Off-Site IT Equipment Handling Approvals
Off-site IT repairs must be at approved facilities matching the equipment's classification level.
Plain language
This control ensures that any IT equipment you send off-site for repairs goes to a place that's approved to handle its sensitive information. If this doesn't happen, your business could accidentally leak confidential data, leading to financial loss or trust issues with clients.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
IT equipment maintained or repaired off site is handled at facilities approved for handling the sensitivity or classification of the IT equipment.
Why it matters
If improper facilities handle repairs, sensitive data can leak, compromising customer trust and violating privacy laws.
Operational notes
Regularly update your list of approved repair facilities to ensure continued compliance with security standards.
Implementation tips
- The IT manager should create a list of approved repair facilities. Begin by identifying facilities that have the necessary security certifications for handling your equipment's classification level.
- The procurement team should ensure contracts with repair facilities include clauses about handling sensitive data. They should work with legal advisors to draft these terms clearly and ensure they cover all security requirements.
- Office managers should track all equipment sent for off-site repair. Use a logbook or spreadsheet that records what was sent, where, when, and if the facility is on the approved list.
- IT support staff should conduct regular checks on repair facilities to confirm compliance. Visit facilities annually to verify that they still meet the security criteria needed for your equipment.
- The compliance officer should establish a review process for repair facility approvals. Schedule reviews at least once a year to reassess each facility's qualifications and adjust the approved list as needed.
Audit / evidence tips
- Askthe list of approved repair facilities: Request documentation that shows which facilities are approved to handle your IT equipmentLook atapproval dates and notes on each one's security measuresGoodlist will have up-to-date entries with clear security criteria for each facility
- Askrecent equipment repair logs: Get copies of logs that track IT equipment sent off-siteLook atentries that include the date sent, destination, and whether the facility is approvedGoodlog will show consistent usage of approved facilities only
- Look atclauses that specify data protection and confidentiality measuresGoodcontract is clear and complies with your security policies
- Askassessment reports on repair facilities: Review documents from recent checks or audits of facilitiesLook atdetails on facility evaluations, security credentials, and compliance statusGoodreport confirms facilities meet all needed security standards
- Look atsections on facility approval criteria and review schedulesGoodpolicy is detailed, current, and accessible to relevant staff
Cross-framework mappings
How ISM-0310 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 7.13 | ISM-0310 requires that IT equipment maintained or repaired off site is handled only at facilities approved for the equipment’s sensitivit... | |
handshakeSupports(2)expand_less | ||
| Annex A 5.21 | ISM-0310 requires organisations to ensure off-site IT repairs are conducted only at facilities approved to handle the asset’s classification | |
| Annex A 5.22 | ISM-0310 requires that off-site maintenance/repairs occur only at approved facilities suitable for the equipment’s classification | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Information technology equipment
See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.