Skip to content
arrow_back
ISM-1037policyASD Information Security Manual (ISM)

Regular Testing of Gateway Security Configurations

Gateways are tested every six months or after changes to ensure they meet security standards.

record_voice_over

Plain language

Every six months, or when there are changes, your network gateways must be tested to make sure they're keeping your systems protected. This is crucial because if gateways aren't secure, hackers could break in and create chaos, like stealing sensitive info or disrupting operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Gateways undergo testing following configuration changes, and at regular intervals no more than six months apart, to validate that they conform to expected security configurations.
policyASD Information Security Manual (ISM)ISM-1037
priority_high

Why it matters

Without regular gateway testing, you risk cyber attacks that could compromise sensitive data and disrupt your business operations.

settings

Operational notes

Regularly update and review your security testing schedule to ensure no tests are missed, and promptly act on any issues found.

build

Implementation tips

  • The IT team should regularly schedule and conduct security tests on gateways. Use a calendar reminder and specific security testing tools to check that settings match your security standards.
  • Office managers and IT should collaborate after any changes to the network gateway to ensure all configurations remain secure. This can involve a checklist to verify settings and permissions.
  • Business owners should allocate a budget for necessary tools and any external security testing services to validate gateway security. Research and choose reputable security consultancy services if needed.
  • System owners should document all changes to the gateway configuration for reference during tests. Maintain a log of changes and ensure it is easily accessible to everyone involved in security.
  • IT staff should be trained regularly on potential security threats to gateways and how to spot issues during testing. Schedule quarterly training sessions to keep the team updated.
fact_check

Audit / evidence tips

  • Askthe gateway testing schedule: Check how often testing is planned and if it aligns with the six-month requirementLook atpast dates and next planned dateGoodwould show tests no further apart than six months
  • Look atspecific dates and signed reportsGoodwill show tests immediately following changes
  • Askdocumentation of identified issues and fixes from the last gateway test: Check that issues were found and correctly resolvedLook atdetailed problem and solution descriptionsGoodhas clear entries with successful resolution notes
  • Look atdates, topics, and attendanceGoodshows regular, ongoing training activities
  • Askto see logs of all gateway configuration changes: Assess these logs to make sure any change is followed by testingLook atchange records and subsequent testing entriesGooddetails every change and its corresponding test
link

Cross-framework mappings

How ISM-1037 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 5.36ISM-1037 requires gateways to be tested after changes and at least every six months to validate conformance to expected security configur...
Annex A 8.9ISM-1037 requires gateways to be tested after configuration changes and at least every six months to confirm they conform to expected sec...
sync_altPartially overlaps(1)expand_less
Annex A 5.35ISM-1037 requires gateways to be tested after configuration changes and at least every six months to confirm they meet expected security ...
handshakeSupports(1)expand_less
Annex A 8.21Annex A 8.21 requires security mechanisms for network services to be implemented and monitored

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for gateways controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls