Skip to content
arrow_back
search
ISM-0258 policy ASD Information Security Manual (ISM)

Establish and Maintain a Web Usage Policy

Develop and maintain a policy to manage how the web is used and accessed.

record_voice_over

Plain language

A web usage policy is about setting clear rules for how employees can use the internet at work. This is important because without guidelines, people might visit unsafe websites, leading to potential security threats like viruses or data breaches, which can harm the business and its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A web usage policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-0258
priority_high

Why it matters

Without a web usage policy, staff may visit unsafe sites, increasing malware, credential theft and data leakage risk, and causing reputational damage.

settings

Operational notes

Review the web usage policy at least annually and after major incidents; brief staff on acceptable browsing and prohibited sites, and align it to current web threats.

Mapping detail

Mapping

Direction

Controls