Skip to content
arrow_back
ISM-0307policyASD Information Security Manual (ISM)

Sanitise Equipment When Not Using Cleared Technician

Sanitise IT equipment if repairs are made by non-cleared technicians.

record_voice_over

Plain language

When fixing or maintaining IT equipment, it's essential to make sure that any sensitive data is wiped clean if the work is done by someone who isn't officially approved for secure tasks. This prevents data from being exposed to unauthorised individuals, protecting your organisation from potential breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

If an appropriately cleared technician is not used to undertake maintenance or repairs to IT equipment, the IT equipment and associated media are sanitised before maintenance or repairs.
policyASD Information Security Manual (ISM)ISM-0307
priority_high

Why it matters

Failing to sanitise equipment exposes sensitive data to unauthorised access, leading to potential data breaches and reputational damage.

settings

Operational notes

Consistently monitor and update data sanitisation processes to align with evolving security threats and best practices.

build

Implementation tips

  • IT Managers should ensure that a checklist is in place for data sanitisation before any repairs. Do this by creating a template that lists all devices, types of data, and steps for erasing it securely.
  • Office Managers need to keep a record of which devices have undergone repairs by non-approved personnel. Track this in a simple logbook or spreadsheet noting the date, device, and technician.
  • Procurement officers should verify that repair contracts include requirements for data sanitisation when non-cleared technicians are involved. Ensure these clauses are visible and acknowledged in contracts.
  • IT Support staff must use data wiping software before handing devices to non-cleared technicians. Select software that fully erases data, not just deletes it, and verify each wipe with a validation report.
  • Team leaders should regularly review and update sanitisation procedures. Schedule monthly meetings to assess if the process is current with best practices and adjust as needed.
fact_check

Audit / evidence tips

  • Askthe data sanitisation policy: Check for a document that describes procedures when non-cleared technicians are usedLook atwhether it includes all steps and responsible partiesGoodis a detailed, clearly updated policy
  • Look atdates, device identifiers, and technician detailsGoodcomplete entries with no gaps in dates
  • Askproof of data wiping tool usage: Request reports or screenshots from the software used for wiping dataLook atconfirmations that data was erased successfullyGoodincludes timestamped reports
  • Look atdistinct terms for sanitisation complianceGoodshows explicit clauses signed by vendors
  • Askto see regular review records for sanitisation processes: Review minutes from meetings discussing improvements to the sanitisation procedureLook atrecent updates and decisionsGoodprovides actionable outcomes from each meeting
link

Cross-framework mappings

How ISM-0307 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 7.10ISM-0307 requires sanitising IT equipment and associated media before maintenance or repairs when work is performed by a technician who i...
sync_altPartially overlaps(4)expand_less
Annex A 5.19ISM-0307 requires sanitising equipment and media before maintenance when an appropriately cleared technician is not used
Annex A 7.13Annex A 7.13 requires equipment to be maintained correctly to preserve the availability, integrity and confidentiality of information
Annex A 7.14ISM-0307 requires sanitising IT equipment and any associated media before maintenance or repair when the technician is not appropriately ...
Annex A 8.10Annex A 8.10 mandates deletion of unnecessary information

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls