Skip to content
arrow_back
search
ISM-0133 policy ASD Information Security Manual (ISM)

Responding to Data Spills by Restricting Access

When a data spill occurs, notify the data owner and limit access to protect information.

record_voice_over

Plain language

Imagine one of your staff accidentally sends confidential customer details to the wrong email list. This is a data spill. It's crucial to act fast by telling the person in charge of that information and restricting who can see it. If you don't, more people might see the confidential data, which can lead to privacy breaches and loss of trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When a data spill occurs, data owners are advised and access to the data is restricted.
policy ASD Information Security Manual (ISM) ISM-0133
priority_high

Why it matters

If access isn’t promptly restricted and data owners advised after a data spill, unauthorised disclosure may occur, increasing impact and undermining trust.

settings

Operational notes

On a data spill, immediately advise data owners and restrict access to affected data; review access logs and confirm restrictions remain until containment is complete.

Mapping detail

Mapping

Direction

Controls