Skip to content
arrow_back
search
ISM-1271 policy ASD Information Security Manual (ISM)

Restrict Network Access to Database Servers

Database server communications are limited to necessary network resources only.

record_voice_over

Plain language

This control is about making sure that your database servers only communicate with parts of the network that really need to. It matters because if you don't do this, hackers could more easily sneak into other sensitive parts of your network through the database, potentially leading to data theft or system disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Network access controls are implemented to restrict database server communications to strictly defined network resources that require access to the database server.
policy ASD Information Security Manual (ISM) ISM-1271
priority_high

Why it matters

If database servers allow broad network access, attackers can reach exposed database ports, leading to unauthorised data access, breaches and server compromise.

settings

Operational notes

Restrict database server ports to approved subnets/hosts only; regularly review firewall/ACL allow-lists and alert on failed or unexpected connections to database services.

Mapping detail

Mapping

Direction

Controls