Skip to content
arrow_back
search
ISM-1577 policy ASD Information Security Manual (ISM)

Ensure Network Segregation from Service Providers

Ensure that an organisation's network is kept separate from its service providers' networks for better security.

record_voice_over

Plain language

This control is about making sure your organisation's network, the system your computers and data use to communicate, is kept separate from the networks of any external service providers you work with. This matters because if your networks are mixed, a security issue or attack on the service provider could spill over and affect your business, putting your data and operations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

An organisation's networks are segregated from their service providers' networks.
policy ASD Information Security Manual (ISM) ISM-1577
priority_high

Why it matters

A breach in a service provider's network could pivot into yours, causing unauthorised access, data theft, or outages if links aren’t segregated.

settings

Operational notes

Review and test segregation of provider connections (VLAN/VRF/ACLs, VPNs, routing, and firewall rules) and remediate any drift detected.

Mapping detail

Mapping

Direction

Controls