ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Framework · ISM

The Information Security Manual, explained.

The ISM is the control catalogue behind Australian government security. ASD releases it every quarter, the current release is September 2026, and it is applied through a risk management framework rather than as a checklist. Nobody certifies against it; a system is assessed and then authorised by a named officer. This page covers how it is built, who it binds, and what changed this year, including the first rules for AI agents.

What changed in 2026IRAP assessments

How it is built

Principles, guidelines, controls.

Three layers. The principles say what a secure organisation looks like. The guidelines say how to get there for each kind of system. The controls are the numbered, testable statements an assessor checks.

Layer 1

49 principles in six functions

GOV 14IDE 6PRO 17DET 5RES 5REC 249PRINCIPLES

Govern, identify, protect, detect, respond and recover. Each principle has an ID like GOV-08, which makes the board accountable for AI being secure, controllable and human-supervised, or PRO-17, which requires cryptographic agility for the post-quantum move.

Layer 2

23 guidelines, one per topic

  • Cyber security roles
  • Cyber security incidents
  • Procurement and outsourcing
  • Security documentation
  • Physical security
  • Personnel security
  • Communications infrastructure
  • Communications systems
  • Enterprise mobility
  • Evaluated products
  • Information technology equipment
  • Media
  • System hardening
  • System management
  • System access
  • Software development
  • Database systems
  • Email
  • Networking
  • Cryptography
  • Gateways
  • Data transfers
  • Security assurance

You read the guidelines that apply to the systems you run. A team with no gateway skips the gateway guideline; a team building software reads the software development one closely.

Layer 3

Controls numbered ISM-xxxx

ISM-2133New · Sep 2026

One of 44 controls added in September 2026. AI agents get an identity distinct from the accounts of the people who run them.

Revision 0 · September 2026

Every control carries an identifier that never changes, a revision number, and applicability markings that say which classifications it applies to. A control can be rescinded; ISM-0521 on disabling IPv6 went in September 2026.

Counts are from the live ISM pages on cyber.gov.au and the September 2026 changes document, read 12 September 2026. The ISM is also published as OSCAL on ASD's GitHub, release v2026.09.4.

Who it binds

Nobody has to comply with the ISM until something makes them.

The ISM is advice from ASD under the Intelligence Services Act. It becomes an obligation through the PSPF, a contract, a state policy or a direction. Which of those reaches you decides how much of it you have to evidence.

Non-corporate Commonwealth entities

The Protective Security Policy Framework. Policy 10 requires the Essential Eight to Maturity Level Two, and the PSPF's Table 21 requires cloud, outsourced ICT and gateway systems up to SECRET to be assessed by IRAP assessors against the ISM.

Suppliers to government

Contracts. A vendor hosting or processing government data inherits the ISM through its customer's authorisation, and is asked for an IRAP assessment against the controls for the classification it handles.

State and territory agencies

Their own policies, which reference ASD's frameworks. The NSW Cyber Security Policy 2026-2027 embeds Essential Eight ML1 controls in its mandatory requirements; Queensland's IS18 and Victoria's VPDSS reference the Essential Eight.

Everyone else

Nobody. ASD's own words: an organisation is not required as a matter of law to comply with the ISM unless legislation or a lawful direction compels it. Private organisations adopt it because it is free, current, and mapped to the Essential Eight they are already asked for.

Applicability markings

Five markings decide which controls apply to a system.

Each control carries one or more markings. You select the controls marked for your system's classification, tailor them, and document the result in the system security plan annex. Most controls apply at every level; the ones that do not are the reason a PROTECTED assessment is a different job from a non-classified one.

The markings changed in December 2024, when ASD introduced NC and dropped the old ALL baseline. Older guidance that talks about “OFFICIAL” controls is describing what is now NC.

NC

Non-classified

Government and non-government systems that hold nothing classified. OFFICIAL sits here; there is no separate OFFICIAL marking.

OS

OFFICIAL: Sensitive

Systems handling information whose compromise could cause limited harm.

P

PROTECTED

The level most vendors to government are assessed at. The Hosting Certification Framework applies from here.

S

SECRET

The highest level IRAP assessors can assess. The CISO remains the authorising officer.

TS

TOP SECRET

Assessed by ASD assessors or their delegates; authorised by the Director-General ASD.

Risk management framework

Six steps, one authorising officer, no certificate.

The ISM's framework draws on NIST SP 800-37. It ends in a decision, made by the CISO or their delegate for everything up to SECRET, to accept the residual risk and authorise the system to operate, with or without constraints, for a period. Each step produces a document, and together those documents are what an assessor asks to see.

