Australian ISM updates intrusion remediation and service provider access controls
Original title: v2026.09.4
The Australian Information Security Manual (ISM) September 2026 edition introduces changes to intrusion handling controls and establishes new requirements for service provider access. Organisations must now restrict service provider access to explicitly approved remote management tools, source addresses, and time windows, with independent logging. Intrusion remediation activities should be coordinated and sequenced to minimize re-compromise risks, with enhanced monitoring continuing until confidence in actor eradication is established.
What changed
- ISM-1731: Amended to recommend using trusted systems separate from a compromised system for planning and coordination of intrusion remediation, rather than just a separate system
- ISM-1732: Amended to recommend intrusion remediation activities be coordinated and sequenced to minimise re-compromise opportunities while balancing operational risk and business continuity, rather than requiring all activities in a single outage window
- ISM-1213: Amended to recommend conducting enhanced monitoring until evidence-based confidence in actor eradication is achieved, rather than capturing full network traffic for a fixed seven-day period
- ISM-2124: New control introduced requiring service provider access to systems be restricted to explicitly approved remote management tools, source network addresses, and time windows
- ISM-1576: Amended to require unauthorised service provider access or administration events be treated as cyber security incidents; new control introduced requiring all service provider system access be independently logged in a manner the service provider cannot modify or delete
What the document requires
The ISM requires organisations to restrict service provider access to systems to explicitly approved remote management tools, source addresses, and time windows.
Who is affected
Australian organisations of all sizes that rely on service providers for system management and those managing intrusion incidents
Summary generated by a language model; the official text prevails. Not legal advice.