Skip to content
arrow_back
search
ISM-1862 policy ASD Information Security Manual (ISM)

Restrict Access and Conceal Web Server IP Addresses

Avoid revealing server IPs and limit access exclusively to WAFs and authorised networks.

record_voice_over

Plain language

This control is about keeping the actual location of your web servers a secret and making sure only the necessary security tools and trusted parties can access them. If you don't, malicious individuals could find and target your servers directly, leading to data breaches or downtime.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If using a WAF, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.
policy ASD Information Security Manual (ISM) ISM-1862
priority_high

Why it matters

Exposed origin IPs let attackers bypass the WAF and hit web servers directly, increasing risk of compromise, data theft and outages.

settings

Operational notes

Audit firewall/ACLs so only WAF egress IPs and authorised management networks can reach origin servers; block direct Internet access and remove leaked DNS records.

Mapping detail

Mapping

Direction

Controls