Unpack Archive Files for Content Filtering at Gateways
Archive files moving through gateways or Cross Domain Solutions are unpacked first so their contents can be content-filtered before being allowed through.
Plain language
When compressed bundles of files (called archive files, such as ZIP files) are sent in or out through your security checkpoints, they must be opened up so the security checks can look inside. The checkpoints here are gateways (the controlled doorway between your network and the outside world) and Cross Domain Solutions, or CDSs (special systems that move data between networks of different sensitivity). If an archive is not unpacked first, harmful files can hide inside it and slip past your filtering unchecked.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Archive files imported or exported via gateways or CDSs are unpacked to undergo content filtering checks.
Why it matters
If archives pass through gateways or Cross Domain Solutions without being unpacked, malware or unauthorised data can hide inside them and bypass filtering, leading to infection or data leakage.
Operational notes
Review the unpacking and filtering rules whenever new archive formats appear or the gateway is updated, and re-run a test archive to confirm filtering still applies to extracted contents.
Implementation tips
- IT or the gateway administrator configures the gateway and any Cross Domain Solution (CDS) to automatically decompress incoming and outgoing archive files (such as ZIP, RAR, 7z and TAR) before the content filtering rules run on them.
- The security team enables recursive unpacking so that archives nested inside other archives are also opened, and sets a sensible depth limit so deeply nested files cannot be used to bypass or overload the filtering.
- The gateway administrator sets the filtering policy to block or quarantine any archive that cannot be fully unpacked, such as password-protected or corrupted files, rather than letting it pass through unchecked.
- IT configures the system to apply the same content filtering checks (for example malware scanning and file type checks) to every file extracted from an archive, not just to the outer archive itself.
- The security team tests the configuration regularly by sending a known test archive (such as one containing the EICAR test file) through the gateway to confirm it is unpacked and the contents are filtered as expected.
Audit / evidence tips
- Askthe gateway and Cross Domain Solution (CDS) configuration that handles archive filesLook atwhether decompression is set to run before content filteringGoodshows the unpack step happens first and feeds every extracted file into the filtering rules
- Askhow nested archives (an archive inside an archive) are handledLook atthe recursive unpacking settings and any depth limitGoodshows nested files are opened and filtered, with a limit that prevents abuse
- Askwhat happens to archives that cannot be unpacked, such as encrypted or password-protected filesLook atthe policy ruleGoodshows these are blocked or quarantined, not allowed through
- Askrecent filtering logs or quarantine recordsLook atentries showing archives being unpacked and individual files being scanned or blockedGoodshows real examples of extracted files being acted on
- Askevidence of testingLook atresults from sending a test archive (for example one with the EICAR test file) through the gatewayGoodshows the archive was unpacked and the threat inside was detected and stopped
Cross-framework mappings
How ISM-1289 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.7 | ISM-1289 requires archive files imported or exported via gateways or CDSs to be unpacked so the extracted contents can be content-filtere... | |
handshakeSupports(1)expand_less | ||
| Annex A 8.20 | ISM-1289 requires gateways or CDSs to unpack archive files so content filtering can be applied to the extracted files during import/export | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Gateways
See all Guidelines for gateways controls, or browse the full ASD ISM library.