Skip to content
arrow_back
search
ISM-0272 policy ASD Information Security Manual (ISM)

Prevent Unauthorised Protective Marking Selection

Ensure users cannot choose classification levels the system cannot handle.

record_voice_over

Plain language

This control makes sure that when you or your team use protective marking tools (like setting labels on emails or documents), you can only choose levels that the system is able to handle. It's important because if employees mark something as more secure than your system can actually manage, it can lead to accidental leaks of sensitive information or overlooked security gaps.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Protective marking tools do not allow users to select protective markings that a system has not been authorised to process, store or communicate.
policy ASD Information Security Manual (ISM) ISM-0272
priority_high

Why it matters

If users can select markings the system isn’t authorised to handle, data may be stored or shared at the wrong classification, increasing risk of compromise.

settings

Operational notes

Configure marking tools to offer only the protective markings the system is authorised to process/store/communicate, and review settings after changes to accreditation.

Mapping detail

Mapping

Direction

Controls