Skip to content
arrow_back
search
ISM-0530 policy ASD Information Security Manual (ISM)

Administer VLANs from Trusted Security Domains

VLANs must be managed from the most secure and trusted part of the network.

record_voice_over

Plain language

When managing Virtual Local Area Networks (VLANs), it's important they are controlled from the safest part of your network. If not done correctly, hackers or unauthorised people could change your network setup, leading to data theft or disruptions in your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Network devices managing VLANs are administered from the most trusted security domain.
policy ASD Information Security Manual (ISM) ISM-0530
priority_high

Why it matters

If VLANs are administered from less-trusted domains, attackers can alter VLAN configs or intercept management traffic, causing outages and breaches.

settings

Operational notes

Administer VLAN changes only from the most trusted domain via a dedicated management network/jump host, and alert on unauthorised access.

Mapping detail

Mapping

Direction

Controls