All Guides
ASD ACSC Framework

The Australian Information Security Manual (ISM): what it is and how to use it

The Information Security Manual is the ASD ACSC cyber security framework for Australian government and industry. Here is what it actually says, what changed in March 2026, and how Australian businesses should approach it without trying to implement every control on day one.

Last reviewed September 202616 min read

What the ISM is

The Information Security Manual (ISM) is published by the Australian Signals Directorate (ASD) through the Australian Cyber Security Centre (ACSC). Its purpose is to outline a cyber security framework that an organisation can apply, using their own risk management framework, to protect their information technology and operational technology systems from cyber threats.

It is structured around two layers. Cyber security principles provide strategic guidance grouped under six functions: Govern, Identify, Protect, Detect, Respond and Recover. Cyber security guidelines provide practical, control-level guidance an organisation applies to specific systems. The full document runs to several hundred pages and is updated regularly. The current version is June 2026.

The ISM is not a tick-list. It is risk-based. You scope the system, decide what controls are appropriate for that system, document the decision, implement, assess, authorise and monitor. Organisations are expected to be able to demonstrate they are adhering to the principles, not necessarily implement every control verbatim.

Read the official ISM on cyber.gov.au

Who it applies to

The ISM is intended for chief information security officers, chief information officers, cyber security professionals and IT managers. In practice, it directly affects three groups of Australian organisations.

Commonwealth and state entities

Non-corporate Commonwealth entities must align to the ISM under the Protective Security Policy Framework (PSPF). Most state agencies follow it as a baseline.

Defence and government suppliers

DISP members, Defence primes and their supply chain. ISM expectations are flowed down through contracts, particularly at OFFICIAL: Sensitive and PROTECTED levels.

Critical infrastructure

Designated assets under the Security of Critical Infrastructure Act 2018 are not formally bound to the ISM, but it is the practical reference for CIRMP-aligned controls.

The ISM is not legally mandatory unless legislation, a direction under legislation, or another lawful authority compels it. The Privacy Act 1988, the SOCI Act and the PSPF are the most common drivers that make ISM alignment expected in practice.

The six cyber security functions

The ISM organises its principles under six functions. They are deliberately aligned with the NIST Cybersecurity Framework so organisations using both can trace coverage in either direction.

Govern

Cyber security leadership, risk management, supplier assurance, personnel suitability, AI accountability and continuous improvement. Sits at the board and executive level.

Identify

Asset, identity and dependency identification, business criticality, resilience requirements and threat-informed risk identification.

Protect

Identity and access management, secure configuration, network segmentation, data protection, cryptographic agility, OT isolation and supply chain security.

Detect

Centralised event logging, baselined access behaviour, anomalous event analysis and continuous evaluation of detection capability.

Respond

Incident planning, reporting, coordination across stakeholders, and prioritised post-incident improvements.

Recover

Business operations resumption, system recovery assurance, including inherited and shared security risks.

Classifications and applicability markings

ISM controls carry applicability markings that tell you which classifications they apply to. The right baseline depends on the most sensitive information your system is authorised to hold. Most Australian SMBs sit at NC or OS.

MarkingClassificationWhat it covers
NCNon-ClassifiedGovernment and non-government systems that do not handle classified information. The applicable baseline for most Australian businesses working with government.
OSOFFICIAL: SensitiveInformation whose compromise would cause limited damage. Common for routine government and contractor work, including many DISP-aligned engagements.
PPROTECTEDInformation whose compromise would cause damage to the national interest. Standard for sensitive government systems and trusted Defence supply chain.
SSECRETInformation whose compromise would cause serious damage. Restricted to security-cleared personnel and accredited environments.
TSTOP SECRETInformation whose compromise would cause exceptionally grave damage. Highly restricted, ASD-assessed environments only.

The six-step risk management process

The ISM draws its risk management approach from NIST SP 800-37 Rev. 2. It is a system lifecycle, not a one-off audit. You walk through it once when the system is built, and then continuously as the threat environment, controls and business context change.

Define the system. Set the system boundary, business criticality and security and resilience objectives, and document them in a system security plan.
Select controls. Choose ISM controls and tailor them to your system, risks and operating environment. Document them in the system security plan annex.
Implement controls. Apply the controls in the system and its operating environment, and record any deviations from the planned implementation.
Assess controls. Verify controls are implemented correctly and operating as intended, via internal assessors or an IRAP assessor for higher classifications.
Authorise the system. The authorising officer reviews residual risk and decides whether to grant authorisation to operate.
Monitor the system. Continuously monitor controls, threats and risks, and feed insights back into governance, detection and improvement activities.

The artefacts produced along the way (system security plan, system security plan annex, security assessment report, plan of action and milestones, continuous monitoring plan) are what auditors, IRAP assessors and prime contractors actually look at. The controls matter, but the documented decision making matters just as much.

What changed in the March 2026 update

The March 2026 release does not restructure the ISM, but it makes meaningful additions in governance, supply chain, identity, OT, cryptography, resilience and detection. These changes mirror what we are seeing in cyber insurance questionnaires and prime contractor security expectations.

Executive AI Accountability (GOV-08)

New governance principle. Boards and executives are accountable for ensuring AI is secure, controllable, human-supervised and used ethically.

Cyber Supply Chain Security (PRO-16)

Supply chain security promoted to a dedicated principle. Independent verification or risk assessment of supplier cyber practices is now expected.

Cryptographic Agility (PRO-17)

Systems must support orderly transitions between cryptographic algorithms, including preparation for post-quantum cryptography.

Identity, Credential and Access Management (PRO-13)

Replaces solid Access Control. Stronger emphasis on detecting misuse of identities and credentials, not just controlling them.

Secure Configuration Management (PRO-04)

Replaces Attack Surface Reduction. Configurations must be baselined, continually monitored and enforced.

Operational Technology controls (PRO-19, PRO-20)

New OT-specific principles for isolation and remote access. Aligns with SOCI Act obligations for designated critical infrastructure assets.

Resilience principles

Resilience Requirement Identification (IDE-06), Legacy System Management (GOV-14) and System Recovery Assurance (REC-02) shift the ISM toward operational resilience, not just prevention.

Detection capability efficacy (DET-04, DET-05)

Baselined high-risk access activity and continuous evaluation of detection capability. Pushes organisations toward behavioural detection and threat hunting.

ASD also publishes a separate "ISM March 2026 changes" document summarising every modified control and principle. Note that ASD has since released the June 2026 ISM, which builds on this structure; check the "ISM June 2026 changes" summary on cyber.gov.au alongside this section.

ISM vs Essential Eight vs SMB1001 vs ISO 27001

Australian businesses regularly get asked about all four. They are not interchangeable, and they sit at different levels of depth and audience. Here is how to think about them.

ISM (ASD ACSC)

thorough cyber security framework with hundreds of controls across six functions. Mandatory for non-corporate Commonwealth entities. The reference standard for IRAP assessments and DISP-aligned work.

Essential Eight (ASD ACSC)

A focused subset of eight mitigation strategies drawn from broader ISM thinking. Practical, prioritised and the usual starting point for Australian SMBs. ASD is evolving the Essential Eight into a new Essentials series over roughly two years, with the Essential Eight remaining current guidance throughout the transition.

SMB1001 (CyberCert)

Tiered certification (Bronze to Diamond) designed specifically for Australian small and mid-sized businesses. Maps cleanly to Essential Eight and ISO 27001 concepts.

ISO 27001

International information security management system standard. Process-heavy. Often required when working with multinational customers or for prime contractor flow-down.

Our pragmatic recommendation

For most Australian SMBs, SMB1001 (Gold and above) beats chasing the ISM

The ISM and the Essential Eight are excellent technical references. They are also written for government CISOs and large enterprise IT teams. For an Australian business of 20 to 250 staff, trying to align directly to the ISM, or even to chase Essential Eight Maturity Level 2 in isolation, is usually the wrong starting point. SMB1001, particularly at Gold, Platinum or Diamond tier, is almost always a better fit.

Why SMB1001 is usually the better choice

Designed for Australian SMBs

Built specifically for businesses under 200 staff. Controls, evidence requirements and language all reflect that reality, not government scale.

A real certificate, not a self-claim

SMB1001 is independently issued by CyberCert. Insurers, prime contractors and clients accept it as proof of cyber maturity. The Essential Eight has no certification body.

Tiered, achievable progression

Bronze through Diamond gives you a defined path. You move up as your business and risk grow, instead of failing a single binary audit.

