Skip to content
arrow_back
search
ISM-0305 policy ASD Information Security Manual (ISM)

On-Site Maintenance by Cleared Technicians

IT equipment maintenance and repairs must be done on-site by technicians with appropriate security clearances.

record_voice_over

Plain language

When IT equipment like computers and servers need fixing or maintenance, the work must be done on-site by technicians who have the right security clearance. This is crucial because it prevents unauthorised people from accessing sensitive information on your devices, which could lead to data breaches or misuse of confidential information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Maintenance and repairs of IT equipment is carried out on site by an appropriately cleared technician.
policy ASD Information Security Manual (ISM) ISM-0305
priority_high

Why it matters

Using uncleared technicians for on-site maintenance can enable unauthorised access to systems, leading to compromise or data exfiltration.

settings

Operational notes

Confirm technician clearances before each visit, supervise on-site work, and record all maintenance actions in logs for later audit.

Mapping detail

Mapping

Direction

Controls