Skip to content
arrow_back
search
ISM-0307 policy ASD Information Security Manual (ISM)

Ensure Proper Sanitisation Before IT Maintenance

Clean IT equipment and media if maintenance is done by non-cleared technicians.

record_voice_over

Plain language

When IT equipment needs repairs and you can't use a technician with the right security clearance, it's important to clean data from the devices first. This helps prevent sensitive information from leaking if someone accidentally or intentionally looks at the data during maintenance.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If an appropriately cleared technician is not used to undertake maintenance or repairs of IT equipment, the IT equipment and associated media is sanitised before maintenance or repair work is undertaken.
policy ASD Information Security Manual (ISM) ISM-0307
priority_high

Why it matters

If IT equipment isn’t sanitised before third‑party maintenance, non‑cleared technicians may access stored sensitive data, causing a breach and loss of trust.

settings

Operational notes

Before handing devices/media to non‑cleared technicians, sanitise per approved method (wipe/crypto‑erase) and record evidence of sanitisation.

Mapping detail

Mapping

Direction

Controls