Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0639Use Evaluated Firewalls Between Security Domains

Official control statement

Evaluated firewalls are used between networks belonging to different security domains.
policyASD Information Security Manual (ISM)ISM-0639

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Firewalls that have been independently evaluated are deployed between networks belonging to different security domains to control the traffic crossing each boundary.

NCOSPASD Information Security ManualGuidelines for gateways
Control Stack classificationPreventativeFirewallsNetwork segmentation
record_voice_over

What this means in practice

This control ensures that wherever two networks belong to different security domains, the firewall placed between them has been independently evaluated. An evaluated firewall has had its security functionality tested and verified by a trusted third party, so the organisation can rely on it to enforce traffic rules correctly at a sensitive boundary. Using an unevaluated firewall at such a point risks the device failing to block malicious or unauthorised traffic passing between domains of differing sensitivity.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2022

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Section

Firewalls

Topic

Using firewalls

priority_high

Why it matters

Without evaluated firewalls at these boundaries, traffic between security domains of differing sensitivity may not be reliably controlled, allowing unauthorised access or data leakage between domains.

settings

Operational notes

Periodically review the evaluation status and version of each boundary firewall, as certifications can lapse and devices can be replaced or upgraded over time.

build

Implementation tips

  • Have network architects identify every boundary where networks of different security domains meet, and document which firewall is required at each of these points.
  • When procuring firewalls for inter-domain boundaries, have the security team select products that carry a recognised independent evaluation, such as Common Criteria certification.
  • Deploy each evaluated firewall inline between the two security domains so that all traffic crossing the boundary must pass through it.
  • Configure each firewall to match the evaluated configuration described in its certification documentation so it operates exactly as it was tested.
  • Maintain a register recording the evaluation status and evaluated version of every boundary firewall, and update it whenever devices are added, replaced or upgraded.
fact_check

Audit / evidence tips

  • AskAsk for a list of all boundaries between networks belonging to different security domains and the firewall deployed at each.Look atNetwork architecture diagrams and the asset register of boundary firewalls.GoodEvery inter-domain boundary has a dedicated firewall recorded against it, with none missing.
  • AskAsk for evidence that each boundary firewall has been independently evaluated.Look atEvaluation certificates or product listings, for example Common Criteria certification records, for each device.GoodA valid evaluation certificate matches the make, model and version of every firewall used at these boundaries.
  • AskAsk how the team confirmed the firewalls are running in their evaluated configuration.Look atLive firewall configuration compared against the evaluated configuration guidance in the certification report.GoodConfigurations align with the evaluated settings, and any deviations are documented and risk-assessed.
  • AskAsk for proof that inter-domain traffic actually traverses the evaluated firewall.Look atRouting tables, firewall logs and traffic flow records at each boundary.GoodLogs confirm all traffic between the domains passes through the evaluated firewall with no bypass paths.
  • AskAsk how the organisation keeps the evaluation status of boundary firewalls current.Look atChange and procurement records alongside the firewall register.GoodThe register is up to date, and any newly added or upgraded boundary firewalls were confirmed as evaluated before deployment.
link

Cross-framework mappings

How ISM-0639 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 8.20ISM-0639 addresses high-assurance evaluation and use of firewalls/diode gateways between different security domains
Annex A 8.22ISM-0639 requires the use of evaluated (high assurance) firewalls/diode gateway solutions when interconnecting networks in different secu...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for gateways controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls