Skip to content
arrow_back
search
ISM-0311 policy ASD Information Security Manual (ISM)

Ensuring Sanitisation of IT Equipment Media

Remove or clean media from IT equipment to ensure data is not left on the device.

record_voice_over

Plain language

This control ensures that any data on IT equipment is either removed or properly cleaned before the equipment leaves your control or is repurposed. This matters because leftover data can fall into the wrong hands, resulting in privacy breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IT equipment containing media is sanitised by removing the media from the IT equipment or by sanitising the media in situ.
policy ASD Information Security Manual (ISM) ISM-0311
priority_high

Why it matters

Residual data on unsanitised media can be recovered, enabling unauthorised access and disclosure of sensitive information, with potential financial loss.

settings

Operational notes

Verify media sanitisation or removal for each device, and record the method, date and approver to support audit and disposal assurance.

Mapping detail

Mapping

Direction

Controls