---
title: "Cyber security principles"
source: "https://www.cyber.gov.au/ism/oscal/v2026.09.4/artifacts/ISM_catalog.json"
collection: "asd-ism"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

# Cyber security principles

Source: https://www.cyber.gov.au/ism/oscal/v2026.09.4/artifacts/ISM_catalog.json
OSCAL release: 2026.09.4
Catalog SHA-256: `237ea09362b8449ed5c5ee85de4725a0468ee73d13af7cf61c26d4e6ac47f12d`
Rendered controls: 49

## The cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1]`

### Overview

#### Purpose of the cyber security principles

The purpose of the cyber security principles is to provide strategic guidance on how an organisation can protect their information technology and operational technology systems from cyber threats. These cyber security principles are grouped into six functions:

- **Govern:** Develop and maintain a strong and resilient cyber security culture.
- **Identify:** Identify assets and associated security risks.
- **Protect:** Implement and maintain security controls to manage security risks.
- **Detect:** Detect and analyse cyber security events to identify cyber security incidents.
- **Respond:** Respond to cyber security incidents.
- **Recover:** Resume normal business operations following cyber security incidents.

#### Implementing the cyber security principles

Within each function, the cyber security principles are listed in a logical sequence that reflects how they should be considered for implementation. The numbers used for the cyber security principles are identifiers only and do not indicate an implementation order.

When implementing the cyber security principles, each cyber security principle should be supported by administrative and technical security controls proportionate to an organisation’s size, complexity, operating environment and risk profile. These security controls should be subject to ongoing risk-based monitoring and assurance activities. Where the term ‘systems’ is used, the elements listed in brackets define the scope of that cyber security principle.

Overall, the cyber security principles are interdependent and must be implemented collectively to achieve comprehensive cyber security outcomes.

### Govern cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[1]`

#### Overview

The Govern (GOV) cyber security principles are:

### ISM-PRINCIPLE-GOV-01 - Executive cyber security accountability

- Label: GOV-01
- Applicability: NC, OS, P, S, TS

#### Statement

The board of directors or executive committee is accountable for cyber security.

### ISM-PRINCIPLE-GOV-08 - Executive artificial intelligence accountability

- Label: GOV-08
- Applicability: NC, OS, P, S, TS

#### Statement

The board of directors or executive committee is accountable for ensuring that artificial intelligence is secure, controllable, human-supervised and used in an ethical and accountable manner.

### ISM-PRINCIPLE-GOV-02 - Cyber security leadership

- Label: GOV-02
- Applicability: NC, OS, P, S, TS

#### Statement

A chief information security officer provides leadership and oversight of cyber security activities and delivers regular and timely risk-based reporting to the board of directors or executive committee on their organisation’s cyber security posture, the effectiveness of security controls, current security risks and emerging cyber threats.

### ISM-PRINCIPLE-GOV-04 - Cyber security resourcing

- Label: GOV-04
- Applicability: NC, OS, P, S, TS

#### Statement

Suitable and sufficient personnel and resources are identified, acquired and maintained in support of cyber security activities.

### ISM-PRINCIPLE-GOV-09 - Security risk management responsibilities

- Label: GOV-09
- Applicability: NC, OS, P, S, TS

#### Statement

Security risk management responsibilities for an organisation and their suppliers, partners and customers, including any shared responsibilities, are documented and communicated to all relevant parties with accountability arrangements in place to ensure their effective implementation.

### ISM-PRINCIPLE-GOV-03 - Security risk management assurance

- Label: GOV-03
- Applicability: NC, OS, P, S, TS

#### Statement

Security risk management activities for an organisation and their systems (infrastructure, operating systems, applications and data) are embedded into organisational risk management frameworks and subject to ongoing monitoring and assurance activities by the board of directors or executive committee.

### ISM-PRINCIPLE-GOV-05 - Security risk acceptance

- Label: GOV-05
- Applicability: NC, OS, P, S, TS

#### Statement

Residual security risks for systems (infrastructure, operating systems, applications and data), including inherited and shared security risks, are accepted before they are authorised for use and continuously monitored and managed throughout their operational life.

