Skip to content
arrow_back
search
ISM-0263 policy ASD Information Security Manual (ISM)

Inspect and Decrypt TLS Traffic through Gateways

Gateways decrypt and check TLS internet traffic for safety reasons.

record_voice_over

Plain language

This control is about making sure the internet traffic that comes into and goes out of your organisation is safe. It does this by temporarily unlocking secure web traffic at a gateway to check for any potential threats, like viruses or hacking attempts. If left unchecked, harmful data can sneak through and cause major damage, like leaking confidential information or disrupting your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

TLS traffic communicated through gateways is decrypted and inspected.
policy ASD Information Security Manual (ISM) ISM-0263
priority_high

Why it matters

Without TLS decryption and inspection at gateways, malware and data exfiltration can hide in encrypted sessions, bypassing gateway security controls.

settings

Operational notes

Maintain gateway TLS interception certificates/keys, review SSL bypass/exemption lists, and verify decrypted traffic is logged and inspected for threats.

Mapping detail

Mapping

Direction

Controls