When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.
Topic
Centralised email gateways
Applicable to
all
History
Priority
must
Jun 2022
When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateways.
Miscellaneous changes were made to rationale and recommendations throughout the publication to clarify content. This included the adoption of ‘control’ terminology, in preference to ‘security control’ terminology, to allow for the capture of other types of controls in the future, such as privacy controls, in addition to security controls.
In addition, formatting changes were made to the system security plan annex template and the cloud controls matrix template in order to increase their alignment, such as the inclusion of an ‘implementation status’ column within the system security plan annex template. Furthermore, a new ‘responsible entity’ column was added to both templates in order to capture information on the responsible system (in the case of inherited controls) or responsible vendor (in the case of multi-vendor systems) that are responsible for the implementation of controls. Note, this column can also be used to capture information on teams or individuals that are responsible for the implementation of controls if desired.
Mar 2022
When users send or receive emails, an authenticated and encrypted channel is used to route emails via their organisation’s centralised email gateway.
Miscellaneous changes were made to rationale and recommendations throughout the publication to clarify content without changing intent. This included a review from the Guidelines for System Hardening chapter through to the Guidelines for Data Transfers chapter.
Mar 2019
When users send email from outside their network, an authenticated and encrypted channel is configured to allow email to be routed via a centralised email gateway.
Security control 0571 was reworded.
Feb 2019
Where users send email from outside their network, an authenticated and encrypted channel is configured to allow email to be sent via the centralised email gateway.
2015
Where users send email from outside their network, an authenticated and encrypted channelmust be configured to allow email to be sent via the centralised email gateway.
2010
Where system users send email from outside their network, an authenticated and encrypted channel mustbe configured to allow email to be sent via the centralised email gateway.
2008
Where an agency has system users or systems that send email from outside the agency’s network, a secure channel should be configured to allow email to be sent via the centralised gateway.