Introduction
Gateway architectures are evolving in response to changes in technology, threat environments, and ways of working. Traditional perimeter-based gateway models are increasingly supplemented or replaced by hybrid and cloud-based implementations, reflecting the adoption of cloud services, remote access solutions, and distributed enterprise environments. Gateways now operate across multiple locations and security zones, including on-premises infrastructure, cloud platforms, and edge services. This has resulted in more distributed gateway capabilities, requiring organisations to consider defence in depth security controls beyond a single network boundary.
The Gateway Security Guidance Package (this guidance) has been developed by the Australian Signals Directorate to assist organisations in addressing these changes. It describes how organisations should approach cyber security challenges and opportunities by embedding gateway security in their architecture to support the secure design, procurement, deployment, operation, and sustainment of gateway services.
The guidance enables organisations to:
- apply government security requirements in the context of their gateway service architecture
- adopt a risk-based approach to gateway design and implementation
- maintain effective principle-based security across diverse environments
- respond to evolving threats and emerging technologies.
It is intended to be applied flexibly, recognising that gateway implementations will vary depending on organisational context.
By aligning security, architecture, and operational practices, this guidance supports organisations to achieve resilient, scalable, and risk-informed gateway outcomes across diverse delivery models.
Gateway policy and advice ecosystem
On 1 July 2026, the Department of Home Affairs released the 2026 update of the Protective Security Policy Framework (PSPF). This update revises gateway security requirements within the Australian Government Gateway Security Standard (the Gateway Standard).
The Gateway Standard outlines the strategic direction and minimum-security standards that Commonwealth entities must apply when using and implementing gateway technologies. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has updated its guidance to ensure alignment with the updated Gateway Standard and incorporated recent advancements in better security practices.
Together, these frameworks form an integrated ecosystem (shown on Figure 1):
- PSPF is the overarching policy framework that governs all Australian government security
- The Gateway Standard sets the minimum-security standards that Commonwealth entities must apply when using and implementing gateway technologies
- Information security manual (ISM) and Infosec Registered Assessors program (IRAP): ISM provides controls and IRAP provides assessment against them
- The Gateway Guidance provides better practice guidance and describes how organisations should approach cyber security challenges and opportunities by embedding gateway security in their architecture.
Guidance for Australian organisations and service providers
This guidance is primarily intended for Australian Government organisations and their service providers. It may also be useful for any organisation designing, procuring, operating, maintaining or disposing off gateway services.
The guidance is non-prescriptive and supports a risk-based approach, recognising that:
- gateway architectures vary across organisations
- implementation approaches will differ based on scale, complexity, and availability requirements
- controls should be applied proportionately to risk.
The primary audiences across this gateway guidance are:
- Gateway security guidance package: Overview (this document) is for all audiences before reading other guides in the package. It provides context, structure, and guidance on how to use the package.
- Gateway security guidance package: Executive guidance is for senior or executive decision-makers who are accountable for designing, procuring, operating, maintaining or disposing of gateway solutions.
- Gateway security guidance package: Gateway security principles is for security, architecture and engineering teams who are responsible for designing or operating gateway solutions in their organisation
- Gateway security guidance package: Gateway operations and management is for engineering, operations and support teams to understand better-practice approaches for operating, maintaining and disposing of gateways
- Gateway security guidance package: Gateway technology guides is for security, architecture, engineering, operations and support teams and provides detailed guidance on key technical concepts referred to throughout the Gateway Guidance package.
Executive guidanceFor senior or executive decision-makers to help them understand their obligations and role in improving cyber security outcomes for their organisation. High-level topics:
| Gateway security principlesFor security, architecture and engineering teams to understand the fundamental design principles and architecture that underpin better gateway security practice. High-level topics:
|
Gateway operations and managementFor engineering, operations and support teams to understand a better-practice approach for operating, maintaining and disposing of gateways. High-level topics:
| Gateway technology guidesFor security, architecture, engineering, operations and support teams for detailed guidance on key technical concepts referred to throughout the Gateway Guidance package. High-level topics:
|
How to use this guidance package
The guidance is intended to be used in a modular manner. Organisations do not need to consume all documents sequentially but instead use relevant sections based on their role and requirements.
Executives and governance
Role: focus on accountability, risk, and compliance
Relevant publications: use the overview and executive guidance.
Procurement and assurance
Role: focus on requirements definition, contractual terms, and validation
Relevant publications: use executive guidance, gateway security principles, and operations and management guidance.
Technical design and implementation
Role: focus on architecture and control implementation
Relevant publications: use gateway security principles and gateway technology guides.
Operations and sustainment
Role: focus on monitoring, maintenance, and continuous improvement
Relevant publications: use gateway security principles, gateway operations and management guidance, and gateway technology guides.
Gateway lifecycle
This guidance supports gateway security across the full lifecycle of capability delivery and operations:
Design
- define system boundaries and security domains
- select appropriate architectural approaches
- align with contemporary security models.
Procurement
- translate security requirements into procurement criteria
- evaluate products and services against required controls.
Deployment
- implement secure configurations
- apply hardening and validation activities.
Operations
- monitor and log gateway activity
- enforce policies and maintain visibility
- respond to security events.
Sustainment
- maintain and update configurations
- respond to emerging threats
- incorporate updated guidance and technologies
- support periodic reassessment
- modify gateway to support changing business requirements.
Decommission
- data and configuration archiving
- sanitisation of infrastructure
- removal of any service integrations and related credentials
- asset disposal or service decommission.
Strategic and emerging technology context
Gateway security must continue to evolve in response to emerging technologies and threats.
Zero Trust Architecture
Gateways are increasingly deployed as policy enforcement points within a Zero Trust architecture, supporting:
- continuous verification
- least privilege access
- removal of implicit trust between network segments.
For more information, refer to ASD’s modern defensible architecture.
Post-quantum cryptography
Organisations need to consider the future impact of quantum computing on cryptographic mechanisms used within gateway services, including secure communications, encryption, and trust anchors. For more information on ASD’s post-quantum readiness, refer to ASD’s planning for post-quantum cryptography.
Artificial intelligence
AI technologies can used to support threat detection and analysis within gateway environments. Organisations should consider associated risks when implementing these capabilities, including model evasion, non-deterministic outcomes, and risks to data integrity.
Organisations should assess risks related to data integrity, model bias, and supply chain dependencies in AI-enabled security and operational functions. AI-enabled attack chaining is expected to increase the patching tempo required of operational teams. Wherever possible, organisations should reduce the number of externally facing services to minimise attack surfaces. To support this, organisations should consider developing a patch automation strategy to reduce the operational burden on system administrators. They should also consider leveraging cloud services where gateway teams cannot sustain a continuous patch management approach to vulnerability management. For more information, refer to ASD’s artificial intelligence.
Contact details
Following substantial updates to the Gateway Guidance in September 2026, ASD’s ACSC welcomes feedback to ensure it remains clear, relevant and useful. If you have any questions or feedback, you can write to us or call us on 1300 CYBER1 (1300 292 371).
The Gateway Guidance is being released in parallel with the Department of Home Affairs Australian Government Gateway Security Standard. We encourage interested stakeholders to provide feedback on the Gateway Standard directly to the Department of Home Affairs.