Skip to content
arrow_back
search
ISM-0535 policy ASD Information Security Manual (ISM)

Prevent VLAN Trunk Sharing Across Security Domains

Ensure network devices do not use shared paths for VLANs from different security areas.

record_voice_over

Plain language

This control is about keeping computer networks safe by not letting different areas of your business share the same connection paths for their computer traffic. If this isn't done, sensitive information from one part of the business could leak into another, leading to privacy breaches or security incidents.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Network devices managing VLANs belonging to different security domains do not share VLAN trunks.
policy ASD Information Security Manual (ISM) ISM-0535
priority_high

Why it matters

If VLAN trunks are shared between security domains, traffic can cross domains via mis-tagging or leaks, causing unauthorised disclosure of sensitive data.

settings

Operational notes

Verify trunk ports only carry VLANs for a single security domain; remove unused VLANs, restrict allowed VLAN lists, and routinely review switch trunk configs.

Mapping detail

Mapping

Direction

Controls