Document Security Requirements in Contractual Arrangements
Include security needs in contracts with service providers and review them to ensure they meet current standards.
Plain language
This control is about making sure your service contracts include rules to keep your data safe and reviewing them regularly to ensure they're still good. If you don't do this, sensitive information might leak, or you could lose access to important data when you need it most.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Security requirements associated with the confidentiality, integrity and availability of data are documented in contractual arrangements with service providers and regularly reviewed to ensure they remain fit for purpose.
Why it matters
Without these precautions, data could be exposed or inaccessible, harming business operations and reputation.
Operational notes
Continuously monitor changes in both legal requirements and technology to keep contractual security needs current and effective.
Implementation tips
- Procurement teams should include specific security clauses in all contracts with service providers. This can be done by consulting with IT experts to list the data protection requirements necessary for confidentiality and availability.
- Managers should regularly review these contracts to ensure they still meet current standards. Set a calendar reminder every six months to check if there have been changes in technology or regulations that affect your security needs.
- The IT team should work with the procurement team to update any contracts whenever new threats or vulnerabilities are identified. Conduct a security risk assessment when new services are added or existing ones significantly change.
- Legal advisors should be involved to ensure these contracts legally bind the service providers to the agreed security standards. Include representatives from legal and compliance to review any updates to ensure no detail is overlooked.
- Service providers should be contacted if terms are not met. Establish a communication line with the providers to address issues quickly, ensuring there's a clear process to mitigate risks if any breach occurs.
Audit / evidence tips
- Askthe latest copy of contracts with the service providers: Verify that security requirements are documentedLook atspecific clauses around data protection measuresGoodshows clear, tailored security requirements documented and signed by all parties
- Askto see any notes or documentation from regular contract reviews: Check whether reviews are scheduled and completed on timeLook atcalendars or logs showing the dates and findings of reviewsGoodlists reviews every six months with findings documented
- Askevidence of communication with service providers regarding security expectationsLook atemails or meeting recordsGoodincludes dated communication logs demonstrating discussion of security needs
- Askrecords of security risk assessmentsLook atevaluation results that might necessitate updating contractsGoodincludes a report outlining potential risks with proposed contract adjustments
- Asknotes or minutes from meetings involving legal and procurement teams: Ensure discussions on contract updates are documentedGoodincludes clear records showing contract changes were reviewed by legal experts
Cross-framework mappings
How ISM-0072 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(3)expand_less | ||
| Annex A 5.19 | Annex A 5.19 requires organisations to define and implement processes to manage information security risks arising from supplier products... | |
| Annex A 5.36 | Annex A 5.36 requires organisations to regularly review compliance with information security policies, rules and standards | |
| Annex A 6.6 | Annex A 6.6 requires the organisation to identify, document, regularly review and obtain signed confidentiality or non-disclosure agreeme... | |
handshakeSupports(2)expand_less | ||
| Annex A 5.14 | Annex A 5.14 requires organisations to define and apply rules/procedures/agreements for transferring information between the organisation... | |
| Annex A 5.32 | Annex A 5.32 requires the organisation to implement procedures to protect intellectual property rights, commonly including contractual co... | |
extensionDepends on(1)expand_less | ||
| Annex A 5.22 | Annex A 5.22 requires monitoring, review and evaluation of supplier practices against expectations, and to manage changes | |
linkRelated(2)expand_less | ||
| Annex A 5.20 | Annex A 5.20 requires information security requirements to be agreed with each supplier | |
| Annex A 5.21 | Annex A 5.21 requires processes and procedures to manage information security risks arising from ICT suppliers and service dependencies | |
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 6.2.2 | Annex A 6.2.2 requires documenting requirements for new AI systems or material enhancements, often including external services, data hand... | |
handshakeSupports(1)expand_less | ||
| Annex A 9.4 | Annex A 9.4 requires AI systems to be used according to intended use and documentation, including constraints relating to confidentiality... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.