Skip to content
arrow_back
search
ISM-0270 policy ASD Information Security Manual (ISM)

Apply Protective Markings to Emails Based on Sensitivity

Emails must be marked to show their highest confidentiality level based on content.

record_voice_over

Plain language

This control means that any email you send needs to have a label or marking telling how sensitive the information is. It’s important because if an email that includes sensitive data is handled carelessly or falls into the wrong hands, it could lead to data theft, legal issues, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Protective markings are applied to emails and reflect the highest sensitivity or classification of the subject, body and attachments.
policy ASD Information Security Manual (ISM) ISM-0270
priority_high

Why it matters

If emails aren’t marked to the highest sensitivity of subject, body or attachments, staff may mishandle them, leading to unauthorised disclosure, reportable breaches and legal or reputational harm.

settings

Operational notes

Configure email tools to apply protective markings by default, validate markings match the highest sensitivity in the subject/body/attachments, and routinely review samples and train users on correct marking.

Mapping detail

Mapping

Direction

Controls