Skip to content
arrow_back
search
ISM-0635 policy ASD Information Security Manual (ISM)

Ensure Network Paths are Isolated in CDSs

Systems manage separate and secure network paths for upward and downward data movements to prevent security breaches.

record_voice_over

Plain language

This control is about keeping certain types of data moving in one direction only on a network, so it doesn’t mix up with other data. By doing this, organisations protect themselves from unwanted data leaks or security breaches that could lead to sensitive information falling into the wrong hands.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

CDSs implement isolated upward and downward network paths.
policy ASD Information Security Manual (ISM) ISM-0635
priority_high

Why it matters

Failing to isolate upward and downward CDS network paths can enable data to traverse between domains, causing cross-contamination, data leakage and unauthorised access.

settings

Operational notes

Regularly validate CDS architecture keeps upward and downward paths physically/logically separated, and test permitted flows to confirm no unintended bridging or reverse transfer.

Mapping detail

Mapping

Direction

Controls