Skip to content
arrow_back
search
ISM-2059 policy ASD Information Security Manual (ISM)

Restrict and Scan File Uploads for Security

Ensure only certain file types are accepted and scanned for viruses before being accessed, executed, or stored.

record_voice_over

Plain language

This control is about making sure that when files are uploaded to your system, only certain types are allowed, and they must be scanned to ensure they're safe. It's important because harmful files could infect your system, leading to data loss or a security breach which could damage your business and reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

File uploads or input are restricted to specific file types, with malicious content scanning occurring prior to file access, file execution or file storage.
policy ASD Information Security Manual (ISM) ISM-2059
priority_high

Why it matters

Unrestricted file uploads can allow malicious files to be stored or executed, leading to malware infection, data loss, and service disruption.

settings

Operational notes

Maintain a strict allow-list of permitted upload types and ensure anti-malware scanning runs before any file is stored, accessed or executed.

Mapping detail

Mapping

Direction

Controls