IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Frameworks & Controls

Australian ISM — September 2026

1,143 controls and 49 security principles with classification applicability and distinct evidence review

All available frameworks

What the app checks

Technical checks run for the selected scope, available connectors and credentials. Results provide evidence for review; missing data is not a pass.

Explicit requirement-to-test mappings

RequirementCollector / testWhat it checks or supports
ISM-0336WINDOWS / WIN-INVENTORY-COVERAGE-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.
ISM-1417WINDOWS / WIN-AV-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.
ISM-1504ENTRA / ENTRA-MFA-REG-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.
ISM-1404ADSEC / AD-LIFECYCLE-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.
ISM-1808VULN / VULN-IMPORT-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.
ISM-1695WINDOWS / WIN-PATCH-FRESHNESS-001Supporting observation only for authorised in-scope IT assets. Independently verify actual enforcement, operating procedures, scope and operating evidence. Registration does not prove MFA enforcement; firewall state does not prove segmentation. Patch age does not prove prescribed remediation deadlines, backup configuration does not prove restoration, and device encryption does not prove all backup copies are protected.

What requires manual review

Confirm scope and applicability, review the requirement guidance, collect policies and records, conduct interviews or observations where needed, and assess evidence relevance and freshness. Record owners, rationale, workpaper conclusions and remediation. An assessor makes the final decision; a technical pass does not approve the whole framework.

Full source catalog for scoped evidence preparation. Applicability and system authorization remain reviewer decisions. Not an IRAP assessment or certification. Australian Signals Directorate, Information security manual, September 2026. Copyright Commonwealth of Australia 2026. Licensed under CC BY 4.0: https://creativecommons.org/licenses/by/4.0/. Source statements reformatted, internal Markdown links rendered as labels; ITAF evidence actions added. No ASD endorsement.

Where it is available

This preparation framework is listed in the C32 Professional/MSP application catalog. Free retains its ISO assessment limits. Availability of a framework is separate from the extent of automated scanning.

Coverage shown here comes from the application’s C32 requirement and mapping catalogs.