ASD ISM 0639Use Evaluated Firewalls Between Security Domains
Official control statement
Evaluated firewalls are used between networks belonging to different security domains.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Firewalls that have been independently evaluated are deployed between networks belonging to different security domains to control the traffic crossing each boundary.
What this means in practice
This control ensures that wherever two networks belong to different security domains, the firewall placed between them has been independently evaluated. An evaluated firewall has had its security functionality tested and verified by a trusted third party, so the organisation can rely on it to enforce traffic rules correctly at a sensitive boundary. Using an unevaluated firewall at such a point risks the device failing to block malicious or unauthorised traffic passing between domains of differing sensitivity.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2022
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Why it matters
Without evaluated firewalls at these boundaries, traffic between security domains of differing sensitivity may not be reliably controlled, allowing unauthorised access or data leakage between domains.
Operational notes
Periodically review the evaluation status and version of each boundary firewall, as certifications can lapse and devices can be replaced or upgraded over time.
Implementation tips
- Have network architects identify every boundary where networks of different security domains meet, and document which firewall is required at each of these points.
- When procuring firewalls for inter-domain boundaries, have the security team select products that carry a recognised independent evaluation, such as Common Criteria certification.
- Deploy each evaluated firewall inline between the two security domains so that all traffic crossing the boundary must pass through it.
- Configure each firewall to match the evaluated configuration described in its certification documentation so it operates exactly as it was tested.
- Maintain a register recording the evaluation status and evaluated version of every boundary firewall, and update it whenever devices are added, replaced or upgraded.
Audit / evidence tips
- AskAsk for a list of all boundaries between networks belonging to different security domains and the firewall deployed at each.Look atNetwork architecture diagrams and the asset register of boundary firewalls.GoodEvery inter-domain boundary has a dedicated firewall recorded against it, with none missing.
- AskAsk for evidence that each boundary firewall has been independently evaluated.Look atEvaluation certificates or product listings, for example Common Criteria certification records, for each device.GoodA valid evaluation certificate matches the make, model and version of every firewall used at these boundaries.
- AskAsk how the team confirmed the firewalls are running in their evaluated configuration.Look atLive firewall configuration compared against the evaluated configuration guidance in the certification report.GoodConfigurations align with the evaluated settings, and any deviations are documented and risk-assessed.
- AskAsk for proof that inter-domain traffic actually traverses the evaluated firewall.Look atRouting tables, firewall logs and traffic flow records at each boundary.GoodLogs confirm all traffic between the domains passes through the evaluated firewall with no bypass paths.
- AskAsk how the organisation keeps the evaluation status of boundary firewalls current.Look atChange and procurement records alongside the firewall register.GoodThe register is up to date, and any newly added or upgraded boundary firewalls were confirmed as evaluated before deployment.
Cross-framework mappings
How ISM-0639 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 8.20 | ISM-0639 addresses high-assurance evaluation and use of firewalls/diode gateways between different security domains | |
| Annex A 8.22 | ISM-0639 requires the use of evaluated (high assurance) firewalls/diode gateway solutions when interconnecting networks in different secu... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Gateways
See all Guidelines for gateways controls, or browse the full ASD ISM library.