Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2150Gateways Block Connections for Unauthorised RMM and Remote Access Tools

Gateways must stop network traffic from remote monitoring and management (RMM) and remote access tools that the organisation has not approved, so attackers cannot use them as a back door.

record_voice_over

Plain language

Remote monitoring and management (RMM) tools and remote access tools (products such as remote-desktop and screen-sharing software) let someone control a computer from somewhere else. IT teams use approved versions of these tools legitimately, but attackers love them too, because a remote access tool that is already installed and talking out to the internet looks like ordinary administration traffic and gives them hands-on-keyboard control without needing to write their own malware. This control says the organisation's gateways (the points where its networks connect to the internet or other external networks) must block the network connections used by RMM and remote access tools that have not been authorised. The organisation decides which of these tools are approved, and everything else in that category is denied at the gateway. It matters because an unauthorised remote access tool is a common way attackers keep persistent access after an initial compromise, and it is also how insiders or well-meaning staff can open unmanaged paths into the network. Blocking the connections at the gateway means that even if such a tool is installed on a device, it cannot reach its operator on the outside.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Administrative tools

Official control statement

Network connections for unauthorised RMM tools and remote access tools are blocked at gateways.
policyASD Information Security Manual (ISM)ISM-2150
priority_high

Why it matters

If unauthorised RMM and remote access tools can connect through the gateway, an attacker who installs one (or abuses one a user has installed) gains interactive, persistent control of internal systems that blends in with legitimate administration traffic. That access can be used to move laterally, steal data and deploy ransomware, and it can persist for long periods because nothing at the network edge stops it. Unmanaged remote access paths also bypass the organisation's approved, monitored remote access channels, so security teams lose visibility of who is connecting and from where.

settings

Operational notes

Day to day, this control depends on two things being kept current: the organisation's list of authorised RMM and remote access tools, and the gateway rules that block everything else in that category.

Gateway administrators maintain block rules (application-control signatures, category filters, domain and IP lists, or protocol and port rules as the platform supports) covering the connections that unauthorised RMM and remote access tools use. Because vendors change their infrastructure and new tools appear regularly, those signatures and lists need routine updates rather than a one-off configuration.

When a business area asks to use a new remote access tool, the request goes through the organisation's approval process before any gateway exception is created, and exceptions are scoped to the approved tool. Gateway logs showing blocked remote access connections are useful signals: repeated blocks from a single host may indicate an installed but unauthorised tool that should be investigated and removed.

build

Implementation tips

  • Security or IT management defines and documents which RMM and remote access tools are authorised for the organisation, so gateway administrators have a clear allow list to build rules against.
  • Gateway or firewall administrators enable application-control or category-based blocking on every internet and external gateway for the RMM and remote access tool category, then add explicit exceptions only for the documented authorised tools.
  • Gateway administrators supplement application signatures with domain, IP and protocol block rules for known unauthorised remote access tools where the gateway platform cannot identify a tool by signature alone.
  • Gateway administrators subscribe to and apply vendor signature and category updates on a regular schedule so newly released or rebranded remote access tools are covered by the block rules.
  • Network security staff configure gateway logging for blocked RMM and remote access connections and hand repeated hits from the same internal host to the security operations team for investigation and tool removal.
fact_check

Audit / evidence tips

  • AskAsk for the organisation's list of authorised RMM and remote access tools and the approval record behind it.Look atCheck that the list is specific, current and formally approved rather than a loose collection of tools people happen to use.GoodA dated, approved list naming each authorised tool exists and the gateway exceptions map directly to it.
  • AskAsk for the gateway or firewall configuration that blocks RMM and remote access tool connections on each internet and external gateway.Look atLook for application-control, category or explicit block rules covering remote access tools, and confirm they apply to all gateways, not just the main one.GoodEvery gateway has an active rule set that denies the remote access tool category by default with narrow exceptions for authorised tools only.
  • AskAsk for evidence that gateway application signatures and block lists are kept up to date.Look atCheck the signature version, update schedule and last update date on each gateway.GoodSignatures and lists have been updated recently on a regular cadence so new or renamed remote access tools are caught.
  • AskAsk for gateway logs or reports showing blocked RMM and remote access tool connections over a recent period.Look atConfirm that blocks are actually being recorded and see whether repeated blocks from the same host were followed up.GoodLogs show the rules firing in practice and repeated hits from an internal host led to an investigation and removal of the tool.
  • AskAsk for the results of any test or validation that unauthorised remote access tools cannot connect through the gateway.Look atLook for a documented test, such as attempting a connection with a non-approved tool from inside the network, and its outcome.GoodA recent test demonstrates that a non-approved tool's connection is blocked at the gateway while an authorised tool still works.
link

Cross-framework mappings

How ISM-2150 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.20ISM-2150 requires gateways to block network connections for unauthorised remote monitoring and management (RMM) and remote access tools t...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system management controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls