Skip to content
arrow_back
search
ISM-0611 policy ASD Information Security Manual (ISM)

Restrict Privileges for Gateway Administrators

Gateway admins have only the necessary access permissions for their tasks.

record_voice_over

Plain language

This guideline is about making sure that people who manage gateway systems have just enough access to do their job and no more. If they have too much access, there's a higher chance of accidental or malicious damage, which could lead to data breaches or loss of service.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

System administrators for gateways are assigned the minimum privileges required to perform their duties.
policy ASD Information Security Manual (ISM) ISM-0611
priority_high

Why it matters

Excess gateway admin privileges can lead to unauthorised data access, increasing the risk of data breaches and service outages.

settings

Operational notes

Regularly review gateway admin accounts and role memberships to confirm only minimum required privileges are assigned, and promptly remove any unnecessary access.

Mapping detail

Mapping

Direction

Controls