Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2160Restricting Networked Management Interfaces to a Segregated Management Network

Put the admin interfaces of servers, switches, firewalls and other IT equipment on their own management network that is cut off from the general network and the internet.

record_voice_over

Plain language

Most IT equipment (servers, switches, routers, firewalls, storage arrays, hypervisors, out-of-band controllers such as iDRAC, iLO or BMCs) has a management interface: a web console, SSH port, API or similar that is used to configure and administer the device. If that interface sits on the same network that staff, contractors and ordinary applications use, or is reachable from the internet, anyone who gets a foothold on the general network (or simply scans the internet) can attempt to log in, exploit a known weakness in the management service, or intercept administrative traffic. This control requires that those networked management interfaces are reachable only from a dedicated management network, and that the management network is segregated from both the wider corporate network and the internet. In practice that means administrators connect to a separate management segment (physically or logically isolated) before they can reach any management interface, and there is no route from a user workstation, an application server or the internet directly to those interfaces. It matters because management interfaces are the highest-value target on a device. Compromising one gives an attacker the ability to change configuration, create accounts, disable logging, push firmware, or reroute traffic. Keeping them off the general network removes an entire class of attack paths and makes lateral movement from a compromised user device to core infrastructure far harder.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Networked management interfaces

Official control statement

Networked management interfaces for IT equipment are only accessible from a dedicated management network that is segregated from the wider network and the internet.
policyASD Information Security Manual (ISM)ISM-2160
priority_high

Why it matters

If management interfaces are reachable from the general network or the internet, a single compromised workstation, phished user account or exposed port gives an attacker a direct path to the consoles that control your infrastructure. From there they can alter firewall rules, create backdoor administrator accounts, disable monitoring, push malicious firmware, or take the equipment offline. Internet-exposed management services are routinely found and exploited through automated scanning, often within hours of exposure. The result can be a full network compromise, extended outages and loss of trust in every device configuration, with recovery requiring rebuilds rather than simple fixes.

settings

Operational notes

Day to day, the management network becomes the only place administrators go to reach device consoles. Administrators typically connect via a jump host, bastion or dedicated administrative workstation that has a presence on the management network, rather than browsing to a device from their everyday desktop.

Keep an authoritative list of which management interfaces exist (including out-of-band controllers and virtual appliance consoles) and which management VLAN or subnet each one lives on. When new equipment is racked or a new virtual appliance is deployed, the build checklist should include moving its management interface onto the management network and confirming nothing on the general network can reach it.

Firewall and ACL rules that enforce the segregation should be treated as sensitive change-controlled configuration. Any change request that would allow traffic from the wider network or the internet into the management network should be treated as an exception requiring explicit approval, and revisited on a schedule. Periodic scans from the general network and from the internet (or a review of external attack surface tooling) confirm no management ports have crept into view. Also watch for devices that were connected temporarily for troubleshooting or vendor support and never moved back.

build

Implementation tips

  • Network team: inventory every IT device with a networked management interface (servers, switches, routers, firewalls, wireless controllers, storage, hypervisors, out-of-band controllers such as iDRAC, iLO and BMCs, and virtual appliances) and record the interface address and the network segment it currently sits on.
  • Network architect: design a dedicated management network (a separate physical network or isolated management VLAN and subnet) and write the segmentation rules so that traffic from the wider corporate network and from the internet cannot reach it; document the design as a network diagram showing the management network, the enforcement points and the permitted flows.
  • Firewall or network administrator: implement the segregation on firewalls, routers and switch ACLs by denying all inbound traffic to the management network from user, server and guest segments and from any internet-facing interface, and confirm there is no NAT, port forward or VPN split that exposes a management interface externally.
  • Systems and infrastructure administrators: move each management interface onto the management network by reconfiguring device management IP addresses or binding management services to the management interface only, and disable management services (web console, SSH, SNMP, API) on interfaces that face the wider network.
  • Security or operations lead: add a step to the equipment build and change checklists requiring that new or reconfigured devices have their management interface placed on the management network, and schedule a recurring scan from the general network and the internet to detect any management interface that becomes reachable from outside the management network.
fact_check

Audit / evidence tips

  • AskAsk for the current network diagram and the register of IT equipment with networked management interfaces.Look atCheck that a distinct management network is shown, that each listed device's management interface is assigned to it, and that the diagram shows the segregation points between the management network, the wider network and the internet.GoodEvery device with a management interface is mapped to the management network, and the diagram makes clear there is no direct path from user segments or the internet into it.
  • AskAsk for the firewall rules, router ACLs and switch VLAN configuration that enforce the boundary of the management network.Look atLook for explicit deny rules blocking inbound traffic to the management subnet from corporate, server, guest and internet-facing zones, and check for any permit rule, NAT or port forward that opens a management interface to those zones.GoodThe rule base denies all inbound access to the management network by default, and any permitted flows are limited to the approved administrative entry point with a documented justification.
  • AskAsk for the running configuration of a sample of devices (a switch, a firewall, a server out-of-band controller and a hypervisor host).Look atConfirm that the management IP address sits in the management subnet and that management services such as SSH, HTTPS console, SNMP and API are bound only to the management interface, not to interfaces on the wider network.GoodSampled devices show management services listening only on the management network address, with management disabled on data-facing interfaces.
  • AskAsk for the results of the most recent scans of the management address range run from the general corporate network and from the internet, or external attack surface reports.Look atCheck that the scans were performed from outside the management network, that the management address range was in scope, and whether any management ports responded.GoodScans from the wider network and the internet show no reachable management interfaces, and any finding since the previous scan has a closed remediation record.
  • AskAsk for the change records and build checklists for equipment commissioned or reconfigured in the last review period.Look atLook for a step that places the management interface on the management network and for evidence that any temporary exception (for example, vendor support access) was approved and later removed.GoodEach new device shows the management interface assigned to the management network at build time, and exceptions have an owner, an expiry and evidence of closure.
link

Cross-framework mappings

How ISM-2160 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.22ISM-2160 requires networked management interfaces for IT equipment to be reachable only from a dedicated management network that is segre...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for networking controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls