traffic separation

ISM-0558 NCOS

IP phones used in public areas do not have the ability to access data networks, voicemail and directory services.

Video conferencing and Internet Protocol telephony › Internet Protocol phones in public areas

ISM-0559 NCOS

Microphones (including headsets and USB handsets) and webcams are not used with non-SECRET workstations in SECRET areas.

Video conferencing and Internet Protocol telephony › Microphones and webcams

ISM-1450 NCOS

Microphones (including headsets and USB handsets) and webcams are not used with non-TOP SECRET workstations in TOP SECRET areas.

Video conferencing and Internet Protocol telephony › Microphones and webcams

ISM-1019 NCOS

A denial of service response plan for video conferencing and IP telephony services is developed, implemented and maintained.

Video conferencing and Internet Protocol telephony › Denial of service response plan

ISM-1805 NCOS

A denial of service response plan for video conferencing and IP telephony services contains the following: • how to identify signs of a denial-of-service attack • how to identify the source of a denial-of-service attack • how capabilities can be maintained during a denial-of-service attack • what actions can be taken to respond to a denial-of-service attack.

Video conferencing and Internet Protocol telephony › Denial of service response plan

ISM-0588 NCOS

An MFD usage policy is developed, implemented and maintained.

Multifunction devices › Multifunction device usage policy

ISM-0245 NCOS

MFDs are not connected to digital telephone systems.

Multifunction devices › Connecting multifunction devices to digital telephone systems

ISM-1854 NCOS

Users authenticate to MFDs before they can print, scan or copy documents.

Multifunction devices › Authenticating to multifunction devices

ISM-0590 NCOS

Authentication measures for MFDs are the same strength as those used for workstations on networks they are connected to.

Multifunction devices › Authenticating to multifunction devices

ISM-0589 NCOS

MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.

Multifunction devices › Scanning and copying documents on multifunction devices

ISM-1855 NCOS

Use of MFDs for printing, scanning and copying purposes, including the capture of shadow copies of documents, are centrally logged.

Multifunction devices › Logging multifunction device use

ISM-1036 NCOS

MFDs are placed in areas where their use can be observed.

Multifunction devices › Observing multifunction device use

ISM-2075 NCOS

Fax machines, and online fax services, are not used for sending or receiving fax messages.

Fax machines and services › Sending and receiving fax messages

Enterprise mobility · 45 controls · 3 Microsoft-assessed

ISM-1297 NCOS

Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.

Enterprise mobility › Privately owned mobile devices and desktop computers

ISM-1400 Microsoft-assessed OS

Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data have enforced separation of classified data and personal data.

Enterprise mobility › Privately owned mobile devices and desktop computers

ISM-1866 OS

Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately owned mobile devices and desktop computers.

Enterprise mobility › Privately owned mobile devices and desktop computers

ISM-2095 OS

Personnel using privately owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are disallowed from granting access to unapproved artificial intelligence agents.

Enterprise mobility › Privately owned mobile devices and desktop computers

ISM-1482 Microsoft-assessed OS

Personnel using organisation-owned mobile devices or desktop computers to access classified systems or data have enforced separation of classified data and personal data.

Enterprise mobility › Organisation-owned mobile devices and desktop computers

ISM-0874 NCOS

Mobile devices and desktop computers access the internet via an organisation’s internet gateway rather than via a direct connection to the internet.

Enterprise mobility › Mobile devices and desktop computers accessing the internet

ISM-0705 NCOS

When accessing an organisation’s network via a VPN connection, split tunnelling is disabled.

Enterprise mobility › Mobile devices and desktop computers accessing the internet

ISM-1533 NCOS

A mobile device management policy is developed, implemented and maintained.

Mobile device management › Mobile device management policy

ISM-1195 Microsoft-assessed NCOS

Mobile Device Management solutions that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Management, version 4.0 or later, are used to enforce mobile device management policy.

Mobile device management › Mobile device management policy

ISM-1867 OS

Mobile devices that access OFFICIAL: Sensitive or PROTECTED systems or data use mobile platforms that have completed a Common Criteria evaluation against the Protection Profile for Mobile Device Fundamentals, version 3.3 or later, and are operated in accordance with the latest version of their associated ASD security configuration guide.

Mobile device management › Approved mobile platforms

ISM-0869 NCOS

Mobile devices encrypt their internal storage and any removable media using ASD-approved cryptography.

Mobile device management › Encrypted storage

ISM-1085 NCOS

Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.

Mobile device management › Encrypted communications

ISM-2108 NCOS

Mobile applications encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.

Mobile device management › Encrypted communications

ISM-1886 NCOS

Mobile devices are configured to operate in a supervised (or equivalent) mode.

Mobile device management › Maintaining mobile device security

ISM-2096 NCOS

Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.

Mobile device management › Maintaining mobile device security

ISM-2097 NCOS

Mobile devices are configured with always on VPN functionality.

Mobile device management › Maintaining mobile device security

ISM-1887 NCOS

Mobile devices are configured with remote locate and wipe functionality.

Mobile device management › Maintaining mobile device security

ISM-1888 NCOS

Mobile devices are configured with secure password-based lock screens.

Mobile device management › Maintaining mobile device security

ISM-2098 NCOS

Mobile devices are configured to prevent data transfers over Universal Serial Bus connections.

Mobile device management › Maintaining mobile device security

ISM-0863 NCOS

Mobile devices prevent personnel from installing non-approved applications once provisioned.

Mobile device management › Maintaining mobile device security

ISM-0864 NCOS

Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.

Mobile device management › Maintaining mobile device security

ISM-1366 NCOS

Security updates are applied to mobile devices as soon as they become available.

Mobile device management › Maintaining mobile device security

ISM-1082 NCOS

A mobile device usage policy is developed, implemented and maintained.

Mobile device usage › Mobile device usage policy

ISM-1083 NCOS

Personnel are advised of the sensitivity or classification permitted for voice and data communications when using mobile devices.

Mobile device usage › Personnel awareness

ISM-1299 NCOS

Personnel are advised to take the following precautions when using mobile devices: • never leave mobile devices or removable media unattended, including by placing them in checked-in luggage or leaving them in hotel safes • never store credentials with mobile devices that they grant access to, such as in laptop computer bags • never lend mobile devices or removable media to untrusted people, even if briefly • never allow untrusted people to connect their mobile devices or removable media to your mobile devices, including for charging • never connect mobile devices to designated charging stations or wall outlet charging ports • never use gifted or unauthorised peripherals, chargers or removable media with mobile devices • never use removable media for data transfers or backups that have not been checked for malicious code beforehand • avoid reuse of removable media once used with other parties’ systems or mobile devices • avoid connecting mobile devices to open or untrusted Wi-Fi networks • consider disabling any communications capabilities of mobile devices when not in use, such as Wi-Fi, Bluetooth, Near Field Communication and ultra-wideband • consider periodically rebooting mobile devices • consider using a VPN connection to encrypt all cellular and wireless communications • consider using encrypted email or messaging apps for all communications.

Mobile device usage › Personnel awareness

ISM-0240 NCOS

Paging, Multimedia Message Service, Short Message Service and messaging apps are not used to communicate sensitive or classified data.

Mobile device usage › Using paging, message services and messaging apps

ISM-1196 NCOS

Non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are configured to remain undiscoverable to other Bluetooth devices except during Bluetooth pairing.

Mobile device usage › Using Bluetooth functionality

ISM-1200 NCOS

Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed using Secure Connections, preferably with Numeric Comparison if supported.

Mobile device usage › Using Bluetooth functionality

ISM-1198 NCOS

Bluetooth pairing for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices is performed in a manner such that connections are only made between intended Bluetooth devices.

Mobile device usage › Using Bluetooth functionality

ISM-1199 NCOS

Bluetooth pairings for non-classified, OFFICIAL: Sensitive and PROTECTED mobile devices are removed when there is no longer a requirement for their use.

Mobile device usage › Using Bluetooth functionality

ISM-2099 NCOS

Mobile devices are not connected to the infotainment systems of connected vehicles.

Mobile device usage › Connecting mobile devices to connected vehicles

ISM-2100 NCOS

Sensitive or classified data is not viewed on mobile devices within or near connected vehicles.

Mobile device usage › Using mobile devices within or near connected vehicles

ISM-2101 NCOS

Sensitive or classified phone calls and conversations are not conducted within or near connected vehicles.

Mobile device usage › Using mobile devices within or near connected vehicles

ISM-0866 NCOS

Sensitive or classified data is not viewed on mobile devices in public locations unless care is taken to reduce the chance of the screen of a mobile device being observed.

Mobile device usage › Using mobile devices in public spaces

ISM-1644 RFFR Core NCOS

Sensitive or classified phone calls and conversations are not conducted in public locations unless care is taken to reduce the chance of conversations being overheard.

Mobile device usage › Using mobile devices in public spaces

ISM-0871 NCOS

Mobile devices are kept under continual direct supervision when being actively used.

Mobile device usage › Maintaining control of mobile devices

ISM-0870 NCOS

Mobile devices are carried or stored in a secured state when not being actively used.

Mobile device usage › Maintaining control of mobile devices

ISM-1084 NCOS

If unable to carry or store mobile devices in a secured state, they are physically transferred in a security briefcase or an approved multi-use satchel, pouch or transit bag.

Mobile device usage › Maintaining control of mobile devices

ISM-0701 NCOS

Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.

Mobile device usage › Mobile device emergency sanitisation processes and procedures

ISM-1298 NCOS

Personnel are advised of privacy and security risks when travelling overseas with mobile devices.

Mobile device usage › Before travelling overseas with mobile devices

ISM-1554 NCOS

If travelling overseas with mobile devices to high or extreme risk countries, personnel are: • issued with newly provisioned user accounts, mobile devices and removable media from a pool of dedicated travel devices which are used solely for work-related activities • advised on how to apply and inspect tamper seals to key areas of mobile devices • advised to avoid taking any personal mobile devices, especially if rooted or jailbroken.

Mobile device usage › Before travelling overseas with mobile devices

ISM-1555 NCOS

Before travelling overseas with mobile devices, personnel take the following actions: • record all details of the mobile devices being taken, such as product types, serial numbers and International Mobile Equipment Identity numbers • update all operating systems and applications • remove all non-essential data, applications and user accounts • backup all remaining data, applications and settings.

Mobile device usage › Before travelling overseas with mobile devices

ISM-1088 NCOS

Personnel report the potential compromise of mobile devices, removable media or credentials to their organisation as soon as possible, especially if they: • provide credentials to foreign government officials • decrypt mobile devices for foreign government officials • have mobile devices taken out of sight by foreign government officials • have mobile devices or removable media stolen, including if later returned • lose mobile devices or removable media, including if later found • observe unusual behaviour of mobile devices.

Mobile device usage › While travelling overseas with mobile devices

ISM-1300 NCOS

Upon returning from travelling overseas with mobile devices, personnel take the following actions: • sanitise and reset mobile devices, including all removable media • decommission any credentials that left their possession during their travel • report if significant doubt exists as to the integrity of any mobile devices or removable media.

Mobile device usage › After travelling overseas with mobile devices

ISM-1556 NCOS

If returning from travelling overseas with mobile devices to high or extreme risk countries, personnel take the following additional actions: • reset credentials used with mobile devices, including those used for remote access to their organisation’s systems • monitor user accounts for any indicators of compromise, such as failed logon attempts.

Mobile device usage › After travelling overseas with mobile devices

Evaluated products · 3 controls · 0 Microsoft-assessed

ISM-0280 NCOS

If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.

Evaluated product procurement › Evaluated product selection

ISM-0285 NCOS

Evaluated products are delivered in a manner consistent with any delivery procedures defined in associated evaluation documentation.

Evaluated product procurement › Delivery of evaluated products

ISM-0289 NCOS

Evaluated products are installed, configured, administered and operated in an evaluated configuration and in accordance with vendor guidance.

Evaluated product usage › Using evaluated products

Information technology equipment · 29 controls · 0 Microsoft-assessed

ISM-1551 NCOS

An IT equipment management policy is developed, implemented and maintained.

IT equipment usage › IT equipment management policy

ISM-1913 NCOS

Approved configurations for IT equipment are developed, implemented and maintained.

IT equipment usage › Hardening IT equipment configurations

ISM-1858 NCOS

IT equipment is hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

IT equipment usage › Hardening IT equipment configurations

ISM-0336 NCOS

A networked IT equipment register is developed, implemented, maintained and regularly verified.

IT equipment usage › IT equipment registers

ISM-1869 NCOS

A non-networked IT equipment register is developed, implemented, maintained and regularly verified.

IT equipment usage › IT equipment registers

ISM-0294 NCOS

IT equipment, except for high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.

IT equipment usage › Labelling IT equipment

ISM-0293 NCOS

IT equipment is classified based on the highest sensitivity or classification of data that it is approved for processing, storing or communicating.

IT equipment usage › Classifying IT equipment

ISM-1599 NCOS

IT equipment is handled in a manner suitable for its sensitivity or classification.

IT equipment usage › Handling IT equipment

ISM-0305 NCOS

Maintenance or repairs of IT equipment are carried out on site by an appropriately cleared technician.

IT equipment maintenance or repairs › On-site maintenance or repairs

ISM-0307 NCOS

If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the IT equipment and associated media are sanitised before maintenance or repairs.

IT equipment maintenance or repairs › On-site maintenance or repairs

ISM-0306 NCOS

If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the technician is escorted by someone who: • has the authority to direct the technician • is appropriately cleared and briefed • is sufficiently familiar with the IT equipment to understand the work being undertaken • takes all responsible measures to ensure the integrity of the IT equipment • takes due care to ensure that data is not disclosed.

IT equipment maintenance or repairs › On-site maintenance or repairs

ISM-0310 NCOS

IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.

IT equipment maintenance or repairs › Off-site maintenance or repairs

ISM-1598 NCOS

Following maintenance or repairs to IT equipment, it is inspected to confirm that it retains its approved configuration and that no unauthorised modifications have been made.

IT equipment maintenance or repairs › Inspection of IT equipment following maintenance or repairs

ISM-0313 NCOS

IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.

