Blog

23 ISM Cybersecurity Guidelines Explained | StickmanCyber

Written by Ajay Unni | Sep 18, 2026, 12:52:27 PM

The Information Security Manual's cybersecurity guidelines are created to provide practical guidance on how organizations can go about safeguarding their systems and data from cyber attacks. These cyber security guidelines cover governance, physical security, personnel security, and information and communications technology security matters. Organisations should consider the cyber security guidelines that are relevant to each of the systems that they operate.

As of September 2026, the ISM contains 23 cyber security guideline chapters, outlined below.

The ISM Cyber Security Guidelines

Guidelines for Cybersecurity roles

An organisation contains a number of key cyber security roles, including the board of directors or executive committee, a Chief Information Security Officer and system owners. This section of the ISM guidelines provides an outline on the purpose and responsibilities of these cyber security roles.

Guidelines for Cybersecurity incidents

Cybersecurity incidents are unwanted or unexpected cyber security events, or a series of such events, that have compromised business operations or have a significant probability of doing so. This section of the ISM guidelines provides an outline on how to detect, manage and report cyber security incidents.

Guidelines for Procurement and Outsourcing

Outsourcing can be a cost-effective option for providing information technology and cloud services. However, third-party risks can be introduced as a consequence and should be appropriately managed. This section of the ISM guidelines provides an outline on cyber supply chain risk management, as well as selecting, managing, using and reviewing managed services and cloud services.

Guidelines for Cyber Security Documentation

Security documentation can be used to define an organisation's cyber security strategy and how to protect their systems. This section of the ISM guidelines outlines how to develop and maintain security documentation, as well as explaining security documentation that an organisation can use to support security assessment and assurance activities.

Guidelines for Physical Security

Protecting physical assets is an important part of ensuring an organisation’s cyber security. This section of the ISM guidelines, outlines physical security measures for facilities and systems, IT equipment and media.

Guidelines for Personnel Security

Personnel security is an important part of ensuring an organisation’s cyber security. This section of the ISM Guidelines, outlines how to conduct cyber security awareness training.

Guidelines for Communications Infrastructure

Communications infrastructure refers to a cable management system, including cables, cable reticulation systems and wall outlet boxes. This section of the ISM Guidelines, outlines cable management, cable labelling and registration, cable patching, and emanation security.

Guidelines for Communications Systems

Communications systems include telephone systems, video conferencing and Internet Protocol telephony, and fax machines and multifunction devices. This section of the ISM guidelines, outlines how to harden these communication systems.

Guidelines for Enterprise mobility

Enterprise mobility refers to the usage of mobile devices within an organisation. This section of the ISM guidelines, outlines the management and use of mobile devices.

Guidelines for Evaluated Products

The Australian Signals Directorate performs product evaluations in order to provide a level of assurance in a product’s security functionality. This section of the ISM Guidelines, outlines how to acquire and use an evaluated product.

Guidelines for Information Technology Equipment

IT equipment is capable of processing, storing or communicating large volumes of data. This section of the ISM Guidelines, outlines the management, maintenance, repair, sanitisation, destruction and disposal for IT equipment.

Guidelines for Media

Media is capable of storing large volumes of information and should be managed appropriately. This section of the ISM guidelines, outlines the usage, sanitisation, destruction and disposal of media.

Guidelines for System Hardening

System hardening is the process of securing systems in order to reduce their attack surface. Different tools and techniques can be used to perform system hardening. This section of the ISM guidelines outlines system hardening processes for operating systems, applications and virtualisation.

Guidelines for System Access

This section of the ISM guidelines covers identity and access management and credential management, including controlling access to systems and their resources.

Guidelines for System Management

System management activities ensure not only the operation of systems but also their security. This section of the ISM guidelines, outlines system management activities that are integral to ensuring system security, such as system administration, system patching, change management, and data backup and restoration.

Guidelines for Security Assurance

System monitoring is able to contribute to the security posture of a system, detect potential cyber security incidents and contribute to investigations following cyber security incidents. This section of the ISM guidelines outlines security monitoring, event logging and security assessments.

Guidelines for Software Development

Secure coding practices should be embedded into an organisation’s software development process. This section of the ISM guidelines, outlines securing the development of traditional, artificial intelligence, mobile and web applications.

Guidelines for Database Systems

Databases can contain large volumes of information and should be secured appropriately. This section of the ISM guidelines, outlines how database servers, database management system software and databases can be hardened.

Guidelines for Email

Emails are a common vehicle for delivering malicious code, for example, malware is often delivered via phishing emails. This section of the ISM guidelines, outlines secure email usage and how to secure email gateways and servers.

Guidelines for Networking

A secure network design is an important part of ensuring an organisation’s overall security posture. This section of the ISM guidelines, outlines the design and configuration of networks, and provides specific guidance on wireless network security and how to ensure service continuity for online services.

Guidelines for Cryptography

The purpose of cryptography is to provide confidentiality, integrity, authentication and non-repudiation of information. Encryption of data at rest can be used to protect sensitive or classified data stored on IT equipment and media while encryption of data in transit can be used to provide protection for information communicated over public network infrastructure. Encryption does not lower the sensitivity or classification of the data. This section of the ISM guidelines, outlines cryptographic fundamentals; cryptographic algorithms; cryptographic protocols such as Transport Layer Security, Secure Shell, Secure/Multipurpose Internet Mail Extensions and Internet Protocol Security; and how to manage cryptographic systems appropriately.

Guidelines for Gateways

Gateways act as information flow control mechanisms at the network layer and may also control information at the higher layers of the Open Systems Interconnection model. This section of the ISM guidelines, outlines different types of gateways, including the use of Cross Domain Solutions, firewalls, diodes, web proxies and content filters, and peripheral switches.

Guidelines for Data Transfers

Data transfers when conducted appropriately can ensure the confidentiality and integrity of data is maintained. This section of the ISM guidelines, outlines securing data transfers between systems.

Now that you understand ISM in greater depth, are you planning to review your current systems, and apply relevant guidance in the Australian government's Information Security Manual? StickmanCyber's expert team can help.