Skip to content
arrow_back
search
ISM-0310 policy ASD Information Security Manual (ISM)

Ensure Off-site IT Repairs Are Conducted at Approved Facilities

IT equipment sent for repair off-site must be taken to facilities that can handle its security level.

record_voice_over

Plain language

When you send your IT equipment out for a fix, like a broken computer or server, it’s vital to ensure it's going to a repair facility that can handle its level of confidentiality. If this isn’t done, there's a risk that sensitive data could be exposed or misused, leading to privacy breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IT equipment maintained or repaired off site is done so at facilities approved for handling the sensitivity or classification of the IT equipment.
policy ASD Information Security Manual (ISM) ISM-0310
priority_high

Why it matters

Repair at unapproved facilities risks exposure of classified data, enabling compromise or espionage and causing financial and reputational harm.

settings

Operational notes

Maintain an approved list of off-site repair facilities by classification, and re-validate partner clearances and secure handling requirements before each repair.

Mapping detail

Mapping

Direction

Controls