Skip to content
arrow_back
ISM-0310policyASD Information Security Manual (ISM)

Off-Site IT Equipment Handling Approvals

Off-site IT repairs must be at approved facilities matching the equipment's classification level.

record_voice_over

Plain language

This control ensures that any IT equipment you send off-site for repairs goes to a place that's approved to handle its sensitive information. If this doesn't happen, your business could accidentally leak confidential data, leading to financial loss or trust issues with clients.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.
policyASD Information Security Manual (ISM)ISM-0310
priority_high

Why it matters

If improper facilities handle repairs, sensitive data can leak, compromising customer trust and violating privacy laws.

settings

Operational notes

Regularly update your list of approved repair facilities to ensure continued compliance with security standards.

build

Implementation tips

  • The IT manager should create a list of approved repair facilities. Begin by identifying facilities that have the necessary security certifications for handling your equipment's classification level.
  • The procurement team should ensure contracts with repair facilities include clauses about handling sensitive data. They should work with legal advisors to draft these terms clearly and ensure they cover all security requirements.
  • Office managers should track all equipment sent for off-site repair. Use a logbook or spreadsheet that records what was sent, where, when, and if the facility is on the approved list.
  • IT support staff should conduct regular checks on repair facilities to confirm compliance. Visit facilities annually to verify that they still meet the security criteria needed for your equipment.
  • The compliance officer should establish a review process for repair facility approvals. Schedule reviews at least once a year to reassess each facility's qualifications and adjust the approved list as needed.
fact_check

Audit / evidence tips

  • Askthe list of approved repair facilities: Request documentation that shows which facilities are approved to handle your IT equipmentLook atapproval dates and notes on each one's security measuresGoodlist will have up-to-date entries with clear security criteria for each facility
  • Askrecent equipment repair logs: Get copies of logs that track IT equipment sent off-siteLook atentries that include the date sent, destination, and whether the facility is approvedGoodlog will show consistent usage of approved facilities only
  • Look atclauses that specify data protection and confidentiality measuresGoodcontract is clear and complies with your security policies
  • Askassessment reports on repair facilities: Review documents from recent checks or audits of facilitiesLook atdetails on facility evaluations, security credentials, and compliance statusGoodreport confirms facilities meet all needed security standards
  • Look atsections on facility approval criteria and review schedulesGoodpolicy is detailed, current, and accessible to relevant staff
link

Cross-framework mappings

How ISM-0310 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 7.13ISM-0310 requires that IT equipment maintained or repaired off site is handled only at facilities approved for the equipment’s sensitivit...
handshakeSupports(2)expand_less
Annex A 5.21ISM-0310 requires organisations to ensure off-site IT repairs are conducted only at facilities approved to handle the asset’s classification
Annex A 5.22ISM-0310 requires that off-site maintenance/repairs occur only at approved facilities suitable for the equipment’s classification

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls