Skip to content
arrow_back
search
ISM-0280 policy ASD Information Security Manual (ISM)

Choose PP-evaluated Products Over EAL-based Ones

Prefer products evaluated against protection profiles over those with EAL evaluations for procurement purposes.

record_voice_over

Plain language

When choosing products to buy for your organisation, it's better to select those that have been evaluated using protection profiles rather than just a general evaluation level. This is important because it ensures the product meets specific security needs and standards, reducing the risk of security breaches that could expose sensitive data or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If procuring an evaluated product, a product that has completed a PP-based evaluation, including against all applicable PP modules (as well as a software bill of materials assessment if applicable), is selected in preference to one that has completed an EAL-based evaluation.
policy ASD Information Security Manual (ISM) ISM-0280
priority_high

Why it matters

Opting for PP-evaluated products over EAL helps ensure required security functions are covered, reducing risk from incomplete evaluations.

settings

Operational notes

Confirm purchases have PP-based certification for all applicable PP modules, and obtain/verify an SBOM assessment where relevant.

Mapping detail

Mapping

Direction

Controls