Skip to content
arrow_back
search
ISM-0345 policy ASD Information Security Manual (ISM)

Disable External Interfaces for Direct Memory Access

Disable external communication ports that could directly access system memory to prevent unauthorised access.

record_voice_over

Plain language

This control is about turning off certain external connections on your computer that could otherwise directly access its memory. It's important because these connections, if left open, could let someone unauthorised get access to your system and steal or damage sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

External communication interfaces that allow DMA are disabled.
policy ASD Information Security Manual (ISM) ISM-0345
priority_high

Why it matters

If DMA-capable interfaces are left enabled, a rogue device can read or alter system memory, enabling credential theft, data exfiltration, or full compromise.

settings

Operational notes

Verify DMA-capable ports (e.g., Thunderbolt/PCIe expansion) are disabled in BIOS/UEFI and OS policy, and re-check after firmware updates or hardware changes.

Mapping detail

Mapping

Direction

Controls