IT equipment sanitisation and destruction › IT equipment sanitisation processes and procedures

ISM-1741 NCOS

IT equipment destruction processes, and supporting IT equipment destruction procedures, are developed, implemented and maintained.

IT equipment sanitisation and destruction › IT equipment destruction processes and procedures

ISM-0311 NCOS

IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.

IT equipment sanitisation and destruction › Sanitising IT equipment

ISM-1742 NCOS

IT equipment that cannot be sanitised is destroyed.

IT equipment sanitisation and destruction › Sanitising IT equipment

ISM-0317 NCOS

At least three pages of random text with no blank areas are printed on each colour printer cartridge or MFD print drum.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-1219 NCOS

MFD print drums and image transfer rollers are inspected and destroyed if there is remnant toner that cannot be removed or a print is visible on the image transfer roller.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-1220 NCOS

Printer and MFD platens are inspected and destroyed if any text or images are retained on the platen.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-1221 NCOS

Printers and MFDs are checked to ensure no pages are trapped in the paper path due to a paper jam.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-0318 NCOS

When unable to sanitise printer cartridges or MFD print drums, they are destroyed as per electrostatic memory devices.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-1534 NCOS

Printer ribbons in printers and MFDs are removed and destroyed.

IT equipment sanitisation and destruction › Sanitising printers and multifunction devices

ISM-1076 NCOS

Televisions and computer monitors with minor burn-in or image persistence are sanitised by displaying a solid white image on the screen for an extended period.

IT equipment sanitisation and destruction › Sanitising televisions and computer monitors

ISM-1222 NCOS

Televisions and computer monitors that cannot be sanitised are destroyed.

IT equipment sanitisation and destruction › Sanitising televisions and computer monitors

ISM-1223 NCOS

Memory in network devices is sanitised using the following processes, in order of preference: • following device-specific guidance provided in evaluation documentation • following vendor sanitisation guidance • loading a dummy configuration file, performing a factory reset and then reinstalling firmware.

IT equipment sanitisation and destruction › Sanitising network devices

ISM-1550 NCOS

IT equipment disposal processes, and supporting IT equipment disposal procedures, are developed, implemented and maintained.

IT equipment disposal › IT equipment disposal processes and procedures

ISM-1217 NCOS

Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate IT equipment with its prior use are removed prior to its disposal.

IT equipment disposal › Disposal of IT equipment

ISM-0316 NCOS

Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.

IT equipment disposal › Disposal of IT equipment

Media · 49 controls · 1 Microsoft-assessed

ISM-1549 NCOS

A media management policy is developed, implemented and maintained.

Media usage › Media management policy

ISM-1359 NCOS

A removable media usage policy is developed, implemented and maintained.

Media usage › Removable media usage policy

ISM-1713 NCOS

A removable media register is developed, implemented, maintained and regularly verified.

Media usage › Removable media register

ISM-0332 NCOS

Media, except for internally mounted fixed media within information technology equipment, is labelled with protective markings reflecting its sensitivity or classification.

Media usage › Labelling media

ISM-0323 NCOS

Media is classified to the highest sensitivity or classification of data it stores, unless the media has been classified to a higher sensitivity or classification.

Media usage › Classifying media

ISM-0337 NCOS

Media is only used with systems that are authorised to process, store or communicate its sensitivity or classification.

Media usage › Classifying media

ISM-0325 NCOS

Any media connected to a system with a higher sensitivity or classification than the media is reclassified to the higher sensitivity or classification, unless the media is read-only or the system has a mechanism through which read-only access can be ensured.

Media usage › Reclassifying media

ISM-0330 NCOS

Before reclassifying media to a lower sensitivity or classification, the media is sanitised or destroyed, and a formal administrative decision is made to reclassify it.

Media usage › Reclassifying media

ISM-1059 Microsoft-assessed NCOS

All data stored on media is encrypted using ASD-approved cryptography.

Media usage › Encrypting media

ISM-0459 NCOS

Full disk encryption, or partial encryption where access controls only allow writing to encrypted partitions or volumes, is implemented when encrypting media.

Media usage › Encrypting media

ISM-2109 NCOS

Pre-boot authentication using passwords, or managed network-based key release, is implemented for media containing encrypted system volumes.

Media usage › Encrypting media

ISM-0831 NCOS

Media is handled in a manner suitable for its sensitivity or classification.

Media usage › Handling media

ISM-1600 NCOS

Media is sanitised before it is used for the first time.

Media usage › Sanitising media before first use

ISM-1642 NCOS

Media is sanitised before it is reused in a different security domain.

Media usage › Sanitising media before first use

ISM-0347 NCOS

When transferring data manually between two systems belonging to different security domains, write-once media is used unless the destination system has a mechanism through which read-only access can be ensured.

Media usage › Using media for data transfers

ISM-0947 NCOS

When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.

Media usage › Using media for data transfers

ISM-0348 NCOS

Media sanitisation processes, and supporting media sanitisation procedures, are developed, implemented and maintained.

Media sanitisation › Media sanitisation processes and procedures

ISM-0351 NCOS

Volatile media is sanitised by removing its power for at least 10 minutes.

Media sanitisation › Volatile media sanitisation

ISM-0354 NCOS

Non-volatile magnetic media is sanitised by overwriting it at least once (or three times if pre-2001 or under 15 GB) in its entirety with a random pattern followed by a read back for verification.

Media sanitisation › Non-volatile magnetic media sanitisation

ISM-1065 NCOS

The host-protected area and device configuration overlay table are reset prior to the sanitisation of non-volatile magnetic hard drives.

Media sanitisation › Non-volatile magnetic media sanitisation

ISM-1067 NCOS

The ATA secure erase command is used, in addition to block overwriting software, to ensure the growth defects table of non-volatile magnetic hard drives is overwritten.

Media sanitisation › Non-volatile magnetic media sanitisation

ISM-0357 NCOS

Non-volatile EPROM media is sanitised by applying three times the manufacturer’s specified ultraviolet erasure time and then overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

Media sanitisation › Non-volatile erasable programmable read-only memory media sanitisation

ISM-0836 NCOS

Non-volatile EEPROM media is sanitised by overwriting it at least once in its entirety with a random pattern followed by a read back for verification.

Media sanitisation › Non-volatile electrically erasable programmable read-only memory media sanitisation

ISM-0359 NCOS

Non-volatile flash memory media is sanitised by overwriting it at least twice in its entirety with a random pattern followed by a read back for verification.

Media sanitisation › Non-volatile flash memory media sanitisation

ISM-1735 NCOS

Media that cannot be successfully sanitised is destroyed prior to its disposal.

Media sanitisation › Media that cannot be successfully sanitised

ISM-0363 NCOS

Media destruction processes, and supporting media destruction procedures, are developed, implemented and maintained.

Media destruction › Media destruction processes and procedures

ISM-0350 NCOS

The following media types are destroyed prior to their disposal: • microfiche and microfilm • optical discs • programmable read-only memory • read-only memory • other types of media that cannot be sanitised.

Media destruction › Media that cannot be sanitised

ISM-1361 NCOS

Security Construction and Equipment Committee-approved equipment or ASIO-approved equipment is used when destroying media.

Media destruction › Media destruction equipment

ISM-1160 NCOS

If using degaussers to destroy media, degaussers evaluated by the United States’ National Security Agency are used.

Media destruction › Media destruction equipment

ISM-1517 NCOS

Equipment that is capable of reducing microform to a fine powder, with resultant particles not showing more than five consecutive characters per particle upon microscopic inspection, is used to destroy microfiche and microfilm.

Media destruction › Media destruction methods

ISM-1722 NCOS

Electrostatic memory devices are destroyed using a furnace/incinerator, hammer mill, disintegrator or grinder/sander.

Media destruction › Media destruction methods

ISM-1723 NCOS

Magnetic floppy disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

Media destruction › Media destruction methods

ISM-1724 NCOS

Magnetic hard disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or degausser.

Media destruction › Media destruction methods

ISM-1725 NCOS

Magnetic tapes are destroyed using a furnace/incinerator, hammer mill, disintegrator, degausser or by cutting.

Media destruction › Media destruction methods

ISM-1726 NCOS

Optical disks are destroyed using a furnace/incinerator, hammer mill, disintegrator, grinder/sander or by cutting.

Media destruction › Media destruction methods

ISM-1727 NCOS

Semiconductor memory is destroyed using a furnace/incinerator, hammer mill or disintegrator.

Media destruction › Media destruction methods

ISM-0368 NCOS

Media destroyed using a hammer mill, disintegrator, grinder/sander or by cutting results in media waste particles no larger than 9 mm.

Media destruction › Media destruction methods

ISM-0361 NCOS

Magnetic media is destroyed using a degausser with a suitable magnetic field strength and magnetic orientation.

Media destruction › Degaussing magnetic media

ISM-0362 NCOS

Product-specific directions provided by degausser manufacturers are followed.

Media destruction › Degaussing magnetic media

ISM-1641 NCOS

Following the use of a degausser, magnetic media is physically damaged by deforming any internal platters.

Media destruction › Degaussing magnetic media

ISM-0370 NCOS

The destruction of media is performed under the supervision of at least one cleared person.

Media destruction › Supervision of destruction

ISM-0371 NCOS

Personnel supervising the destruction of media supervise its handling to the point of destruction and ensure that the destruction is completed successfully.

Media destruction › Supervision of destruction

ISM-0372 NCOS

The destruction of media storing accountable material is performed under the supervision of at least two cleared personnel.

Media destruction › Supervision of accountable material destruction

ISM-0373 NCOS

Personnel supervising the destruction of media storing accountable material supervise its handling to the point of destruction, ensure that the destruction is completed successfully and sign a destruction certificate afterwards.

Media destruction › Supervision of accountable material destruction

ISM-0839 OS

The destruction of media storing accountable material is not outsourced.

Media destruction › Outsourcing media destruction

ISM-0840 OS

When outsourcing the destruction of media storing non-accountable material, a National Association for Information Destruction AAA certified destruction service with endorsements, as specified in ASIO’s Protective Security Circular-167, is used.

Media destruction › Outsourcing media destruction

ISM-0374 NCOS

Media disposal processes, and supporting media disposal procedures, are developed, implemented and maintained.

Media disposal › Media disposal processes and procedures

ISM-0378 NCOS

Labels and markings indicating the owner, sensitivity, classification or any other marking that can associate media with its prior use are removed prior to its disposal.

Media disposal › Disposal of media

ISM-0375 NCOS

Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.

Media disposal › Disposal of media

System hardening · 216 controls · 18 Microsoft-assessed

ISM-1743 NCOS

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for operating systems.

Operating system hardening › Operating system selection

ISM-1407 ML3 NCOS

The latest release, or the previous release, of operating systems are used.

Operating system hardening › Operating system releases and versions

ISM-1408 NCOS

Where supported, 64-bit versions of operating systems are used.

Operating system hardening › Operating system releases and versions

ISM-1406 NCOS

SOEs are used for workstations and servers.

Operating system hardening › Standard Operating Environments

ISM-1608 NCOS

SOEs provided by third parties are scanned for malicious code and configurations.

Operating system hardening › Standard Operating Environments

ISM-1588 NCOS

SOEs are reviewed and updated at least annually.

Operating system hardening › Standard Operating Environments

ISM-1914 NCOS

Approved configurations for operating systems are developed, implemented and maintained.

Operating system hardening › Hardening operating system configurations

ISM-1409 NCOS

Operating systems are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Operating system hardening › Hardening operating system configurations

ISM-1601 NCOS

Microsoft’s attack surface reduction rules are implemented.

Operating system hardening › Hardening operating system configurations

ISM-0383 NCOS

Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Operating system hardening › Hardening operating system configurations

ISM-0380 NCOS

Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.

Operating system hardening › Hardening operating system configurations

ISM-0341 NCOS

Automatic execution features for removable media are disabled.

Operating system hardening › Hardening operating system configurations

ISM-1654 RFFR Core ML1 NCOS

Internet Explorer 11 is disabled or removed.

Operating system hardening › Hardening operating system configurations

ISM-1655 ML3 NCOS

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.

Operating system hardening › Hardening operating system configurations

ISM-1492 NCOS

Operating system exploit protection functionality is enabled.

Operating system hardening › Hardening operating system configurations

ISM-1745 NCOS

Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.

Operating system hardening › Hardening operating system configurations

ISM-1584 NCOS

Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.

Operating system hardening › Hardening operating system configurations

ISM-1491 NCOS

Unprivileged users are prevented from running script execution engines, including: • Windows Script Host (cscript.exe and wscript.exe) • PowerShell (powershell.exe, powershell_ise.exe and pwsh.exe) • Command Prompt (cmd.exe) • Windows Management Instrumentation (wmic.exe) • Microsoft Hypertext Markup Language (HTML) Application Host (mshta.exe).

Operating system hardening › Hardening operating system configurations

ISM-1592 NCOS

Unprivileged users do not have the ability to install unapproved applications.

Operating system hardening › Application management

ISM-0382 NCOS

Unprivileged users do not have the ability to uninstall or disable approved applications.

Operating system hardening › Application management

ISM-0843 RFFR Core ML1 Microsoft-assessed NCOS

Application control is implemented on workstations.

Operating system hardening › Application control

ISM-1490 ML2 Microsoft-assessed NCOS

Application control is implemented on internet-facing servers.

Operating system hardening › Application control

ISM-1656 ML3 Microsoft-assessed NCOS

Application control is implemented on non-internet-facing servers.

Operating system hardening › Application control

ISM-1870 RFFR Core ML1 Microsoft-assessed NCOS

Application control is applied to user profiles and temporary folders used by operating systems, web browsers and email clients.

Operating system hardening › Application control

ISM-1871 ML2 Microsoft-assessed NCOS

Application control is applied to all locations other than user profiles and temporary folders used by operating systems, web browsers and email clients.

Operating system hardening › Application control

ISM-1657 RFFR Core ML1 NCOS

Application control restricts the execution of executables, libraries, scripts, installers, compiled HTML, HTML applications and control panel applets to an organisation-approved set.

Operating system hardening › Application control

ISM-1658 ML3 NCOS

Application control restricts the execution of drivers to an organisation-approved set.

Operating system hardening › Application control

ISM-0955 NCOS

Application control is implemented using cryptographic hash rules, publisher certificate rules or path rules.

Operating system hardening › Application control

ISM-1471 NCOS

When implementing application control using publisher certificate rules, publisher names and product names are used.

Operating system hardening › Application control

ISM-1392 NCOS

When implementing application control using path rules, only approved users can modify approved files and write to approved folders.

Operating system hardening › Application control

ISM-1746 NCOS

When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.

Operating system hardening › Application control

ISM-1544 ML2 NCOS

Microsoft’s recommended application blocklist is implemented.

Operating system hardening › Application control

ISM-1659 ML3 NCOS

Microsoft’s vulnerable driver blocklist is implemented.

Operating system hardening › Application control

ISM-1582 ML2 NCOS

Application control rulesets are validated at least annually.

Operating system hardening › Application control

ISM-0846 NCOS

All users, except for local administrator accounts and break glass accounts, cannot disable, bypass or be exempted from application control.

Operating system hardening › Application control

ISM-1660 ML2 NCOS

Allowed and blocked application control events are centrally logged.

Operating system hardening › Application control

ISM-1889 ML2 NCOS

Command line process creation events are centrally logged.

Operating system hardening › Command Shell

ISM-1621 ML3 NCOS

Windows PowerShell 2.0 is disabled or removed.

Operating system hardening › PowerShell

ISM-1622 ML3 NCOS

PowerShell is configured to use Constrained Language Mode.

Operating system hardening › PowerShell

ISM-1623 ML2 NCOS

PowerShell module logging, script block logging and transcription events are centrally logged.

Operating system hardening › PowerShell

ISM-1624 NCOS

PowerShell script block logs are protected by Protected Event Logging functionality.

Operating system hardening › PowerShell

ISM-1341 NCOS

A HIPS or EDR solution is implemented on workstations.

Operating system hardening › Host-based intrusion detection and response solution

ISM-1034 NCOS

A HIPS or EDR solution is implemented on critical servers and high-value servers.

Operating system hardening › Host-based intrusion detection and response solution

ISM-1416 NCOS

A software firewall is implemented on workstations and servers to restrict inbound and outbound network connections to an organisation-approved set of applications and services.

Operating system hardening › Software firewall

ISM-1417 RFFR Core Microsoft-assessed NCOS

An antivirus application is implemented on workstations and servers with: • signature-based detection functionality enabled and set to a high level • heuristic-based detection functionality enabled and set to a high level • reputation rating functionality enabled • ransomware protection functionality enabled • detection signatures configured to update at least daily • regular scanning configured for all fixed disks and removable media.

Operating system hardening › Antivirus application

ISM-1418 NCOS

If there is no business requirement for reading from removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Operating system hardening › Device access control

ISM-0343 NCOS

If there is no business requirement for writing to removable media and devices, such functionality is disabled via the use of a device access control application or by disabling external communication interfaces.

Operating system hardening › Device access control

ISM-0345 NCOS

External communication interfaces that allow DMA are disabled.

Operating system hardening › Device access control

ISM-1976 NCOS

Security-relevant events for Apple macOS operating systems are centrally logged.

Operating system hardening › Operating system event logging

ISM-1977 NCOS

Security-relevant events for Linux operating systems are centrally logged.

Operating system hardening › Operating system event logging

ISM-0582 RFFR Core NCOS

Security-relevant events for Microsoft Windows operating systems are centrally logged.

Operating system hardening › Operating system event logging

ISM-0938 NCOS

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for user applications.

User application hardening › User application selection

ISM-1467 NCOS

The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are used.

User application hardening › User application releases

ISM-1915 NCOS

Approved configurations for user applications are developed, implemented and maintained.

User application hardening › Hardening user application configurations

ISM-2110 NCOS

User applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

User application hardening › Hardening user application configurations

ISM-1806 NCOS

Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

User application hardening › Hardening user application configurations

ISM-1470 NCOS

Unneeded user accounts, components, services and functionality of user applications are disabled or removed.

User application hardening › Hardening user application configurations

ISM-1235 NCOS

Extensions for user applications are restricted to an organisation-approved set.

User application hardening › Hardening user application configurations

ISM-2111 NCOS

All temporary installation files created during user application installation processes are removed after user applications have been installed.

User application hardening › Hardening user application configurations

ISM-2112 OS

AI applications that process classified data have their ability to directly access external public data sources disabled.

User application hardening › Artificial intelligence applications

ISM-2113 NCOS

AI applications are configured to flag organisationally defined risky actions for human approval prior to their execution.

User application hardening › Artificial intelligence applications

ISM-2114 NCOS

Baselines of expected behaviour and performance for AI applications are established and monitored for unexpected deviations.

User application hardening › Artificial intelligence applications

ISM-1748 NCOS

Email client security settings cannot be changed by users.

User application hardening › Email clients

ISM-1859 ML2 NCOS

Office productivity suites are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

User application hardening › Office productivity suites

ISM-1667 ML2 NCOS

Microsoft Office is blocked from creating child processes.

User application hardening › Office productivity suites

ISM-1668 ML2 NCOS

Microsoft Office is blocked from creating executable content.

User application hardening › Office productivity suites

ISM-1669 ML2 NCOS

Microsoft Office is blocked from injecting code into other processes.

User application hardening › Office productivity suites

ISM-1542 ML2 NCOS

Microsoft Office is configured to prevent activation of Object Linking and Embedding packages.

User application hardening › Office productivity suites

ISM-1823 ML2 NCOS

Office productivity suite security settings cannot be changed by users.

User application hardening › Office productivity suites

ISM-1671 RFFR Core ML1 Microsoft-assessed NCOS

Microsoft Office macros are disabled for users that do not have a demonstrated business requirement.

User application hardening › Office productivity suites

ISM-1488 RFFR Core ML1 Microsoft-assessed NCOS

Microsoft Office macros in files originating from the internet are blocked.

User application hardening › Office productivity suites

ISM-1672 RFFR Core ML1 Microsoft-assessed NCOS

Microsoft Office macro antivirus scanning is enabled.

User application hardening › Office productivity suites

ISM-1673 ML2 Microsoft-assessed NCOS

Microsoft Office macros are blocked from making Win32 API calls.

User application hardening › Office productivity suites

ISM-1674 ML3 Microsoft-assessed NCOS

Only Microsoft Office macros running from within a sandboxed environment, a Trusted Location or that are digitally signed by a trusted publisher are allowed to execute.

User application hardening › Office productivity suites

ISM-1890 ML3 NCOS

Microsoft Office macros are checked to ensure they are free of malicious code before being digitally signed or placed within Trusted Locations.

User application hardening › Office productivity suites

ISM-1487 ML3 NCOS

Only privileged users responsible for checking that Microsoft Office macros are free of malicious code can write to and modify content within Trusted Locations.

User application hardening › Office productivity suites

ISM-1675 ML3 NCOS

Microsoft Office macros digitally signed by an untrusted publisher cannot be enabled via the Message Bar or Backstage View.

User application hardening › Office productivity suites

ISM-1891 ML3 NCOS

Microsoft Office macros digitally signed by signatures other than V3 signatures cannot be enabled via the Message Bar or Backstage View.

User application hardening › Office productivity suites

ISM-1676 ML3 NCOS

Microsoft Office’s list of trusted publishers is validated at least annually.

User application hardening › Office productivity suites

ISM-1489 RFFR Core ML1 NCOS

Microsoft Office macro security settings cannot be changed by users.

User application hardening › Office productivity suites

ISM-1670 ML2 NCOS

PDF applications are blocked from creating child processes.

User application hardening › Portable Document Format applications

ISM-1860 ML2 NCOS

PDF applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

User application hardening › Portable Document Format applications

ISM-1824 ML2 NCOS

PDF application security settings cannot be changed by users.

User application hardening › Portable Document Format applications

ISM-1825 NCOS

Security product security settings cannot be changed by users.

User application hardening › Security products

ISM-1486 RFFR Core ML1 NCOS

Web browsers do not process Java from the internet.

User application hardening › Web browsers

ISM-1485 RFFR Core ML1 NCOS

Web browsers do not process web advertisements from the internet.

User application hardening › Web browsers

ISM-1412 ML2 NCOS

Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

User application hardening › Web browsers

ISM-1585 RFFR Core ML1 NCOS

Web browser security settings cannot be changed by users.

User application hardening › Web browsers

ISM-1826 NCOS

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.

Server application hardening › Server application selection

ISM-1483 NCOS

The latest release of internet-facing server applications is used.

Server application hardening › Server application releases

ISM-1916 NCOS

Approved configurations for server applications are developed, implemented and maintained.

Server application hardening › Hardening server application configurations

ISM-1246 NCOS

Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.

Server application hardening › Hardening server application configurations

ISM-1260 NCOS

Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Server application hardening › Hardening server application configurations

ISM-1247 NCOS

Unneeded user accounts, components, services and functionality of server applications are disabled or removed.

Server application hardening › Hardening server application configurations

ISM-2115 NCOS

Extensions for server applications are restricted to an organisation-approved set.

Server application hardening › Hardening server application configurations

ISM-1245 NCOS

All temporary installation files created during server application installation processes are removed after server applications have been installed.

Server application hardening › Hardening server application configurations

ISM-1249 NCOS

Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.

Server application hardening › Restricting privileges for server applications

ISM-1250 NCOS

The user accounts under which server applications run have limited access to their underlying server’s file system.

Server application hardening › Restricting privileges for server applications

ISM-1926 NCOS

Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.

Server application hardening › Microsoft Active Directory services

ISM-1927 NCOS

Access to Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers is limited to privileged users that require access.

Server application hardening › Microsoft Active Directory services

ISM-1928 NCOS

Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.

Server application hardening › Microsoft Active Directory services

ISM-1830 NCOS

Security-relevant events for Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are centrally logged.

Server application hardening › Microsoft Active Directory services

ISM-1827 NCOS

Microsoft AD DS domain controllers are administered using dedicated domain administrator user accounts that are not used to administer other systems.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1929 NCOS

Lightweight Directory Access Protocol signing is enabled on Microsoft AD DS domain controllers.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1828 NCOS

The Print Spooler service is disabled on Microsoft AD DS domain controllers.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1829 NCOS

Passwords are not stored in Group Policy Preferences.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1930 NCOS

Passwords are prevented from being stored in Group Policy Preferences.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1931 NCOS

SID Filtering is enabled for domain and forest trusts.

Server application hardening › Microsoft Active Directory Domain Services domain controllers

ISM-1832 NCOS

Only service accounts and computer accounts are configured with Service Principal Names (SPNs).

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1932 NCOS

The number of service accounts configured with an SPN is minimised.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1933 NCOS

Service accounts configured with an SPN do not have DCSync permissions.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-2010 NCOS

Service accounts configured with an SPN use the Advanced Encryption Standard for encryption.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1834 NCOS

Duplicate SPNs do not exist within the domain.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1833 NCOS

User accounts are provisioned with the minimum privileges required.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1934 NCOS

User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1835 NCOS

Privileged user accounts are configured as sensitive and cannot be delegated.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1935 NCOS

Computer accounts are not configured for unconstrained delegation.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1836 NCOS

User accounts require Kerberos pre-authentication.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1838 NCOS

The UserPassword attribute for user accounts is not used.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1936 NCOS

The sIDHistory attribute for user accounts is not used.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1937 NCOS

User accounts are checked at least weekly for the presence of the sIDHistory attribute.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1839 NCOS

Account properties accessible by unprivileged users are not used to store passwords.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1840 NCOS

User account passwords do not use reversible encryption.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1841 NCOS

Unprivileged user accounts cannot add machines to the domain.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1842 NCOS

Dedicated privileged service accounts are used to add machines to the domain.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1843 NCOS

User accounts with unconstrained delegation are reviewed at least annually, and those without an SPN or demonstrated business requirement are removed.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1844 NCOS

Computer accounts that are not Microsoft AD DS domain controllers are not trusted for delegation to services.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1938 NCOS

The Domain Computers security group does not have write or modify permissions to any Microsoft Active Directory objects.

Server application hardening › Microsoft Active Directory Domain Services account hardening

ISM-1620 NCOS

Privileged user accounts are members of the Protected Users security group.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1939 NCOS

The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly privileged security groups is minimised.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1940 NCOS

Service accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1941 NCOS

Computer accounts are not members of the Domain Admins, Enterprise Admins or other highly privileged security groups.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1942 NCOS

The Domain Computers security group is not a member of any privileged or highly privileged security groups.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1845 NCOS

When a user account is disabled, it is removed from all security group memberships.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1846 NCOS

The Pre-Windows 2000 Compatible Access security group does not contain user accounts.

Server application hardening › Microsoft Active Directory Domain Services security group memberships

ISM-1943 NCOS

Strong mapping between certificates and users is enforced.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1944 NCOS

The EDITF_ATTRIBUTESUBJECTALTNAME2 flag is removed from Microsoft AD CS CA configurations.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1945 NCOS

The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1946 NCOS

Unprivileged user accounts do not have write access to certificate templates.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1947 NCOS

Extended Key Usages that enable user authentication are removed.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1948 NCOS

CA Certificate Manager approval is required for certificate templates that allow a Subject Alternative Name to be supplied.

Server application hardening › Microsoft Active Directory Certificate Services

ISM-1949 NCOS

Microsoft AD FS servers are administered using a dedicated service account that is not used to administer other systems.

Server application hardening › Microsoft Active Directory Federation Services

ISM-1950 NCOS

Soft matching between Microsoft AD DS and Microsoft Entra ID is disabled following initial synchronisation activities.

Server application hardening › Microsoft Entra Connect

ISM-1951 NCOS

Hard match takeover is disabled for Microsoft Entra Connect servers.

Server application hardening › Microsoft Entra Connect

ISM-1952 NCOS

Privileged user accounts are not synchronised between Microsoft AD DS and Microsoft Entra ID.

Server application hardening › Microsoft Entra Connect

ISM-1978 NCOS

Security-relevant events for server applications on internet-facing servers are centrally logged.

Server application hardening › Server application event logging

ISM-1979 NCOS

Security-relevant events for server applications on non-internet-facing servers are centrally logged.

Server application hardening › Server application event logging

ISM-1546 NCOS

Users are authenticated before they are granted access to a system and its resources.

Authentication hardening › Authenticating to systems

ISM-1603 NCOS

Authentication methods susceptible to replay attacks are disabled.

Authentication hardening › Insecure authentication methods

ISM-1055 NCOS

LAN Manager and NT LAN Manager authentication methods are disabled.

Authentication hardening › Insecure authentication methods

ISM-2076 NCOS

Security questions are not used for authentication purposes.

Authentication hardening › Insecure authentication methods

ISM-2077 NCOS

Email is not used for out-of-band authentication purposes.

Authentication hardening › Insecure authentication methods

ISM-1504 RFFR Core ML1 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate users to their organisation’s online services that process, store or communicate their organisation’s sensitive data.

Authentication hardening › Multi-factor authentication

ISM-1679 RFFR Core ML1 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate users to third-party online services that process, store or communicate their organisation’s sensitive data.

Authentication hardening › Multi-factor authentication

ISM-1680 RFFR Core ML1 NCOS

Multi-factor authentication (where available) is used to authenticate users to third-party online services that process, store or communicate their organisation’s non-sensitive data.

Authentication hardening › Multi-factor authentication

ISM-1892 RFFR Core ML1 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate users to their organisation’s online customer services that process, store or communicate their organisation’s sensitive customer data.

Authentication hardening › Multi-factor authentication

ISM-1893 RFFR Core ML1 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate users to third-party online customer services that process, store or communicate their organisation’s sensitive customer data.

Authentication hardening › Multi-factor authentication

ISM-1681 RFFR Core ML1 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate customers to online customer services that process, store or communicate sensitive customer data.

Authentication hardening › Multi-factor authentication

ISM-1919 NCOS

When multi-factor authentication is used to authenticate users or customers to online services or online customer services, all other authentication protocols that do not support multi-factor authentication are disabled.

Authentication hardening › Multi-factor authentication

ISM-1173 ML2 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate privileged users of systems.

Authentication hardening › Multi-factor authentication

ISM-0974 ML2 Microsoft-assessed NCOS

Multi-factor authentication is used to authenticate unprivileged users of systems.

Authentication hardening › Multi-factor authentication

ISM-1505 ML3 NCOS

Multi-factor authentication is used to authenticate users of data repositories.

Authentication hardening › Multi-factor authentication

ISM-1401 RFFR Core ML1 NCOS

Multi-factor authentication uses either: something users have and something users know, or something users have that is unlocked by something users know or are.

Authentication hardening › Multi-factor authentication

ISM-1872 ML2 NCOS

Multi-factor authentication used for authenticating users of online services is phishing-resistant.

Authentication hardening › Multi-factor authentication

ISM-1873 ML2 NCOS

Multi-factor authentication used for authenticating customers of online customer services provides a phishing-resistant option.

Authentication hardening › Multi-factor authentication

ISM-1874 ML3 NCOS

Multi-factor authentication used for authenticating customers of online customer services is phishing-resistant.

Authentication hardening › Multi-factor authentication

ISM-1682 ML2 NCOS

Multi-factor authentication used for authenticating users of systems is phishing-resistant.

Authentication hardening › Multi-factor authentication

ISM-1894 ML3 NCOS

Multi-factor authentication used for authenticating users of data repositories is phishing-resistant.

Authentication hardening › Multi-factor authentication

ISM-2011 NCOS

When phishing-resistant multi-factor authentication is used by user accounts, other non-phishing-resistant multi-factor authentication options are disabled for such user accounts.

Authentication hardening › Multi-factor authentication

ISM-1920 NCOS

When multi-factor authentication is used to authenticate users to online services, online customer services, systems or data repositories – that process, store or communicate their organisation’s sensitive data or sensitive customer data – users are prevented from self-enrolling into multi-factor authentication from untrustworthy devices.

Authentication hardening › Multi-factor authentication

ISM-1683 ML2 NCOS

Successful and unsuccessful multi-factor authentication events are centrally logged.

Authentication hardening › Multi-factor authentication

ISM-0417 NCOS

When systems cannot support multi-factor authentication, single-factor authentication using passwords is implemented instead.

Authentication hardening › Single-factor authentication

ISM-1895 NCOS

Successful and unsuccessful single-factor authentication events are centrally logged.

Authentication hardening › Single-factor authentication

ISM-1559 NCOS

Passwords used for multi-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 6 characters.

Authentication hardening › Password strength

ISM-0421 NCOS

Passwords used for single-factor authentication on non-classified, OFFICIAL: Sensitive and PROTECTED systems are a minimum of 15 characters.

Authentication hardening › Password strength

ISM-1558 NCOS

Passwords using a sequence of words for single-factor authentication are not constructed using: • a list of categorised words • a real sentence in a natural language • song lyrics, movie or television show quotes, literature, or any other publicly available material • less than 4 random words for non-classified, OFFICIAL: Sensitive and PROTECTED systems; 5 random words for SECRET systems; or 6 random words for TOP SECRET systems.

Authentication hardening › Password strength

ISM-2078 NCOS

Passwords appearing in lists of commonly used passwords or lists of compromised passwords are not used.

Authentication hardening › Password strength

ISM-2079 NCOS

Maximum length limits for passwords are not less than 64 characters.

Authentication hardening › Password strength

ISM-2080 NCOS

Password complexity requirements are not imposed for passwords.

Authentication hardening › Password strength

ISM-2081 NCOS

All ASCII printable characters are supported for passwords.

Authentication hardening › Password strength

ISM-1593 NCOS

Users provide sufficient evidence to verify their identity when requesting new credentials.

Authentication hardening › Setting credentials for user accounts

ISM-1227 NCOS

Credentials set for user accounts are randomly generated.

Authentication hardening › Setting credentials for user accounts

ISM-1594 NCOS

Credentials are provided to users via a secure communications channel or, if not possible, split into two parts with one part provided to users and the other part provided to supervisors.

Authentication hardening › Setting credentials for user accounts

ISM-1595 NCOS

Credentials provided to users are changed on first use.

Authentication hardening › Setting credentials for user accounts

ISM-1596 NCOS

Credentials are not reused by users across different systems.

Authentication hardening › Setting credentials for user accounts

ISM-1953 NCOS

Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.

Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

ISM-1685 ML2 NCOS

Credentials for break glass accounts, local administrator accounts and service accounts are long, unique, unpredictable and managed.

Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

ISM-1795 NCOS

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are a minimum of 30 characters.

Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

ISM-1954 NCOS

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.

Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

ISM-1619 NCOS

Service accounts are created as group Managed Service Accounts.

Authentication hardening › Setting credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts

ISM-1590 NCOS

Credentials for user accounts are changed if: • they are compromised • they are suspected of being compromised • they are discovered stored on networks in the clear • they are discovered being transferred across networks in the clear • membership of a shared user account changes.

Authentication hardening › Changing credentials

ISM-1955 NCOS

Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.

Authentication hardening › Changing credentials

ISM-1847 NCOS

Credentials for the Kerberos Key Distribution Center’s service account (KRBTGT) are changed twice, allowing for replication to all Microsoft AD DS domain controllers in-between each change, if the domain has been directly compromised, the domain is suspected of being compromised or they have not been changed in the past 12 months.

Authentication hardening › Changing credentials

ISM-1956 NCOS

Microsoft AD FS token-signing and encryption certificates are changed twice in quick succession if they are compromised, they are suspected of being compromised or they have not been changed in the past 12 months.

Authentication hardening › Changing credentials

ISM-1597 NCOS

Credentials are obscured as they are entered into systems.

Authentication hardening › Protecting credentials

ISM-1980 NCOS

Credential hint functionality is not used for systems.

Authentication hardening › Protecting credentials

ISM-0418 NCOS

Physical credentials are kept separate from systems they are used to authenticate to, except for when performing authentication activities.

Authentication hardening › Protecting credentials

ISM-1402 NCOS

Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.

Authentication hardening › Protecting credentials

ISM-1957 NCOS

Private keys for Microsoft AD CS CA servers are protected by a hardware security module.

Authentication hardening › Protecting credentials

ISM-1896 ML3 NCOS

Memory integrity functionality is enabled.

Authentication hardening › Protecting credentials

ISM-1861 ML3 NCOS

Local Security Authority protection functionality is enabled.

Authentication hardening › Protecting credentials

ISM-1686 ML3 NCOS

Credential Guard functionality is enabled.

Authentication hardening › Protecting credentials

ISM-1897 ML3 NCOS

Remote Credential Guard functionality is enabled.

Authentication hardening › Protecting credentials

ISM-1749 NCOS

Cached credentials are limited to one previous logon.

Authentication hardening › Protecting credentials

ISM-1875 NCOS

Networks are scanned at least monthly to identify any credentials that are being stored in the clear.

Authentication hardening › Protecting credentials

ISM-1403 NCOS

User accounts, except for break glass accounts, are protected by fixed or risk-based lockout mechanisms aligned to a maximum of five failed logon attempts, with either indefinite or automated lockout durations.

Authentication hardening › User account lockouts

ISM-0853 NCOS

User sessions are terminated and workstations are restarted at least daily.

Authentication hardening › Session termination

ISM-0428 NCOS

Services are configured with a session lock that: • activates after a maximum of 15 minutes of user inactivity, a maximum of 12 hours of overall session time or when manually activated by users • blocks access to all session content • requires users to re-authenticate using all authentication factors to unlock the session • denies users the ability to disable the session locking mechanism.

Authentication hardening › Session locking

ISM-2012 NCOS

Systems are configured with a screen lock that: • activates after a maximum of 15 minutes of user inactivity, or when manually activated by users • conceals all content on the screen • ensures that the screen does not enter a power saving state before the screen lock is activated • requires users to re-authenticate using all authentication factors to unlock the system • denies users the ability to disable the screen locking mechanism.

Authentication hardening › Screen locking

ISM-0408 NCOS

Systems have a logon banner that reminds users of their security responsibilities when accessing the system and its resources.

Authentication hardening › Logon banner

ISM-1460 NCOS

When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.

Virtualisation hardening › Functional separation between operating environments

ISM-1604 NCOS

When using a software-based isolation mechanism that consumes shared physical computing resources, the configuration of the isolation mechanism is hardened by removing unneeded functionality and restricting access to the administrative interface used to manage the isolation mechanism.

Virtualisation hardening › Functional separation between operating environments

ISM-1605 NCOS

When using a software-based isolation mechanism that consumes shared physical computing resources, the underlying operating system is hardened.

Virtualisation hardening › Functional separation between operating environments

ISM-1606 NCOS

When using a software-based isolation mechanism that consumes shared physical computing resources, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.

Virtualisation hardening › Functional separation between operating environments

ISM-1848 NCOS

When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism or underlying operating system is replaced when it is no longer supported by a vendor.

Virtualisation hardening › Functional separation between operating environments

ISM-1607 NCOS

When using a software-based isolation mechanism that consumes shared physical resources, integrity monitoring and centralised event logging is performed for the isolation mechanism and underlying operating system.

Virtualisation hardening › Functional separation between operating environments

System management · 56 controls · 8 Microsoft-assessed

ISM-0042 NCOS

System administration processes, and supporting system administration procedures, are developed, implemented and maintained.

System administration › System administration processes and procedures

ISM-1211 RFFR Core NCOS

System administrators perform system administration activities in accordance with the system’s change and configuration management plan.

System administration › System administration processes and procedures

ISM-1898 ML3 NCOS

Secure Admin Workstations are used in the performance of administrative activities.

System administration › Separate privileged operating environments

ISM-1380 RFFR Core ML1 NCOS

Privileged users use separate privileged and unprivileged operating environments.

System administration › Separate privileged operating environments

ISM-1687 ML2 NCOS

Privileged operating environments are not virtualised within unprivileged operating environments.

System administration › Separate privileged operating environments

ISM-1688 RFFR Core ML1 NCOS

Unprivileged user accounts cannot logon to privileged operating environments.

System administration › Separate privileged operating environments

ISM-1689 RFFR Core ML1 NCOS

Privileged user accounts (excluding local administrator accounts) cannot logon to unprivileged operating environments.

System administration › Separate privileged operating environments

ISM-1958 NCOS

User accounts with DCSync permissions cannot logon to unprivileged operating environments.

System administration › Separate privileged operating environments

ISM-1385 NCOS

Administrative infrastructure is segregated from the wider network and the internet.

System administration › Administrative infrastructure

ISM-1750 NCOS

Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.

System administration › Administrative infrastructure

ISM-1386 NCOS

Network management traffic can only originate from administrative infrastructure.

System administration › Administrative infrastructure

ISM-1387 ML2 NCOS

Administrative activities are conducted through jump servers.

System administration › Administrative infrastructure

ISM-1899 NCOS

Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.

System administration › Administrative infrastructure

ISM-1493 NCOS

Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.

System administration › Software registers

ISM-1643 NCOS

Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.

System administration › Software registers

ISM-1143 RFFR Core NCOS

Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.

System maintenance › Patch management processes and procedures

ISM-0298 NCOS

A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.

System maintenance › Patch management processes and procedures

ISM-1876 RFFR Core ML1 Microsoft-assessed NCOS

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1690 RFFR Core ML1 Microsoft-assessed NCOS

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1691 RFFR Core ML1 Microsoft-assessed NCOS

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

System maintenance › Mitigating known vulnerabilities

ISM-1692 ML3 Microsoft-assessed NCOS

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1901 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1693 ML2 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

System maintenance › Mitigating known vulnerabilities

ISM-1877 RFFR Core ML1 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1694 RFFR Core ML1 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1695 RFFR Core ML1 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

System maintenance › Mitigating known vulnerabilities

ISM-1696 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1902 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1878 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1751 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1879 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1697 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1903 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1904 ML3 NCOS

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

System maintenance › Mitigating known vulnerabilities

ISM-1905 RFFR Core ML1 NCOS

Online services that are no longer supported by vendors are removed.

