Skip to content
arrow_back
search
ISM-1037 policy ASD Information Security Manual (ISM)

Regular Testing for Security of Gateways

Gateways are tested every six months and after changes to ensure they meet security standards.

record_voice_over

Plain language

This control is about regularly testing the security of gateways, like your internet router, to ensure they're safely configured. If this testing isn't done, hackers might exploit weaknesses to access your systems, leading to data breaches or service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate they conform to expected security configurations.
policy ASD Information Security Manual (ISM) ISM-1037
priority_high

Why it matters

Failure to test gateways regularly can leave insecure configurations undetected, enabling intrusion via network entry points and causing outages or data compromise.

settings

Operational notes

Test gateways after configuration changes and at least every six months; review findings promptly and remediate any deviations from approved secure configurations.

Mapping detail

Mapping

Direction

Controls