ASD ISM 2150Gateways Block Connections for Unauthorised RMM and Remote Access Tools
Gateways must stop network traffic from remote monitoring and management (RMM) and remote access tools that the organisation has not approved, so attackers cannot use them as a back door.
Plain language
Remote monitoring and management (RMM) tools and remote access tools (products such as remote-desktop and screen-sharing software) let someone control a computer from somewhere else. IT teams use approved versions of these tools legitimately, but attackers love them too, because a remote access tool that is already installed and talking out to the internet looks like ordinary administration traffic and gives them hands-on-keyboard control without needing to write their own malware. This control says the organisation's gateways (the points where its networks connect to the internet or other external networks) must block the network connections used by RMM and remote access tools that have not been authorised. The organisation decides which of these tools are approved, and everything else in that category is denied at the gateway. It matters because an unauthorised remote access tool is a common way attackers keep persistent access after an initial compromise, and it is also how insiders or well-meaning staff can open unmanaged paths into the network. Blocking the connections at the gateway means that even if such a tool is installed on a device, it cannot reach its operator on the outside.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
05 Sept 2026
E8 maturity levels
N/A
Official control statement
Network connections for unauthorised RMM tools and remote access tools are blocked at gateways.
Why it matters
If unauthorised RMM and remote access tools can connect through the gateway, an attacker who installs one (or abuses one a user has installed) gains interactive, persistent control of internal systems that blends in with legitimate administration traffic. That access can be used to move laterally, steal data and deploy ransomware, and it can persist for long periods because nothing at the network edge stops it. Unmanaged remote access paths also bypass the organisation's approved, monitored remote access channels, so security teams lose visibility of who is connecting and from where.
Operational notes
Day to day, this control depends on two things being kept current: the organisation's list of authorised RMM and remote access tools, and the gateway rules that block everything else in that category.
Gateway administrators maintain block rules (application-control signatures, category filters, domain and IP lists, or protocol and port rules as the platform supports) covering the connections that unauthorised RMM and remote access tools use. Because vendors change their infrastructure and new tools appear regularly, those signatures and lists need routine updates rather than a one-off configuration.
When a business area asks to use a new remote access tool, the request goes through the organisation's approval process before any gateway exception is created, and exceptions are scoped to the approved tool. Gateway logs showing blocked remote access connections are useful signals: repeated blocks from a single host may indicate an installed but unauthorised tool that should be investigated and removed.
Implementation tips
- Security or IT management defines and documents which RMM and remote access tools are authorised for the organisation, so gateway administrators have a clear allow list to build rules against.
- Gateway or firewall administrators enable application-control or category-based blocking on every internet and external gateway for the RMM and remote access tool category, then add explicit exceptions only for the documented authorised tools.
- Gateway administrators supplement application signatures with domain, IP and protocol block rules for known unauthorised remote access tools where the gateway platform cannot identify a tool by signature alone.
- Gateway administrators subscribe to and apply vendor signature and category updates on a regular schedule so newly released or rebranded remote access tools are covered by the block rules.
- Network security staff configure gateway logging for blocked RMM and remote access connections and hand repeated hits from the same internal host to the security operations team for investigation and tool removal.
Audit / evidence tips
- AskAsk for the organisation's list of authorised RMM and remote access tools and the approval record behind it.Look atCheck that the list is specific, current and formally approved rather than a loose collection of tools people happen to use.GoodA dated, approved list naming each authorised tool exists and the gateway exceptions map directly to it.
- AskAsk for the gateway or firewall configuration that blocks RMM and remote access tool connections on each internet and external gateway.Look atLook for application-control, category or explicit block rules covering remote access tools, and confirm they apply to all gateways, not just the main one.GoodEvery gateway has an active rule set that denies the remote access tool category by default with narrow exceptions for authorised tools only.
- AskAsk for evidence that gateway application signatures and block lists are kept up to date.Look atCheck the signature version, update schedule and last update date on each gateway.GoodSignatures and lists have been updated recently on a regular cadence so new or renamed remote access tools are caught.
- AskAsk for gateway logs or reports showing blocked RMM and remote access tool connections over a recent period.Look atConfirm that blocks are actually being recorded and see whether repeated blocks from the same host were followed up.GoodLogs show the rules firing in practice and repeated hits from an internal host led to an investigation and removal of the tool.
- AskAsk for the results of any test or validation that unauthorised remote access tools cannot connect through the gateway.Look atLook for a documented test, such as attempting a connection with a non-approved tool from inside the network, and its outcome.GoodA recent test demonstrates that a non-approved tool's connection is blocked at the gateway while an authorised tool still works.
Cross-framework mappings
How ISM-2150 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.20 | ISM-2150 requires gateways to block network connections for unauthorised remote monitoring and management (RMM) and remote access tools t... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System management
See all Guidelines for system management controls, or browse the full ASD ISM library.