Introduction
Gateway decisions are no longer just technical or infrastructure decisions. They influence how an organisation manages cyber risk, enable modern ways of working, protect sensitive information, and maintains operational resilience. Senior executives and decision-makers need to understand why particular gateway approaches have been selected, what risks they introduce, and whether the organisation can effectively operate and assure them over time.
Gateways provide organisations with cyber security protection at the network perimeter. A gateway is a boundary system that separates different security domains and enforces organisational security policies for data transfers between different security domains.
They form a critical component of a layered defence in depth strategy and may be shared across multiple organisations to provide a common suite of security controls. A typical use case is between an organisation’s internal network and the internet.
Since the release in July 2022 of the Australian Signals Directorate’s Australian Cyber Security Centre’s (ASD’s ACSC) Gateway Security Guidance Package (the Gateway Guidance), there have been significant advances in technology and changes to service delivery. Advancements and updates to gateway requirements under the Department of Home Affairs's Protective Security Policy Framework (PSPF) Release 2025, including the new Australian Government Gateway Security Standard (the Gateway Standard) have prompted updates to the Gateway Guidance, building on the approach adopted in the 2025 updates.
Under the Gateway Standard, non-corporate Commonwealth entities (NCEs)[1] are encouraged to adopt a risk-based authorisation model. This approach is consistent with the ASD's Information Security Manual (ISM), the intent of the ASD's Foundations for modern defensible architecture (MDA), and by leveraging cloud security offerings, such as Security Service Edge (SSE) solutions.
This executive guidance is for senior or executive decision-makers who are accountable for the design, procurement, operation, maintenance and disposal of gateway services. It is intended to reinforce executive accountability for gateway security risks, guide strategic procurement and commercial decisions, support oversight of assurance processes including ASD’s Infosec Registered Assessors Program (IRAP) assessments, and ensure executive decisions are traceable to operational, technical, and architectural practices.
Purpose of this guidance
The guidance is not a policy, certification framework or checklist. Organisations should consider their own unique operating environment and requirements alongside this guidance.
This guidance recognises the diverse nature of current enterprise information and communications technology (ICT) environments, which include on-premises, cloud and mobile services. It does not recommend specific technologies but allows organisations to interpret and apply this guidance to align with their cyber security needs and organisational context. Organisations should consider this guidance alongside their relevant policies, frameworks and needs.
Definition of a gateway
The definition of a gateway in the ISM is:
Gateways securely manages data flows between connected networks from different security domains
There are a set of capabilities that enable an organisation to securely:
- provide services to external parties
- exchange information with others
- support remote work
- operate across trusted and untrusted networks (including the internet).
A gateway is a network boundary solution responsible for controlling the flow of data into and out of an organisation’s ICT environment or security domain. This position in the network means that gateways are critical implementation points. They provide a broad range of security capabilities that enforce an organisation’s security policies before allowing access into or out of the organisation’s network.
Cross domain solutions
A Cross Doman Solution (CDS) is a system comprising security enforcing functions tailored to mitigate the specific security risks of accessing or transferring information between security domains. A CDS may be an integrated appliance or, more commonly, be composed of discrete technologies or sub-systems, with each sub-system consisting of hardware and/or software components. CDSs are implemented between SECRET or TOP SECRET networks and any other networks belonging to different security domains. Example use cases for a CDS include ingesting publicly available data from an OFFICIAL network into a SECRET classified analysis system or consolidating the presentation of differently classified desktop systems into a single client. They can also be used where high-assurance security policy enforcement capability is needed to manage risk.
For more information, refer to the ISM and resources for Cross Domain Solutions.
The threat environment
ASD’s ACSC has observed malicious actors increasingly targeting ‘edge devices’. These devices are typically deployed in gateways as routers, firewalls, and Virtual Private Networks concentrators - and act as security intermediaries between internal networks, cloud services and the internet.
As gateway architecture evolve towards hybrid models integrating on-premises infrastructure with cloud-delivered security services, they present an expanded attack surface. Adversaries are no longer limited to exploiting a single perimeter control, instead they target the interfaces, trust relationships, and policy enforcement points across these environments. Edge devices remain attractive targets as they often process or store sensitive information, are accessible from external networks, and enforce organisational security policies. If compromised, they can enable attackers to bypass perimeter controls, intercept sensitive traffic (including classified information), manipulate policy enforcement policies, or gain persistent access to internal systems and cloud services.
The rapid exploitation of newly disclosed vulnerabilities is now standard tradecraft. Both sophisticated and opportunistic threat actors routinely conduct scanning and reconnaissance against internet facing systems to identify and exploit unpatched devices[2]. Increasingly, attackers are leveraging automation and AI enabled tooling to accelerate reconnaissance, vulnerability discovery, and exploitation at scale, reducing the time between vulnerability disclosure and active compromise. In parallel, adversaries are exploiting identity systems and trusted service relationships, including those underpinning cloud and hybrid gateway models. This includes abuse of authentication flows, token theft, and the use of legitimate services to evade detection by blurring the distinction between trusted and untrusted traffic.
Targeting of Australian networks continues to evolve in scale, speed, and sophistication. This reinforces the need for organisations to continuously strengthen their security posture, with a focus on visibility, control, and resilience across both on-premises and cloud-based gateway components.
Senior executives and decision-makers are accountable for managing cyber risk and ensuring confidentiality, integrity and availability of their organisation’s data and systems. These risks can be mitigated through implementation of layered adaptive security controls across the ICT environment, including hybrid gateway architectures. For executive and technical guidance on edge devices, refer to ASD’s securing edge devices.
For more information on the current threat environment, refer to ASD’s ACSC reports and statistics, which includes the Annual Cyber Threat Report and the Commonwealth Cyber Security Posture Report.
Key questions for executives
The following questions are intended to help executives have more informed conversations with architecture, security, and operational teams when selecting, procuring or operating gateway services.
Risk and accountability
- Are the risks associated with the gateway environment clearly defined and understood?
- Has each risk been assigned a clear decision (mitigate, accept, transfer, avoid)?
- Who is accountable for accepting and managing each risk?
Architecture decisions
- Are the architectural decisions documented, justified, and aligned with business objectives?
- Are the cost, security, and operational impact understood if the technology fails or is compromised?
Visibility and monitoring
- Does the organisation have visibility of all critical data flows and who has access to it?
- Would suspicious activity or data theft be noticed quickly enough to act?
Frameworks
- Are we aligned with ASD’s frameworks such as MDA, ISM, and Secure by Design?
Providers and outsourcing
- Are shared responsibilities documented for each shared service provider?
- Has the organisation conducted a supply chain risk assessment of the provider and its services?
Incident response
- Would an attack through a gateway be detected and contained within a timeframe the organisation can tolerate?
- Has the organisation exercised these scenarios with operational teams and providers to verify desired outcomes?
Lifecycle and maintenance
- Are the current gateway technologies up to date, supported, and capable of meeting emerging organisational needs?
- Does the organisation have a plan to modernise or replace legacy gateway capabilities?
Assurance and compliance
- Can the organisation demonstrate that controls are operating effectively?
- Is the organisation prepared for assurance activities such as IRAP assessments?
Executive oversight considerations
Accountability and shared responsibility
Senior and executive decision-makers retain accountability for governance, risk management, and assurance of gateways, including when services are outsourced. Outsourcing does not transfer risk; organisations must actively govern outsourced or managed gateway services.
Executives should implement formal artefacts to support accountability such as:
- Responsible, Accountable, Consulted, Informed (RACI) models that clearly define responsibilities across internal teams and service providers
- risk acceptance and escalation processes that document thresholds and decision pathways
- service and data ownership accountability models that clarifies accountability for services and data flows.
Procurement and commercial risk oversight
Executives are responsible for strategic procurement decisions and need to consider the following;
- assessing long-term managed service contracts for resilience and flexibility
- planning for vendor exit strategies and contract portability
- supply chain risks including considerations on physical and personnel related threats. For more information, refer to the Hosting Certification Framework.
- incorporating secure-by-design expectations and contractual reporting requirements.
Assurance and IRAP governance
Executives play a key role in reviewing and interpreting assurance outputs including:
- understanding IRAP scope and limitations
- clarifying service provider vs customer assurance responsibilities
- assessing Phase 1 and Phase 2 reports completeness, quality, relevance, and timeliness
- ensuring residual risks align with organisational risk appetite
- confirming follow-up actions are assigned and monitored.
Emerging technology risk oversight
Executives need to account for strategic risks arising from emerging technologies such as:
- Post-Quantum Cryptography (PQC): planning migration to quantum-resistant algorithms
- Artificial Intelligence (AI): Operational and supply chain risks
Post-Quantum Cryptography
Organisations should consider the future impact of quantum computing on cryptographic mechanisms used within gateway technologies, including secure communications, encryption, and trust anchors.
Organisations will need to develop a cryptographic material lifecycle plan, including requirements for adopting PQC algorithms, managing significantly shorter key lifetimes, algorithm deprecation, and secure storage of key material. Gateway hardware procurement should include PQC requirements in all future procurements. For more information on ASD’s post-quantum readiness, refer to ASD’s planning for post-quantum cryptography.
Artificial Intelligence
AI technologies can used to support threat detection and analysis within gateway environments. Organisations should consider associated risks when implementing these capabilities, including model evasion, non-deterministic outcomes, and risks to data integrity.
Organisations should assess risks related to data integrity, model bias, and supply chain dependencies in AI-enabled security and operational functions. For more information, refer to ASD’s Artificial intelligence , and DTA’s Policy for the responsible use of AI in government - Version 2.0: Strategy and oversight.
Requirements for government organisations
Australian Government organisations, particularly NCEs, must operate within several policies and frameworks. These frameworks govern how NCEs design, procure, operate, maintain and dispose of gateway solutions.
Senior and executive decision-makers are accountable for ensuring their organisation complies with these requirements. At a minimum, they should be familiar with the frameworks described in this guidance. While these requirements do not apply to private sector organisations, service providers and vendors offering products or services to government organisations should also be aware of them.
NCEs implementing gateways that need to operate at the SECRET or TOP SECRET security levels should follow this guide along with guidance on ASD's Cross Domain Solutions. For these high-security environments, extra services and additional monitoring and logging due to the serious risk of leaking highly classified information. NCEs that design, procure, operate, maintain and dispose of CDS services in these environments should contact ASD’s ACSC for specific advice.
Protective Security Policy Framework
The PSPF sets out Australia government policy and prescribes what Australia government entities must do to protect their people, information and resources, both domestically and internationally. It is what makes the Gateway Standard mandatory for all non-corporate government entities. NCEs must apply and adhere to the PSPF when designing, procuring, operating, maintaining and disposing of gateways. This includes when using the gateway services of another organisation or service provider. NCEs cannot transfer this accountability to a third-party gateway service provider or other NCEs.
Section 13.3 of the PSPF requires that NCEs must only process, store or communicate information and data on ICT systems where an Authorising Officer (or their delegate) with appropriate authority has authorised the system to operate based on the acceptance of the residual cyber security risks associated with its operation. The relevant Accountable Officer for a system, including gateways, must understand the risks associated with using the system and should review the system’s security plan regularly.
Gateway Security Standard
The Gateway Standard replaces the Australian Government Gateway Policy (Gateway Policy). The Gateway Standard describes the strategic direction for Australian Government use of gateway services and sets the minimum security standard expected from Commonwealth entities when using gateway capabilities, including SSE. It forms part of a broader coordinated uplift of the Australian Government’s cyber security consultation agenda led by the Department of Home Affairs (Home Affairs).
Shield 4 of the 2023-2030 Australian Cyber Security Strategy highlights the importance of this uplift. To support this critical agenda, Home Affairs is consolidating several government IT infrastructure policies under a cohesive Resilient Digital Infrastructure strategy. This includes reviewing and updating the Gateway Policy (now the Gateway Standard) and the Secure Cloud Strategy, and integrating reforms to the Hosting Certification Framework.
