What the ISM is
The Information Security Manual (ISM) is published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). Its purpose is to outline a cyber security framework that an organisation can apply, using their own risk management framework, to protect their information technology and operational technology systems from cyber threats.
It is structured around two layers. Cyber security principles provide strategic guidance grouped under six functions: Govern, Identify, Protect, Detect, Respond and Recover. Cyber security guidelines provide practical, control-level guidance an organisation applies to specific systems. The full document runs to several hundred pages and is updated regularly. The current version is June 2026.
The ISM is not a tick-list. It is risk-based. You scope the system, decide what controls are appropriate for that system, document the decision, implement, assess, authorise and monitor. Organisations are expected to be able to demonstrate they are adhering to the principles, not necessarily implement every control verbatim.
Read the official ISM on cyber.gov.auWho it applies to
The ISM is intended for chief information security officers, chief information officers, cyber security professionals and IT managers. In practice, it directly affects three groups of Australian organisations.
Commonwealth and state entities
Non-corporate Commonwealth entities must align to the ISM under the Protective Security Policy Framework (PSPF). Most state agencies follow it as a baseline.
Defence and government suppliers
DISP members, Defence primes and their supply chain. ISM expectations are flowed down through contracts, particularly at OFFICIAL: Sensitive and PROTECTED levels.
Critical infrastructure
Designated assets under the Security of Critical Infrastructure Act 2018 are not formally bound to the ISM, but it is the practical reference for CIRMP-aligned controls.
The ISM is not legally mandatory unless legislation, a direction under legislation, or another lawful authority compels it. The Privacy Act 1988, the SOCI Act and the PSPF are the most common drivers that make ISM alignment expected in practice.
The six cyber security functions
The ISM organises its principles under six functions. They are deliberately aligned with the NIST Cybersecurity Framework so organisations using both can trace coverage in either direction.
Govern
Cyber security leadership, risk management, supplier assurance, personnel suitability, AI accountability and continuous improvement. Sits at the board and executive level.
Identify
Asset, identity and dependency identification, business criticality, resilience requirements and threat-informed risk identification.
Protect
Identity and access management, secure configuration, network segmentation, data protection, cryptographic agility, OT isolation and supply chain security.
Detect
Centralised event logging, baselined access behaviour, anomalous event analysis and continuous evaluation of detection capability.
Respond
Incident planning, reporting, coordination across stakeholders, and prioritised post-incident improvements.
Recover
Business operations resumption, system recovery assurance, including inherited and shared security risks.
Classifications and applicability markings
ISM controls carry applicability markings that tell you which classifications they apply to. The right baseline depends on the most sensitive information your system is authorised to hold. Most Australian SMBs sit at NC or OS.
| Marking | Classification | What it covers |
|---|---|---|
| NC | Non-Classified | Government and non-government systems that do not handle classified information. The applicable baseline for most Australian businesses working with government. |
| OS | OFFICIAL: Sensitive | Information whose compromise would cause limited damage. Common for routine government and contractor work, including many DISP-aligned engagements. |
| P | PROTECTED | Information whose compromise would cause damage to the national interest. Standard for sensitive government systems and trusted Defence supply chain. |
| S | SECRET | Information whose compromise would cause serious damage. Restricted to security-cleared personnel and accredited environments. |
| TS | TOP SECRET | Information whose compromise would cause exceptionally grave damage. Highly restricted, ASD-assessed environments only. |
The six-step risk management process
The ISM draws its risk management approach from NIST SP 800-37 Rev. 2. It is a system lifecycle, not a one-off audit. You walk through it once when the system is built, and then continuously as the threat environment, controls and business context change.
The artefacts produced along the way (system security plan, system security plan annex, security assessment report, plan of action and milestones, continuous monitoring plan) are what auditors, IRAP assessors and prime contractors actually look at. The controls matter, but the documented decision making matters just as much.
