ASD Information Security Manual
The Australian Signals Directorate's comprehensive cyber security framework for protecting information technology and operational technology systems from cyber threats. The ISM provides more than 1,100 controls across system hardening, network security, access control, cryptography, gateways, and more -- ASD publishes a mapping between the Essential Eight and the ISM's controls.
See where NodeZero appliesWhat is the ASD ISM?
The Information Security Manual (ISM) is the Australian Signals Directorate's comprehensive cyber security framework, providing more than 1,100 controls for protecting information technology and operational technology systems from cyber threats. While the Essential Eight represents the eight most effective of ASD's Strategies to Mitigate Cyber Security Incidents, the ISM is ASD's full control framework -- covering system hardening, network security, access control, cryptography, gateway architecture, email security, web application security, database security, virtualisation, cloud computing, and much more.
The ISM is updated regularly (typically quarterly) to reflect evolving threats and technology changes. Each control carries a "must" or "should" requirement and an applicability marking keyed to the government classification scheme — from non-classified through OFFICIAL: Sensitive and PROTECTED to SECRET and TOP SECRET. Organisations pursuing IRAP (Infosec Registered Assessors Program) assessment are assessed against the ISM controls relevant to their system's classification level and risk profile -- IRAP assessors cover systems up to SECRET, with TOP SECRET assessments undertaken by ASD assessors. The ISM is the standard behind government system authorisation and cloud service assessment under the IRAP framework.
Where NodeZero applies
NodeZero tests the technical ISM chapters where autonomous penetration testing provides direct evidence: system hardening (operating system and application configuration), network security (segmentation, lateral movement, firewall rules), access control (credentials, MFA, privilege escalation), gateway security (boundary controls), software security (application vulnerabilities and patching), and cryptography (cipher strength and protocol configuration). For governance chapters, personnel security, physical security, media handling, and system-specific risk assessment documentation, we map what sits outside autonomous testing so your IRAP assessment or accreditation submission covers the full ISM scope.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following requires separate evidence: Governance, personnel, and physical security.
Showing coverage grouped by compliance category.
System hardening (Guidelines for system hardening)
Very strong coverage. NodeZero tests OS, application and server hardening effectiveness through proof-of-exploit attack chains and EDR-telemetry analysis.
Internal pentestingCore
Returns proof-of-exploit evidence on which unneeded services and functionality actually create attack paths — not a theoretical configuration review.
Endpoint Security EffectivenessCore
NodeZero attempts execution of known-bad payloads on workstations during attack chains; per-host block/allow telemetry across 40+ EDR vendors surfaces workstations where successful execution proves neither EDR nor application-control policy stopped them.
Network security (Guidelines for networking)
Strong coverage. NodeZero tests network segmentation, boundaries, lateral movement, server separation, and management-plane exposure.
Segmentation testingCore
Enumerates IPs, ports, services, and applications across zones to validate that the ISM-1181 segregation design actually holds.
Internal pentestingCore
Proves end-to-end attack paths that cross network boundaries — direct evidence of where ISM-1182 traffic restrictions break down.
Access control and authentication (Guidelines for system hardening / system management)
Very strong coverage. NodeZero tests credentials, MFA, AD configuration, privilege escalation paths, and account separation across the identity surface.
AD Password AuditCore
First AI to solve GOAD in 14 minutes (Horizon3-reported); it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit — attack-side evidence of which passwords are weak or crackable in practice, supporting rather than certifying the ISM-0421 length requirement.
Phishing Impact TestingCore
Feeds credentials captured by your phishing tool into a supporting internal pentest and proves what each one reaches — where a single captured credential reaches privileged systems, that is attack-impact evidence MFA was not enforced or was bypassable on those accounts.
BloodHound (integrated)Core
Built-in AD attack-graph visualisation — makes the over-privileged service accounts that ISM-1249 requires to be minimised visible and fixable.
Internal pentestingCore
Proves end-to-end paths from initial access through privilege escalation — surfaces where ISM-1380 separation between privileged and unprivileged environments has broken down.
