Skip to content
arrow_back
search
ISM-0078 policy ASD Information Security Manual (ISM)

Australian Supervision of AUSTEO/AGAO Data Systems

Only Australian nationals should control systems handling sensitive Australian data.

record_voice_over

Plain language

This control requires that any system handling sensitive Australian data, specifically AUSTEO (Australian Eyes Only) or AGAO (Australian Government Access Only), must always be managed by an Australian citizen. This matters because allowing foreign nationals to control these systems increases the risk of sensitive data being accessed by individuals or entities not authorised by the Australian Government.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

May 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Systems processing, storing or communicating AUSTEO or AGAO data remain at all times under the control of an Australian national working for or on behalf of the Australian Government.
policy ASD Information Security Manual (ISM) ISM-0078
priority_high

Why it matters

Allowing non-Australian nationals to manage AUSTEO/AGAO systems risks data leaks to unauthorised foreign entities, compromising national security.

settings

Operational notes

Weekly confirm AUSTEO/AGAO admins are Australian nationals acting for the Australian Government, and review access lists/logs for any non-compliant accounts.

Mapping detail

Mapping

Direction

Controls