Verification Record
AOS-ISM-2026-001 · v1.1

Stated, Not Required

An assessment of the Guidelines for procurement and outsourcing in the Australian Signals Directorate’s Information security manual, June 2026 release, with one comparison to March 2026. The chapter’s opening narrative states that foreign-owned suppliers operating in Australia may be subject to a foreign government’s lawful access to data belonging to their customers. No control in the chapter requires an organisation to establish whether any particular supplier is. This record pins both releases, the built PDF, and its timestamp.

Reference
AOS-ISM-2026-001
Assessed
17 August 2026
Version
v1.1
The chain

Verification chain

Four things are pinned, and each can be checked independently of the others.

The assessment PDF. SHA-256: 2201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450

Download the file and run shasum -a 256 over it. If the value differs, the file is not the one struck here.

The timestamp. The receipt AOS-ISM-2026-001-v1.1.pdf.ots is an OpenTimestamps proof over exactly those bytes, submitted to four calendars on 19 August 2026 and pending confirmation in the Bitcoin blockchain at the time of publication. It establishes that the file existed no later than the moment it was stamped. It establishes nothing about whether the file is correct.

The assessed source. The assessment rests on 8 pinned artefacts: two releases of the Information security manual, the chapter from each, the release change log, the control list, and the publisher’s archived-releases index. All 8 are pinned by hash and no row records a third-party capture. Quotations were read from text extracted from the pinned PDFs, not at page-image resolution; control numbers, revisions and applicability markings were read from the printed control line as the document sets it out.

RefArtefactSHA-256Third-party copy
I-ISM-1ISM Guidelines for procurement and outsourcing, June 2026 release. cyber.gov.au page as served, first published and last updated 09 Jun 202632c8af6a8f467f5a573faa76b93d01005bb4e078b3d4931e6fa0fe3b8c1bffa6-
I-ISM-2ISM Guidelines for procurement and outsourcing (June 2026), PDF chapter, 9 pages, linked from I-ISM-1272cc6cdc11ecce202fe1969dcddefbd31317b40b2b5b27f8e6b8999de978048-
I-ISM-3Information security manual (June 2026), full release, 261 pages, authorised PDF from cyber.gov.aube2f7c32855ccad55f09c3397e1ea8f79b30907b5a155568c2d8943ef668693f-
I-ISM-4ISM June 2026 changes (June 2026), the release change log, 6 pages4780b0c27a1faf766f3e117a11bfc2800deb409228ea7f2903cb60f5379ee4b9-
I-ISM-5System security plan annex template (June 2026), the machine-readable list of every control in the releasec7e2f6dc52ae558fd29732adc5faf36f8de404f58248513b179fdd48eecb3d34-
I-ISM-6Information security manual (March 2026), full release ZIP, 27 chapter PDFs, retrieved from the PUBLISHER's archived-releases index (not a third-party copy, not an archive capture)10daaaeea199ad69e23daf6ada05165c97aca839392d5bd176c60f72a5cedc3d-
I-ISM-7ISM Guidelines for procurement and outsourcing (March 2026), chapter PDF extracted from I-ISM-6, 9 pages, self-identifying 'Last updated: March 2026'2fb43141801d0b4145266fa4a7fcb055963b7ccd64587ec5a4fd3234d9f44df7-
I-ISM-8ASD archived ISM releases index, the page that publishes nine prior releases; the discovery source for I-ISM-6f4a2410022bdc2719914f56e08b42e4fa43087314d75f8eda77ffbde68e9f43c-

No row in this register records a third-party capture. All 8 artefacts above were retrieved from their publisher by this practice and are held in this corpus. That is a statement about what this register holds, not about what exists - no archive index was queried, and an absence here is not evidence of an absence in any archive. A reader who wants to check a quotation against an independent copy must locate one. Until this practice records one, the alternatives are this site and the publisher’s own server.

The build. The PDF is produced deterministically from tracked source by build.sh, with SOURCE_DATE_EPOCH pinned to the assessment date. Repeat builds on one machine and one toolchain are byte-identical; independent third-party reproducibility is not established and is not claimed. Verify by SHA-256, not by rebuild.

Versions

Version history

Two versions. v1.1 corrects two figures in v1.0 and withdraws one sentence. A revision does not replace its predecessor: v1.0’s bytes are unchanged, its hash still resolves, and the file remains downloadable at its own address. v1.0 was published 17 August 2026 and v1.1 on 19 August 2026; both were assessed on 17 August 2026, and the revision keeps v1.0’s SOURCE_DATE_EPOCH, because a revision is not a new reading - it is the same reading, corrected.

VersionAssessedPublishedSHA-256Status
v1.117 August 202619 August 20262201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450current

The cover carries 17 August 2026, the date the assessment was made. Publication followed on 19 August 2026. An assessment is a reading of a source at a moment, and the document’s retrieval times and viewed dates already fix that moment; the cover is not moved to the upload date, because that would put two dates on one act of reading.

Corrections

Corrections

Two figures and one sentence, corrected at v1.1. v1.0 stated that the June 2026 chapter carries 39 controls; it carries 38, counted at this revision by rendering all nine pages and counting the printed control entries. v1.0 also stated that control ISM-0138 entered the chapter between the March and June releases; it is in neither release of this chapter, and the two control sets are identical. The sentence naming eight controls as this chapter’s is corrected to seven, with the eighth identifier explained as belonging to another chapter.

No finding moves. The finding is that the chapter states the risk in narrative and requires nothing about it in any control, and that holds at either count and in both releases. The error was found on 19 August 2026 by rendering the pages and counting, before any external party raised it. The full account and its reach determination are in the practice’s corrections register.

Corrections made before publication are not listed here. They are recorded in the case’s own scope file, which is where the drafting record belongs. This section exists to hold what changes after a reader could have relied on it, and it will say so plainly if that ever happens.

Download

Assessment PDF

AOS-ISM-2026-001-v1.1.pdf · 125,538 bytes · 12 pages

SHA-256: 2201d59a8568455ee78ba412250d16967119b04f57d6abe75e928ccc8e960450

OpenTimestamps receipt