Skip to content
arrow_back
ISM-1461policyASD Information Security Manual (ISM)

Same Classification and Security Domain for Shared Isolation Hosts

When software isolation shares one physical server for SECRET or TOP SECRET work, the server and every environment on it must be the same classification and security domain.

record_voice_over

Plain language

Some servers use software (called a hypervisor) to run several separate "virtual" computers on a single physical machine, all sharing the same hardware. This control says that if you do this for highly sensitive work classified as SECRET or TOP SECRET, then the physical server and every virtual environment running on it must all carry the same classification and belong to the same security domain (a group of systems trusted to handle the same level of information). In plain terms, you must not mix different sensitivity levels on the one shared machine, because software separation alone is not strong enough to keep top-secret information safe from less-trusted neighbours sharing the same hardware.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

When using a software-based isolation mechanism that consumes shared physical computing resources for SECRET or TOP SECRET operating environments, the physical server and all operating environments are of the same classification and belong to the same security domain.
policyASD Information Security Manual (ISM)ISM-1461
priority_high

Why it matters

Mixing different classifications or security domains on one shared physical server can let highly sensitive SECRET or TOP SECRET information leak to less-trusted environments through shared hardware.

settings

Operational notes

Re-check shared SECRET and TOP SECRET hosts whenever environments are added, moved or rebuilt, since software-based isolation alone does not justify mixing classifications or security domains.

build

Implementation tips

  • The IT or infrastructure team should keep a register that lists each physical server using software-based isolation, recording its classification and security domain so it is clear no SECRET or TOP SECRET host is shared with anything of a different level.
  • System administrators should configure virtualisation hosts so that only operating environments of the identical classification and security domain can be created or migrated onto a given physical server, blocking mixed-level placement at the configuration stage.
  • The team setting up SECRET or TOP SECRET systems should label each physical server and every virtual environment on it with its classification, and verify all labels match before the server is put into use.
  • Change managers should add a check to the approval process so that any request to add a new virtual environment to a shared SECRET or TOP SECRET host is rejected unless it has the same classification and security domain.
  • The security or governance lead should arrange periodic reviews of shared SECRET and TOP SECRET hosts to confirm no lower-classification or different-domain environment has been added over time.
fact_check

Audit / evidence tips

  • Askthe inventory of physical servers that use software-based isolation for SECRET or TOP SECRET workLook atwhether each entry records the classification and security domain of the host and every environment on itGoodis a complete, current register showing all match on each shared host
  • Askhow the organisation prevents environments of different classifications from sharing one physical serverLook atthe virtualisation host configuration and placement rulesGoodshows technical controls that stop mixed-level environments being placed together, not just a written policy
  • Askto see the classification labels for a sample SECRET or TOP SECRET shared server and its virtual environmentsLook atwhether the physical host label matches every operating environment running on itGoodis consistent labelling with no mismatches
  • Askthe change-control records covering additions of new virtual environments to shared high-classification hostsLook atwhether each approval confirmed matching classification and security domainGoodshows approvals explicitly verified this before deployment
  • Askthe most recent review of shared SECRET and TOP SECRET hostsLook atthe findings and any corrective actionsGoodis a dated review confirming all environments on each host share the same classification and domain, with issues tracked to closure
link

Cross-framework mappings

How ISM-1461 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
extensionDepends on(1)expand_less
Annex A 5.12ISM-1461 requires that when virtualisation is used to share a physical server for SECRET or TOP SECRET computing environments, the host a...

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-RA-ML2.3ISM-1461 requires same-classification and same-security-domain co-tenancy when virtualising SECRET or TOP SECRET environments on shared p...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls