If the Essential Eight is the headline, the Information Security Manual is the book. Published by the Australian Signals Directorate, the ISM is a comprehensive cyber security control catalogue — hundreds of controls across governance, personnel, physical, communications, system hardening, cryptography and more.
Most Australian organisations meet the Essential Eight and never open the ISM. Entities handling classified or otherwise sensitive government information do not have that option.
How the ISM is organised
The ISM is built around four cyber security principles:
- Govern — identifying and managing security risks.
- Protect — implementing controls to reduce security risks.
- Detect — identifying and understanding cyber security events and incidents.
- Respond — responding to and recovering from incidents.
Beneath the principles sit guidelines by subject area, and within those, individual controls. Each control carries an identifier and an applicability marking indicating which classification levels it applies to — commonly OFFICIAL and OFFICIAL: Sensitive, PROTECTED, SECRET and TOP SECRET.
That applicability marking is the ISM's central mechanism. You do not implement every control; you implement the controls applicable to the classification of the information your system handles.
It changes quarterly
Unlike ISO standards on multi-year revision cycles, the ISM is updated on a quarterly cadence. Controls are added, amended and withdrawn regularly.
Plan for this. A control baseline captured once and treated as stable will drift out of alignment within a year, and the drift is invisible unless someone owns tracking the release notes.
The System Security Plan
The ISM is applied through documentation, and the central artefact is the System Security Plan — describing a system, its classification, the controls applicable to it, how each is implemented, and any that are not, with the risk accepted and by whom.
Supporting artefacts typically include an incident response plan, a continuous monitoring plan, and a security risk management plan. Where formal authorisation applies, these feed an authority to operate decision.
Manage ISM and Essential Eight from one control set
GRC Copilot maps evidence across frameworks, so controls you evidence once satisfy multiple obligations rather than being collected separately for each.
Try GRC Copilot free Generate an AI-powered assessment Download checklist Book a demo
How the ISM relates to the Essential Eight
The Essential Eight is a prioritised subset of the ISM's mitigation strategies, drawn from the broader Strategies to Mitigate Cyber Security Incidents. The relationship is straightforward:
- The Essential Eight is what you implement first, because those eight deliver the most risk reduction for the effort.
- The ISM is what applies when the information you handle requires the full catalogue.
Meeting the Essential Eight does not make you ISM compliant — it covers a fraction of the catalogue. But every Essential Eight control has ISM equivalents, so the work is cumulative rather than duplicated.
Who actually needs the ISM
- Australian government entities operating systems that handle official or classified information.
- Contractors and service providers whose systems process, store or communicate government information — the obligation flows down through contract.
- Cloud providers seeking to serve government workloads, where ISM alignment is a practical precondition.
- Defence industry participants, often alongside sector-specific requirements.
If none of these describe you, the Essential Eight is almost certainly where your effort belongs.
Practical advice for first-time ISM work
- Establish classification first. Everything downstream — which controls apply, how much rigour, what the plan must say — follows from the classification of the information. Getting this wrong wastes the entire effort.
- Scope to a system, not the organisation. The ISM is applied per system. Trying to apply it enterprise-wide at once produces a document nobody can maintain.
- Do the Essential Eight first anyway. Those controls are in the catalogue, they are high value, and they are the ones most likely to be tested.
- Own the quarterly update. Assign someone to read the release notes and assess the delta. Without this, your baseline silently ages.
- Write the non-implementations down. A control not implemented, with a documented risk acceptance and a named approver, is a defensible position. Silence is not.
Frequently asked questions
Is the ISM mandatory?
It applies to Australian government entities through the broader protective security policy framework, and reaches suppliers through contract. It is not a general legal requirement for private organisations with no government exposure.
How many controls are in the ISM?
Several hundred, but the number applicable to any given system is much smaller because applicability is filtered by classification. Counting the whole catalogue overstates the work considerably.
Can we be certified against the ISM?
Not in the ISO sense. Systems are assessed and, where relevant, authorised to operate. The output is an authorisation decision for a system rather than an organisational certificate.
Does ISO 27001 help with the ISM?
Yes, for the management system layer — risk assessment, governance, review and improvement all transfer. The ISM control detail and the classification-driven applicability are additional, and the System Security Plan has no ISO equivalent.
Key takeaways
- The ISM is the full catalogue; the Essential Eight is its highest-value subset.
- Control applicability is driven by information classification, so classify first.
- The ISM updates quarterly — assign ownership of the delta or your baseline ages silently.
- The System Security Plan is the central artefact, and documented non-implementation beats silence.