Skip to content
arrow_back
search
ISM-0316 policy ASD Information Security Manual (ISM)

Formal Decision on IT Equipment Disposal

Before IT equipment is publicly released, it must be sanitised and authorised after a formal decision.

record_voice_over

Plain language

When a business needs to get rid of old computers or electronic devices, it's essential to ensure all data is wiped clean and authorised for disposal. If this isn't done, sensitive information could end up in the wrong hands, leading to privacy breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Following sanitisation, destruction or declassification, a formal administrative decision is made to release IT equipment, or its waste, into the public domain.
policy ASD Information Security Manual (ISM) ISM-0316
priority_high

Why it matters

Without a formal release decision after sanitisation/destruction, IT equipment or waste may be released publicly while still sensitive, causing data exposure and reputational harm.

settings

Operational notes

Record a formal administrative release decision (approver, date, asset IDs, sanitisation/destruction evidence) before IT equipment or waste is released into the public domain.

Mapping detail

Mapping

Direction

Controls