What changed in the March 2026 update
The March 2026 release does not restructure the ISM, but it makes meaningful additions in governance, supply chain, identity, OT, cryptography, resilience and detection. These changes mirror what we are seeing in cyber insurance questionnaires and prime contractor security expectations.
Executive AI Accountability (GOV-08)
New governance principle. Boards and executives are accountable for ensuring AI is secure, controllable, human-supervised and used ethically.
Cyber Supply Chain Security (PRO-16)
Supply chain security promoted to a dedicated principle. Independent verification or risk assessment of supplier cyber practices is now expected.
Cryptographic Agility (PRO-17)
Systems must support orderly transitions between cryptographic algorithms, including preparation for post-quantum cryptography.
Identity, Credential and Access Management (PRO-13)
Replaces solid Access Control. Stronger emphasis on detecting misuse of identities and credentials, not just controlling them.
Secure Configuration Management (PRO-04)
Replaces Attack Surface Reduction. Configurations must be baselined, continually monitored and enforced.
Operational Technology controls (PRO-19, PRO-20)
New OT-specific principles for isolation and remote access. Aligns with SOCI Act obligations for designated critical infrastructure assets.
Resilience principles
Resilience Requirement Identification (IDE-06), Legacy System Management (GOV-14) and System Recovery Assurance (REC-02) shift the ISM toward operational resilience, not just prevention.
Detection capability efficacy (DET-04, DET-05)
Baselined high-risk access activity and continuous evaluation of detection capability. Pushes organisations toward behavioural detection and threat hunting.
ASD also publishes a separate "ISM March 2026 changes" document summarising every modified control and principle. Note that ASD has since released the June 2026 ISM, which builds on this structure; check the "ISM June 2026 changes" summary on cyber.gov.au alongside this section.
ISM vs Essential Eight vs SMB1001 vs ISO 27001
Australian businesses regularly get asked about all four. They are not interchangeable, and they sit at different levels of depth and audience. Here is how to think about them.
ISM (ASD ACSC)
thorough cyber security framework with hundreds of controls across six functions. Mandatory for non-corporate Commonwealth entities. The reference standard for IRAP assessments and DISP-aligned work.
Essential Eight (ASD ACSC)
A focused subset of eight mitigation strategies drawn from broader ISM thinking. Practical, prioritised and the usual starting point for Australian SMBs. ASD is evolving the Essential Eight into a new Essentials series over roughly two years, with the Essential Eight remaining current guidance throughout the transition.
SMB1001 (CyberCert)
Tiered certification (Bronze to Diamond) designed specifically for Australian small and mid-sized businesses. Maps cleanly to Essential Eight and ISO 27001 concepts.
ISO 27001
International information security management system standard. Process-heavy. Often required when working with multinational customers or for prime contractor flow-down.
Our pragmatic recommendation
For most Australian SMBs, SMB1001 (Gold and above) beats chasing the ISM
The ISM and the Essential Eight are excellent technical references. They are also written for government CISOs and large enterprise IT teams. For an Australian business of 20 to 250 staff, trying to align directly to the ISM, or even to chase Essential Eight Maturity Level 2 in isolation, is usually the wrong starting point. SMB1001, particularly at Gold, Platinum or Diamond tier, is almost always a better fit.
Why SMB1001 is usually the better choice
Designed for Australian SMBs
Built specifically for businesses under 200 staff. Controls, evidence requirements and language all reflect that reality, not government scale.
A real certificate, not a self-claim
SMB1001 is independently issued by CyberCert. Insurers, prime contractors and clients accept it as proof of cyber maturity. The Essential Eight has no certification body.
Tiered, achievable progression
Bronze through Diamond gives you a defined path. You move up as your business and risk grow, instead of failing a single binary audit.
Maps cleanly to E8 and ISO 27001
SMB1001 covers the same control families as Essential Eight and ISO 27001, so the work counts toward those standards if you ever need them later.
