Skip to content
arrow_back
ISM-1826policyASD Information Security Manual (ISM)

Select Vendors Committed to Secure Design for Servers

Choose server vendors who ensure secure designs and use safe programming practices.

record_voice_over

Plain language

When choosing companies to buy your computer servers from, make sure they are serious about safety from the very start. This matters because if the computer servers are not built securely, they can be more easily hacked, which could lead to loss of customer information, downtime, or financial trouble.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Vendors that have demonstrated a commitment to Secure by Design and Secure by Default principles and practices, including secure programming practices and either memory-safe programming languages or less preferably memory-safe programming practices, are used for server applications.
policyASD Information Security Manual (ISM)ISM-1826
priority_high

Why it matters

Choosing server app vendors without Secure by Design/Default increases bug density and memory-safety flaws, enabling RCE, data loss and outages.

settings

Operational notes

Require evidence of Secure by Design/Default (SDLC, secure coding, VDP). Prefer memory-safe languages; otherwise verify mitigations and testing for memory bugs.

build

Implementation tips

  • IT teams should ask vendors about their security practices: Contact vendor representatives to learn about how they ensure their server products are secure from the start. Inquire about their use of memory-safe programming languages or techniques.
  • Managers should evaluate vendor security certifications: Ensure that vendors have relevant security certifications such as ISO 27001 or attestations that show their commitment to secure designs. Request documentation or proof of certification from vendors.
  • System administrators should test the security features: Once servers are purchased, they should be tested in a controlled environment to confirm advertised security features are present and working. Use tools to verify if security settings are enabled by default.
  • Procurement teams should keep records of vendor assessments: Create a file or database entry for each vendor that lists their security practices, certifications, and evaluation results. This ensures there is a record to refer back to for future purchases.
fact_check

Audit / evidence tips

  • AskVendor security policy documents: Request copies of vendor documentation that describe their Secure by Design and Secure by Default policiesGoodContains detailed descriptions of how security is integrated into server design
  • AskVendor compliance reports: Request any reports that show the vendor's compliance with security standardsGoodWould show up-to-date, clean compliance reports with recognitions by third parties
  • AskTo see records of vendor evaluations: Review procurement records to see the criteria used to assess server vendorsGoodMeans seeing detailed assessments focusing on security
  • AskTo see server security configuration tests: Request demonstration results of security configurations on newly purchased serversGoodShows comprehensive tests confirming security settings are as specified
  • AskTo see meeting minutes from procurement discussionsGoodHas minutes showing security was a key topic of discussion with actions assigned to verify it
link

Cross-framework mappings

How ISM-1826 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(3)expand_less
Annex A 5.19ISM-1826 requires organisations to choose server vendors that demonstrate commitment to Secure by Design and secure programming practices...
Annex A 5.21ISM-1826 requires organisations to select server application vendors committed to Secure by Design/Secure by Default practices, including...
Annex A 5.22ISM-1826 requires selecting vendors whose server applications are engineered with Secure by Design/Secure by Default and strong secure pr...
sync_altPartially overlaps(1)expand_less
Annex A 8.30ISM-1826 requires choosing server application vendors that demonstrate secure design and secure programming practices, including preferen...
handshakeSupports(3)expand_less
Annex A 8.25ISM-1826 requires selecting vendors who build server applications using Secure by Design/Secure by Default principles and secure programm...
Annex A 8.27ISM-1826 requires the organisation to select server vendors that demonstrate Secure by Design/Secure by Default and strong secure program...
Annex A 8.28ISM-1826 requires selecting vendors for server applications who apply secure programming practices and, preferably, use memory-safe progr...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls