Skip to content
arrow_back
search
ISM-1439 policy ASD Information Security Manual (ISM)

Restrict IP Disclosure in CDNs

Avoid sharing web server IPs and limit access to them by CDNs and authorised networks for security.

record_voice_over

Plain language

This control is about making sure only certified networks, like Content Delivery Networks (CDNs), know the IP addresses of your web servers. If these IP addresses get into the wrong hands, cyber attackers could bypass your security and directly attack your servers.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If using CDNs, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the CDNs and authorised management networks.
policy ASD Information Security Manual (ISM) ISM-1439
priority_high

Why it matters

Exposing origin server IPs enables attackers to bypass CDN protections, directly target the origin, and cause outages or data compromise.

settings

Operational notes

Maintain allowlists so origin servers only accept traffic from CDN egress IP ranges and authorised management networks; review and update rules when CDN IPs change.

Mapping detail

Mapping

Direction

Controls