Skip to content
arrow_back
search
ISM-0616 policy ASD Information Security Manual (ISM)

Ensure Separation of Duties for Gateway Admins

Different people handle administrative tasks for gateways to reduce security risks.

record_voice_over

Plain language

Separating duties for those who manage the gateways of a network means different people handle different tasks to reduce risks. This is important because if one person controls everything, they could make a mistake or do something harmful, putting the whole network at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Separation of duties is implemented in performing administrative activities for gateways.
policy ASD Information Security Manual (ISM) ISM-0616
priority_high

Why it matters

Without separation of duties for gateway admins, a single error or malicious act could change gateway rules and expose the network to unauthorised access.

settings

Operational notes

Define distinct gateway admin tasks (e.g., rule changes vs approval), enforce dual approval for changes, and review role assignments regularly to prevent overlap.

Mapping detail

Mapping

Direction

Controls