Lower cost and shorter timeline
Months and thousands of dollars, not years and tens of thousands. ISO 27001 and full ISM alignment are an order of magnitude more expensive.
Aligns with cyber insurance questions
The control areas in SMB1001 are exactly what Australian cyber insurers ask about: MFA, backup, EDR, training, admin separation, incident response.
Why Gold, Platinum and Diamond cover more ground than chasing the ISM or Essential Eight directly
Bronze through Gold are director-attested
You sign a self-declaration. Gold demands substantial real controls, but the lower tiers demonstrate intent more than capability, and evidence behind the attestation is what insurers and primes actually weigh.
Platinum and Diamond are independently audited
Third-party auditors verify the controls under the CyberCert scheme. That is the level that most moves the needle in procurement, insurance renewals and DISP-aligned questionnaires.
Gold reflects what good looks like in 2026
MFA everywhere, EDR, structured backup, admin separation, security awareness training, documented incident response. This is the Australian baseline now.
Platinum and Diamond cover ISM-style depth
They introduce governance, supplier assurance, monitoring and resilience controls that mirror the March 2026 ISM updates without the government-scale overhead.
Higher tiers age better
Cyber insurance, prime contractor and SOCI Act expectations keep ratcheting up. Starting at Gold or higher avoids re-doing the work in 12 months.
Closer to ISM and ISO 27001 evidence
The artefacts produced at Platinum and Diamond (policies, asset registers, IR plan, supplier register) are reusable if you ever do need to align to the ISM or pursue ISO 27001.
When you should still align to the ISM: if you are bidding for non-corporate Commonwealth contracts, joining DISP, operating SOCI Act critical infrastructure, or hosting government data. Outside those cases, SMB1001 at Gold or higher delivers more practical value for the cost.
What it means for Australian SMBs
The ISM is written for CISOs and government IT managers, not for a 60-person engineering firm in Brisbane. That does not mean it is irrelevant. It means you take a pragmatic, scoped approach.
You do not need to implement every ISM control
The ISM is risk-based. Controls are custom to your system classification, business criticality and operating environment. Most Australian SMBs sit at NC or OS level.
Start with Essential Eight, not the full ISM
The Essential Eight gives you the most defensible baseline for the lowest effort. ISM alignment becomes relevant when you bid for government work, DISP membership or IRAP-assessed engagements.
Document the system, not just the controls
A system security plan and a system security plan annex are core ISM artefacts. Insurers, auditors and prime contractors increasingly want to see them.
Treat governance as a workforce question
GOV-02, GOV-08, GOV-11 and GOV-12 all push security accountability up to the executive level. Pair this with the Australian Cyber Workforce Playbook when planning capacity.
Plan for cryptographic agility now
PRO-17 expects systems to be ready to transition algorithms, including for post-quantum. This is a multi-year roadmap item, not a one-off project.
Use Real Bytes as your MSP and MSSP
ISM alignment requires people, process and tooling across all six functions. Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name. We deliver against the ISM in the parts of the framework where most SMBs cannot resource it themselves.
How we map to the six ISM functions
| ISM function and example controls | How Real Bytes covers it |
|---|---|
| Govern (GOV-02, GOV-09, GOV-11, GOV-14) | Documented security leadership reporting, risk register, supplier assurance, legacy system management plan and continuous improvement cadence. |
| Identify (IDE-01, IDE-04, IDE-05, IDE-06) | Asset and identity inventory, system dependency mapping, threat-informed risk identification, resilience requirement workshops. |
| Protect (PRO-04, PRO-08, PRO-13, PRO-16, PRO-18) | Microsoft Entra ID and Conditional Access, Intune secure baselines, Defender for Endpoint and Office, network segmentation, supplier verification. |
| Detect (DET-01, DET-02, DET-04, DET-05) | Centralised logging, SOC monitoring, behavioural detection, baselined privileged and remote access, monthly detection capability review. |
| Respond (RES-01, RES-02, RES-05) | Documented incident response runbook, OAIC notifiable data breach support, coordinated response across business, insurer, legal and ASD if required. |
| Recover (REC-01, REC-02) | Backup design and testing, system recovery assurance, business operations resumption planning, post-incident improvement reviews. |
Managed IT & Cyber Security
Full MSP / MSSP managed service. Helpdesk, infrastructure and SOC under one roof.
