Skip to content
arrow_back
search
ISM-0571 policy ASD Information Security Manual (ISM)

Ensure Secure Email Transmission via Gateways

Emails should be sent through secure and encrypted channels using central gateways.

record_voice_over

Plain language

This control ensures that when you're sending or receiving emails, they're going through a central system that makes sure they're both encrypted and authenticated. It matters because if emails aren't transmitted securely, sensitive information could be exposed to cybercriminals, leading to data breaches and loss of trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation's centralised email gateways.
policy ASD Information Security Manual (ISM) ISM-0571
priority_high

Why it matters

Without secure email gateways, intercepted emails expose sensitive data, risking breaches and damaging organisational trust.

settings

Operational notes

Regularly verify central email gateway routing and enforce authenticated, encrypted transport (e.g. TLS) for inbound and outbound mail.

Mapping detail

Mapping

Direction

Controls