Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0639Use Evaluated Firewalls Between Security Domains

Firewalls that have been independently evaluated are deployed between networks belonging to different security domains to control the traffic crossing each boundary.

record_voice_over

Plain language

This control ensures that wherever two networks belong to different security domains, the firewall placed between them has been independently evaluated. An evaluated firewall has had its security functionality tested and verified by a trusted third party, so the organisation can rely on it to enforce traffic rules correctly at a sensitive boundary. Using an unevaluated firewall at such a point risks the device failing to block malicious or unauthorised traffic passing between domains of differing sensitivity.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2022

Control Stack last updated

10 Aug 2026

E8 maturity levels

N/A

Official control statement

Evaluated firewalls are used between networks belonging to different security domains.
policyASD Information Security Manual (ISM)ISM-0639
priority_high

Why it matters

Without evaluated firewalls at these boundaries, traffic between security domains of differing sensitivity may not be reliably controlled, allowing unauthorised access or data leakage between domains.

settings

Operational notes

Periodically review the evaluation status and version of each boundary firewall, as certifications can lapse and devices can be replaced or upgraded over time.

build

Implementation tips

  • Have network architects identify every boundary where networks of different security domains meet, and document which firewall is required at each of these points.
  • When procuring firewalls for inter-domain boundaries, have the security team select products that carry a recognised independent evaluation, such as Common Criteria certification.
  • Deploy each evaluated firewall inline between the two security domains so that all traffic crossing the boundary must pass through it.
  • Configure each firewall to match the evaluated configuration described in its certification documentation so it operates exactly as it was tested.
  • Maintain a register recording the evaluation status and evaluated version of every boundary firewall, and update it whenever devices are added, replaced or upgraded.
fact_check

Audit / evidence tips

  • AskAsk for a list of all boundaries between networks belonging to different security domains and the firewall deployed at each.GoodEvery inter-domain boundary has a dedicated firewall recorded against it, with none missing.
  • AskAsk for evidence that each boundary firewall has been independently evaluated.GoodA valid evaluation certificate matches the make, model and version of every firewall used at these boundaries.
  • AskAsk how the team confirmed the firewalls are running in their evaluated configuration.GoodConfigurations align with the evaluated settings, and any deviations are documented and risk-assessed.
  • AskAsk for proof that inter-domain traffic actually traverses the evaluated firewall.GoodLogs confirm all traffic between the domains passes through the evaluated firewall with no bypass paths.
  • AskAsk how the organisation keeps the evaluation status of boundary firewalls current.GoodThe register is up to date, and any newly added or upgraded boundary firewalls were confirmed as evaluated before deployment.
link

Cross-framework mappings

How ISM-0639 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(3)expand_less
Annex A 8.12ISM-0639 requires evaluated diode gateways/firewalls to control and constrain traffic between different security domains, primarily to re...
Annex A 8.20ISM-0639 addresses high-assurance evaluation and use of firewalls/diode gateways between different security domains
Annex A 8.22ISM-0639 requires the use of evaluated (high assurance) firewalls/diode gateway solutions when interconnecting networks in different secu...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for gateways controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls