Australian ISM June 2024 Update Released
The Australian Signals Directorate (ASD) released the June 2024 update to the Information Security Manual (ISM), the security control framework underpinning IRAP assessments for Australian government systems. The update split the GOVERN cyber security principles into separate GOVERN and IDENTIFY sets, extended CISO governance responsibilities to operational technology alongside IT, added controls addressing generative AI and large language model security, tightened multi-factor authentication requirements including disabling authentication protocols that do not support MFA, and adopted OWASP mobile application security standards. The ISM is updated quarterly, and this release restructured the manual's principles more substantially than a typical quarterly revision.
Key Analytics
Impact Analysis
Cloud service providers and other systems assessed under IRAP must evaluate their compliance posture against the updated ISM controls, as IRAP assessments reference the current ISM version. CISOs of assessed organizations should confirm that governance charters, risk reporting lines, and cyber supply chain processes cover operational technology as well as IT. Organizations deploying AI systems should map the new LLM-related controls to their environments, and identity teams should verify that legacy authentication protocols lacking MFA support are disabled. Organizations maintaining IRAP assessments should review the delta between this version and the version used in their last assessment to identify controls requiring remediation before their next surveillance assessment.
Recommended Actions
- Download the ISM June 2024 changes summary and perform a delta analysis against the ISM version used in your most recent IRAP assessment
- Update security governance documentation to reflect the split GOVERN and IDENTIFY principle sets and extend CISO oversight to operational technology
- Disable authentication protocols that do not support MFA, and assess AI and mobile application deployments against the new OWASP-aligned controls
Always verify requirements with official regulatory sources.
Estimated Remediation Effort
Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.
A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.
- ›Delta analysis between the June 2024 ISM and the version used in your last IRAP assessment
- ›Governance charter updates extending CISO oversight to operational technology
- ›Disablement of authentication protocols that do not support MFA
The Cost of Waiting
Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.
Roughly 40 to 95 hours avoided by preparing early
Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.