Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0874Ensure Internet Access via Organisation's Gateway

Official control statement

Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.
policyASD Information Security Manual (ISM)ISM-0874

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.

NCOSPASD Information Security ManualGuidelines for enterprise mobility
Control Stack classificationPreventativeMobile devicesInternet access
record_voice_over

What this means in practice

All internet traffic from your organisation's mobile devices and computers should go through a secure, central point - your internet gateway. This is crucial because if devices connect directly to the internet, they could fall prey to attacks or data leaks that a gateway might prevent.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2026

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Mobile devices and desktop computers accessing the internet

priority_high

Why it matters

If you don't use a secure internet gateway, your devices may be exposed to cyber threats and data breaches, compromising sensitive information.

settings

Operational notes

Regularly audit and update how devices connect to the internet, ensuring compliance with the gateway policy to maintain security.

build

Implementation tips

  • IT team should purchase and set up a VPN service: Choose a reputable VPN provider that supports both desktop and mobile devices. Install the VPN software on all devices used by employees and configure it to always connect to the internet via the VPN.
  • Managers should inform employees: Communicate to employees why VPN use is important and how they should use it for all work-related internet activities. Conduct a short training session or send easy-to-understand instructions via email.
  • System administrators should enable automatic VPN connections: Ensure all organisation devices are set to automatically connect to the VPN when accessing the internet. This can often be set up in the device's network settings or through the VPN software itself.
  • Procurement should ensure VPN compatibility: When purchasing new devices, confirm that they are compatible with your chosen VPN service and its software. Check with the vendor or your IT team to avoid issues with essential security setups.
  • IT team should monitor VPN usage: Set up regular checks to ensure that employees' devices are connecting through the VPN. Use network monitoring tools to verify secure connections and address any issues promptly.
fact_check

Audit / evidence tips

  • AskThe VPN service agreement: Request a copy of the contract or terms of use with the VPN providerLook atThe security features advertised, like encryption standards. Good means it includes strong encryption and covers both desktop and mobile access
  • AskDevice configuration records: Request logs or records showing devices are set up to use the VPNLook atDetails showing automatic VPN connection settings. Good means all organisational devices have active VPN configurations
  • AskEmployee training materials: Request the materials or records from the VPN training sessionLook atHow clearly they explain VPN use and security benefits. Good means materials are straightforward and well-understood by employees
  • AskNetwork monitoring reports: Request reports that track VPN connection activityLook atWhether they show consistent VPN use across all devices. Good means minimal cases of unprotected connections and quick resolution of any lapses
  • AskThe process documentation on handling VPN failures: Request the procedure document that details what happens if the VPN fails or can't be connectedLook atClear steps and contact points for resolving issues. Good means there is a robust, well-outlined contingency plan
link

Cross-framework mappings

How ISM-0874 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(3)expand_less
Annex A 8.1Annex A 8.1 requires organisations to protect information accessible via endpoint devices such as laptops and mobiles
Annex A 8.20ISM-0874 requires endpoints to use an organisation-controlled internet gateway for outbound internet access, preventing unmanaged direct ...
Annex A 8.22ISM-0874 requires endpoints to access the internet through a VPN to the organisation's internet gateway, centralising egress and inspecti...
handshakeSupports(1)expand_less
Annex A 8.23ISM-0874 requires all user devices to route internet access through the organisation's gateway instead of direct connections

E8

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
E8-RA-ML1.3ISM-0874 requires mobile devices and desktop computers to access the internet via a VPN connection to the organisation's internet gateway...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls