Skip to content
arrow_back
search
ISM-0313 policy ASD Information Security Manual (ISM)

Develop and Maintain IT Equipment Sanitisation Procedures

Organisations must create and uphold processes for properly cleaning and disposing of IT equipment.

record_voice_over

Plain language

This control is about ensuring that your organisation properly cleans and disposes of IT equipment like computers and smartphones. If you don't do this, sensitive information could be accidentally shared when old devices are discarded or sold, which could lead to data breaches and damage your business's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IT equipment sanitisation processes, and supporting IT equipment sanitisation procedures, are developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-0313
priority_high

Why it matters

Improper sanitisation of IT equipment can lead to data leaks, exposing sensitive information when devices are discarded, compromising business integrity.

settings

Operational notes

Maintain documented sanitisation procedures, train staff, and verify data wiping (or destruction) is completed and recorded before disposal, resale or reuse.

Mapping detail

Mapping

Direction

Controls