Skip to content
arrow_back
search
ISM-1524 policy ASD Information Security Manual (ISM)

Ensure Rigorous Testing of Content Filters

Content filters need thorough testing to make sure they work properly and can't be bypassed.

record_voice_over

Plain language

This control is about making sure that content filters, which block harmful or unwanted information from entering an organisation's systems, are thoroughly tested. If these filters don't work properly or can be easily bypassed, the organisation is at risk of data breaches, exposure to malware, or inappropriate content reaching employees, which could lead to legal trouble or damage to the organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Content filters used by CDSs undergo rigorous security testing to ensure they perform as expected and cannot be bypassed.
policy ASD Information Security Manual (ISM) ISM-1524
priority_high

Why it matters

Poorly tested CDS content filters may be bypassed, enabling unauthorised data transfer or malware ingress and causing breaches.

settings

Operational notes

Routinely regression-test CDS content filters using known bypass cases (encoding tricks, polyglots, archives, malformed files) and verify blocks.

Mapping detail

Mapping

Direction

Controls