The Australian Signals Directorate's technical control library for government systems. The baseline behind System Security Plans and IRAP assessment.
The Information Security Manual is the Australian Government's cyber security technical control library, published by the Australian Signals Directorate through the Australian Cyber Security Centre. It sets out the controls organisations apply to protect systems and data from cyber threats, organised around a risk management framework.
Two things distinguish it from an ISO standard. First, it is a control library rather than a management system — it tells you what technical and procedural controls to apply, not how to govern the programme that applies them. Second, it is updated frequently, on a regular release cycle rather than a multi-year revision. Documentation written against a specific ISM release ages quickly, which is why control mapping matters more than restating control text.
The ISM is applied through a system-by-system process. An organisation defines the system, classifies the data it handles, selects the applicable controls, documents them in a System Security Plan, and supports that with a Security Risk Management Plan, Incident Response Plan and Continuous Monitoring Plan. Where formal assessment is required, an IRAP assessor evaluates the system against the ISM.
The ISM is not a certification scheme. There is no ISM certificate. What exists is an assessed system, a documented control set, and an authorisation decision made by the responsible entity.
Non-corporate Commonwealth entities apply the ISM through PSPF obligations. The framework requires a cyber security strategy and uplift plan aligned to the ISM.
The larger group in practice. If you build, host or operate a system that handles Commonwealth information, ISM alignment reaches you through your contract. Cloud and SaaS vendors selling into government encounter this first and hardest.
Typically cloud service providers and system operators whose government customers require an independent assessment of the system against ISM controls before it can be used.
Where DISP membership and ISM alignment frequently arrive together as contract conditions.
ISM work is system-scoped rather than organisation-scoped, which is the most important difference from an ISO programme.
Establish the system boundary and the highest classification of data it handles. This determines which controls apply and is the decision that drives everything else.
Assess the system against the applicable ISM controls. Controls are risk-based, so the output is a set of decisions with justifications rather than a pass/fail list.
The SSP documents the system, its boundary, the controls applied and the justification for any not applied. It is the central artefact an assessor works from.
Security Risk Management Plan, Incident Response Plan, and a Continuous Monitoring Plan. These are required alongside the SSP and are frequently the weakest part of a first submission.
Close the technical gaps, typically including Essential Eight uplift, which is a distinct workstream in its own right.
Depending on the system and the requirement, this may be an IRAP assessment by a registered assessor, or an agency-led review. Soveriq prepares the evidence and attends.
Soveriq assesses systems against the ISM, authors the System Security Plan and supporting documentation, and builds the remediation roadmap. Where ISO 27001 is in place, we map the existing ISMS across rather than duplicating governance that already exists.
We structure documentation against ISM control identifiers rather than restating control text, so an ISM update becomes a review rather than a rewrite.
A note on our current position. Soveriq is not an IRAP assessor and is not currently a DISP member. Our work here is advisory, documentation and readiness. We would rather state that plainly than have you discover it during procurement.
On internal review. Where Soveriq has built your control set, we do not then assess it and present that as independent assurance. What we provide is readiness validation, labelled as such, performed by someone independent of the build where genuine independence is required, and disclosed to you in writing.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. IRAP assessor fees are separate and paid directly to the assessor.
For non-corporate Commonwealth entities, ISM alignment is required through the PSPF. For suppliers, it becomes binding through your contract. Either way the obligation is real, but it arrives via a different route depending on who you are.
Not always. IRAP assessment is required for certain systems and certain classifications, and is commonly requested for cloud services handling government data. Many suppliers need ISM alignment and an SSP without a formal IRAP assessment. Establishing which applies to you is the first question worth answering, because the cost difference is substantial.
The ISM is a technical control library; ISO 27001 is a management system. They work well together: the ISMS provides the governance envelope and the ISM supplies the technical baseline. An existing ISO 27001 system meaningfully reduces ISM work.
By tying your documented control set to ISM control identifiers rather than restating the text, so an update becomes a review rather than a rewrite. This is the single most useful structural decision in an ISM engagement.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope