Mycelium 365 — Managed IT, Microsoft 365 and Azure across Australia, New Zealand and the United States
    Australian regulation

    Information Security Manual (ISM)

    The Information Security Manual is the Australian Signals Directorate's cyber security framework for government systems. It provides risk-based controls across governance, personnel, physical and technical security, applied according to the sensitivity of the information, and is referenced by Commonwealth entities and their suppliers.

    What Information Security Manual (ISM) means in practice

    The ISM is considerably broader than the Essential Eight, which is a subset of the mitigation strategies it draws on. It is structured as guidelines covering areas such as cyber security roles, system hardening, network design, cryptography, gateways, data transfers, and evaluated products, with individual controls tagged by applicability to classification levels.

    The ISM applies directly to Australian Government entities, but its practical audience is much wider. Any organisation supplying services to Commonwealth or state government departments, or handling government data, will encounter ISM controls in contracts, security assessments and tender documentation. Defence supply chain participants encounter them alongside the Defence Industry Security Program.

    Its approach is risk-based rather than checklist-based. Controls are selected and applied according to the classification of the information and the assessed risk, with a defined process for accepting residual risk where a control cannot be met. This is more flexible than a mandatory list, but it places the burden on the organisation to document the reasoning, which is what assessors examine.

    For Microsoft environments, the practically important areas are identity and authentication requirements, event logging and retention, hardening of workstations and servers, cryptographic standards for data at rest and in transit, and restrictions on where data may be stored and processed. Microsoft publishes ISM guidance for its Australian cloud offerings, and the Australian regions carry IRAP assessments that reduce but do not remove the work an organisation must do on its own configuration.

    The Protective Security Policy Framework sits above the ISM and covers the broader protective security obligations — governance, information, personnel and physical security — for Commonwealth entities. Organisations working in this space generally need to understand both, and how their own accountability differs from the entity they supply.

    How we help with this

    Related terms

    Back to the full glossary

    Ready to simplify and secure your technology?

    Book a free, no-obligation Discovery Call to talk through your Microsoft 365, Azure, security, or support needs — no sales pitch, just a straight conversation.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.