Skip to content
arrow_back
search
ISM-1529 policy ASD Information Security Manual (ISM)

Limit Cloud Services to Community or Private for SECRETS

For SECRET or TOP SECRET services, only community or private clouds should be used to ensure security.

record_voice_over

Plain language

When dealing with SECRET or TOP SECRET information, it's crucial to use cloud services that are either exclusively public or private. This helps protect extremely sensitive data from being exposed or accessed by unauthorised parties. If these precautions aren't taken, confidential secrets might get leaked, which could severely harm your organisation's reputation and security.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Only community or private clouds are used for outsourced SECRET and TOP SECRET cloud services.
policy ASD Information Security Manual (ISM) ISM-1529
priority_high

Why it matters

Using public clouds for SECRET info risks data leaks, potentially compromising national security and damaging organisational trust.

settings

Operational notes

Confirm outsourced SECRET/TOP SECRET workloads run only in community or private clouds; periodically validate the service’s cloud model and contract terms.

Mapping detail

Mapping

Direction

Controls