Skip to content
    Back to Regulatory Radar
    InformationalFramework UpdateJune 1, 2024

    Australian ISM June 2024 Update Released

    The Australian Signals Directorate (ASD) released the June 2024 update to the Information Security Manual (ISM), the security control framework underpinning IRAP assessments for Australian government systems. The update split the GOVERN cyber security principles into separate GOVERN and IDENTIFY sets, extended CISO governance responsibilities to operational technology alongside IT, added controls addressing generative AI and large language model security, tightened multi-factor authentication requirements including disabling authentication protocols that do not support MFA, and adopted OWASP mobile application security standards. The ISM is updated quarterly, and this release restructured the manual's principles more substantially than a typical quarterly revision.

    IRAPSaaSDefense

    Key Analytics

    June 1, 2024
    Event Date
    Time Remaining
    August 1, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Cloud service providers and other systems assessed under IRAP must evaluate their compliance posture against the updated ISM controls, as IRAP assessments reference the current ISM version. CISOs of assessed organizations should confirm that governance charters, risk reporting lines, and cyber supply chain processes cover operational technology as well as IT. Organizations deploying AI systems should map the new LLM-related controls to their environments, and identity teams should verify that legacy authentication protocols lacking MFA support are disabled. Organizations maintaining IRAP assessments should review the delta between this version and the version used in their last assessment to identify controls requiring remediation before their next surveillance assessment.

    Recommended Actions

    • Download the ISM June 2024 changes summary and perform a delta analysis against the ISM version used in your most recent IRAP assessment
    • Update security governance documentation to reflect the split GOVERN and IDENTIFY principle sets and extend CISO oversight to operational technology
    • Disable authentication protocols that do not support MFA, and assess AI and mobile application deployments against the new OWASP-aligned controls

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Moderate30-65 hours
    Key Workstreams
    • Delta analysis between the June 2024 ISM and the version used in your last IRAP assessment
    • Governance charter updates extending CISO oversight to operational technology
    • Disablement of authentication protocols that do not support MFA

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 30-65 hours
    Start cold under pressureModerate · 70-160 hours

    Roughly 40 to 95 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events