Skip to content
arrow_back
search
ISM-1420 policy ASD Information Security Manual (ISM)

Ensure Non-Production Security Matches Production

Data from live systems can't be used in test setups unless test setups are just as secure.

record_voice_over

Plain language

This control ensures that if you want to use real data from your live systems for testing purposes, your test environment must be just as secure as your live environment. If the test setup isn’t up to par, sensitive information could be exposed, leading to privacy breaches or data loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Data from production environments is not used in non-production environments unless the non-production environment is secured to at least the same level as the production environment.
policy ASD Information Security Manual (ISM) ISM-1420
priority_high

Why it matters

If non-production isn’t secured like production, using production data in test/dev can expose sensitive information and cause a breach.

settings

Operational notes

Only use production data in non-production when controls match production; verify via audits and apply equivalent access, logging and patching.

Mapping detail

Mapping

Direction

Controls