ASD Information Security Manual (ISM)

The Australian Signals Directorate's technical control library for government systems. The baseline behind System Security Plans and IRAP assessment.

Australian Signals Directorate (ASD), through the Australian Cyber Security Centre.

What it is

The Information Security Manual is the Australian Government's cyber security technical control library, published by the Australian Signals Directorate through the Australian Cyber Security Centre. It sets out the controls organisations apply to protect systems and data from cyber threats, organised around a risk management framework.

Two things distinguish it from an ISO standard. First, it is a control library rather than a management system — it tells you what technical and procedural controls to apply, not how to govern the programme that applies them. Second, it is updated frequently, on a regular release cycle rather than a multi-year revision. Documentation written against a specific ISM release ages quickly, which is why control mapping matters more than restating control text.

The ISM is applied through a system-by-system process. An organisation defines the system, classifies the data it handles, selects the applicable controls, documents them in a System Security Plan, and supports that with a Security Risk Management Plan, Incident Response Plan and Continuous Monitoring Plan. Where formal assessment is required, an IRAP assessor evaluates the system against the ISM.

The ISM is not a certification scheme. There is no ISM certificate. What exists is an assessed system, a documented control set, and an authorisation decision made by the responsible entity.

Who it's for

Commonwealth entities

Non-corporate Commonwealth entities apply the ISM through PSPF obligations. The framework requires a cyber security strategy and uplift plan aligned to the ISM.

Suppliers to Commonwealth entities

The larger group in practice. If you build, host or operate a system that handles Commonwealth information, ISM alignment reaches you through your contract. Cloud and SaaS vendors selling into government encounter this first and hardest.

Organisations seeking IRAP assessment

Typically cloud service providers and system operators whose government customers require an independent assessment of the system against ISM controls before it can be used.

Defence supply chain

Where DISP membership and ISM alignment frequently arrive together as contract conditions.

Why implement it

  • It is the price of entry for government systems work. A system that cannot be documented against the ISM cannot be authorised to handle government data, which ends the commercial conversation.
  • The SSP is reusable. Once a system is properly documented, subsequent agency engagements ask for the same artefact rather than starting again.
  • It forces the classification conversation. Many organisations have never formally established what classification of data their system actually handles, and that answer changes the control set substantially.
  • It is technically substantive. Unlike some compliance work, ISM controls address real attack paths. The uplift has security value independent of the paperwork.
  • It maps onto ISO 27001. Where an ISMS exists, the governance layer is already built and the ISM work concentrates on technical controls and system documentation.

How implementation works

ISM work is system-scoped rather than organisation-scoped, which is the most important difference from an ISO programme.

1. Define the system and its classification

Establish the system boundary and the highest classification of data it handles. This determines which controls apply and is the decision that drives everything else.

2. Control gap assessment

Assess the system against the applicable ISM controls. Controls are risk-based, so the output is a set of decisions with justifications rather than a pass/fail list.

3. Author the System Security Plan

The SSP documents the system, its boundary, the controls applied and the justification for any not applied. It is the central artefact an assessor works from.

4. Supporting documentation

Security Risk Management Plan, Incident Response Plan, and a Continuous Monitoring Plan. These are required alongside the SSP and are frequently the weakest part of a first submission.

5. Remediate

Close the technical gaps, typically including Essential Eight uplift, which is a distinct workstream in its own right.

6. Assessment

Depending on the system and the requirement, this may be an IRAP assessment by a registered assessor, or an agency-led review. Soveriq prepares the evidence and attends.

How Soveriq helps

Soveriq assesses systems against the ISM, authors the System Security Plan and supporting documentation, and builds the remediation roadmap. Where ISO 27001 is in place, we map the existing ISMS across rather than duplicating governance that already exists.

We structure documentation against ISM control identifiers rather than restating control text, so an ISM update becomes a review rather than a rewrite.

A note on our current position. Soveriq is not an IRAP assessor and is not currently a DISP member. Our work here is advisory, documentation and readiness. We would rather state that plainly than have you discover it during procurement.

On internal review. Where Soveriq has built your control set, we do not then assess it and present that as independent assurance. What we provide is readiness validation, labelled as such, performed by someone independent of the build where genuine independence is required, and disclosed to you in writing.

What the engagement looks like

  • Module 01 — Gap analysis. System-scoped control assessment against the applicable ISM baseline, with a prioritised remediation roadmap.
  • Module 02 — Build. System Security Plan, SRMP, IRP and Continuous Monitoring Plan, plus the control implementation itself.
  • Module 03 — Internal review of control implementation ahead of formal assessment, subject to the impartiality position above.
  • Module 04 — Representation during IRAP assessment or agency review.
  • Module 05 — Continuous compliance, including tracking ISM updates against your documented control set.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. IRAP assessor fees are separate and paid directly to the assessor.

Common questions

Is the ISM mandatory?

For non-corporate Commonwealth entities, ISM alignment is required through the PSPF. For suppliers, it becomes binding through your contract. Either way the obligation is real, but it arrives via a different route depending on who you are.

Do we need an IRAP assessment?

Not always. IRAP assessment is required for certain systems and certain classifications, and is commonly requested for cloud services handling government data. Many suppliers need ISM alignment and an SSP without a formal IRAP assessment. Establishing which applies to you is the first question worth answering, because the cost difference is substantial.

How does the ISM relate to ISO 27001?

The ISM is a technical control library; ISO 27001 is a management system. They work well together: the ISMS provides the governance envelope and the ISM supplies the technical baseline. An existing ISO 27001 system meaningfully reduces ISM work.

The ISM keeps changing. How do we keep up?

By tying your documented control set to ISM control identifiers rather than restating the text, so an update becomes a review rather than a rewrite. This is the single most useful structural decision in an ISM engagement.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope