Skip to content
arrow_back
search
ISM-1158 policy ASD Information Security Manual (ISM)

High Assurance Evaluation for Network Diodes

Diodes ensure secure, one-way data flow between secret and other networks.

Preventative S TS ASD Information Security ManualGuidelines for gatewayshigh assurancenetwork security
record_voice_over

Plain language

This control is about ensuring that any special equipment called a 'network diode' used to send information in one direction between highly secure networks and other networks has been thoroughly checked for security. This matters because without these checks, sensitive information could accidentally or maliciously leak into less secure areas, leading to serious security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Evaluated diodes used for controlling the data flow of unidirectional gateways between SECRET or TOP SECRET networks and any other networks complete a high assurance evaluation.
policy ASD Information Security Manual (ISM) ISM-1158
priority_high

Why it matters

If a diode lacks a high assurance evaluation, unidirectional gateways may fail, enabling data leakage from SECRET/TOP SECRET networks to lower domains.

settings

Operational notes

Use only network diodes that have completed high assurance evaluation; confirm model/firmware against evaluated product lists and re-check status after upgrades or replacements.

Mapping detail

Mapping

Direction

Controls