Skip to content
arrow_back
search
ISM-0269 policy ASD Information Security Manual (ISM)

Restrict Sensitive Emails to Verified Recipients

Sensitive emails must not go to groups unless all recipients' nationalities are confirmed.

record_voice_over

Plain language

This control ensures that emails with sensitive Australian government data are only sent to people whose nationalities we know and trust. It matters because sending such emails to unknown or unverified recipients could lead to information ending up in the wrong hands, risking national security or privacy breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Emails containing Australian Eyes Only, Australian Government Access Only or Releasable To data are not sent to email distribution lists unless the nationality of all members of email distribution lists can be confirmed.
policy ASD Information Security Manual (ISM) ISM-0269
priority_high

Why it matters

Sending AEO/AGAO/REL data to distribution lists without confirming every member’s nationality can disclose sensitive information to ineligible recipients and breach policy.

settings

Operational notes

Regularly audit distribution list membership and maintain evidence of each member’s confirmed nationality before allowing AEO/AGAO/REL emails to be sent to the list.

Mapping detail

Mapping

Direction

Controls