Skip to content
arrow_back
search
ISM-1931 policy ASD Information Security Manual (ISM)

Ensure SID Filtering for Domain and Forest Trusts

Enable SID filtering for enhanced security between domain and forest trusts.

record_voice_over

Plain language

This control is all about making sure that only the right people have access to the right things in your computer network. It involves setting up a security check called SID filtering, which helps prevent unauthorised access from other parts of your network. Without this, someone from another part of the network could potentially access sensitive information or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SID Filtering is enabled for domain and forest trusts.
policy ASD Information Security Manual (ISM) ISM-1931
priority_high

Why it matters

Without SID filtering on domain/forest trusts, attackers can inject SIDs to gain unauthorised access across trusts.

settings

Operational notes

Regularly verify SID filtering is enabled on all domain/forest trusts and review trust changes at least quarterly.

Mapping detail

Mapping

Direction

Controls