  1. Monitoring loops back to reassessment

Step 02

Select controls

Controls chosen and tailored by marking, inherited controls identified, and the selection approved by the authorising officer.

Produces

SSP annex

Alvor generates the system security plan from the record

Authorising officer · NC to SECRET

The organisation's CISO, or their delegate

Authorising officer · TOP SECRET

Director-General ASD, or their delegate

Authorising officer · Commercial providers

The CISO of the organisation being served

2025 to 2026

The ISM now has rules for AI agents.

Seven quarterly releases in a row have moved the manual toward architecture and AI. The September 2026 release is the biggest of them: 44 new controls, and the first that treat an AI agent as a principal with its own identity, register entry and approval gate.

  1. Dec 2024

    NC marking introduced; the old ALL baseline replaced by a non-classified baseline.

  2. Jun 2025

    Govern and Identify principles rewritten around Secure by Design.

  3. Sep 2025

    Recover added as a sixth function; AI controls strengthened.

  4. Dec 2025

    AI usage policy requirements added. Fax machine guidance removed.

  5. Mar 2026

    Principles reorganised across Govern, Identify and Protect; legacy system and exposure minimisation principles added.

  6. Jun 2026

    AI application hardening guidance; the data protection principle renamed cryptographic protection.

  7. Sep 2026 · current

    44 new controls, ISM-2124 to ISM-2167, most of them about AI agents, workload identity and service-provider access.

Control record

ISM-2133

Not assessed

Framework

ISM (September 2026)

Introduced

September 2026 release

Revision

0

Subject

AI agent identity

Owner

Unassigned

Evidence

None attached

The September 2026 AI-agent set

  • ISM-2133Each AI agent has an identity distinct from the accounts of personnel
  • ISM-2134, 2135An AI agent register
  • ISM-2113Human approval before sensitive or high-impact actions
  • ISM-2137 to 2140OAuth consent and device-code controls
  • ISM-2141 to 2148Short-lived workload credentials
  • ISM-2124, 2125Service-provider access logging

Control IDs from ASD's ISM September 2026 changes document. Control text is ASD's and is not reproduced here.

ISM and the Essential Eight

The Essential Eight is a slice of the ISM.

ASD publishes a mapping between the Essential Eight maturity model and the ISM (October 2024), so each maturity-level requirement points at the ISM controls that implement it. A team that runs Maturity Level Two is already evidencing part of the ISM, and the same evidence serves both.

The successor to the Essential Eight, the Essentials series, is described by ASD as grounded in the ISM. That is the direction of travel: the manual is the catalogue, and the Essential Eight and its successor are prioritised views of it.

The Essential EightThe maturity modelThe Essentials series

In Alvor

Run your ISM program in Alvor.

Any framework you are held to can live in Alvor. This is what that looks like for an ISM program: the controls, the documents the framework produces, the evidence, and where it all runs.

Add the ISM as a framework, in ASD's own structure

You can add any framework in Alvor. For the ISM that means the 23 guidelines as domains and every control with its ISM identifier and markings, built in the framework builder in ASD's structure. From there it works like every other framework in the platform: owners, evidence, assessments, crosswalks and reporting.

Compliance

The SSP and its annex, generated from the record

The ISM's framework produces a system security plan and a control annex, and both are read by whoever assesses and authorises the system. Alvor generates them from the controls, assets and risks already on file, so the document is a view of the record rather than a separate project.

System security plan

Evidence attached once, read by three frameworks

The Essential Eight at every level and ISO 27001:2022 ship in the library. A crosswalk maps controls between installed frameworks, so the evidence behind an ISM control is the evidence behind its Essential Eight and ISO 27001 counterparts. Status never propagates across a crosswalk; each framework is assessed on its own wording.

Compliance

A Sydney instance, or inside your own network

Each customer runs on a dedicated single-tenant instance in the region they choose, including ap-southeast-2. For data that cannot leave, the same platform runs on your own servers or air-gapped. AI is bring-your-own-model, including self-hosted models.

Deployment models
SSP as a Service for the authorisation packageAlvor for Australian organisationsThe ISM on cyber.gov.au

Questions

Common questions about the ISM

Applying the ISM through its risk management framework and getting the system authorised by its authorising officer. There is no ISM certificate. A system is defined, its controls are selected by classification and documented in the system security plan annex, implemented, assessed by your own assessors or IRAP assessors, and then authorised to operate by the CISO or their delegate on the basis of the residual risk.

Get started

See how Alvor works for your role

Whether you lead security, run IT, manage compliance, or sit in the C-suite - we'll show you your view.

Request DemoView Pricing
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyDisclosure