Skip to content
arrow_back
search
ISM-1270 policy ASD Information Security Manual (ISM)

Separate Network Segments for Database Servers

Databases should be on a different network than user computers to enhance security.

record_voice_over

Plain language

This control is about keeping your database servers, which store important business information, on a separate computer network from the one your employees use for everyday tasks. This is like keeping your company's safe in a locked room with controlled access so outsiders and even some insiders can't easily get to it. If database servers are not separated, it increases the risk of unauthorised access, which could lead to data leaks, financial loss, or damage to your business's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Database servers are placed on a different network segment to user workstations.
policy ASD Information Security Manual (ISM) ISM-1270
priority_high

Why it matters

Without separating database servers from user workstations, a compromised endpoint can reach databases directly, enabling unauthorised access, exfiltration, or tampering.

settings

Operational notes

Place database servers in a separate VLAN/subnet from user networks; restrict inter-segment access with firewalls/ACLs to only required ports and source hosts.

Mapping detail

Mapping

Direction

Controls