Verification chain
Four things are pinned, and each can be checked independently of the others.
The assessment PDF. SHA-256: 2201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450
Download the file and run shasum -a 256 over it. If the value differs, the file is not the one struck here.
The timestamp. The receipt AOS-ISM-2026-001-v1.1.pdf.ots is an OpenTimestamps proof over exactly those bytes, submitted to four calendars on 19 August 2026 and pending confirmation in the Bitcoin blockchain at the time of publication. It establishes that the file existed no later than the moment it was stamped. It establishes nothing about whether the file is correct.
The assessed source. The assessment rests on 8 pinned artefacts: two releases of the Information security manual, the chapter from each, the release change log, the control list, and the publisher’s archived-releases index. All 8 are pinned by hash and no row records a third-party capture. Quotations were read from text extracted from the pinned PDFs, not at page-image resolution; control numbers, revisions and applicability markings were read from the printed control line as the document sets it out.
| Ref | Artefact | SHA-256 | Third-party copy |
|---|---|---|---|
| I-ISM-1 | ISM Guidelines for procurement and outsourcing, June 2026 release. cyber.gov.au page as served, first published and last updated 09 Jun 2026 | 32c8af6a8f467f5a573faa76b93d01005bb4e078b3d4931e6fa0fe3b8c1bffa6 | - |
| I-ISM-2 | ISM Guidelines for procurement and outsourcing (June 2026), PDF chapter, 9 pages, linked from I-ISM-1 | 272cc6cdc11ecce202fe1969dcddefbd31317b40b2b5b27f8e6b8999de978048 | - |
| I-ISM-3 | Information security manual (June 2026), full release, 261 pages, authorised PDF from cyber.gov.au | be2f7c32855ccad55f09c3397e1ea8f79b30907b5a155568c2d8943ef668693f | - |
| I-ISM-4 | ISM June 2026 changes (June 2026), the release change log, 6 pages | 4780b0c27a1faf766f3e117a11bfc2800deb409228ea7f2903cb60f5379ee4b9 | - |
| I-ISM-5 | System security plan annex template (June 2026), the machine-readable list of every control in the release | c7e2f6dc52ae558fd29732adc5faf36f8de404f58248513b179fdd48eecb3d34 | - |
| I-ISM-6 | Information security manual (March 2026), full release ZIP, 27 chapter PDFs, retrieved from the PUBLISHER's archived-releases index (not a third-party copy, not an archive capture) | 10daaaeea199ad69e23daf6ada05165c97aca839392d5bd176c60f72a5cedc3d | - |
| I-ISM-7 | ISM Guidelines for procurement and outsourcing (March 2026), chapter PDF extracted from I-ISM-6, 9 pages, self-identifying 'Last updated: March 2026' | 2fb43141801d0b4145266fa4a7fcb055963b7ccd64587ec5a4fd3234d9f44df7 | - |
| I-ISM-8 | ASD archived ISM releases index, the page that publishes nine prior releases; the discovery source for I-ISM-6 | f4a2410022bdc2719914f56e08b42e4fa43087314d75f8eda77ffbde68e9f43c | - |
No row in this register records a third-party capture. All 8 artefacts above were retrieved from their publisher by this practice and are held in this corpus. That is a statement about what this register holds, not about what exists - no archive index was queried, and an absence here is not evidence of an absence in any archive. A reader who wants to check a quotation against an independent copy must locate one. Until this practice records one, the alternatives are this site and the publisher’s own server.
The build. The PDF is produced deterministically from tracked source by build.sh, with SOURCE_DATE_EPOCH pinned to the assessment date. Repeat builds on one machine and one toolchain are byte-identical; independent third-party reproducibility is not established and is not claimed. Verify by SHA-256, not by rebuild.
Version history
Two versions. v1.1 corrects two figures in v1.0 and withdraws one sentence. A revision does not replace its predecessor: v1.0’s bytes are unchanged, its hash still resolves, and the file remains downloadable at its own address. v1.0 was published 17 August 2026 and v1.1 on 19 August 2026; both were assessed on 17 August 2026, and the revision keeps v1.0’s SOURCE_DATE_EPOCH, because a revision is not a new reading - it is the same reading, corrected.
| Version | Assessed | Published | SHA-256 | Status |
|---|---|---|---|---|
| v1.1 | 17 August 2026 | 19 August 2026 | 2201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450 | current |
The cover carries 17 August 2026, the date the assessment was made. Publication followed on 19 August 2026. An assessment is a reading of a source at a moment, and the document’s retrieval times and viewed dates already fix that moment; the cover is not moved to the upload date, because that would put two dates on one act of reading.
Corrections
Two figures and one sentence, corrected at v1.1. v1.0 stated that the June 2026 chapter carries 39 controls; it carries 38, counted at this revision by rendering all nine pages and counting the printed control entries. v1.0 also stated that control ISM-0138 entered the chapter between the March and June releases; it is in neither release of this chapter, and the two control sets are identical. The sentence naming eight controls as this chapter’s is corrected to seven, with the eighth identifier explained as belonging to another chapter.
No finding moves. The finding is that the chapter states the risk in narrative and requires nothing about it in any control, and that holds at either count and in both releases. The error was found on 19 August 2026 by rendering the pages and counting, before any external party raised it. The full account and its reach determination are in the practice’s corrections register.
Corrections made before publication are not listed here. They are recorded in the case’s own scope file, which is where the drafting record belongs. This section exists to hold what changes after a reader could have relied on it, and it will say so plainly if that ever happens.
Assessment PDF
SHA-256: 2201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450