Information Security Manual (ISM)
ASD's control catalogue for Australian government systems — and the shared dialect for anyone who needs to speak the same language. Applicability, tailoring, and dated exceptions are the work.
The Information Security Manual is issued by the Australian Signals Directorate. It is the detailed control catalogue that Australian government entities use for system security, and that industry often borrows when a contract, IRAP assessment, or board paper needs the same vocabulary as Canberra.
Essential Eight is the floor of eight strategies. The ISM is the catalogue underneath and beside that floor: identity, cryptography, networking, system management, physical security, and the rest. You do not implement every control. You determine which controls apply to the system, tailor them to the environment, and record exceptions with an owner, a residual risk, and a review date.
Applicability is a decision, not a feeling. For each system boundary, name the ISM controls in scope, the ones out of scope (and why), and the compensating controls where you deviate. That record is what IRAP assessors, internal audit, and your future self will ask for when something breaks.
The ISM is updated. A printed or PDF copy from years ago is an artefact, not a program. Subscribe to ASD/ACSC release notes, re-check applicability when a major ISM revision lands, and keep Essential Eight maturity evidence aligned to the same system boundaries you used for ISM tailoring.
Pair the ISM with Essential Eight for the commodity-intrusion floor, with your risk process for residual risk, and with SOCI / PSPF / IRAP obligations where those regimes apply. The glossary entry is a definition; this page is the practitioner habit: apply, tailor, evidence, refresh.
See also:
Fact source: ASD's ACSC — Information Security Manual (ISM).
