Skip to content
arrow_back
search
ISM-1274 policy ASD Information Security Manual (ISM)

Ensure Non-Production Databases Match Production Security

Production data can only be used in non-production areas if they are secured equally as well.

record_voice_over

Plain language

When using copies of your main, everyday database for testing or development, those copies need to be protected just as well as the original. If not, sensitive information could be leaked, leading to privacy breaches or other security issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Database contents from production environments are not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
policy ASD Information Security Manual (ISM) ISM-1274
priority_high

Why it matters

Using production data in a less-secure non-production environment can expose sensitive records, causing breaches, loss of trust and compliance penalties.

settings

Operational notes

Do not copy production data into dev/test unless the environment meets production-equivalent controls (access, logging, encryption). Otherwise use masked/synthetic data.

Mapping detail

Mapping

Direction

Controls