Skip to content
arrow_back
search
ISM-0958 policy ASD Information Security Manual (ISM)

Implement Domain Name Allow and Block Lists

Create a list of approved or blocked domains for secure web traffic management.

record_voice_over

Plain language

This control is about managing which websites people in your organisation can visit. By approving or blocking specific websites, you can prevent staff from accidentally visiting harmful or inappropriate sites, which can protect your data and your organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

An organisation-approved list of domain names, or list of website categories, is implemented for all Hypertext Transfer Protocol and Hypertext Transfer Protocol Secure traffic communicated through gateways.
policy ASD Information Security Manual (ISM) ISM-0958
priority_high

Why it matters

Without managed domain allow/block lists for web gateway traffic, users may reach malicious sites, causing malware infection, credential theft and data breaches.

settings

Operational notes

Maintain allow/block and category lists on all HTTP/HTTPS gateways, review exceptions, update from threat intel, and prevent bypass via direct IP, alternate DNS or proxies.

Mapping detail

Mapping

Direction

Controls