### ISM-PRINCIPLE-GOV-06 - Security risk communication

- Label: GOV-06
- Applicability: NC, OS, P, S, TS

#### Statement

Residual security risks for systems (infrastructure, operating systems, applications and data), including inherited and shared security risks, are transparently and mutually communicated with stakeholders.

### ISM-PRINCIPLE-GOV-10 - System exposure minimisation

- Label: GOV-10
- Applicability: NC, OS, P, S, TS

#### Statement

Information about the design, configuration and operation of systems (infrastructure, operating systems, applications and data) is not publicly disclosed or shared externally unless necessary for commercial, legal, regulatory or security purposes, with any disclosure minimised, controlled and logged.

### ISM-PRINCIPLE-GOV-11 - Supplier cyber security assurance

- Label: GOV-11
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems, applications and data) are delivered and supported by trustworthy suppliers whose cyber security practices are regularly independently verified or otherwise risk-assessed.

### ISM-PRINCIPLE-GOV-12 - Personnel suitability assurance

- Label: GOV-12
- Applicability: NC, OS, P, S, TS

#### Statement

Personnel are granted access to systems (infrastructure, operating systems, applications and data) only where their suitability and trustworthiness have been established and are subject to ongoing assurance.

### ISM-PRINCIPLE-GOV-13 - Cyber security and safety

- Label: GOV-13
- Applicability: NC, OS, P, S, TS

#### Statement

Security controls for systems (infrastructure, operating systems, applications and data) do not compromise human, physical or environmental safety.

### ISM-PRINCIPLE-GOV-14 - Legacy system management

- Label: GOV-14
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems, applications and data) that are not capable of meeting cyber security requirements are managed using compensating security controls, along with enhanced monitoring and assurance activities, to maintain an acceptable level of residual risk until they can be decommissioned or replaced.

### ISM-PRINCIPLE-GOV-07 - Continuous cyber security improvement

- Label: GOV-07
- Applicability: NC, OS, P, S, TS

#### Statement

Security risk management and associated cyber security activities are continually measured and reviewed using cyber threat intelligence and assurance activities, including exercises informed by real-world cyber threats, to identify, prioritise and incorporate improvements in governance arrangements, shared responsibilities and the effectiveness of security controls.

### Identify cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[2]`

#### Overview

The Identify (IDE) cyber security principles are:

### ISM-PRINCIPLE-IDE-01 - Asset identification

- Label: IDE-01
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems, applications, identities, credentials and data) are continually and centrally identified and documented.

### ISM-PRINCIPLE-IDE-05 - Asset interdependencies

- Label: IDE-05
- Applicability: NC, OS, P, S, TS

#### Statement

Interdependencies between systems (infrastructure, operating systems, applications and data) are continually and centrally identified and documented, including how the compromise of one system could affect the security or business operations of other dependent systems.

### ISM-PRINCIPLE-IDE-02 - Business criticality rating identification

- Label: IDE-02
- Applicability: NC, OS, P, S, TS

#### Statement

Business criticality ratings for systems (infrastructure, operating systems, applications and data) are identified and documented.

### ISM-PRINCIPLE-IDE-03 - Security requirement identification

- Label: IDE-03
- Applicability: NC, OS, P, S, TS

#### Statement

Security requirements for systems (infrastructure, operating systems, applications and data) are identified and documented.

### ISM-PRINCIPLE-IDE-06 - Resilience requirement identification

- Label: IDE-06
- Applicability: NC, OS, P, S, TS

#### Statement

Resilience requirements for systems (infrastructure, operating systems, applications and data) are identified and documented.

### ISM-PRINCIPLE-IDE-04 - Security risk identification

- Label: IDE-04
- Applicability: NC, OS, P, S, TS

#### Statement

Security risks for an organisation and their systems (infrastructure, operating systems, applications and data) are identified, including by using current strategic and sector-specific cyber threat intelligence and threat modelling, and are documented along with any associated risk management decisions.

### Protect cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[3]`

#### Overview

The Protect (PRO) cyber security principles are:

### ISM-PRINCIPLE-PRO-01 - Secure system lifecycle

- Label: PRO-01
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems and applications) are planned, designed, developed, tested, deployed, maintained and decommissioned according to their business criticality ratings and security and resilience requirements using Secure by Design and Secure by Default principles and practices.

### ISM-PRINCIPLE-PRO-16 - Cyber supply chain security

- Label: PRO-16
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber supply chains supporting systems (infrastructure, operating systems, applications and data) are secure, resilient and support effective and coordinated cyber security incident response.

### ISM-PRINCIPLE-PRO-13 - Identity, credential and access management

- Label: PRO-13
- Applicability: NC, OS, P, S, TS

#### Statement

Robust and secure identity, credential and access management is used to establish, maintain and control access to systems (infrastructure, operating systems, applications and data) and to support effective detection of identity and credential misuse.

### ISM-PRINCIPLE-PRO-12 - Least privilege access

- Label: PRO-12
- Applicability: NC, OS, P, S, TS

#### Statement

Users are granted the minimum access to systems (infrastructure, operating systems, applications and data) required to undertake their duties or functions.

### ISM-PRINCIPLE-PRO-05 - Secure administration

- Label: PRO-05
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems, applications and data) are administered in a secure, accountable and auditable manner.

### ISM-PRINCIPLE-PRO-04 - Secure configuration management

- Label: PRO-04
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems and applications) are securely configured to approved and maintained baselines, including by reducing attack surfaces and attack paths, with configurations continually monitored and consistently enforced.

### ISM-PRINCIPLE-PRO-06 - Vulnerability management

- Label: PRO-06
- Applicability: NC, OS, P, S, TS

#### Statement

Vulnerabilities in systems (infrastructure, operating systems, applications and data) are identified, documented, validated and prioritised for remediation or mitigation in a timely manner, with all remediation and mitigation actions verified for effectiveness.

### ISM-PRINCIPLE-PRO-07 - Trustworthy software

- Label: PRO-07
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (operating systems and applications) only permit the execution of software that is supported, verified and authorised.

### ISM-PRINCIPLE-PRO-08 - Cryptographic protection

- Label: PRO-08
- Applicability: NC, OS, P, S, TS

#### Statement

Data is encrypted and authenticated at rest and in transit using ASD-approved cryptography to protect its confidentiality and integrity.

### ISM-PRINCIPLE-PRO-17 - Cryptographic agility

- Label: PRO-17
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems and applications) are designed, configured and managed to support timely, prioritised and orderly changes to cryptography, including post-quantum cryptography.

### ISM-PRINCIPLE-PRO-10 - Regular and proven backups

- Label: PRO-10
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems, applications and data) are regularly backed up in a secure and proven manner, including through the validation of restoration capabilities.

### ISM-PRINCIPLE-PRO-18 - Network segmentation and segregation

- Label: PRO-18
- Applicability: NC, OS, P, S, TS

#### Statement

Systems (infrastructure, operating systems and applications) are segmented into network zones based on business criticality and trust levels, with only authorised, controlled and monitored inbound and outbound communication paths between network zones permitted.

### ISM-PRINCIPLE-PRO-19 - Operational technology isolation

- Label: PRO-19
- Applicability: NC, OS, P, S, TS

#### Statement

Operational technology systems (infrastructure) are logically and physically isolated from information technology systems (infrastructure) and all external infrastructure, with only authorised, controlled and monitored communication paths between systems permitted.

### ISM-PRINCIPLE-PRO-20 - Remote access to operational technology

- Label: PRO-20
- Applicability: NC, OS, P, S, TS

#### Statement

Access to operational technology systems (infrastructure, operating systems, applications and data) over untrusted infrastructure is authorised, controlled and monitored.

### ISM-PRINCIPLE-PRO-09 - Content filtering

- Label: PRO-09
- Applicability: NC, OS, P, S, TS

#### Statement

Data communicated between different security domains for systems (infrastructure and applications) is controlled and subject to inspection and verification.

### ISM-PRINCIPLE-PRO-14 - Cyber security awareness training

- Label: PRO-14
- Applicability: NC, OS, P, S, TS

#### Statement

Personnel are provided with ongoing cyber security awareness training, including operational security considerations, tailored to their duties, access levels and current cyber threats.

