As we navigate through an ever-evolving digital landscape, staying updated with the latest cybersecurity guidelines is crucial. On 13th June 2024, the Australian Signals Directorate (ASD) published a quarterly update to the Information Security Manual (ISM), introducing several notable changes and enhancements. These updates aim to strengthen cybersecurity measures across organisations, with a particular focus on operational technology (OT) and emerging threats.
In this blog, we take a detailed look at the key updates:
Key Changes
1) Governance of OT Cyber Security
A new control has been introduced recommending that an organisation’s Chief Information Security Officer (CISO) provide cybersecurity leadership not just for IT, but also for OT. This expanded role ensures a comprehensive approach to securing both IT and OT environments.
2) OT Cyber Supply Chain Security
New controls have been added to extend cyber supply chain security measures to cover OT equipment. This is a significant step in protecting the broader spectrum of technology assets within organisations.
3) AI Application Development
In light of the increasing use of artificial intelligence, two critical controls have been introduced:
-
OWASP Top 10 Vulnerabilities:
Organisations are advised to mitigate vulnerabilities identified in OWASP’s Top 10 for large language model (LLM) applications.
-
Adversarial Suffixes:
LLM applications should evaluate user prompts to detect and mitigate adversarial suffixes designed to generate sensitive or harmful content.
4) Multi-Factor Authentication (MFA) Deployments
To enhance authentication security:
- All other authentication protocols that don’t support MFA should be disabled.
- For sensitive or classified systems, MFA enrolment should only be allowed from trustworthy devices.
5) Mobile App Development
A new control recommends using OWASP’s mobile app security verification standard to support ‘secure-by-design’ principles in mobile app development activities. This ensures that mobile applications are developed with robust security measures from the outset.
6) Internal Cyber Security Reporting
CISOs are now advised to report on both IT and OT cyber security matters to their organisation’s audit, risk, and compliance committee, in addition to their Executive Committee (ExCo) or Board of Directors. This dual reporting structure enhances oversight and ensures comprehensive risk management.
Other Changes
-
Cyber Security Principles:
Amendments have been made to the Cyber Security Principles under the categories of Govern, Identify, Protect, and Respond.
-
System Management:
A new control recommends that the likelihood of system compromise be frequently assessed, especially when working exploits exist for unmitigated vulnerabilities.
-
Language and Structure:
Various language, grammatical, and control ordering changes were made throughout the ISM to clarify the intent of controls, increase readability, and eliminate duplication of content.
These updates reflect the ASD’s commitment to continuously improving cybersecurity frameworks and adapting to new challenges.
Stay compliant with the changes and if you need any assistance, our consultants can help!
You can contact us at 1300 802 163 or e-mail – sales@anitechgroup.com.




Recent Comments