Skip to content
arrow_back
ISM-0072policyASD Information Security Manual (ISM)

Document Security Requirements in Contractual Arrangements

Include security needs in contracts with service providers and review them to ensure they meet current standards.

record_voice_over

Plain language

This control is about making sure your service contracts include rules to keep your data safe and reviewing them regularly to ensure they're still good. If you don't do this, sensitive information might leak, or you could lose access to important data when you need it most.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.
policyASD Information Security Manual (ISM)ISM-0072
priority_high

Why it matters

Without these precautions, data could be exposed or inaccessible, harming business operations and reputation.

settings

Operational notes

Continuously monitor changes in both legal requirements and technology to keep contractual security needs current and effective.

build

Implementation tips

  • Procurement teams should include specific security clauses in all contracts with service providers. This can be done by consulting with IT experts to list the data protection requirements necessary for confidentiality and availability.
  • Managers should regularly review these contracts to ensure they still meet current standards. Set a calendar reminder every six months to check if there have been changes in technology or regulations that affect your security needs.
  • The IT team should work with the procurement team to update any contracts whenever new threats or vulnerabilities are identified. Conduct a security risk assessment when new services are added or existing ones significantly change.
  • Legal advisors should be involved to ensure these contracts legally bind the service providers to the agreed security standards. Include representatives from legal and compliance to review any updates to ensure no detail is overlooked.
  • Service providers should be contacted if terms are not met. Establish a communication line with the providers to address issues quickly, ensuring there's a clear process to mitigate risks if any breach occurs.
fact_check

Audit / evidence tips

  • Askthe latest copy of contracts with the service providers: Verify that security requirements are documentedLook atspecific clauses around data protection measuresGoodshows clear, tailored security requirements documented and signed by all parties
  • Askto see any notes or documentation from regular contract reviews: Check whether reviews are scheduled and completed on timeLook atcalendars or logs showing the dates and findings of reviewsGoodlists reviews every six months with findings documented
  • Askevidence of communication with service providers regarding security expectationsLook atemails or meeting recordsGoodincludes dated communication logs demonstrating discussion of security needs
  • Askrecords of security risk assessmentsLook atevaluation results that might necessitate updating contractsGoodincludes a report outlining potential risks with proposed contract adjustments
  • Asknotes or minutes from meetings involving legal and procurement teams: Ensure discussions on contract updates are documentedGoodincludes clear records showing contract changes were reviewed by legal experts
link

Cross-framework mappings

How ISM-0072 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(3)expand_less
Annex A 5.19Annex A 5.19 requires organisations to define and implement processes to manage information security risks arising from supplier products...
Annex A 5.36Annex A 5.36 requires organisations to regularly review compliance with information security policies, rules and standards
Annex A 6.6Annex A 6.6 requires the organisation to identify, document, regularly review and obtain signed confidentiality or non-disclosure agreeme...
handshakeSupports(2)expand_less
Annex A 5.14Annex A 5.14 requires organisations to define and apply rules/procedures/agreements for transferring information between the organisation...
Annex A 5.32Annex A 5.32 requires the organisation to implement procedures to protect intellectual property rights, commonly including contractual co...
extensionDepends on(1)expand_less
Annex A 5.22Annex A 5.22 requires monitoring, review and evaluation of supplier practices against expectations, and to manage changes
linkRelated(2)expand_less
Annex A 5.20Annex A 5.20 requires information security requirements to be agreed with each supplier
Annex A 5.21Annex A 5.21 requires processes and procedures to manage information security risks arising from ICT suppliers and service dependencies

ISO 42001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 6.2.2Annex A 6.2.2 requires documenting requirements for new AI systems or material enhancements, often including external services, data hand...
handshakeSupports(1)expand_less
Annex A 9.4Annex A 9.4 requires AI systems to be used according to intended use and documentation, including constraints relating to confidentiality...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls