Skip to content
arrow_back
search
ISM-1522 policy ASD Information Security Manual (ISM)

Ensure CDSs Separate Upward and Downward Data Paths

CDSs have independent security controls for data going both up and down between networks.

record_voice_over

Plain language

A Cross Domain Solution (CDS) ensures that when information is sent between different networks, the path for sending information from a less sensitive network to a more sensitive one is kept separate from the path going in the opposite direction. This is important because mixing these paths could allow unauthorised access to sensitive information or cause data leaks, similar to leaving a door unlocked for outsiders to slip in unnoticed.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

CDSs implement independent security-enforcing functions for upward and downward network paths.
policy ASD Information Security Manual (ISM) ISM-1522
priority_high

Why it matters

Improper separation can allow cross-domain leakage or a bypass, enabling data exfiltration downward or compromise of high-side networks via the wrong path.

settings

Operational notes

Regularly confirm CDSs enforce separate, independent security functions for upward and downward paths, and test that failures in one path cannot affect the other.

Mapping detail

Mapping

Direction

Controls