Skip to content
arrow_back
search
ISM-0271 policy ASD Information Security Manual (ISM)

Prevent Automatic Email Marking by Protective Tools

Protective tools for emails don't automatically add security labels to your messages.

record_voice_over

Plain language

This control is about making sure that email security tools don’t automatically add labels to your emails like 'Confidential' or 'Sensitive'. If such labels are added without your knowledge, it could lead to either sensitive information being shared too broadly or normal emails being overly restricted, which can cause confusion and harm communication.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Protective marking tools do not automatically insert protective markings into emails.
policy ASD Information Security Manual (ISM) ISM-0271
priority_high

Why it matters

If tools auto-insert protective markings, emails may be over- or under-marked, causing oversharing of sensitive data or unnecessary access restrictions.

settings

Operational notes

Audit email clients/add-ins to confirm no auto protective marking is applied. Disable auto-labelling features and train staff to manually select the correct marking.

Mapping detail

Mapping

Direction

Controls