ACSC Information Security Manual

Essential Eight is the floor. The ISM is the whole building.

Gap assessment and alignment against the Australian Government's Information Security Manual — for businesses that need to demonstrate more than the baseline eight strategies.

20+ areas
Guidelines spanning governance, personnel, physical and technical controls
Risk-based
Controls selected and tailored to your systems, not applied as a blanket checklist
Beyond E8
Covers what the Essential Eight alone was never meant to
What's covered

The Essential Eight is a subset. This is the full framework.

The ISM sets out controls the Essential Eight doesn't touch — governance, personnel, physical security, cryptography, cloud. Scope is tailored to which of these actually apply to your environment.

Governance & risk

Policies, risk framework and oversight structured the way the ISM expects them to be, not just written down once.

Access & identity

Authentication, privilege and identity lifecycle assessed to the ISM's standard — a step beyond just switching on MFA.

System hardening

Operating systems, applications and network devices configured against ISM-aligned baselines, not vendor defaults.

Data & cryptography

Classification, encryption at rest and in transit, and key management assessed against ISM cryptographic requirements.

Cloud & third parties

Shared responsibility, vendor assessment and supply chain risk — where a lot of ISM gaps actually turn up.

Logging & monitoring

Centralised logging, retention and alerting reviewed against what the ISM requires you to actually be able to see.

Incident response & recovery

Plans checked against whether they'd actually work under pressure, not just whether one exists in a folder somewhere.

Personnel & physical

Vetting, physical access controls and staff awareness — the human and physical layers a purely technical audit misses.

How it runs

Four steps, scoped to what's relevant to you.

01 — DISCOVER

Map what applies

Not every ISM guideline applies to every business — we work out which ones actually govern your environment first.

02 — ASSESS

Test against the standard

Controls checked against the relevant ISM guidelines, including the parts a technical scan alone would never catch.

03 — REPORT

Show the gaps plainly

A clear compliance position — what's aligned, what isn't, and what evidence backs each finding.

04 — REMEDIATE

Close them out

A prioritised uplift plan, sequenced by what's actually blocking your compliance position first.

Who this is for

Built for businesses that need the full framework, not just the baseline.

If you're already aligned to Essential Eight and being asked for more, this is usually what's next.

Government contracts or panels that specify ISM alignment, not just Essential Eight.

Defence industry supply chain work that requires evidence against the broader framework.

Regulated or critical infrastructure businesses whose obligations go beyond the baseline eight.

“Essential Eight tells you the floor is solid. The ISM is what tells you the rest of the building is too.”
— Ezatech

Ready to find out what's in scope?

Tell us what's driving the requirement — a contract, a panel, an accreditation — and we'll scope the assessment.

Book a consultation →