Skip to content
arrow_back
ISM-1460policyASD Information Security Manual (ISM)

Secure By Design Vendor Isolation Mechanisms

Use software isolation tools from vendors committed to secure design principles and practices.

record_voice_over

Plain language

This control is about making sure the software you use to separate different parts of your computer or network comes from a trusted vendor. If the vendor doesn't follow safe design practices, you could be left vulnerable to security breaches, putting your data and operations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.
policyASD Information Security Manual (ISM)ISM-1460
priority_high

Why it matters

Using untrusted vendors for isolation mechanisms can lead to security breaches, exposing sensitive data and potentially bringing business operations to a halt.

settings

Operational notes

Regularly review and update vendor agreements to ensure continued adherence to security standards as technology and threats evolve.

build

Implementation tips

  • The IT team should assess current software vendors. Ensure they follow security best practices by reviewing their design and development processes. This means checking if vendors use safe programming methods and languages to prevent security flaws.
  • Procurement should work closely with the IT team to choose vendors. Focus on those who actively demonstrate 'Secure by Design' principles. Seek recommendations or case studies that show their commitment to security in their products.
  • Managers should ensure regular training sessions for staff. Emphasise the importance of choosing and using software from reputable vendors, highlighting the potential risks of using poorly designed software.
  • IT teams should perform regular audits of vendor software. Check for ongoing commitment to updates and security patching. This involves reviewing vendor communication and ensuring they provide timely updates for any security vulnerabilities.
  • Executives should allocate budget for security-oriented software vendors. Highlight the necessity of investing in securely designed software as a way to prevent costly breaches and demonstrate to stakeholders a commitment to security.
fact_check

Audit / evidence tips

  • Askvendor documentation showing their secure design processLook atthe details of their security practices and any certificationsGoodwill include documentation of 'Secure by Design' principles and recent security audits
  • Goodis a list showing the use of safe languages and practices
  • Aska record of software updates and patches from vendorsLook atthe frequency and nature of updatesGoodis regular updates, especially for any security issues
  • Goodincludes regular, comprehensive training sessions specifically addressing secure software use
  • Askvendor selection criteria documents from the procurement teamLook atsecurity considerations within these criteriaGoodwill show a prioritisation of security and reputable vendor practices
link

Cross-framework mappings

How ISM-1460 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.27ISM-1460 requires that when an organisation uses software-based isolation to share a physical server, the isolation mechanism comes from ...
sync_altPartially overlaps(1)expand_less
Annex A 8.28ISM-1460 requires the isolation mechanism vendor to demonstrate Secure by Design/Secure by Default practices, explicitly calling out secu...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls