Skip to content
arrow_back
search
ISM-0267 policy ASD Information Security Manual (ISM)

Blocking Access to Unapproved Webmail Services

Prevent access to webmail services that haven't been approved by the organisation.

record_voice_over

Plain language

This control is about stopping people in your business from using email services that your organisation hasn't approved. It matters because using unapproved email services can increase the risk of sensitive information leaking out, which can lead to data breaches and damage to your organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Access to non-approved webmail services is blocked.
policy ASD Information Security Manual (ISM) ISM-0267
priority_high

Why it matters

Unapproved webmail can expose sensitive data to unauthorised entities, leading to data breaches and reputational damage.

settings

Operational notes

Maintain an approved webmail allowlist and enforce blocks via proxy/DNS/firewall; review logs regularly and update rules as services change.

Mapping detail

Mapping

Direction

Controls