ISM

Information Security Manual compliance

ISM-aligned control assessment, documentation, and implementation support for Australian organisations managing classified or sensitive information.

AGSVA Cleared Team Canberra-Based ISM-Experienced

ISM Control Assessment

Assessment Status

Information Security Governance Compliant ✓
Personnel Security Compliant ✓
Communications Security Gap Identified
System Hardening Compliant ✓
Access Control In Review

ISM Controls

Assessed

Gap Report

3

Items Ready

The challenge

Why ISM compliance matters

Hundreds of controls

The ISM contains hundreds of security controls across multiple domains. Determining which apply to your environment and how to evidence compliance is a significant task.

Constantly evolving

The ISM is updated regularly by ASD. Keeping pace with changes and understanding their impact on your compliance posture requires ongoing attention.

Mapping to other frameworks

You may already have controls in place for Essential Eight, PSPF, or DSPF. Understanding where ISM overlaps — and where it doesn't — avoids duplicated effort.

What you get

What's included in ISM Compliance

ISM control applicability assessment

We determine which ISM controls apply to your systems based on classification level, deployment model, and operational context.

Gap analysis and compliance report

Detailed assessment of your current control posture against applicable ISM requirements.

Control implementation guidance

Practical recommendations for implementing or remediating ISM controls in your specific environment.

Policy and documentation support

Security documentation aligned to ISM requirements, including system security plans and operating procedures.

Framework mapping

Clear mapping between ISM controls and your existing compliance obligations (E8, PSPF, DSPF) to identify overlap and reduce effort.

Right for you

Who should consider ISM compliance assessment

DISP-registered organisations

ISM compliance underpins your DISP cyber security requirements. We help you understand and evidence the specific ISM controls relevant to your membership level.

Government service providers

Your government clients expect ISM-aligned security. We help you demonstrate compliance and manage the ongoing control assessment cycle.

Deep-tech and defence technology

You're building systems or platforms for classified environments. ISM compliance is foundational to your security assurance.

Proof

Real engagements, real outcomes

Anonymised

Federal department

ML2 across a complex, multi-system estate.

Led the department's Essential Eight maturity review using ACSC verification methodology, then ran continuous-assurance activities through annual PSPF reporting and ASD cyber survey submissions — keeping E8 posture live between formal reviews.

Anonymised

Federal agency

3 Security Risk Assessments cleared in one review window.

Scoped, assessed, and reported on three high-priority SRAs in a single calendar year — an enterprise integration platform, a supplier-security uplift, and a public-facing online services portal with paired penetration testing — all delivered inside the agency's assessment window.

Anonymised

Federal agency

Board-ready cyber governance, stood up from scratch.

Delivered executive and board-ready cyber governance papers, stood up a Foreign Ownership Control and Influence process, and supported system accreditation activities across a shared-services environment — so the agency walked into its next review with defensible answers.

Common questions

Frequently asked questions

How does the ISM relate to Essential Eight?

The Essential Eight is a subset of ISM mitigation strategies prioritised by ASD for baseline cyber resilience. ISM compliance is broader, covering governance, personnel security, communications security, and more. Achieving E8 ML2 addresses a significant portion of your ISM cyber requirements.

Do we need to comply with every ISM control?

No. ISM control applicability depends on your system's classification level, deployment model, and operational context. We help you determine exactly which controls apply and focus your effort where it matters.

How often does the ISM change?

ASD updates the ISM regularly — typically multiple times per year. Our advisory services help you stay across changes and assess their impact on your compliance posture.

How long does ISM alignment take?

Most initial ISM gap assessments run 4-6 weeks. Remediation timelines depend on the gap size — we'll give you a costed roadmap so you can budget and sequence the work.

How do we budget for ISM work?

ISM engagements are scoped and priced per environment. Starting-from pricing is provided after an initial scoping conversation so you can plan the investment accurately.

How is this different from our MSP or a Big 4 consultancy?

MSPs implement controls; we assess them against the ISM and the specific evidence standards federal reviewers apply. We've delivered ISM alignment for federal agencies — not just read the document.

Get started

Need help with ISM compliance?

Talk to our team about your ISM requirements and compliance obligations.

Canberra-based • AGSVA cleared • ISM-experienced