Segregate Public Wireless Networks from Organisation Networks
Ensure public wireless networks are separate from organisation networks for security.
Plain language
This control is about keeping your business's internal network separate from the public Wi-Fi you offer visitors. If you don't separate these networks, a hacker using the public Wi-Fi could jump across and access sensitive company information.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Public wireless networks provided for public use are segregated from all other organisation networks.
Why it matters
Merging public and private networks risks exposing sensitive company data to unauthorised access, leading to data breaches.
Operational notes
Regularly review network settings and policies to ensure continued segregation between public and private networks, preventing unauthorised access.
Implementation tips
- The IT team should set up the wireless network: Ensure there's a separate wireless network specifically for staff and another for public use. This can usually be done by setting up different network names (SSIDs) for each purpose.
- Managers should communicate clear usage policies: Make sure staff know which Wi-Fi network to connect to and why it's important. This helps prevent accidental connections to public networks by employees.
- The IT team should use network segmentation tools: Implement tools or hardware that physically and logically separate the networks. This may involve using different routers or configuring virtual local area networks (VLANs).
- HR should provide ongoing training: Regularly educate employees about the risks of using public networks. Training should include how to identify the correct network and the dangers of using public ones for sensitive work.
- The IT team should audit networks regularly: Schedule periodic checks to ensure that the networks remain securely separated. This can involve testing the network configurations to confirm no crossover.
Audit / evidence tips
- Asknetwork configuration documentation: Request network setup documents outlining the separationLook atnetwork tables or maps to see if staff and public networks are distinctGoodwill show separate configurations for each network
- Look athardware placements and connectionsGoodsetup uses dedicated devices for public and private networks
- Look atalerts or logs showing attempts to cross from public to private networksGoodshows no successful connection attempts between the networks
- Askevidence of staff training sessions: Request attendance records or training materials that cover network separationGoodwill include dates and content covered in the training
- Look atpolicy documents regarding network use: Check the policies provided to staff about which networks to useGoodpolicy clearly instructs staff to use internal networks for work purposes only
Cross-framework mappings
How ISM-0536 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.22 | ISM-0536 requires that public wireless networks provided for general public use are segregated from all other organisation networks | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Networking
See all Guidelines for networking controls, or browse the full ASD ISM library.