Australian Information Security Manual
Guidelines for gateways

Australian Information Security Manual ISM-1862: If using a WAF, disclosing the IP addresses of web servers under an organisation's control

If using a WAF, disclosing the IP addresses of web servers under an organisation's control (referred to as origin servers) is avoided and access to the origin servers is restricted to the WAF and authorised management networks.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Other controls in Guidelines for gateways

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.