Secure By Design Vendor Isolation Mechanisms
Use software isolation tools from vendors committed to secure design principles and practices.
Plain language
This control is about making sure the software you use to separate different parts of your computer or network comes from a trusted vendor. If the vendor doesn't follow safe design practices, you could be left vulnerable to security breaches, putting your data and operations at risk.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Virtualisation HardeningOfficial control statement
When using a software-based isolation mechanism that consumes shared physical computing resources, the isolation mechanism is from a vendor that has demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices.
Why it matters
Using untrusted vendors for isolation mechanisms can lead to security breaches, exposing sensitive data and potentially bringing business operations to a halt.
Operational notes
Regularly review and update vendor agreements to ensure continued adherence to security standards as technology and threats evolve.
Implementation tips
- The IT team should assess current software vendors. Ensure they follow security best practices by reviewing their design and development processes. This means checking if vendors use safe programming methods and languages to prevent security flaws.
- Procurement should work closely with the IT team to choose vendors. Focus on those who actively demonstrate 'Secure by Design' principles. Seek recommendations or case studies that show their commitment to security in their products.
- Managers should ensure regular training sessions for staff. Emphasise the importance of choosing and using software from reputable vendors, highlighting the potential risks of using poorly designed software.
- IT teams should perform regular audits of vendor software. Check for ongoing commitment to updates and security patching. This involves reviewing vendor communication and ensuring they provide timely updates for any security vulnerabilities.
- Executives should allocate budget for security-oriented software vendors. Highlight the necessity of investing in securely designed software as a way to prevent costly breaches and demonstrate to stakeholders a commitment to security.
Audit / evidence tips
- Askvendor documentation showing their secure design processLook atthe details of their security practices and any certificationsGoodwill include documentation of 'Secure by Design' principles and recent security audits
- Goodis a list showing the use of safe languages and practices
- Aska record of software updates and patches from vendorsLook atthe frequency and nature of updatesGoodis regular updates, especially for any security issues
- Goodincludes regular, comprehensive training sessions specifically addressing secure software use
- Askvendor selection criteria documents from the procurement teamLook atsecurity considerations within these criteriaGoodwill show a prioritisation of security and reputable vendor practices
Cross-framework mappings
How ISM-1460 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.27 | ISM-1460 requires that when an organisation uses software-based isolation to share a physical server, the isolation mechanism comes from ... | |
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.28 | ISM-1460 requires the isolation mechanism vendor to demonstrate Secure by Design/Secure by Default practices, explicitly calling out secu... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.