Maps cleanly to E8 and ISO 27001

SMB1001 covers the same control families as Essential Eight and ISO 27001, so the work counts toward those standards if you ever need them later.

Lower cost and shorter timeline

Months and thousands of dollars, not years and tens of thousands. ISO 27001 and full ISM alignment are an order of magnitude more expensive.

Aligns with cyber insurance questions

The control areas in SMB1001 are exactly what Australian cyber insurers ask about: MFA, backup, EDR, training, admin separation, incident response.

Why Gold, Platinum and Diamond cover more ground than chasing the ISM or Essential Eight directly

Bronze through Gold are director-attested

You sign a self-declaration. Gold demands substantial real controls, but the lower tiers demonstrate intent more than capability, and evidence behind the attestation is what insurers and primes actually weigh.

Platinum and Diamond are independently audited

Third-party auditors verify the controls under the CyberCert scheme. That is the level that most moves the needle in procurement, insurance renewals and DISP-aligned questionnaires.

Gold reflects what good looks like in 2026

MFA everywhere, EDR, structured backup, admin separation, security awareness training, documented incident response. This is the Australian baseline now.

Platinum and Diamond cover ISM-style depth

They introduce governance, supplier assurance, monitoring and resilience controls that mirror the March 2026 ISM updates without the government-scale overhead.

Higher tiers age better

Cyber insurance, prime contractor and SOCI Act expectations keep ratcheting up. Starting at Gold or higher avoids re-doing the work in 12 months.

Closer to ISM and ISO 27001 evidence

The artefacts produced at Platinum and Diamond (policies, asset registers, IR plan, supplier register) are reusable if you ever do need to align to the ISM or pursue ISO 27001.

When you should still align to the ISM: if you are bidding for non-corporate Commonwealth contracts, joining DISP, operating SOCI Act critical infrastructure, or hosting government data. Outside those cases, SMB1001 at Gold or higher delivers more practical value for the cost.

What it means for Australian SMBs

The ISM is written for CISOs and government IT managers, not for a 60-person engineering firm in Brisbane. That does not mean it is irrelevant. It means you take a pragmatic, scoped approach.

You do not need to implement every ISM control

The ISM is risk-based. Controls are custom to your system classification, business criticality and operating environment. Most Australian SMBs sit at NC or OS level.

Start with Essential Eight, not the full ISM

The Essential Eight gives you the most defensible baseline for the lowest effort. ISM alignment becomes relevant when you bid for government work, DISP membership or IRAP-assessed engagements.

Document the system, not just the controls

A system security plan and a system security plan annex are core ISM artefacts. Insurers, auditors and prime contractors increasingly want to see them.

Treat governance as a workforce question

GOV-02, GOV-08, GOV-11 and GOV-12 all push security accountability up to the executive level. Pair this with the Australian Cyber Workforce Playbook when planning capacity.

Plan for cryptographic agility now

PRO-17 expects systems to be ready to transition algorithms, including for post-quantum. This is a multi-year roadmap item, not a one-off project.

Use Real Bytes as your MSP and MSSP

ISM alignment requires people, process and tooling across all six functions. Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name. We deliver against the ISM in the parts of the framework where most SMBs cannot resource it themselves.

How we map to the six ISM functions

ISM function and example controlsHow Real Bytes covers it
Govern (GOV-02, GOV-09, GOV-11, GOV-14)Documented security leadership reporting, risk register, supplier assurance, legacy system management plan and continuous improvement cadence.
Identify (IDE-01, IDE-04, IDE-05, IDE-06)Asset and identity inventory, system dependency mapping, threat-informed risk identification, resilience requirement workshops.
Protect (PRO-04, PRO-08, PRO-13, PRO-16, PRO-18)Microsoft Entra ID and Conditional Access, Intune secure baselines, Defender for Endpoint and Office, network segmentation, supplier verification.
Detect (DET-01, DET-02, DET-04, DET-05)Centralised logging, SOC monitoring, behavioural detection, baselined privileged and remote access, monthly detection capability review.
Respond (RES-01, RES-02, RES-05)Documented incident response runbook, OAIC notifiable data breach support, coordinated response across business, insurer, legal and ASD if required.
Recover (REC-01, REC-02)Backup design and testing, system recovery assurance, business operations resumption planning, post-incident improvement reviews.

