Skip to content
arrow_back
search
ISM-0571 policy ASD Information Security Manual (ISM)

Ensure Secure Email Transmission via Gateways

Emails should be sent through secure and encrypted channels using central gateways.

record_voice_over

Plain language

This control ensures that when you're sending or receiving emails, they're going through a central system that makes sure they're both encrypted and authenticated. It matters because if emails aren't transmitted securely, sensitive information could be exposed to cybercriminals, leading to data breaches and loss of trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation's centralised email gateways.
policy ASD Information Security Manual (ISM) ISM-0571
priority_high

Why it matters

Without secure email gateways, intercepted emails expose sensitive data, risking breaches and damaging organisational trust.

settings

Operational notes

Regularly verify central email gateway routing and enforce authenticated, encrypted transport (e.g. TLS) for inbound and outbound mail.

build

Implementation tips

  • Email service providers should make sure all outgoing and incoming emails pass through a secured central gateway. This can be done by setting up your email accounts and settings so all email traffic is automatically routed through this gateway.
  • IT managers should configure the central email gateways to enforce encryption. They can do this by enabling Transport Layer Security (TLS) settings which scramble the email data during transmission.
  • Business owners should ensure their staff are using approved email services only. They can do this by communicating to employees which email systems are authorised and spot-checking to make sure personal accounts aren't being used.
  • System administrators should regularly update the gateway software to protect against new vulnerabilities. This involves checking for updates from the software vendor and applying them as soon as possible.
  • IT departments should implement and test the gateway's authentication systems regularly. This means setting up a process where emails are checked for valid sending and receiving parties, and holding periodic security tests to ensure everything works correctly.
fact_check

Audit / evidence tips

  • AskThe email gateway configuration settings: Obtain documentation showing how email traffic is routed and encrypted GoodIncludes a specified encryption method like TLS and a clear routing path through the gateway
  • GoodShows consistent updates aligned with vendor recommendations
  • AskA sample of email traffic logs from the gateway: Examine how email data is encrypted and authenticated during transmission GoodShows logs indicating all emails go through the gateway with encryption
  • GoodFeatures documented attendance and policy acknowledgment
  • AskTo see the list of approved email services: Verify the list against used accounts GoodConfirms only authorised services are in active use
link

Cross-framework mappings

How ISM-0571 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

Control Notes Details
layers Partially meets (1) expand_less
Annex A 5.14 ISM-0571 requires emails to be sent and received via an organisation's centralised email gateways using authenticated and encrypted channels
handshake Supports (1) expand_less
Annex A 8.24 ISM-0571 requires emails to traverse authenticated and encrypted channels via centralised email gateways

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

Mapping detail

Mapping

Direction

Controls