Skip to content
arrow_back
search
ISM-1269 policy ASD Information Security Manual (ISM)

Ensure Databases and Web Servers are Separated

Databases and web servers should be kept separate to enhance security.

record_voice_over

Plain language

This control is about keeping your database servers (where you store all your important data) separate from your web servers (which manage your website). Keeping these servers separate is crucial because it reduces the chances of an attacker accessing sensitive information if your website is hacked.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Database servers and web servers are functionally separated.
policy ASD Information Security Manual (ISM) ISM-1269
priority_high

Why it matters

Mixing databases and web servers invites attackers to access sensitive data via compromised web apps, risking data breaches.

settings

Operational notes

Regularly audit server connections to ensure strict separation and configure firewalls to limit inter-server communication.

Mapping detail

Mapping

Direction

Controls