Skip to content
arrow_back
search
ISM-0375 policy ASD Information Security Manual (ISM)

Decide on Public Release of Data Storage Media

After data is erased or destroyed, a formal decision allows media to be sent to the public.

record_voice_over

Plain language

When you delete or destroy data stored on media like hard drives or USB sticks, you need to make a formal decision about whether it's safe to let those items go into the public. This matters because if data isn't completely erased or destroyed, someone could retrieve sensitive information, leading to potential privacy breaches or data theft.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Following sanitisation, destruction or declassification, a formal administrative decision is made to release media, or its waste, into the public domain.
policy ASD Information Security Manual (ISM) ISM-0375
priority_high

Why it matters

Without a documented administrative decision to release sanitised/destroyed media (or waste) to the public domain, residual data may be exposed, causing privacy breaches and theft.

settings

Operational notes

Record a formal, authorised release decision (including scope: media vs waste) after confirming sanitisation/destruction and declassification results; retain approvals and evidence before public disposal.

Mapping detail

Mapping

Direction

Controls