Insider Threat TestingCore
Starts from a real user's perspective and proves what the account can actually reach — empirical evidence of where over-provisioning lets users exceed the minimum privileges ISM-1833 requires.
Gateway security (Guidelines for gateways)
Strong coverage. NodeZero attacks gateway boundaries from both internal and external positions to validate segregation, filtering and authentication effectiveness.
Segmentation testingCore
Validates filtering and inspection effectiveness at the gateways ISM-0628 requires — proves whether cross-domain exploit chains are actually contained.
Internal pentestingCore
Probes the gateway from each connected network and enumerates which protocols, ports and destinations are actually reachable — surfaces unexpected flows that the ISM-0631 explicit-allow rule should have blocked.
External pentestingCore
Attempts protocol-misuse attacks (HTTP smuggling, DNS tunnelling, encoded payloads) against the gateway — successful traversal is direct evidence the ISM-1192 transport-and-above inspection isn't catching the attack class.
Software security and patching (Guidelines for system management / software development)
Very strong coverage. NodeZero discovers assets, fingerprints software versions, exploits unpatched vulnerabilities, and provides Rapid Response evidence for critical CVEs — often within hours of disclosure, and in some cases ahead of the public patch.
Internal pentestingCore
Every NodeZero pentest begins with automated discovery — enumerating every reachable host, service, and application from the attacker perspective.
External pentestingCore
NodeZero's exploit catalogue is continuously updated by Horizon3.ai's attack team — its own testing delivers current attack-side evidence of what is actually exploitable, and it can ingest CVE scanner output to enrich the picture.
Rapid ResponsePro & Elite
Rapid Response runs the real exploit for a newly-disclosed critical CVE, often within hours of disclosure and in some cases ahead of the public patch — telling you whether an online service is exploitable inside the ISM-1876 window. It evidences exposure, not that the patch was applied on time.
Web application pentestingPriced separately
Continuous OWASP Top 10 coverage in pre-prod and production web applications — complements the SAST/DAST/SCA regime ISM-0402 requires.
Cryptography (Guidelines for cryptography)
Partial coverage. NodeZero tests for weak ciphers, deprecated protocols, and unencrypted communications on services it can reach.
External pentestingCore
Probes public-facing services for unencrypted channels, deprecated TLS, weak ciphers, and downgradeable protocols — the exact failures ISM-0469 requires to be eliminated.
Internal pentestingCore
Probes SSH services on reachable hosts for password-based authentication acceptance and weak credentials — surfaces services that still accept passwords against ISM-0485's public-key-only requirement.
Email and web security (Guidelines for email / gateways)
Strong coverage. NodeZero validates SPF/DKIM/DMARC posture, email-server transport, open-relay exposure and web-content-filter bypass.
External pentestingCore
External recon enumerates an organisation's domains and probes their DNS for SPF records — surfaces domains and subdomains that fall short of the authoritative-sender enumeration ISM-0574 requires.
Monitoring and incident response (Guidelines for system monitoring / cyber security incidents)
Limited coverage. NodeZero adds an active deception layer and produces verifiable test signals, but the SIEM and incident-response pipeline themselves sit outside autonomous testing.
NodeZero TripwiresPro & Elite
Honeytoken decoys (AWS credential files, MySQL dumps, Windows process monitors) on high-risk assets alert the moment an attacker interacts — adds an active indicator-of-compromise source of the kind ISM-0120 expects cyber security personnel to have available.
Internal pentestingCore
Every NodeZero action against critical servers is timestamped with proof-of-exploit detail — comparing the NodeZero attack timeline to SIEM detection telemetry surfaces gaps where the timely-analysis requirement isn't being met for that asset class.
Database security (Guidelines for database systems)
Strong coverage. NodeZero tests database network exposure, segregation, account-level access controls, and lateral-movement paths involving database hosts.
Internal pentestingCore
Internal pentests probe whether database services and web services share a host or trust boundary — surfaces functional collocations that ISM-1269 requires to be split.
Segmentation testingCore
Chains attack paths from user workstations to database hosts — direct evidence of whether the ISM-1270 network-segment separation actually contains lateral movement.
