What Information Security Manual (ISM) means in practice
The ISM is considerably broader than the Essential Eight, which is a subset of the mitigation strategies it draws on. It is structured as guidelines covering areas such as cyber security roles, system hardening, network design, cryptography, gateways, data transfers, and evaluated products, with individual controls tagged by applicability to classification levels.
The ISM applies directly to Australian Government entities, but its practical audience is much wider. Any organisation supplying services to Commonwealth or state government departments, or handling government data, will encounter ISM controls in contracts, security assessments and tender documentation. Defence supply chain participants encounter them alongside the Defence Industry Security Program.
Its approach is risk-based rather than checklist-based. Controls are selected and applied according to the classification of the information and the assessed risk, with a defined process for accepting residual risk where a control cannot be met. This is more flexible than a mandatory list, but it places the burden on the organisation to document the reasoning, which is what assessors examine.
For Microsoft environments, the practically important areas are identity and authentication requirements, event logging and retention, hardening of workstations and servers, cryptographic standards for data at rest and in transit, and restrictions on where data may be stored and processed. Microsoft publishes ISM guidance for its Australian cloud offerings, and the Australian regions carry IRAP assessments that reduce but do not remove the work an organisation must do on its own configuration.
The Protective Security Policy Framework sits above the ISM and covers the broader protective security obligations — governance, information, personnel and physical security — for Commonwealth entities. Organisations working in this space generally need to understand both, and how their own accountability differs from the entity they supply.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Notifiable Data Breaches (NDB) schemeThe Notifiable Data Breaches scheme, under the Privacy Act 1988, requires covered organisations to notify affected individuals and the Office of the Australian Information Commissioner about eligible data breaches — unauthorised access, disclosure or loss of personal information likely to result in serious harm — as soon as practicable..
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