System maintenance › Cessation of support

ISM-1704 RFFR Core ML1 NCOS

Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

System maintenance › Cessation of support

ISM-0304 ML3 NCOS

Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

System maintenance › Cessation of support

ISM-1501 RFFR Core ML1 NCOS

Operating systems that are no longer supported by vendors are replaced.

System maintenance › Cessation of support

ISM-1753 NCOS

Internet-facing network devices that are no longer supported by vendors are replaced.

System maintenance › Cessation of support

ISM-1981 NCOS

Non-internet-facing network devices that are no longer supported by vendors are replaced.

System maintenance › Cessation of support

ISM-1982 NCOS

Networked IT equipment that is no longer supported by vendors is replaced.

System maintenance › Cessation of support

ISM-1809 NCOS

When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating controls are implemented until such time that they can be removed or replaced.

System maintenance › Cessation of support

ISM-1510 NCOS

A digital preservation policy is developed, implemented and maintained.

Data backup and restoration › Digital preservation policy

ISM-1547 RFFR Core NCOS

Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.

Data backup and restoration › Data backup and restoration processes and procedures

ISM-1548 RFFR Core NCOS

Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.

Data backup and restoration › Data backup and restoration processes and procedures

ISM-1511 RFFR Core ML1 Microsoft-assessed NCOS

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

Data backup and restoration › Performing and retaining backups

ISM-1810 RFFR Core ML1 Microsoft-assessed NCOS

Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

Data backup and restoration › Performing and retaining backups

ISM-1811 RFFR Core ML1 Microsoft-assessed NCOS

Backups of data, applications and settings are retained in a secure and resilient manner.

Data backup and restoration › Performing and retaining backups

ISM-1812 RFFR Core ML1 NCOS

Unprivileged user accounts cannot access backups belonging to other user accounts.

Data backup and restoration › Backup access

ISM-1813 ML3 NCOS

Unprivileged user accounts cannot access their own backups.

Data backup and restoration › Backup access

ISM-1705 ML2 NCOS

Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.

Data backup and restoration › Backup access

ISM-1706 ML3 NCOS

Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.

Data backup and restoration › Backup access

ISM-1814 RFFR Core ML1 NCOS

Unprivileged user accounts are prevented from modifying and deleting backups.

Data backup and restoration › Backup modification and deletion

ISM-1707 ML2 NCOS

Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

Data backup and restoration › Backup modification and deletion

ISM-1708 ML3 NCOS

Backup administrator accounts are prevented from modifying and deleting backups during their retention period.

Data backup and restoration › Backup modification and deletion

ISM-1515 RFFR Core ML1 Microsoft-assessed NCOS

Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.

Data backup and restoration › Testing restoration of backups

Security assurance · 35 controls · 7 Microsoft-assessed

ISM-0580 RFFR Core NCOS

A security monitoring policy is developed, implemented and maintained.

Security monitoring › Security monitoring policy

ISM-1405 RFFR Core Microsoft-assessed NCOS

A centralised event logging facility is implemented.

Security monitoring › Centralised event logging facility

ISM-1983 Microsoft-assessed NCOS

Event logs sent to a centralised event logging facility are sent as soon as possible after they occur.

Security monitoring › Centralised event logging facility

ISM-1984 NCOS

Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.

Security monitoring › Centralised event logging facility

ISM-1985 Microsoft-assessed NCOS

Event logs are protected from unauthorised access.

Security monitoring › Centralised event logging facility

ISM-1815 RFFR Core ML2 Microsoft-assessed NCOS

Event logs are protected from unauthorised modification and deletion.

Security monitoring › Centralised event logging facility

ISM-0988 RFFR Core NCOS

An accurate and consistent time source is used for event logging.

Security monitoring › Centralised event logging facility

ISM-0585 RFFR Core NCOS

For each event logged, the date and time of the event, the relevant user or process, the relevant filename, the event description, and the information technology equipment involved are captured.

Security monitoring › Event log details

ISM-1959 NCOS

To the extent possible, event logs are captured and stored in a consistent and structured format.

Security monitoring › Event log details

ISM-0120 NCOS

Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.

Security monitoring › Event log monitoring

ISM-2116 NCOS

Cyber threat intelligence services are used to support the detection of cyber security events and the identification of cyber security incidents.

Security monitoring › Event log monitoring

ISM-2117 NCOS

Suitable AI models are used to augment the detection of cyber security events and the identification of cyber security incidents.

Security monitoring › Event log monitoring

ISM-1986 NCOS

Event logs from critical servers are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1906 ML2 NCOS

Event logs from internet-facing servers are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1907 ML3 NCOS

Event logs from non-internet-facing servers are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-0109 RFFR Core ML3 NCOS

Event logs from workstations are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1987 NCOS

Event logs from security products are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1960 NCOS

Event logs from internet-facing network devices are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1961 NCOS

Event logs from non-internet-facing network devices are analysed in a timely manner to detect cyber security events.

Security monitoring › Event log monitoring

ISM-1228 ML2 NCOS

Cyber security events are analysed in a timely manner to identify cyber security incidents.

Security monitoring › Event log monitoring

ISM-1988 NCOS

Event logs are retained in a searchable manner for at least 12 months.

Security monitoring › Event log retention

ISM-1989 NCOS

Event logs are retained as per minimum retention requirements for various classes of records as set out by the National Archives of Australia’s Administrative Functions Disposal Authority Express (AFDA Express) Version 2 publication.

Security monitoring › Event log retention

ISM-1807 RFFR Core ML1 NCOS

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

Security assessments › Vulnerability scanning

ISM-1808 RFFR Core ML1 NCOS

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

Security assessments › Vulnerability scanning

ISM-1698 RFFR Core ML1 Microsoft-assessed NCOS

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.

Security assessments › Vulnerability scanning

ISM-1699 RFFR Core ML1 Microsoft-assessed NCOS

A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

Security assessments › Vulnerability scanning

ISM-1700 ML2 NCOS

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.

Security assessments › Vulnerability scanning

ISM-1701 RFFR Core ML1 Microsoft-assessed NCOS

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.

Security assessments › Vulnerability scanning

ISM-1702 RFFR Core ML1 NCOS

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.

Security assessments › Vulnerability scanning

ISM-1752 NCOS

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.

Security assessments › Vulnerability scanning

ISM-1703 ML3 NCOS

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.

Security assessments › Vulnerability scanning

ISM-1900 ML3 NCOS

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.

Security assessments › Vulnerability scanning

ISM-1921 NCOS

The likelihood of system compromise is frequently assessed when working exploits exist for unmitigated vulnerabilities.

Security assessments › Vulnerability scanning

ISM-2118 NCOS

Vulnerability assessments and penetration tests are conducted for systems prior to their deployment, including prior to the deployment of significant changes, and at least annually thereafter.

Security assessments › Vulnerability assessments and penetration tests

ISM-2119 NCOS

Suitable AI models are used to augment vulnerability assessments and penetration tests.

Security assessments › Vulnerability assessments and penetration tests

Software development · 108 controls · 0 Microsoft-assessed

ISM-0400 NCOS

Development, testing, staging and production environments are segregated.

Software development fundamentals › Development, testing, staging and production environments

ISM-1419 NCOS

Development and modification of software only take place in development environments.

Software development fundamentals › Development, testing, staging and production environments

ISM-1420 NCOS

Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

Software development fundamentals › Development, testing, staging and production environments

ISM-2023 NCOS

An authoritative source for software is established and maintained.

Software development fundamentals › Authoritative source for software

ISM-2024 NCOS

The authoritative source for software is used for all software development activities.

Software development fundamentals › Authoritative source for software

ISM-1422 NCOS

Unauthorised access to the authoritative source for software is prevented.

Software development fundamentals › Authoritative source for software

ISM-1816 NCOS

Unauthorised modification of the authoritative source for software is prevented.

Software development fundamentals › Authoritative source for software

ISM-2025 NCOS

An issue tracking solution is used to link software development tasks to security issues and decisions, change or feature requests, programming issues, or bug fixes.

Software development fundamentals › Issue tracking

ISM-2026 NCOS

All software artefacts are scanned for malicious content before being imported into the authoritative source for software.

Software development fundamentals › Software artefacts

ISM-2027 NCOS

All software artefacts are verified by a digital signature, or a secure hash provided over a secure channel, before being imported into the authoritative source for software.

Software development fundamentals › Software artefacts

ISM-2028 NCOS

All software artefacts are tested to detect known weaknesses using static application security testing (SAST), dynamic application security testing (DAST) or software composition analysis (SCA), depending on the software artefact type, before being imported into the authoritative source for software.

Software development fundamentals › Software artefacts

ISM-2102 NCOS

Existing software artefacts in the authoritative source for software are periodically tested to detect known weaknesses using SAST, DAST or SCA, depending on the software artefact type, throughout the software development life cycle.

Software development fundamentals › Software artefacts

ISM-2029 NCOS

The authoritative source for software restricts the use and import of third-party libraries and software components to trustworthy sources.

Software development fundamentals › Software artefacts

ISM-2030 NCOS

Scanning is used during commits to identify plain text or encoded secrets and keys, which are then blocked from being stored in the authoritative source for software.

Software development fundamentals › Software artefacts

ISM-2031 NCOS

Compilers, interpreters and build tools (including pipelines) that provide security features to improve executable file security are implemented and such security features are used.

Software development fundamentals › Build solution

ISM-2032 NCOS

The build solution ensures that all automated testing is completed without warnings, alerts or errors before building software artefacts.

Software development fundamentals › Build solution

ISM-2120 NCOS

A secure software development policy is developed, implemented and maintained.

Software development fundamentals › Secure software development

ISM-2033 NCOS

All software security requirements are documented, stored securely and maintained throughout the software development life cycle.

Software development fundamentals › Secure software development

ISM-2034 NCOS

Security design decisions are documented and reviewed throughout the software development cycle.

Software development fundamentals › Secure software development

ISM-2035 NCOS

Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.

Software development fundamentals › Secure software development

ISM-2036 NCOS

Security responsibilities for software developers are identified and documented.

Software development fundamentals › Secure software development

ISM-2121 NCOS

Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks are not used.

Software development fundamentals › Secure software development

ISM-2037 NCOS

Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.

Software development fundamentals › Secure software development

ISM-2038 NCOS

A software developer cyber security knowledge and skills register is implemented and maintained.

Software development fundamentals › Secure software development

ISM-0401 NCOS

Secure by Design principles and practices are followed throughout the software development life cycle.

Software development fundamentals › Secure software development

ISM-1238 NCOS

Threat modelling is used in support of the software development life cycle.

Software development fundamentals › Secure software development

ISM-2039 NCOS

The software threat model is reviewed throughout the software development life cycle to ensure it reflects the as-built software and any changes to the threat environment.

Software development fundamentals › Secure software development

ISM-2040 NCOS

Secure programming practices for the chosen programming language are used for software development.

Software development fundamentals › Secure software development

ISM-2041 NCOS

Memory-safe programming languages, or less preferably memory-safe programming practices, are used for software development.

Software development fundamentals › Secure software development

ISM-2042 NCOS

Secure by Default principles and practices are followed throughout the software development life cycle, including by ensuring that all built-in security measures are included and enabled in the base product at no extra cost to consumers.

Software development fundamentals › Secure software development

ISM-1780 NCOS

SecDevOps practices are used for software development.

Software development fundamentals › Secure software development

ISM-2043 NCOS

Software is architected and structured to support readability and maintainability.

Software development fundamentals › Secure software development

ISM-1796 NCOS

Files containing executable content are digitally signed by a certificate with a verifiable chain of trust as part of software development.

Software development fundamentals › Secure software development

ISM-1797 NCOS

Installers, patches and updates are digitally signed or provided with cryptographic checksums as part of software development.

Software development fundamentals › Secure software development

ISM-2044 NCOS

Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.

Software development fundamentals › Secure software development

ISM-2045 NCOS

Application backwards compatibility does not compromise any security measures or features.

Software development fundamentals › Secure software development

ISM-2046 NCOS

Where software allows user impersonation, sensitive data is not logged and appropriate permissions are set.

Software development fundamentals › Secure software development

ISM-2047 NCOS

Where software allows an authentication factor to be reset, the user is notified of the reset through a secondary channel.

Software development fundamentals › Secure software development

ISM-2048 NCOS

Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.

Software development fundamentals › Secure software development

ISM-2049 NCOS

When user permissions or credentials are changed, software forces all impacted users to re-authenticate.

Software development fundamentals › Secure software development

ISM-2050 NCOS

When digital signatures are processed by software, they are validated against a certificate trust chain and checked for revocation using a Certificate Revocation List or with the Online Certificate Status Protocol.

Software development fundamentals › Secure software development

ISM-2051 NCOS

Software generates sufficient event logs to support the detection of cyber security events.

Software development fundamentals › Secure software development

ISM-2052 NCOS

Event logs produced by software ensure that any sensitive data is protected.

Software development fundamentals › Secure software development

ISM-1798 NCOS

Secure configuration guidance, in the form of a hardening guide or loosening guide, is produced and made available to consumers as part of software development.

Software development fundamentals › Secure software development

ISM-2053 NCOS

End of life procedures for software, including procedures for software removal and the archival or destruction of user accounts and data, are produced and made available to consumers.

Software development fundamentals › Secure software development

ISM-2054 NCOS

If a software bill of materials is available for imported third-party software components, it is used during software development to ensure such software components have no known vulnerabilities.

Software development fundamentals › Software bill of materials

ISM-1730 NCOS

A software bill of materials is produced and made available to consumers of software.

Software development fundamentals › Software bill of materials

ISM-2082 NCOS

If a cryptographic bill of materials is available for imported third-party software components, it is used during software development to ensure such software components provide support for standardised implementations of ASD-Approved Cryptographic Algorithms.

Software development fundamentals › Cryptographic bill of materials

ISM-2083 NCOS

A cryptographic bill of materials is produced and made available to consumers of software.

Software development fundamentals › Cryptographic bill of materials

ISM-2055 NCOS

If a software build provenance is available for imported third-party software components, it is used during software development to ensure such software components are built to an appropriate standard.

Software development fundamentals › Software build provenance

ISM-2056 NCOS

A software build provenance is produced and made available to consumers of software.

Software development fundamentals › Software build provenance

ISM-1818 NCOS

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.

Software development fundamentals › Network application programming interfaces

ISM-2013 NCOS

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.

Software development fundamentals › Network application programming interfaces

ISM-1817 NCOS

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.

Software development fundamentals › Network application programming interfaces

ISM-2014 NCOS

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.

Software development fundamentals › Network application programming interfaces

ISM-1910 NCOS

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.

Software development fundamentals › Network application programming interfaces

ISM-2015 NCOS

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.

Software development fundamentals › Network application programming interfaces

ISM-1240 NCOS

Validation and sanitisation are performed on all input received over the internet by software.

Software development fundamentals › Software input handling

ISM-2016 NCOS

Validation and sanitisation are performed on all input received over a local network by software.

Software development fundamentals › Software input handling

ISM-2057 NCOS

All input validation rules are documented, implemented in code, and tested using both positive and negative unit tests and integration tests.

Software development fundamentals › Software input handling

ISM-2058 NCOS

Data sources and serialised data inputs are validated before being deserialised.

Software development fundamentals › Software input handling

ISM-2059 NCOS

File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.

Software development fundamentals › Software input handling

ISM-1275 NCOS

All queries to databases from software are filtered for legitimate content and correct syntax.

Software development fundamentals › Software interaction with databases

ISM-1276 NCOS

Parameterised queries or stored procedures, instead of dynamically generated queries, are used by software for database interactions.

Software development fundamentals › Software interaction with databases

ISM-1278 NCOS

Software is designed or configured to provide as little error information as possible about the structure of databases.

Software development fundamentals › Software interaction with databases

ISM-1536 RFFR Core NCOS

All queries to databases from software that are initiated by users, and any resulting crash or error messages, are centrally logged.

Software development fundamentals › Software interaction with databases

ISM-2061 NCOS

Peer reviews are conducted on all critical and security-related software components.

Software development fundamentals › Software security testing

ISM-2060 NCOS

Code reviews are utilised to ensure software components meets Secure by Design principles and practices as well as secure programming practices.

Software development fundamentals › Software security testing

ISM-2062 NCOS

Unit testing and integration testing, covering both positive and negative use cases, are used for software components to ensure code quality and correctness.

Software development fundamentals › Software security testing

ISM-0402 NCOS

Software is comprehensively tested for vulnerabilities using SAST, DAST and SCA prior to its initial release, any subsequent release, and periodically to help identify any previously unidentified vulnerabilities.

Software development fundamentals › Software security testing

ISM-2122 NCOS

Suitable AI models are used to augment software security testing.

Software development fundamentals › Software security testing

ISM-1616 NCOS

A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.

Software development fundamentals › Vulnerability disclosure program

ISM-1755 NCOS

A vulnerability disclosure policy is developed, implemented and maintained.

Software development fundamentals › Vulnerability disclosure program

ISM-1756 NCOS

Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.

Software development fundamentals › Vulnerability disclosure program

ISM-1717 NCOS

A ‘security.txt’ file is hosted for each of an organisation’s internet-facing website domains to assist in the responsible disclosure of vulnerabilities in the organisation’s products and services.

Software development fundamentals › Vulnerability disclosure program

ISM-1908 NCOS

Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.

Software development fundamentals › Reporting and resolving vulnerabilities

ISM-1754 NCOS

Vulnerabilities identified in software are resolved in a timely manner.

Software development fundamentals › Reporting and resolving vulnerabilities

ISM-1909 NCOS

In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.

Software development fundamentals › Reporting and resolving vulnerabilities

ISM-1911 NCOS

Security-relevant usage, error messages and crashes for software are centrally logged.

Software development fundamentals › Software event logging

ISM-2084 NCOS

AI-specific documentation, including AI model cards and AI system cards (or equivalent artefacts), is used to document AI model characteristics, system architectures, use cases and security risks.

Artificial intelligence application development › Secure artificial intelligence application development

ISM-2072 NCOS

AI models are stored in a non-executable file format that does not allow arbitrary code execution.

Artificial intelligence application development › Secure artificial intelligence application development

ISM-2085 NCOS

The exposure of exact AI model confidence scores in API outputs or user interfaces is prevented.

Artificial intelligence application development › Secure artificial intelligence application development

ISM-2103 NCOS

Organisational data generated, collected or processed by AI applications is not used for training, fine-tuning or improving AI models unless informed and explicit consent has been obtained from data owners in advance.

Artificial intelligence application development › Data collection, retention and use

ISM-2123 NCOS

All prompts and outputs associated with chat sessions are securely deleted when chat sessions are removed from AI applications.

Artificial intelligence application development › Data collection, retention and use

ISM-2086 NCOS

The source and integrity of AI models, structures and weights are verified.

Artificial intelligence application development › Artificial intelligence model poisoning

ISM-2087 NCOS

The source and integrity of training data for AI models is verified.

Artificial intelligence application development › Artificial intelligence model poisoning

ISM-2088 NCOS

Data validation and verification techniques are used to ensure the reliability and accuracy of training data used by AI models.

Artificial intelligence application development › Artificial intelligence model poisoning

ISM-2089 NCOS

AI model performance metrics are monitored and anomalies are investigated.

Artificial intelligence application development › Unbounded consumption

ISM-2090 NCOS

Rate limiting is applied to inference queries for AI models.

Artificial intelligence application development › Unbounded consumption

ISM-2091 NCOS

Resource limits are enforced for AI models.

Artificial intelligence application development › Unbounded consumption

ISM-2092 NCOS

Access control policies are implemented to enforce fine-grained permissions for AI applications.

Artificial intelligence application development › Excessive agency

ISM-2093 NCOS

Role-based access controls are implemented for AI applications to restrict access to sensitive data.

Artificial intelligence application development › Excessive agency

ISM-1924 NCOS

Generative AI applications evaluate user prompts to detect and mitigate adversarial inputs or suffixes designed to elicit unintended behaviour or assist in the generation of sensitive or harmful content.

Artificial intelligence application development › Prompt injection

ISM-2094 NCOS

Content filtering is implemented by AI applications to detect and block sensitive data exposure and improper output.

Artificial intelligence application development › Sensitive data exposure and improper output

ISM-1922 NCOS

The OWASP Mobile Application Security Verification Standard is used in the development of mobile applications.

Mobile application development › Secure mobile application development

ISM-1239 NCOS

Robust web application frameworks are used in the development of web applications.

Web application development › Secure web application design and development

ISM-0971 NCOS

The OWASP Application Security Verification Standard is used in the development of web applications.

Web application development › Secure web application design and development

ISM-1849 NCOS

The OWASP Top 10 Proactive Controls are used in the development of web applications.

Web application development › Secure web application design and development

ISM-1850 NCOS

The OWASP Top 10 are mitigated in the development of web applications.

Web application development › Secure web application design and development

ISM-2063 NCOS

If supported, web application session cookies set the HttpOnly flag, Secure flag and the SameSite flag by default.

Web application development › Secure web application design and development

ISM-2064 NCOS

Web application session cookies contain only digitally signed opaque bearer tokens.

Web application development › Secure web application design and development

ISM-2065 NCOS

Web application session cookies using opaque bearer tokens that are not digitally signed use non-sequential random identifiers with a minimum of 128 bits of entropy, preferably 256 bits of entropy.

Web application development › Secure web application design and development

ISM-2066 NCOS

Web application sessions are centrally managed server side.

Web application development › Secure web application design and development

ISM-2067 NCOS

Web applications that support Single Sign On equally support Single Logout.

Web application development › Secure web application design and development

ISM-1424 NCOS

Content-Security-Policy, Hypertext Transfer Protocol Strict Transport Security and X-Frame-Options are specified by web server software via security policy in response headers.

Web application development › Web security policy response headers

ISM-1552 NCOS

All web application content is offered exclusively using HTTPS.

Web application development › Web application interactions

ISM-1851 NCOS

The OWASP API Security Top 10 are mitigated in the development of web APIs.

Web application development › Web application programming interfaces

ISM-1241 NCOS

Output encoding is performed on all output produced by web applications.

Web application development › Web application output encoding

Database systems · 13 controls · 0 Microsoft-assessed

ISM-1269 NCOS

Database servers and web servers are functionally separated.

Database servers › Functional separation between database servers and web servers

ISM-1277 NCOS

Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.

Database servers › Communications between database servers and web servers

ISM-1270 NCOS

Database servers are placed on a different network segment to user workstations.

Database servers › Network environment

ISM-1271 NCOS

Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.

Database servers › Network environment

ISM-1272 NCOS

If only local access to a database is required, networking functionality of database management system applications is disabled or directed to listen solely to the localhost interface.

Database servers › Network environment

ISM-1273 NCOS

Database servers for development, testing, staging and production environments are segregated.

Database servers › Segregation of development, testing, staging and production database servers

ISM-1243 NCOS

A database register is developed, implemented, maintained and regularly verified.

Databases › Database register

ISM-1256 NCOS

File-based access controls are applied to database files.

Databases › Protecting databases

ISM-0393 NCOS

Databases and their contents are classified based on the sensitivity or classification of data that they contain.

Databases › Protecting database contents

ISM-1255 NCOS

Database users’ ability to access, insert, modify and remove database contents is restricted based on their work duties.

Databases › Protecting database contents

ISM-1268 NCOS

The need-to-know principle is enforced for database contents through the application of minimum privileges, database views, database roles and data tokenisation.

Databases › Protecting database contents

ISM-1274 NCOS

Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.

Databases › Segregation of development, testing, staging and production databases

ISM-1537 RFFR Core NCOS

Security-relevant events for databases are centrally logged, including: • access or modification of particularly important content • addition of new users, especially privileged users • changes to user roles or privileges • attempts to elevate user privileges • queries containing comments • queries containing multiple embedded queries • database and query alerts or failures • database structure changes • database administrator actions • use of executable commands • database logons and logoffs.

Databases › Database event logging

Email · 25 controls · 2 Microsoft-assessed

ISM-0264 NCOS

An email usage policy is developed, implemented and maintained.

Email usage › Email usage policy

ISM-0267 NCOS

Access to non-approved webmail services is blocked.

Email usage › Webmail services

ISM-0270 NCOS

Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.

Email usage › Protective markings for emails

ISM-0271 Microsoft-assessed NCOS

Protective marking tools do not automatically insert protective markings into emails.

Email usage › Protective marking tools

ISM-0272 Microsoft-assessed NCOS

Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.

Email usage › Protective marking tools

ISM-1089 NCOS

Protective marking tools do not allow users replying to or forwarding emails to select protective markings lower than previously used.

Email usage › Protective marking tools

ISM-0565 NCOS

Email servers are configured to block, log and report emails with inappropriate protective markings.

Email usage › Handling emails with inappropriate, invalid or missing protective markings

ISM-1023 NCOS

The intended recipients of blocked inbound emails, and the senders of blocked outbound emails, are notified.

Email usage › Handling emails with inappropriate, invalid or missing protective markings

ISM-0569 NCOS

Emails are routed via centralised email gateways.

Email gateways and servers › Centralised email gateways

ISM-0571 NCOS

When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.

Email gateways and servers › Centralised email gateways

ISM-0570 NCOS

Where backup or alternative email gateways are in place, they are maintained at the same standard as the primary email gateway.

Email gateways and servers › Email gateway maintenance activities

ISM-0567 NCOS

Email servers only relay emails destined for or originating from their domains (including subdomains).

Email gateways and servers › Open relay email servers

ISM-0572 NCOS

Opportunistic TLS encryption is enabled on email servers that make incoming or outgoing email connections over public network infrastructure.

Email gateways and servers › Email server transport encryption

ISM-1589 NCOS

MTA-STS is enabled to prevent the unencrypted transfer of emails between email servers.

Email gateways and servers › Email server transport encryption

ISM-0574 NCOS

SPF is used to specify authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).

Email gateways and servers › Sender Policy Framework

ISM-1183 NCOS

A hard fail SPF record is used when specifying authorised email servers (or lack thereof) for an organisation’s domains (including subdomains).

Email gateways and servers › Sender Policy Framework

ISM-1151 NCOS

SPF is used to verify the authenticity of incoming emails.

Email gateways and servers › Sender Policy Framework

ISM-0861 NCOS

DKIM signing is enabled on emails originating from an organisation’s domains (including subdomains).

Email gateways and servers › DomainKeys Identified Mail

ISM-1026 NCOS

DKIM signatures on incoming emails are verified.

Email gateways and servers › DomainKeys Identified Mail

ISM-1027 NCOS

Email distribution list applications used by external senders is configured such that it does not break the validity of the sender’s DKIM signature.

Email gateways and servers › DomainKeys Identified Mail

ISM-1540 NCOS

DMARC records are configured for an organisation’s domains (including subdomains) such that emails are rejected if they do not pass DMARC checks.

Email gateways and servers › Domain-based Message Authentication, Reporting and Conformance

ISM-1799 NCOS

Incoming emails are rejected if they do not pass DMARC checks.

Email gateways and servers › Domain-based Message Authentication, Reporting and Conformance

ISM-1234 NCOS

Email content filtering is implemented to filter potentially harmful content in email bodies and attachments.

Email gateways and servers › Email content filtering

ISM-1502 NCOS

Emails arriving via an external connection where the email source address uses an internal domain, or internal subdomain, are blocked at the email gateway.

Email gateways and servers › Blocking suspicious emails

ISM-1024 NCOS

Notifications of undeliverable emails are only sent to senders that can be verified via SPF or other trusted means.

Email gateways and servers › Notifications of undeliverable emails

Networking · 70 controls · 1 Microsoft-assessed

ISM-0518 NCOS

Network documentation is developed, implemented and maintained.

Network design and configuration › Network documentation

ISM-0516 NCOS

Network documentation includes high-level network diagrams showing all connections into networks and logical network diagrams showing all critical servers, high-value servers, network devices and network security appliances.

Network design and configuration › Network documentation

ISM-1912 NCOS

Network documentation includes device settings for all critical servers, high-value servers, network devices and network security appliances.

Network design and configuration › Network documentation

ISM-1178 NCOS

Network documentation provided to a third party, or published in public tender documentation, only contains details necessary for other parties to undertake contractual services.

Network design and configuration › Network documentation

ISM-1181 NCOS

Networks are segregated into multiple network zones according to the criticality of servers, services and data.

Network design and configuration › Network segmentation and segregation

ISM-1577 NCOS

An organisation’s networks are segregated from their service providers’ networks.

Network design and configuration › Network segmentation and segregation

ISM-1532 NCOS

VLANs are not used to separate network traffic between an organisation’s networks and public network infrastructure.

Network design and configuration › Using Virtual Local Area Networks

ISM-0529 NCOS

VLANs are not used to separate network traffic between networks belonging to different security domains.

Network design and configuration › Using Virtual Local Area Networks

ISM-0530 NCOS

Network devices managing VLANs are administered from the most trusted security domain.

Network design and configuration › Using Virtual Local Area Networks

ISM-0535 NCOS

Network devices managing VLANs belonging to different security domains do not share VLAN trunks.

Network design and configuration › Using Virtual Local Area Networks

ISM-1364 NCOS

Network devices managing VLANs terminate VLANs belonging to different security domains on separate physical network interfaces.

Network design and configuration › Using Virtual Local Area Networks

ISM-2068 NCOS

Internet connectivity for networked devices is strictly limited to those that require access.

Network design and configuration › Functional separation between networked devices and the internet

ISM-1863 NCOS

Networked management interfaces for IT equipment are not directly exposed to the internet.

Network design and configuration › Networked management interfaces

ISM-0385 NCOS

Servers maintain effective functional separation from each other.

Network design and configuration › Functional separation between servers

ISM-1479 NCOS

Servers minimise communications with other servers at the network and file system level.

Network design and configuration › Functional separation between servers

ISM-1781 Microsoft-assessed NCOS

All data communicated over network infrastructure is encrypted using ASD-approved cryptography.

Network design and configuration › Network encryption

ISM-0521 NCOS

IPv6 functionality is disabled in dual-stack network devices unless it is being used.

Network design and configuration › Using Internet Protocol version 6

ISM-1186 NCOS

IPv6 capable network security appliances are used on IPv6 and dual-stack networks.

Network design and configuration › Using Internet Protocol version 6

ISM-1428 NCOS

Unless explicitly required, IPv6 tunnelling is disabled on all network devices.

Network design and configuration › Using Internet Protocol version 6

ISM-1429 NCOS

IPv6 tunnelling is blocked by network security appliances at externally connected network boundaries.

Network design and configuration › Using Internet Protocol version 6

ISM-1430 NCOS

Dynamically assigned IPv6 addresses are configured with Dynamic Host Configuration Protocol version 6 in a stateful manner with lease data stored in a centralised event logging facility.

Network design and configuration › Using Internet Protocol version 6

ISM-0520 NCOS

Network access controls are implemented on networks to prevent the connection of unauthorised network devices and networked IT equipment.

Network design and configuration › Network access controls

ISM-1182 NCOS

Network access controls are implemented to limit the flow of network traffic within and between network segments to only that required for business purposes.

Network design and configuration › Network access controls

ISM-1006 NCOS

Security measures are implemented to prevent unauthorised access to network management traffic.

Network design and configuration › Network management traffic

ISM-1962 NCOS

SMB version 1 is not used on networks.

Network design and configuration › Using the Server Message Block protocol

ISM-1311 NCOS

SNMP version 1 and SNMP version 2 are not used on networks.

Network design and configuration › Using the Simple Network Management Protocol

ISM-1312 NCOS

All default SNMP community strings on network devices are changed and write access is disabled.

Network design and configuration › Using the Simple Network Management Protocol

ISM-1028 NCOS

A NIDS or NIPS is deployed in gateways between an organisation’s networks and other networks they do not manage.

Network design and configuration › Using Network-based Intrusion Detection and Prevention Systems

ISM-1030 NCOS

A NIDS or NIPS is located immediately inside the outermost firewall for gateways and configured to generate event logs and alerts for network traffic that contravenes any rule in a firewall ruleset.

Network design and configuration › Using Network-based Intrusion Detection and Prevention Systems

ISM-1627 NCOS

Inbound network connections from anonymity networks are blocked.

Network design and configuration › Blocking anonymity network traffic

ISM-1628 NCOS

Outbound network connections to anonymity networks are blocked.

Network design and configuration › Blocking anonymity network traffic

ISM-2017 NCOS

DNS traffic is encrypted by clients and servers using ASD-approved cryptography.

Network design and configuration › Encrypted Domain Name System Services

ISM-1782 NCOS

A protective DNS service is used to block access to known malicious domain names.

Network design and configuration › Protective Domain Name System Services

ISM-1800 NCOS

Network devices are flashed with trusted firmware before they are used for the first time.

Network design and configuration › Flashing network devices with trusted firmware before first use

ISM-1304 NCOS

Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.

Network design and configuration › Default user accounts and credentials for network devices

ISM-0534 NCOS

Unused physical ports on network devices are disabled.

Network design and configuration › Disabling unused physical ports on network devices

ISM-1801 NCOS

Network devices are restarted at least monthly.

Network design and configuration › Regularly restarting network devices

ISM-1963 NCOS

Security-relevant events for internet-facing network devices are centrally logged.

Network design and configuration › Network device event logging

ISM-1964 NCOS

Security-relevant events for non-internet-facing network devices are centrally logged.

Network design and configuration › Network device event logging

ISM-1314 NCOS

All wireless devices are Wi-Fi Alliance certified.

Wireless networks › Choosing wireless devices

ISM-0536 NCOS

Public wireless networks provided for public use are segregated from all other organisation networks.

Wireless networks › Public wireless networks

ISM-1315 NCOS

The administrative interface on wireless access points is disabled for wireless network connections.

Wireless networks › Administrative interfaces for wireless access points

ISM-1710 NCOS

Settings for wireless access points are hardened.

Wireless networks › Default settings

ISM-1316 NCOS

Default SSIDs of wireless access points are changed.

Wireless networks › Default settings

ISM-1317 NCOS

SSIDs of non-public wireless networks are not readily associated with an organisation, the location of their premises or the functionality of wireless networks.

Wireless networks › Default settings

ISM-1318 NCOS

SSID broadcasting is not disabled on wireless access points.

Wireless networks › Default settings

ISM-1320 NCOS

MAC address filtering is not used to restrict which devices can connect to wireless networks.

Wireless networks › Media Access Control address filtering

ISM-1319 NCOS

Static addressing is not used for assigning IP addresses on wireless networks.

Wireless networks › Static addressing

ISM-1332 NCOS

WPA3-Enterprise 192-bit mode is used to protect the confidentiality and integrity of all wireless network traffic.

Wireless networks › Confidentiality and integrity of wireless network traffic

ISM-1321 NCOS

802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.

Wireless networks › 802.1X authentication

ISM-1711 NCOS

User identity confidentiality is used if available with EAP-TLS implementations.

Wireless networks › 802.1X authentication

ISM-1322 NCOS

Evaluated supplicants, authenticators, wireless access points and authentication servers are used in wireless networks.

Wireless networks › Evaluation of 802.1X authentication implementation

ISM-1324 NCOS

Certificates are generated using an evaluated certificate authority or hardware security module.

Wireless networks › Generating and issuing certificates for authentication

ISM-1323 NCOS

Certificates are required for devices and users accessing wireless networks.

Wireless networks › Generating and issuing certificates for authentication

ISM-1327 NCOS

Certificates are protected by logical and physical access controls, encryption, and user authentication.

Wireless networks › Generating and issuing certificates for authentication

ISM-1330 NCOS

The PMK caching period is not set to greater than 1440 minutes (24 hours).

Wireless networks › Caching 802.1X authentication outcomes

ISM-1712 NCOS

The use of FT (802.11r) is disabled unless authenticator-to-authenticator communications are secured by an ASD-Approved Cryptographic Protocol.

Wireless networks › Fast Basic Service Set Transition

ISM-1454 NCOS

Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.

Wireless networks › Remote Authentication Dial-In User Service authentication

ISM-1334 NCOS

Wireless networks implement sufficient frequency separation from other wireless networks.

Wireless networks › Interference between wireless networks

ISM-1335 NCOS

Wireless access points enable the use of the 802.11w amendment to protect management frames.

Wireless networks › Protecting management frames on wireless networks

ISM-1338 NCOS

Instead of deploying a small number of wireless access points that broadcast on high power, a greater number of wireless access points that use less broadcast power are deployed to achieve the desired footprint for wireless networks.

Wireless networks › Wireless network footprint

ISM-1437 NCOS

Cloud service providers are used for hosting online services.

Service continuity for online services › Cloud-based hosting of online services

ISM-1579 NCOS

Cloud service providers’ ability to scale resources dynamically in response to genuine spikes in demand is discussed and verified as part of capacity and availability planning for online services.

Service continuity for online services › Capacity and availability planning and monitoring for online services

ISM-1580 NCOS

Where a high availability requirement exists for online services, the services are architected to automatically transition between availability zones.

Service continuity for online services › Capacity and availability planning and monitoring for online services

ISM-1581 NCOS

Continuous real-time monitoring of the capacity and availability of online services is performed.

Service continuity for online services › Capacity and availability planning and monitoring for online services

ISM-1438 NCOS

Where a high availability requirement exists for website hosting, CDNs that cache websites are used.

Service continuity for online services › Using content delivery networks

ISM-1439 NCOS

If using CDNs, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.

Service continuity for online services › Using content delivery networks

ISM-1431 NCOS

Denial-of-service attack mitigation strategies are discussed with cloud service providers, specifically: • their capacity to withstand denial-of-service attacks • costs likely to be incurred as a result of denial-of-service attacks • availability monitoring and thresholds for notification of denial-of-service attacks • thresholds for turning off any online services or functionality during denial-of-service attacks • pre-approved actions that can be undertaken during denial-of-service attacks • any arrangements with upstream service providers to block malicious network traffic as far upstream as possible.

Service continuity for online services › Denial-of-service attack mitigation strategies

ISM-1436 NCOS

Critical online services are segregated from other online services that are more likely to be targeted as part of denial-of-service attacks.

Service continuity for online services › Denial-of-service attack mitigation strategies

ISM-1432 NCOS

Domain names for online services are protected via registrar locking and confirming that domain registration details are correct.

Service continuity for online services › Denial-of-service attack mitigation strategies

Cryptography · 59 controls · 0 Microsoft-assessed

ISM-0507 NCOS

Cryptographic key management processes, and supporting cryptographic key management procedures, are developed, implemented and maintained.

Cryptographic fundamentals › Cryptographic key management processes and procedures

ISM-0457 OS

Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used when encrypting media that contains OFFICIAL: Sensitive or PROTECTED data.

Cryptographic fundamentals › Cryptographic implementation assurance

ISM-0465 OS

Cryptographic equipment, applications or libraries that have completed a Common Criteria evaluation against an ASD-endorsed Protection Profile are used to protect OFFICIAL: Sensitive or PROTECTED data when communicated over insufficiently secure networks, outside of appropriately secure areas or via public network infrastructure.

Cryptographic fundamentals › Cryptographic implementation assurance

ISM-0455 NCOS

Where practical, cryptographic equipment, applications and libraries provide a means of data recovery to allow for circumstances where the encryption key is unavailable due to loss, damage or failure.

Cryptographic fundamentals › Data recovery

ISM-0462 NCOS

When a user authenticates to the encryption functionality of IT equipment or media, it is treated in accordance with its original sensitivity or classification until the user deauthenticates from the encryption functionality.

Cryptographic fundamentals › Handling encrypted IT equipment and media

ISM-0501 NCOS

Keyed cryptographic equipment is transported based on the sensitivity or classification of its keying material.

Cryptographic fundamentals › Transporting cryptographic equipment

ISM-0142 NCOS

The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.

Cryptographic fundamentals › Reporting cryptographic-related cyber security incidents

ISM-1091 NCOS

Keying material is changed when compromised or suspected of being compromised.

Cryptographic fundamentals › Reporting cryptographic-related cyber security incidents

ISM-1080 NCOS

An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.

Cryptographic algorithms › Using cryptographic algorithms

ISM-0471 NCOS

Only AACAs or high assurance cryptographic algorithms are used by cryptographic equipment, applications and libraries.

Cryptographic algorithms › Using cryptographic algorithms

ISM-0994 NCOS

ECDH is used in preference to DH.

Cryptographic algorithms › Asymmetric cryptographic algorithms

ISM-0472 NCOS

When using DH for agreeing on encryption session keys, a modulus of at least 2048 bits is used, preferably 3072 bits.

Cryptographic algorithms › Using Diffie-Hellman

ISM-1629 NCOS

When using DH for agreeing on encryption session keys, a modulus and associated parameters are selected according to NIST SP 800-56A Rev. 3.

Cryptographic algorithms › Using Diffie-Hellman

ISM-1446 NCOS

When using elliptic curve cryptography, a suitable curve from NIST SP 800-186 is used.

Cryptographic algorithms › Using Elliptic Curve Cryptography

ISM-0474 NCOS

When using ECDH for agreeing on encryption session keys, a base point order and key size of at least 224 bits is used, preferably the NIST P-384 curve.

Cryptographic algorithms › Using Elliptic Curve Diffie-Hellman

ISM-0475 NCOS

When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.

Cryptographic algorithms › Using the Elliptic Curve Digital Signature Algorithm

ISM-1990 NCOS

When using ML-DSA and ML-KEM, as per FIPS 204 and FIPS 203 respectively, adherence to pre-requisite FIPS 140-3 validation is preferred.

Cryptographic algorithms › Using post-quantum cryptographic algorithms

ISM-1991 NCOS

When using ML-DSA for digital signatures, ML-DSA-65 or ML-DSA-87 is used, preferably ML-DSA-87.

Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm

ISM-1992 NCOS

When using ML-DSA for digital signatures, the hedged variant is used whenever possible.

Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm

ISM-1993 NCOS

Pre-hashed variants of ML-DSA-65 and ML-DSA-87 are only used when the performance of default variants is unacceptable.

Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm

ISM-1994 NCOS

When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.

Cryptographic algorithms › Using the Module-Lattice-Based Digital Signature Algorithm

ISM-1995 NCOS

When using ML-KEM for encapsulating encryption session keys (and similar keys), ML-KEM-768 or ML-KEM-1024 is used, preferably ML-KEM-1024.

Cryptographic algorithms › Using the Module-Lattice-Based Key Encapsulation Mechanism

ISM-0476 NCOS

When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.

Cryptographic algorithms › Using Rivest-Shamir-Adleman

ISM-0477 NCOS

When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.

Cryptographic algorithms › Using Rivest-Shamir-Adleman

ISM-1766 NCOS

When using SHA-2 for hashing, an output size of at least 224 bits is used, preferably SHA-384 or SHA-512.

Cryptographic algorithms › Using Secure Hashing Algorithms

ISM-1769 NCOS

When using AES for encryption, AES-128, AES-192 or AES-256 is used, preferably AES-256.

Cryptographic algorithms › Using symmetric cryptographic algorithms

ISM-0479 NCOS

Symmetric cryptographic algorithms are not used in Electronic Codebook Mode.

Cryptographic algorithms › Using symmetric cryptographic algorithms

ISM-2073 NCOS

A post-quantum cryptography transition plan is developed, implemented and maintained.

Cryptographic algorithms › Transitioning to post-quantum cryptography

ISM-1917 NCOS

The development and procurement of new cryptographic equipment, applications and libraries ensures support for the use of ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by no later than 2030.

Cryptographic algorithms › Transitioning to post-quantum cryptography

ISM-1996 NCOS

When a post-quantum traditional hybrid scheme is used, either the post-quantum cryptographic algorithm, the traditional cryptographic algorithm or both are AACAs.

Cryptographic algorithms › Post-quantum traditional hybrid schemes

ISM-0469 NCOS

An AACP or high assurance cryptographic protocol is used when encrypting data in transit.

Cryptographic protocols › Using cryptographic protocols

ISM-0481 NCOS

Only AACPs or high assurance cryptographic protocols are used by cryptographic equipment, applications and libraries.

Cryptographic protocols › Using cryptographic protocols

ISM-1139 NCOS

Only the latest version of TLS is used for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1369 NCOS

AES-GCM is used for encryption of TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1370 NCOS

Only server-initiated secure renegotiation is used for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1372 NCOS

DH or ECDH is used for key establishment of TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1448 NCOS

When using DH or ECDH for key establishment of TLS connections, the ephemeral variant is used.

Transport Layer Security › Configuring Transport Layer Security

ISM-1373 NCOS

Anonymous DH is not used for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1374 NCOS

SHA-2-based certificates are used for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1375 NCOS

SHA-2 is used for the Hash-based Message Authentication Code (HMAC) and pseudorandom function (PRF) for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1553 NCOS

TLS compression is disabled for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1453 NCOS

Perfect Forward Secrecy (PFS) is used for TLS connections.

Transport Layer Security › Configuring Transport Layer Security

ISM-1506 NCOS

The use of SSH version 1 is disabled for SSH connections.

Secure Shell › Configuring Secure Shell

ISM-0484 NCOS

The SSH daemon is configured to: • only listen on the required interfaces (ListenAddress xxx.xxx.xxx.xxx) • have a suitable login banner (Banner x) • have a login authentication timeout of no more than 60 seconds (LoginGraceTime 60) • disable host-based authentication (HostbasedAuthentication no) • disable rhosts-based authentication (IgnoreRhosts yes) • disable the ability to log in directly as root (PermitRootLogin no) • disable empty passwords (PermitEmptyPasswords no) • disable connection forwarding (AllowTCPForwarding no) • disable gateway ports (GatewayPorts no) • disable X11 forwarding (X11Forwarding no).

Secure Shell › Configuring Secure Shell

ISM-0485 NCOS

Public key-based authentication is used for SSH connections.

Secure Shell › Authentication mechanisms

ISM-1449 NCOS

SSH private keys are protected with a password or a key encryption key.

Secure Shell › Authentication mechanisms

ISM-0487 NCOS

When using logins without a password for SSH connections, the following are disabled: • access from IP addresses that do not require access • port forwarding • agent credential forwarding • X11 forwarding • console access.

Secure Shell › Automated remote access

ISM-0488 NCOS

If using remote access without the use of a password for SSH connections, the ‘forced command’ option is used to specify what command is executed and parameter checking is enabled.

Secure Shell › Automated remote access

ISM-0489 NCOS

When SSH-agent or similar key caching applications are used, it is limited to workstations and servers with screen locks and key caches that are set to expire within four hours of inactivity.

Secure Shell › SSH-agent

ISM-0490 NCOS

Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.

Secure/Multipurpose Internet Mail Extension › Configuring Secure/Multipurpose Internet Mail Extension

ISM-0494 NCOS

Tunnel mode is used for IPsec connections; however, if using transport mode, an IP tunnel is used.

Internet Protocol Security › Mode of operation

ISM-0496 NCOS

The ESP protocol is used for authentication and encryption of IPsec connections.

Internet Protocol Security › Protocol selection

ISM-1233 NCOS

IKE version 2 is used for key exchange when establishing IPsec connections.

Internet Protocol Security › Key exchange

ISM-1771 NCOS

AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.

Internet Protocol Security › Encryption algorithms

ISM-1772 NCOS

PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.

Internet Protocol Security › Pseudorandom function

ISM-0998 NCOS

AUTH_HMAC_SHA2_256_128, AUTH_HMAC_SHA2_384_192, AUTH_HMAC_SHA2_512_256 or NONE (only with AES-GCM) is used for authenticating IPsec connections, preferably NONE.

Internet Protocol Security › Integrity algorithms

ISM-0999 NCOS

DH or ECDH is used for key establishment of IPsec connections, preferably 384-bit random ECP group, 3072-bit MODP Group or 4096-bit MODP Group.

Internet Protocol Security › Diffie-Hellman groups

ISM-0498 NCOS

A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.

Internet Protocol Security › Security association lifetimes

ISM-1000 NCOS

PFS is used for IPsec connections.

Internet Protocol Security › Perfect Forward Secrecy

Gateways · 47 controls · 1 Microsoft-assessed

ISM-0628 NCOS

Gateways are implemented between networks belonging to different security domains.

Gateways › Implementing gateways

ISM-0637 NCOS

Gateways implement a demilitarised zone if external parties require access to an organisation’s services.

Gateways › Implementing gateways

ISM-0631 NCOS

Gateways only allow explicitly authorised data flows.

Gateways › Implementing gateways

ISM-1192 NCOS

Gateways inspect and filter data flows at the transport and above network layers.

Gateways › Implementing gateways

ISM-1427 NCOS

Gateways perform ingress traffic filtering to detect and prevent IP source address spoofing.

Gateways › Implementing gateways

ISM-1520 NCOS

System administrators for gateways undergo appropriate employment screening, and where necessary hold an appropriate security clearance, based on the sensitivity or classification of gateways.

Gateways › System administrators for gateways

ISM-0611 NCOS

System administrators for gateways are assigned the minimum privileges required to perform their duties.

Gateways › System administrators for gateways

ISM-0616 NCOS

Separation of duties is implemented in performing administrative activities for gateways.

Gateways › System administrators for gateways

ISM-0612 NCOS

System administrators for gateways are formally trained on the operation and management of gateways.

Gateways › System administrators for gateways

ISM-1774 NCOS

Gateways are managed via a secure path isolated from all connected networks.

Gateways › System administration of gateways

ISM-0629 NCOS

For gateways between networks belonging to different security domains, any shared components are managed by system administrators for the higher security domain or by system administrators from a mutually agreed upon third party.

Gateways › System administration of gateways

ISM-0619 NCOS

Users authenticate to other networks accessed via gateways.

Gateways › Authenticating to networks accessed via gateways

ISM-0622 NCOS

IT equipment authenticates to other networks accessed via gateways.

Gateways › Authenticating to networks accessed via gateways

ISM-1783 NCOS

Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.

Gateways › Border Gateway Protocol routing security

ISM-2018 NCOS

Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.

Gateways › Border Gateway Protocol routing security

ISM-0634 NCOS

Security-relevant events for gateways are centrally logged, including: • data packets and data flows permitted through gateways • data packets and data flows attempting to leave gateways • real-time alerts for attempted intrusions.

Gateways › Gateway event logging

ISM-1037 NCOS

Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate that they conform to expected security configurations.

Gateways › Assessment of gateways

ISM-0100 NCOS

Non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET gateways undergo an IRAP assessment, using the latest release of the ISM available prior to the beginning of the IRAP assessment (or a subsequent release), at least every 24 months.

Gateways › Assessment of gateways

ISM-1528 NCOS

Evaluated firewalls are used between an organisation’s networks and public network infrastructure.

Firewalls › Using firewalls

ISM-0639 NCOS

Evaluated firewalls are used between networks belonging to different security domains.

Firewalls › Using firewalls

ISM-1862 NCOS

If using a WAF, disclosing the IP addresses of web servers under an organisation’s control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.

Web application firewalls › Using web application firewalls

ISM-0643 NCOS

Evaluated diodes are used for controlling the data flow of unidirectional gateways between an organisation’s networks and public network infrastructure.

Diodes › Using diodes

ISM-1157 NCOS

Evaluated diodes are used for controlling the data flow of unidirectional gateways between networks.

Diodes › Using diodes

ISM-0260 NCOS

All web access, including that by internal servers, is conducted through web proxies.

Web proxies › Using web proxies

ISM-0261 NCOS

The following details are centrally logged for websites accessed via web proxies: • web address • date and time • user • amount of data uploaded and downloaded • internal and external IP addresses.

Web proxies › Web proxy event logging

ISM-0963 NCOS

Web content filtering is implemented to filter potentially harmful web-based content.

Web content filters › Using web content filters

ISM-0961 NCOS

Client-side active content is restricted by web content filters to an organisation-approved list of domain names.

Web content filters › Using web content filters

ISM-1237 NCOS

Web content filtering is applied to outbound web traffic where appropriate.

Web content filters › Using web content filters

ISM-0263 NCOS

TLS traffic communicated through gateways is decrypted and inspected.

Web content filters › Transport Layer Security filtering

ISM-0958 NCOS

An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.

Web content filters › Allowing and blocking access to domain names

ISM-1236 NCOS

Malicious domain names, dynamic domain names and domain names that can be registered anonymously for free are blocked by web content filters.

Web content filters › Allowing and blocking access to domain names

ISM-1171 NCOS

Attempts to access websites through their IP addresses instead of their domain names are blocked by web content filters.

Web content filters › Allowing and blocking access to domain names

ISM-0659 NCOS

Files imported or exported via gateways or CDSs undergo content filtering checks.

Content filtering › Performing content filtering

ISM-0651 NCOS

Files identified by content filtering checks as malicious, or that cannot be inspected, are blocked.

Content filtering › Performing content filtering

ISM-0652 NCOS

Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.

Content filtering › Performing content filtering

ISM-1293 NCOS

Encrypted files imported or exported via gateways or CDSs are decrypted to undergo content filtering checks.

Content filtering › Encrypted files

ISM-1289 NCOS

Archive files imported or exported via gateways or CDSs are unpacked to undergo content filtering checks.

Content filtering › Archive files

ISM-1290 NCOS

Archive files are unpacked in a controlled manner to ensure content filter performance or availability is not adversely affected.

Content filtering › Archive files

ISM-1288 Microsoft-assessed NCOS

Files imported or exported via gateways or CDSs undergo antivirus scanning using multiple different scanning engines.

Content filtering › Antivirus scanning

ISM-1389 NCOS

Executable files imported via gateways or CDSs are automatically executed in a sandbox to detect any suspicious behaviour.

Content filtering › Automated dynamic analysis

ISM-0649 NCOS

Files imported or exported via gateways or CDSs are filtered for allowed file types.

Content filtering › Allowing specific content types

ISM-1284 NCOS

Files imported or exported via gateways or CDSs undergo content validation.

Content filtering › Content validation

ISM-1965 NCOS

Files imported or exported via gateways or CDSs undergo content checking.

Content filtering › Content checking

ISM-1286 NCOS

Files imported or exported via gateways or CDSs undergo content conversion.

Content filtering › Content conversion

ISM-1287 NCOS

Files imported or exported via gateways or CDSs undergo content sanitisation.

Content filtering › Content sanitisation

ISM-0677 NCOS

Files imported or exported via gateways or CDSs that have a digital signature or cryptographic checksum are validated.

Content filtering › Validating file integrity

ISM-0591 NCOS

Evaluated peripheral switches are used when sharing peripherals between systems.

Peripheral switches › Using peripheral switches

Data transfers · 8 controls · 1 Microsoft-assessed

ISM-0663 NCOS

Data transfer processes, and supporting data transfer procedures, are developed, implemented and maintained.

Data transfers › Data transfer processes and procedures

ISM-0661 NCOS

Users transferring data to and from systems are held accountable for data transfers they perform.

Data transfers › User responsibilities

ISM-0657 NCOS

When manually importing data to systems, the data is scanned for malicious and active content.

Data transfers › Manual import of data

ISM-1778 NCOS

When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

Data transfers › Manual import of data

ISM-1187 Microsoft-assessed NCOS

When manually exporting data from systems, the data is checked for unsuitable protective markings.

Data transfers › Manual export of data

ISM-1779 NCOS

When manually exporting data from systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.

Data transfers › Manual export of data

ISM-1586 NCOS

Data transfer logs are used to record all data imports and exports from systems.

Data transfers › Monitoring data import and export

ISM-1294 NCOS

Data transfer logs for systems are partially verified at least monthly.

Data transfers › Monitoring data import and export

Control text is reproduced from the Australian Government Information Security Manual (June 2026), published by the Australian Signals Directorate, and the DEWR RFFR Statement of Applicability template. This library is provided as a reference; always work from the department's current SoA template and the latest ISM. "Microsoft-assessed" indicates a control our Checkpoint console can propose a status for from a live Microsoft Graph signal — every proposed status is confirmed by a practitioner before it enters the SoA.

Turn this list into an accredited SoA

We load this entire SoA into your own Microsoft 365 tenant, assess the technical baseline automatically, and drive the gaps to closure on an ISO 27001 ISMS backbone.

Microsoft Teams