Insider Threat TestingCore
Starts from a real database user's perspective and proves the account's blast radius across the host and adjacent systems — empirical evidence whether work-duty restrictions hold at the application layer. Schema-aware row/view-level access auditing is complementary work.
See every control mapped to NodeZero
The full control-by-control coverage map — every ASD ISMrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
The ISM is not law on its own -- the Protective Security Policy Framework requires Australian Government entities to apply the ISM's principles and controls on a risk-based approach. Agencies select and apply ISM controls based on the system's classification (the ISM marks controls for non-classified, OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET systems), each control's must/should requirement, and the results of a system-specific risk assessment.
Beyond direct government use, the ISM applies to organisations assessed under the IRAP framework -- including cloud service providers whose services are IRAP-assessed for government use. Private sector organisations that provide ICT services to government are typically required to demonstrate ISM alignment as part of their contractual obligations.
If your organisation operates systems for the Australian Government, provides cloud or managed services to government agencies, or is undergoing IRAP assessment, the ISM is the standard you are assessed against. Even organisations not directly subject to the ISM often use it as a comprehensive security baseline that goes well beyond the Essential Eight.
Common questions
What is the ISM and who has to apply it?
The Information Security Manual (ISM) is the Australian Signals Directorate's cyber security framework for protecting information technology and operational technology systems from cyber threats — 1,101 controls in the June 2026 release. The ISM is not law on its own; the Protective Security Policy Framework requires Australian Government entities to apply its principles and controls on a risk-based approach, and cloud providers serving government undergo IRAP assessment against it.
cyber.gov.au — ISM overviewHow is the ISM different from the Essential Eight?
They are separate ASD publications with a published mapping between them. The Essential Eight is drawn from ASD's Strategies to Mitigate Cyber Security Incidents — the eight most effective strategies — while the ISM is ASD's full control framework, with more than 1,100 controls covering system hardening, networking, cryptography, gateways, email, database systems, access control and cloud services. ASD publishes a mapping from each Essential Eight maturity requirement to the ISM controls behind it.
cyber.gov.au — Essential Eight overviewHow does the ISM relate to IRAP assessments?
The ISM is the standard IRAP assessments are conducted against. Under the Infosec Registered Assessors Program, an independent assessor examines whether the ISM controls relevant to a system's classification and risk profile are implemented correctly and operating as intended. IRAP assessors cover systems up to SECRET; TOP SECRET assessments are undertaken by ASD assessors or their delegates. An IRAP assessment does not itself certify or accredit a system.
cyber.gov.au — IRAP overviewHow does NodeZero help with ISM compliance?
NodeZero is a continuous security validation platform that tests the technical areas of the ISM: system hardening, networking, gateway, email and database security, access control and authentication, software security and patching — with proof-of-exploit evidence for each finding. Governance, personnel security, physical security and media handling sit outside autonomous testing; we map those areas so your IRAP assessment or accreditation submission covers the full ISM scope.
cyber.gov.au — ISM cyber security guidelinesDoes NodeZero replace an IRAP assessment?
No. An IRAP assessment is an independent engagement by a registered human assessor, and NodeZero does not perform assessments or generate accreditation documentation. What it closes is the blind spot between engagements: the ISM is updated regularly — in practice a new release every quarter — so the control set you were assessed against six months ago may have changed. Regular NodeZero pentests produce attack-based evidence you can put in front of an assessor.
cyber.gov.au — IRAP overviewCan NodeZero cover the ISM's vulnerability scanning and patching controls?
Yes, on the verification side. Every NodeZero pentest begins with automated asset discovery, fingerprints operating system and software versions, and exploits unpatched vulnerabilities — the signal the ISM's daily, weekly and fortnightly vulnerability scanning controls require. For internet-facing systems and online services, where vendors assess a vulnerability as critical or working exploits exist, the ISM's patching window is 48 hours — and Rapid Response tests often arrive within hours of disclosure. Applying the patches remains your work.
cyber.gov.au — ISM guidelines for system managementClose the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.