Framework · ISM
The ISM is the control catalogue behind Australian government security. ASD releases it every quarter, the current release is September 2026, and it is applied through a risk management framework rather than as a checklist. Nobody certifies against it; a system is assessed and then authorised by a named officer. This page covers how it is built, who it binds, and what changed this year, including the first rules for AI agents.
How it is built
Three layers. The principles say what a secure organisation looks like. The guidelines say how to get there for each kind of system. The controls are the numbered, testable statements an assessor checks.
Layer 1
49 principles in six functions
Govern, identify, protect, detect, respond and recover. Each principle has an ID like GOV-08, which makes the board accountable for AI being secure, controllable and human-supervised, or PRO-17, which requires cryptographic agility for the post-quantum move.
Layer 2
23 guidelines, one per topic
You read the guidelines that apply to the systems you run. A team with no gateway skips the gateway guideline; a team building software reads the software development one closely.
Layer 3
Controls numbered ISM-xxxx
One of 44 controls added in September 2026. AI agents get an identity distinct from the accounts of the people who run them.
Revision 0 · September 2026
Every control carries an identifier that never changes, a revision number, and applicability markings that say which classifications it applies to. A control can be rescinded; ISM-0521 on disabling IPv6 went in September 2026.
Counts are from the live ISM pages on cyber.gov.au and the September 2026 changes document, read 12 September 2026. The ISM is also published as OSCAL on ASD's GitHub, release v2026.09.4.
Who it binds
The ISM is advice from ASD under the Intelligence Services Act. It becomes an obligation through the PSPF, a contract, a state policy or a direction. Which of those reaches you decides how much of it you have to evidence.
Non-corporate Commonwealth entities
The Protective Security Policy Framework. Policy 10 requires the Essential Eight to Maturity Level Two, and the PSPF's Table 21 requires cloud, outsourced ICT and gateway systems up to SECRET to be assessed by IRAP assessors against the ISM.
Suppliers to government
Contracts. A vendor hosting or processing government data inherits the ISM through its customer's authorisation, and is asked for an IRAP assessment against the controls for the classification it handles.
State and territory agencies
Their own policies, which reference ASD's frameworks. The NSW Cyber Security Policy 2026-2027 embeds Essential Eight ML1 controls in its mandatory requirements; Queensland's IS18 and Victoria's VPDSS reference the Essential Eight.
Everyone else
Nobody. ASD's own words: an organisation is not required as a matter of law to comply with the ISM unless legislation or a lawful direction compels it. Private organisations adopt it because it is free, current, and mapped to the Essential Eight they are already asked for.
Applicability markings
Each control carries one or more markings. You select the controls marked for your system's classification, tailor them, and document the result in the system security plan annex. Most controls apply at every level; the ones that do not are the reason a PROTECTED assessment is a different job from a non-classified one.
The markings changed in December 2024, when ASD introduced NC and dropped the old ALL baseline. Older guidance that talks about “OFFICIAL” controls is describing what is now NC.
Non-classified
Government and non-government systems that hold nothing classified. OFFICIAL sits here; there is no separate OFFICIAL marking.
OFFICIAL: Sensitive
Systems handling information whose compromise could cause limited harm.
PROTECTED
The level most vendors to government are assessed at. The Hosting Certification Framework applies from here.
SECRET
The highest level IRAP assessors can assess. The CISO remains the authorising officer.
TOP SECRET
Assessed by ASD assessors or their delegates; authorised by the Director-General ASD.
Risk management framework
The ISM's framework draws on NIST SP 800-37. It ends in a decision, made by the CISO or their delegate for everything up to SECRET, to accept the residual risk and authorise the system to operate, with or without constraints, for a period. Each step produces a document, and together those documents are what an assessor asks to see.
Step 02
Select controls
Controls chosen and tailored by marking, inherited controls identified, and the selection approved by the authorising officer.
Produces
SSP annex
Authorising officer · NC to SECRET
The organisation's CISO, or their delegate
Authorising officer · TOP SECRET
Director-General ASD, or their delegate
Authorising officer · Commercial providers
The CISO of the organisation being served
2025 to 2026
Seven quarterly releases in a row have moved the manual toward architecture and AI. The September 2026 release is the biggest of them: 44 new controls, and the first that treat an AI agent as a principal with its own identity, register entry and approval gate.
Dec 2024
NC marking introduced; the old ALL baseline replaced by a non-classified baseline.
Jun 2025
Govern and Identify principles rewritten around Secure by Design.
Sep 2025
Recover added as a sixth function; AI controls strengthened.
Dec 2025
AI usage policy requirements added. Fax machine guidance removed.
Mar 2026
Principles reorganised across Govern, Identify and Protect; legacy system and exposure minimisation principles added.
Jun 2026
AI application hardening guidance; the data protection principle renamed cryptographic protection.
Sep 2026 · current
44 new controls, ISM-2124 to ISM-2167, most of them about AI agents, workload identity and service-provider access.
Control record
ISM-2133
Framework
ISM (September 2026)
Introduced
September 2026 release
Revision
0
Subject
AI agent identity
Owner
Unassigned
Evidence
None attached
The September 2026 AI-agent set
Control IDs from ASD's ISM September 2026 changes document. Control text is ASD's and is not reproduced here.
ISM and the Essential Eight
ASD publishes a mapping between the Essential Eight maturity model and the ISM (October 2024), so each maturity-level requirement points at the ISM controls that implement it. A team that runs Maturity Level Two is already evidencing part of the ISM, and the same evidence serves both.
The successor to the Essential Eight, the Essentials series, is described by ASD as grounded in the ISM. That is the direction of travel: the manual is the catalogue, and the Essential Eight and its successor are prioritised views of it.
In Alvor
Any framework you are held to can live in Alvor. This is what that looks like for an ISM program: the controls, the documents the framework produces, the evidence, and where it all runs.
Add the ISM as a framework, in ASD's own structure
You can add any framework in Alvor. For the ISM that means the 23 guidelines as domains and every control with its ISM identifier and markings, built in the framework builder in ASD's structure. From there it works like every other framework in the platform: owners, evidence, assessments, crosswalks and reporting.
ComplianceThe SSP and its annex, generated from the record
The ISM's framework produces a system security plan and a control annex, and both are read by whoever assesses and authorises the system. Alvor generates them from the controls, assets and risks already on file, so the document is a view of the record rather than a separate project.
System security planEvidence attached once, read by three frameworks
The Essential Eight at every level and ISO 27001:2022 ship in the library. A crosswalk maps controls between installed frameworks, so the evidence behind an ISM control is the evidence behind its Essential Eight and ISO 27001 counterparts. Status never propagates across a crosswalk; each framework is assessed on its own wording.
ComplianceA Sydney instance, or inside your own network
Each customer runs on a dedicated single-tenant instance in the region they choose, including ap-southeast-2. For data that cannot leave, the same platform runs on your own servers or air-gapped. AI is bring-your-own-model, including self-hosted models.
Deployment modelsQuestions
Applying the ISM through its risk management framework and getting the system authorised by its authorising officer. There is no ISM certificate. A system is defined, its controls are selected by classification and documented in the system security plan annex, implemented, assessed by your own assessors or IRAP assessors, and then authorised to operate by the CISO or their delegate on the basis of the residual risk.
Get started
Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.