Skip to content
arrow_back
search
ISM-0027 policy ASD Information Security Manual (ISM)

Mandatory Authorisation for System Operation

System owners must get permission from an authorising officer to operate certain systems.

record_voice_over

Plain language

Before you can start using certain types of systems, you need approval from a designated person in your organisation, like a manager. This approval is important because it ensures the system is safe to use and doesn't put sensitive information at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S

ISM last updated

Mar 2026

Control Stack last updated

24 Mar 2026

E8 maturity levels

N/A

Official control statement

System owners obtain an authorisation to operate for each non-classified, OFFICIAL: Sensitive, PROTECTED and SECRET system from its authorising officer.
policy ASD Information Security Manual (ISM) ISM-0027
priority_high

Why it matters

Without authorisation, systems may operate without adequate security checks, increasing the risk of data breaches or other security incidents.

settings

Operational notes

Regularly review and update system authorisation to reflect any changes in system use or organisational policies, keeping security measures relevant and effective.

Mapping detail

Mapping

Direction

Controls