Label IT Equipment with Sensitivity Markings
Label IT equipment, except high assurance, with appropriate sensitivity or classification markings.
Plain language
It's important to label IT equipment, apart from high-security items, with how sensitive the information on it is. If we don't, we risk losing control of private data, which could lead to legal troubles, financial loss, or harm to our reputation.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Section
It Equipment UsageOfficial control statement
IT equipment, except for high assurance IT equipment, is labelled with protective markings reflecting its sensitivity or classification.
Why it matters
Unlabelled IT equipment can lead to data leaks, causing legal issues, financial loss, and damage to reputation.
Operational notes
Regular checks are essential to ensure all IT equipment maintains its correct sensitivity labels, avoiding data mishandling.
Implementation tips
- The IT team should create a list of all equipment that needs sensitivity labels. They can identify devices like computers, servers, and even tablets that store or process sensitive information.
- Managers must assign labels to each piece of equipment based on the type of data it holds. They can use categories like 'Confidential' or 'Internal Use Only' to reflect the sensitivity.
- Procurement staff should ensure new equipment comes pre-labelled or ready for labelling. They can specify this requirement when ordering new gear.
- IT support should regularly check and update the labels as data classification changes. This involves physically inspecting the equipment to ensure the labels are current and correct.
- HR should train staff on recognising and respecting these labels to maintain information security. This can be done through workshops or regular briefings on security policies.
Audit / evidence tips
- Askan inventory of all IT equipment with their sensitivity labelsLook atthe completeness and classification of each itemGoodexample has a current list with each item marked according to sensitivity guidelines
- Goodis a clear process with roles and detailed instructions
- Look atattendance and comprehension of training sessionsGoodshows regular training with updated materials
- Askrecent inspection reports of labelled equipmentLook atthe dates and findings regarding label accuracy and visibilityGoodincludes a recent checklist confirming labels are correct
- Look atdetailed entries documenting reasons for changesGoodlogs the date, reason, and person responsible for each update
Cross-framework mappings
How ISM-0294 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 5.13 | ISM-0294 requires organisations to label IT equipment (excluding high assurance equipment) with protective markings that reflect the equi... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Information technology equipment
See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.