ASD ISM 0874Ensure Internet Access via Organisation's Gateway
Official control statement
Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Mobile devices and desktop computers access the internet via an organisation's internet gateway rather than via a direct connection to the internet.
What this means in practice
All internet traffic from your organisation's mobile devices and computers should go through a secure, central point - your internet gateway. This is crucial because if devices connect directly to the internet, they could fall prey to attacks or data leaks that a gateway might prevent.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2026
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for enterprise mobilitySection
Enterprise mobilityTopic
Mobile devices and desktop computers accessing the internet
Why it matters
If you don't use a secure internet gateway, your devices may be exposed to cyber threats and data breaches, compromising sensitive information.
Operational notes
Regularly audit and update how devices connect to the internet, ensuring compliance with the gateway policy to maintain security.
Implementation tips
- IT team should purchase and set up a VPN service: Choose a reputable VPN provider that supports both desktop and mobile devices. Install the VPN software on all devices used by employees and configure it to always connect to the internet via the VPN.
- Managers should inform employees: Communicate to employees why VPN use is important and how they should use it for all work-related internet activities. Conduct a short training session or send easy-to-understand instructions via email.
- System administrators should enable automatic VPN connections: Ensure all organisation devices are set to automatically connect to the VPN when accessing the internet. This can often be set up in the device's network settings or through the VPN software itself.
- Procurement should ensure VPN compatibility: When purchasing new devices, confirm that they are compatible with your chosen VPN service and its software. Check with the vendor or your IT team to avoid issues with essential security setups.
- IT team should monitor VPN usage: Set up regular checks to ensure that employees' devices are connecting through the VPN. Use network monitoring tools to verify secure connections and address any issues promptly.
Audit / evidence tips
- AskThe VPN service agreement: Request a copy of the contract or terms of use with the VPN providerLook atThe security features advertised, like encryption standards. Good means it includes strong encryption and covers both desktop and mobile access
- AskDevice configuration records: Request logs or records showing devices are set up to use the VPNLook atDetails showing automatic VPN connection settings. Good means all organisational devices have active VPN configurations
- AskEmployee training materials: Request the materials or records from the VPN training sessionLook atHow clearly they explain VPN use and security benefits. Good means materials are straightforward and well-understood by employees
- AskNetwork monitoring reports: Request reports that track VPN connection activityLook atWhether they show consistent VPN use across all devices. Good means minimal cases of unprotected connections and quick resolution of any lapses
- AskThe process documentation on handling VPN failures: Request the procedure document that details what happens if the VPN fails or can't be connectedLook atClear steps and contact points for resolving issues. Good means there is a robust, well-outlined contingency plan
Cross-framework mappings
How ISM-0874 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(3)expand_less | ||
| Annex A 8.1 | Annex A 8.1 requires organisations to protect information accessible via endpoint devices such as laptops and mobiles | |
| Annex A 8.20 | ISM-0874 requires endpoints to use an organisation-controlled internet gateway for outbound internet access, preventing unmanaged direct ... | |
| Annex A 8.22 | ISM-0874 requires endpoints to access the internet through a VPN to the organisation's internet gateway, centralising egress and inspecti... | |
handshakeSupports(1)expand_less | ||
| Annex A 8.23 | ISM-0874 requires all user devices to route internet access through the organisation's gateway instead of direct connections | |
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| E8-RA-ML1.3 | ISM-0874 requires mobile devices and desktop computers to access the internet via a VPN connection to the organisation's internet gateway... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Enterprise mobility
See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.