Same Classification and Security Domain for Shared Isolation Hosts
When software isolation shares one physical server for SECRET or TOP SECRET work, the server and every environment on it must be the same classification and security domain.
Plain language
Some servers use software (called a hypervisor) to run several separate "virtual" computers on a single physical machine, all sharing the same hardware. This control says that if you do this for highly sensitive work classified as SECRET or TOP SECRET, then the physical server and every virtual environment running on it must all carry the same classification and belong to the same security domain (a group of systems trusted to handle the same level of information). In plain terms, you must not mix different sensitivity levels on the one shared machine, because software separation alone is not strong enough to keep top-secret information safe from less-trusted neighbours sharing the same hardware.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Virtualisation HardeningOfficial control statement
When using a software-based isolation mechanism that consumes shared physical computing resources for SECRET or TOP SECRET operating environments, the physical server and all operating environments are of the same classification and belong to the same security domain.
Why it matters
Mixing different classifications or security domains on one shared physical server can let highly sensitive SECRET or TOP SECRET information leak to less-trusted environments through shared hardware.
Operational notes
Re-check shared SECRET and TOP SECRET hosts whenever environments are added, moved or rebuilt, since software-based isolation alone does not justify mixing classifications or security domains.
Implementation tips
- The IT or infrastructure team should keep a register that lists each physical server using software-based isolation, recording its classification and security domain so it is clear no SECRET or TOP SECRET host is shared with anything of a different level.
- System administrators should configure virtualisation hosts so that only operating environments of the identical classification and security domain can be created or migrated onto a given physical server, blocking mixed-level placement at the configuration stage.
- The team setting up SECRET or TOP SECRET systems should label each physical server and every virtual environment on it with its classification, and verify all labels match before the server is put into use.
- Change managers should add a check to the approval process so that any request to add a new virtual environment to a shared SECRET or TOP SECRET host is rejected unless it has the same classification and security domain.
- The security or governance lead should arrange periodic reviews of shared SECRET and TOP SECRET hosts to confirm no lower-classification or different-domain environment has been added over time.
Audit / evidence tips
- Askthe inventory of physical servers that use software-based isolation for SECRET or TOP SECRET workLook atwhether each entry records the classification and security domain of the host and every environment on itGoodis a complete, current register showing all match on each shared host
- Askhow the organisation prevents environments of different classifications from sharing one physical serverLook atthe virtualisation host configuration and placement rulesGoodshows technical controls that stop mixed-level environments being placed together, not just a written policy
- Askto see the classification labels for a sample SECRET or TOP SECRET shared server and its virtual environmentsLook atwhether the physical host label matches every operating environment running on itGoodis consistent labelling with no mismatches
- Askthe change-control records covering additions of new virtual environments to shared high-classification hostsLook atwhether each approval confirmed matching classification and security domainGoodshows approvals explicitly verified this before deployment
- Askthe most recent review of shared SECRET and TOP SECRET hostsLook atthe findings and any corrective actionsGoodis a dated review confirming all environments on each host share the same classification and domain, with issues tracked to closure
Cross-framework mappings
How ISM-1461 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
extensionDepends on(1)expand_less | ||
| Annex A 5.12 | ISM-1461 requires that when virtualisation is used to share a physical server for SECRET or TOP SECRET computing environments, the host a... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| E8-RA-ML2.3 | ISM-1461 requires same-classification and same-security-domain co-tenancy when virtualising SECRET or TOP SECRET environments on shared p... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.