ISM-0639

Evaluated firewalls are used between networks belonging to different security domains.

Topic
Using firewalls
Applicable to
all

History

Priority
must
Mar 2022
Evaluated firewalls are used between networks belonging to different security domains.
Miscellaneous changes were made to rationale and recommendations throughout the publication to clarify content without changing intent. This included a review from the Guidelines for System Hardening chapter through to the Guidelines for Data Transfers chapter.
Apr 2019
An evaluated firewall is used between networks belonging to different security domains.
Security control 0639 was modified to cover the use of evaluated firewalls between official networks belonging to different security domains.
Mar 2019
An evaluated firewall is used between official and classified networks, and classified networks belonging to different security domains.
2015
Agencies must use an ASD approved firewall between networks of different security domains.
2010
Agencies must use a firewall from DSD’s EPL, as shown in the table below, in their gateway when connectinga network to another network in a different security domain.
2008
Agencies must use devices that meet the minimum requirement and/or evaluated assurance level (EAL) as shown in the following table.