Information Security Manual (ISM)
The ISM provides baseline security controls that entities must consider when designing, implementing, maintaining, operating, and decommissioning gateway solutions. As per the PSPF, the decision to authorise (or re-authorise) an ICT system to operate, including gateways, must be based on the ISM’s six-step, risk-based approach for cyber security as shown on figure 1
Infosec Registered Assessors Program
Under the IRAP, ASD’s ACSC endorses individuals from the private and public sectors to provide security assessment services. IRAP aims to enhance the security of broader industry and Australian Government systems and data. Organisations should refer to the IRAP Consumer Guide for more information on how best to:
- engage an IRAP assessor
- prepare for an IRAP assessment
- understand the assessment process
- use the information provided in an IRAP assessment report.
For more information on the ISM controls relating to assessing gateways, refer to Guidelines for gateways.
Figure 2 shows best practice for organisations on how to assess and authorise gateways.
Gateway Provider
- Service
- For managed gateways: Select IRAP assessed solutions.
- Gateway services up to PROTECTED to be hosted by DTA's and HCF certified strategic facilities and services.
Gateway Consumer
- Define the system
- Supply chain assessment
- Customer supply chain assessment:
- Review IRAP report and other security collateral (inc. SRMP / SSP)
- BoM / SBoM review
- Identify critical security components and services
- Concepts of Operations (CONOPS)
- Customer supply chain assessment:
- Supply chain assessment
- Select Controls
- System design approval
- Design approval:
- High level design
- Detailed design
- Risk assessment
- Controls selection
- Design approval:
- System design approval
- Implement controls
- Build, configure and integration
- Design approval:
- High level design
- Detailed design
- Risk assessment
- Controls selection
- Integration:
- SOC and SIEM
- Incident response
- Health monitoring
- CI/CD and IaC integration
- Organisational assurance and processes (architectural reviews, change management, etc)
- ASD integration
- Design approval:
- Build, configure and integration
- Assess controls
- Assessment
- Assessment actions:
- Penetration testing documentation pack
- Detailed design
- Conduct IRAP assessment
- Assessment actions:
- Assessment
- Authorise the system
- Authorisation
- Authorising Officer actions:
- Penetration testing documentation pack
- Detailed design
- Conduct IRAP assessment
- Authorising Officer actions:
- Authorisation
Gateway Provider and Consumer
- Monitor the system
- Continuous assurance
- Vulnerability management
- Change management
- Ongoing risk management
- Configuration management
- Penetration testing
- Continuous assurance
More information
For more information on topics covered in this guidance, refer to the following ASD’s ACSC publications:
- ASD's Information Security Manual
- ASD's Strategies to mitigate cyber security incidents and the Essential Eight
- ASD's Security considerations for edge devices
- ASD's Fundamentals of Cross Domain Solutions
- ASD's Guidelines for gateways
- ASD's Implementing network segmentation and segregation
- ASD's Cyber security incident response planning: Executive guidance
- ASD's Cyber security incident response planning: Practitioner guidance
Contact us
Following substantial updates to the Gateway Guidance in September 2026, ASD’s ACSC welcomes feedback to ensure it remains clear, relevant and useful. If you have any questions or feedback, you can write to us or call us on 1300 CYBER1 (1300 292 371).
The Gateway Guidance is being released in parallel with the Department of Home Affairs Australian Government Gateway Security Standard. We encourage interested stakeholders to provide feedback on the Gateway Standard directly to Home Affairs.
Footnotes
- Non-corporate and corporate Commonwealth entities are government bodies that are subject to the Public Governance, Performance and Accountability Act 2013. More information: Non-corporate Commonwealth entity (NCE) | Department of Finance
- An 'unpatched' device is any device (including software running on a device) that has not been kept up to date with the latest security updates, as recommended and provided by the relevant vendor.