Skip to content
arrow_back
search
ISM-1782 policy ASD Information Security Manual (ISM)

Use Protective DNS to Block Malicious Domains

A service that prevents access to harmful website addresses.

record_voice_over

Plain language

A protective DNS service acts as a filter for internet connections by blocking access to known harmful websites. This matters because if you're not blocking these bad sites, you risk exposing your systems to viruses, data theft, or disruptions that can damage your business or organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A protective DNS service is used to block access to known malicious domain names.
policy ASD Information Security Manual (ISM) ISM-1782
priority_high

Why it matters

Without protective DNS filtering, users may resolve and connect to known malicious domains, increasing malware infection and credential theft risk.

settings

Operational notes

Ensure the protective DNS service ingests current threat intel feeds and review allow/block exceptions regularly to prevent bypass and false positives.

Mapping detail

Mapping

Direction

Controls