Skip to content
arrow_back
search
ISM-0634 policy ASD Information Security Manual (ISM)

Central Logging for Gateway Security Events

Log gateway events and alerts to monitor data flows and detect intrusion attempts.

record_voice_over

Plain language

This control is about making sure all the important activities happening at your internet gateways are logged and tracked. By doing this, you can catch any suspicious attempts to access or send data through your network. If you skip this, you might miss warning signs of a potential data breach or hacker, which could lead to loss of sensitive information and a damaged reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security-relevant events for gateways are centrally logged, including: - data packets and data flows permitted through gateways - data packets and data flows attempting to leave gateways - real-time alerts for attempted intrusions.
policy ASD Information Security Manual (ISM) ISM-0634
priority_high

Why it matters

Failure to centrally log gateway packet/flow events and intrusion alerts can hide data exfiltration paths and successful intrusion attempts, increasing breach impact.

settings

Operational notes

Centrally collect gateway permit/deny flow logs and intrusion alerts; regularly validate log delivery, retention, and alert tuning to detect exfiltration attempts.

Mapping detail

Mapping

Direction

Controls