Not sure how much ISM alignment you actually need?

Most Australian SMBs do not need full ISM compliance. They need defensible Essential Eight maturity, a documented system security plan for their critical system, and supplier and identity controls that match the March 2026 changes. We can scope that with you in a single conversation.

Book an ISM scoping conversation

A practical eight-step action plan

If you have been told to align to the ISM and are not sure where to start, this is the order we usually recommend.

Read the Executive Summary of the current Information Security Manual (June 2026) and the Using the ISM companion document. Both are short and free.
Decide whether your business needs to align to the ISM at all. If you are not bidding for government, DISP or IRAP work, the Essential Eight Maturity Model is usually the better starting point.
If you do need ISM alignment, identify your highest-classification system (most often NC or OS) and document its boundary and business criticality.
Map your existing controls against the six functions: Govern, Identify, Protect, Detect, Respond, Recover. Be honest about gaps.
Prioritise the March 2026 changes that affect you: AI accountability (GOV-08), supply chain security (PRO-16), identity and credential management (PRO-13), and OT controls if you have any.
Document a system security plan and annex for at least your most critical system. This is the artefact insurers, auditors and primes will ask for.
Decide which ISM functions you will run in-house and which you will run through a co-managed MSP / MSSP arrangement.
Review annually against ASD ACSC ISM updates. Quarterly minor updates are common.

Frequently asked questions

What is the Information Security Manual (ISM)?

The ISM is the Australian Signals Directorate cyber security framework for protecting information technology and operational technology systems. It defines six cyber security functions, hundreds of practical controls, and a six-step risk management process based on NIST SP 800-37. It is published and updated by ASD ACSC and is freely available on cyber.gov.au.

Is the ISM mandatory for Australian businesses?

Compliance with the ISM is not required by law unless legislation, a direction under legislation, or another lawful authority compels it. In practice, non-corporate Commonwealth entities must align to the ISM under the Protective Security Policy Framework (PSPF), and many state government and Defence supply chain contracts flow ISM expectations down to private suppliers.

How does the ISM relate to the Essential Eight?

The Essential Eight is a focused mitigation strategy set published by ASD ACSC. The ISM is the broader framework. The Essential Eight is the prioritised starting point for most Australian businesses, while the full ISM applies when you handle government information, work in DISP, or operate critical infrastructure under the SOCI Act. In June 2026, ASD confirmed it is evolving the Essential Eight into a new Essentials series over roughly two years, with the Essential Eight remaining current guidance throughout the transition. The ISM itself is unaffected by this change.

What are system classifications NC, OS, P, S and TS?

They are sensitivity markings that determine which ISM controls apply to a system. NC is non-classified, OS is OFFICIAL: Sensitive, P is PROTECTED, S is SECRET and TS is TOP SECRET. Each tier requires progressively stronger controls and, at higher classifications, ASD or IRAP assessment.

What is an IRAP assessment?

The Infosec Registered Assessors Program (IRAP) is an ASD initiative that authorises endorsed assessors to evaluate systems against ISM controls. IRAP assessments are commonly required for OFFICIAL: Sensitive, PROTECTED and SECRET systems used by Australian government agencies, and for cloud services seeking government uptake.

What changed in the March 2026 ISM update?

Key changes include a new Executive AI Accountability principle (GOV-08), Cyber Supply Chain Security promoted to its own principle (PRO-16), Cryptographic Agility (PRO-17) covering post-quantum readiness, replacement of solid Access Control with Identity, Credential and Access Management (PRO-13), and new operational technology principles (PRO-19, PRO-20). Resilience and detection capability themes were also strengthened.

Can Real Bytes help us align to the ISM?

Yes. We help Australian businesses align to the ISM where it is relevant, usually as part of broader Essential Eight uplift, DISP readiness, cyber insurance preparation or prime contractor questionnaires. We are an Australian MSP and MSSP, with engineers and analysts you deal with by name.

Sources and further reading

All references in this guide are drawn from publicly available Australian government and standards sources.

Need to align to the ISM without building a full security team?

Real Bytes is an Australian MSP and MSSP. We help businesses align to the ISM where it is relevant, usually alongside Essential Eight uplift, DISP readiness or prime contractor work.