Government Security

ISM Compliance Explained: A Practical Guide to the Information Security Manual

What ISM compliance really means, how the risk-based approach works, and the practical steps to apply the Australian Government Information Security Manual to your systems.

Muhammad Anwar
· 3 min read

ISM compliance is one of the most misunderstood obligations in Australian cybersecurity. Many organisations treat the Information Security Manual as a giant checklist to tick off. In practice, the ISM is a risk-based framework — and the organisations that get the most from it are the ones that use it to make better decisions, not just to produce evidence.

What the ISM actually is

The Australian Government Information Security Manual (ISM), published by the Australian Signals Directorate, sets out cybersecurity principles and controls to protect systems and data. It applies to Australian Government entities, and it is increasingly used as a benchmark by contractors, critical infrastructure operators and anyone handling government information.

The ISM is organised into:

  • Cybersecurity principles — the outcomes you are trying to achieve (govern, protect, detect, respond).
  • Guidelines — topic areas such as system management, network security, cryptography, personnel security and supply chain.
  • Controls — specific requirements, each tagged by applicability to classification levels.

It is updated regularly, so ISM compliance is never a “set and forget” exercise.

The risk-based approach — the part people skip

The ISM is designed to be applied through a risk management framework. In simple terms:

  1. Define the system — its purpose, boundary, data, users and classification.
  2. Select controls applicable to that system and its classification.
  3. Tailor — decide where controls are not applicable and document why, or where compensating controls are used.
  4. Implement and document controls in a System Security Plan.
  5. Assess the effectiveness of controls.
  6. Authorise the system to operate, accepting any residual risk.
  7. Monitor continuously and re-assess as the system or threats change.

The step most often done poorly is tailoring. Excluding a control without a documented, risk-based justification is one of the most common findings I see in assessments — and it’s one of the easiest to fix.

Where organisations go wrong

From assessments across government and the Defence supply chain, the same patterns appear again and again:

  • Spreadsheet compliance. Controls marked “implemented” with no evidence of effectiveness.
  • No defined system boundary. If you can’t say what’s in scope, you can’t say what’s protected — especially with cloud and SaaS services.
  • Documentation written after the build. A System Security Plan should shape design decisions, not describe them afterwards.
  • No named control owners. Controls without owners decay quietly until the next assessment.
  • Outdated control versions. Teams assess against an ISM release that’s two years old.

A practical path to ISM compliance

If you’re starting out, or your current program has stalled, this sequence works:

  1. Inventory your systems and agree classifications and boundaries.
  2. Pick one priority system rather than boiling the ocean.
  3. Run a gap assessment against the current ISM release for that system.
  4. Prioritise by risk, not by control count — fix what reduces the most risk first.
  5. Assign owners and set evidence expectations for each control.
  6. Write or refresh the SSP alongside the fixes.
  7. Repeat for the next system, reusing common controls.

ISM compliance isn’t the goal. A system that’s demonstrably secure — and a decision-maker who understands the residual risk — is the goal.

How the ISM connects to other frameworks

The ISM doesn’t sit alone. It supports the Protective Security Policy Framework (PSPF), it maps well to NIST SP 800-53, and it underpins IRAP assessments. Building one control set that satisfies several frameworks is far cheaper than running parallel compliance programs.

Frequently asked questions

Is ISM compliance mandatory?

The ISM is mandated for many Australian Government entities through the PSPF. For private organisations it is generally voluntary, but it’s often required contractually when handling government information or delivering services to government.

How often does the ISM change?

ASD updates the ISM regularly, typically several times a year. Each update can add, modify or remove controls, so programs need a process to review changes and assess their impact.

What’s the difference between the ISM and an IRAP assessment?

The ISM is the set of controls. An IRAP assessment is an independent assessment, by an ASD-endorsed assessor, of how well a system implements those controls.


Need an independent view of your ISM posture? Explore government assurance services or talk to my AI agent.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.