Co-managed IT
Augment your internal team. Keep what works, fill the ISM functions you cannot resource.
Virtual CISO (vCISO)
Senior security leadership on retainer. Authorising officer support, board reporting, ISM gap analysis.
Not sure how much ISM alignment you actually need?
Most Australian SMBs do not need full ISM compliance. They need defensible Essential Eight maturity, a documented system security plan for their critical system, and supplier and identity controls that match the March 2026 changes. We can scope that with you in a single conversation.
Book an ISM scoping conversationA practical eight-step action plan
If you have been told to align to the ISM and are not sure where to start, this is the order we usually recommend.
Frequently asked questions
What is the Information Security Manual (ISM)?
The ISM is the Australian Signals Directorate cyber security framework for protecting information technology and operational technology systems. It defines six cyber security functions, hundreds of practical controls, and a six-step risk management process based on NIST SP 800-37. It is published and updated by ASD ACSC and is freely available on cyber.gov.au.
Is the ISM mandatory for Australian businesses?
Compliance with the ISM is not required by law unless legislation, a direction under legislation, or another lawful authority compels it. In practice, non-corporate Commonwealth entities must align to the ISM under the Protective Security Policy Framework (PSPF), and many state government and Defence supply chain contracts flow ISM expectations down to private suppliers.
How does the ISM relate to the Essential Eight?
The Essential Eight is a focused mitigation strategy set published by ASD ACSC. The ISM is the broader framework. The Essential Eight is the prioritised starting point for most Australian businesses, while the full ISM applies when you handle government information, work in DISP, or operate critical infrastructure under the SOCI Act. In June 2026, ASD confirmed it is evolving the Essential Eight into a new Essentials series over roughly two years, with the Essential Eight remaining current guidance throughout the transition. The ISM itself is unaffected by this change.
What are system classifications NC, OS, P, S and TS?
They are sensitivity markings that determine which ISM controls apply to a system. NC is non-classified, OS is OFFICIAL: Sensitive, P is PROTECTED, S is SECRET and TS is TOP SECRET. Each tier requires progressively stronger controls and, at higher classifications, ASD or IRAP assessment.
What is an IRAP assessment?
The Infosec Registered Assessors Program (IRAP) is an ASD initiative that authorises endorsed assessors to evaluate systems against ISM controls. IRAP assessments are commonly required for OFFICIAL: Sensitive, PROTECTED and SECRET systems used by Australian government agencies, and for cloud services seeking government uptake.
What changed in the March 2026 ISM update?
Key changes include a new Executive AI Accountability principle (GOV-08), Cyber Supply Chain Security promoted to its own principle (PRO-16), Cryptographic Agility (PRO-17) covering post-quantum readiness, replacement of solid Access Control with Identity, Credential and Access Management (PRO-13), and new operational technology principles (PRO-19, PRO-20). Resilience and detection capability themes were also strengthened.
Can Real Bytes help us align to the ISM?
Yes. We help Australian businesses align to the ISM where it is relevant, usually as part of broader Essential Eight uplift, DISP readiness, cyber insurance preparation or prime contractor questionnaires. We are an Australian MSP and MSSP, with engineers and analysts you deal with by name.
Sources and further reading
All references in this guide are drawn from publicly available Australian government and standards sources.
Need to align to the ISM without building a full security team?
Real Bytes is an Australian MSP and MSSP. We help businesses align to the ISM where it is relevant, usually alongside Essential Eight uplift, DISP readiness or prime contractor work.

Remote Support