### ISM-PRINCIPLE-PRO-15 - Physical access control

- Label: PRO-15
- Applicability: NC, OS, P, S, TS

#### Statement

Physical access to facilities and systems (infrastructure and data) is restricted to authorised personnel and monitored for unusual activities.

### Detect cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[4]`

#### Overview

The Detect (DET) cyber security principles are:

### ISM-PRINCIPLE-DET-01 - Centralised event logging

- Label: DET-01
- Applicability: NC, OS, P, S, TS

#### Statement

Security-relevant event logs and configuration changes for systems (infrastructure, operating systems, applications and data) are centrally collected, protected against unauthorised modification or deletion, and retained to support effective cyber security event detection and investigation.

### ISM-PRINCIPLE-DET-04 - Baselined high-risk access activities

- Label: DET-04
- Applicability: NC, OS, P, S, TS

#### Statement

Baseline patterns of identity and credential access activities, privileged access activities, and remote access activities are established and maintained for systems (infrastructure, operating systems, applications and data) to enable the detection of anomalous or unexpected behaviour.

### ISM-PRINCIPLE-DET-02 - Cyber security event detection

- Label: DET-02
- Applicability: NC, OS, P, S, TS

#### Statement

Anomalous or unexpected events and behaviours for systems (infrastructure, operating systems, applications and data) are analysed in a timely manner to detect cyber security events.

### ISM-PRINCIPLE-DET-03 - Cyber security incident identification

- Label: DET-03
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security events are analysed in a timely manner to identify cyber security incidents.

### ISM-PRINCIPLE-DET-05 - Detection capability efficacy

- Label: DET-05
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security event detection capabilities are regularly evaluated for effectiveness and continuously refined, including by using current strategic and sector-specific cyber threat intelligence, to improve the detection of cyber security events.

### Respond cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[5]`

#### Overview

The Respond (RES) cyber security principles are:

### ISM-PRINCIPLE-RES-01 - Cyber security incident planning

- Label: RES-01
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security incident response, business continuity and disaster recovery plans for systems (infrastructure, operating systems, applications and data) support continued business operations during cyber security incidents, and the resumption of normal business operations following cyber security incidents.

### ISM-PRINCIPLE-RES-05 - Cyber security incident coordination

- Label: RES-05
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security incident roles and responsibilities are defined, documented and exercised to support the internal and external coordination and management of cyber security incidents, including responsibilities for declaring cyber security incidents and undertaking pre-approved response and recovery activities.

### ISM-PRINCIPLE-RES-03 - Cyber security incident response

- Label: RES-03
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security incidents are contained, eradicated and recovered from in a timely manner.

### ISM-PRINCIPLE-RES-02 - Cyber security incident reporting

- Label: RES-02
- Applicability: NC, OS, P, S, TS

#### Statement

Cyber security incidents, including associated response and recovery activities, are reported internally and externally to relevant bodies and stakeholders in a timely manner.

### ISM-PRINCIPLE-RES-04 - Cyber security incident insights

- Label: RES-04
- Applicability: NC, OS, P, S, TS

#### Statement

Lessons learnt from cyber security incidents are captured, and areas for improvement are identified, prioritised and actioned in a timely manner.

### Recover cyber security principles

OSCAL sort-id: `catalog[1].group[02].group[1].group[6]`

#### Overview

The Recover (REC) cyber security principles are:

### ISM-PRINCIPLE-REC-02 - System recovery assurance

- Label: REC-02
- Applicability: NC, OS, P, S, TS

#### Statement

Following cyber security incidents, systems (infrastructure, operating systems, applications and data) are verified through assurance activities to ensure they are secure and capable of supporting the resumption of normal business operations.

### ISM-PRINCIPLE-REC-01 - Business operations resumption

- Label: REC-01
- Applicability: NC, OS, P, S, TS

#### Statement

Residual security risks for systems (infrastructure, operating systems, applications and data), including inherited and shared security risks, are accepted prior to the resumption of normal business operations following cyber security incidents.
