Skip to content
arrow_back
search
ISM-0072 policy ASD Information Security Manual (ISM)

Ensure Security in Contracts with Service Providers

Service contracts must include security measures for data protection and be regularly reviewed to ensure they're effective.

record_voice_over

Plain language

This control is about making sure any contracts with external service providers include clear rules about how they must protect your data. It's important because if these rules aren't in place, a provider could mishandle your data, leading to privacy breaches, financial loss, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and reviewed on a regular and ongoing basis to ensure they remain fit for purpose.
policy ASD Information Security Manual (ISM) ISM-0072
priority_high

Why it matters

If security requirements aren’t written and reviewed in service provider contracts, data confidentiality, integrity and availability may be compromised, causing financial and reputational harm.

settings

Operational notes

Regularly review and update provider contract security clauses (e.g., access controls, incident reporting, audit rights) to ensure they remain fit for purpose and are being met.

Mapping detail

Mapping

Direction

Controls