14 July 2026
ISM Journey: From the 2019 Release to AI-Native Assurance
A field-level view of how the ACSC ISM evolved from its 2019 foundation through the pandemic, Essential Eight uplift, Zero Trust and AI adoption — and what the next 12 months look like.
The Australian Cyber Security Centre's Information Security Manual (ISM) has become the quiet backbone of Australian government and critical infrastructure security. But it didn't arrive fully formed. Tracing its journey from the first 2019 release through to today's AI-assisted assurance programmes shows how much the practice of security has changed — and where it's heading next.
I've mapped this out as an animated timeline at /ism-journey. Below is the written version.
2019: Foundation
In 2019 the ACSC consolidated its cyber guidance into the first ISM. The shift was subtle but important: it moved away from prescriptive checklists toward a risk-based framework, and it became the baseline against which Australian government systems would be assessed. For the first time, organisations had a single reference point that tied policy, controls and implementation guidance together.
2020: Pandemic Response
COVID-19 forced remote work onto every organisation overnight. The perimeter dissolved into home offices, BYOD devices and VPN concentrators. The ACSC responded with secure remote access guidance, and boards suddenly cared about patching, MFA and endpoint protection in ways they hadn't before. The year's practical lesson: identity and access become the perimeter when the office disappears.
2021: Framework Refresh
The 2021 ISM update reflected the cloud and hybrid environments that had become normal during the pandemic. The Essential Eight Maturity Model was refined, and ransomware guidance — particularly around backups and recovery — was sharpened. Security started being treated as a continuity issue, not just a compliance one.
2022: Maturity Model
2022 brought a tighter Essential Eight Maturity Model with clearer testing criteria. Application control, macro settings and administrative privilege restrictions came under sharper scrutiny. Many organisations began measuring themselves against ML2 and ML3 targets, and the language of "maturity" started replacing the language of "tick-box compliance."
2023: Cloud & Identity
Cloud security controls expanded significantly, while credential theft and phishing campaigns drove a stronger push for phishing-resistant MFA and identity governance. SaaS security posture management became mainstream. The ISM was no longer just about on-premise infrastructure; it was now written for multi-cloud, SaaS-first operating models.
H2 2024: Baseline
With the framework context established, organisations began running full ISM control inventories. The focus was on building a clean baseline: mapping controls to ACSC guidance, creating risk-based remediation backlogs, and giving executives a maturity view by domain rather than a single red-amber-green score.
H1 2025: Uplift
The Essential Eight ML2 uplift became the dominant programme. Patching, MFA, application control and macro restrictions were pushed to ML2, supported by automated evidence capture. The result was not just better security — it was shorter audit preparation cycles, from weeks to days.
H2 2025: Zero Trust
The next perimeter shift moved from network-based trust to identity-first Zero Trust. Conditional access, device posture and least-privilege segmentation replaced the VPN for SaaS access. The assumption of trust inside the network was retired, and continuous verification became the default.
H1 2026: AI Adoption
AI moved from a novelty into the SOC and GRC loop. LLM-assisted alert triage reduced noise by roughly 60%, AI-assisted policy drafting accelerated control mapping, and data classification plus prompt governance became the new guardrails. The question shifted from "Can we use AI?" to "How do we use it securely?"
H2 2026 → H1 2027: Forecast
Looking ahead, the next phase is autonomous assurance. Continuous control monitoring will replace annual audit theatre, agentic systems will handle tier-1 incident response, and the new ASD "Essentials" principles framework will align with ISM programmes. The target is no longer a static maturity level — it's a security posture that adapts as fast as the threat landscape.
What This Means for Your Programme
If your roadmap is still framed around hitting a fixed maturity number, it's worth revisiting. The frameworks underneath those numbers are changing. The good news: the work already done on patching, MFA, application control and Zero Trust is not wasted. It becomes the foundation for the next stage, not the endpoint.
Want to see the journey as an animated timeline? View the interactive ISM Journey here.