Skip to content
arrow_back
search
ISM-0521 policy ASD Information Security Manual (ISM)

Disable Unused IPv6 on Dual-Stack Devices

Turn off IPv6 capabilities on network devices unless they are actively being used.

record_voice_over

Plain language

This control is about turning off IPv6 on devices that use both older and newer internet protocols unless the newer one is needed. This is important because leaving extra connections open on your network can expose your business to unnecessary risks, such as cyber-attacks that target unused pathways.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IPv6 functionality is disabled in dual-stack network devices unless it is being used.
policy ASD Information Security Manual (ISM) ISM-0521
priority_high

Why it matters

If IPv6 remains enabled but unused on dual-stack devices, attackers can exploit IPv6 paths to bypass IPv4 controls, enabling unauthorised access.

settings

Operational notes

Audit dual-stack devices for IPv6 use; if not required, disable IPv6 on interfaces and OS stacks, and confirm monitoring and firewall rules cover any remaining IPv6.

Mapping detail

Mapping

Direction

Controls