Skip to content
arrow_back
search
ISM-0290 policy ASD Information Security Manual (ISM)

Secure Configuration of High Assurance IT Equipment

Ensure high-grade IT gear is set up and operated per ASD standards for security.

record_voice_over

Plain language

This control is about ensuring that any high-grade IT equipment in your organisation is set up and used following the standards set by the Australian Signals Directorate (ASD). This matters because if the equipment isn't configured properly, it could lead to security vulnerabilities, making it easier for hackers to access sensitive information or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

High assurance IT equipment is installed, configured, administered and operated in an evaluated configuration and in accordance with ASD guidance.
policy ASD Information Security Manual (ISM) ISM-0290
priority_high

Why it matters

If high assurance equipment is not operated in its evaluated configuration, security claims may not hold, enabling compromise of protected information and services.

settings

Operational notes

Regularly confirm the device matches its evaluated build (firmware, patches, settings); disable non-evaluated functions and tightly restrict admin access per ASD guidance.

Mapping detail

Mapping

Direction

Controls