Skip to content
arrow_back
search
ISM-0447 policy ASD Information Security Manual (ISM)

Restrict Privileged Access for Foreign Nationals

Foreign nationals can't have privileged access to systems handling AGAO data except if seconded.

record_voice_over

Plain language

This rule means that foreign nationals aren't allowed to have special access to important systems that handle sensitive Australian Government data, unless they are temporarily working as part of an agreement. This is crucial because if those who aren't local don't have the right checks or trust, they could accidentally or intentionally harm the systems or data, leading to data theft, system failure, or breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

May 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Foreign nationals, excluding seconded foreign nationals, do not have privileged access to systems that process, store or communicate AGAO data.
policy ASD Information Security Manual (ISM) ISM-0447
priority_high

Why it matters

If foreign nationals have privileged access, AGAO data may be exposed or altered, increasing risk of unauthorised disclosure and national security harm.

settings

Operational notes

Maintain a register of privileged accounts and verify holders are not foreign nationals (except seconded). Review access and revoke exceptions promptly.

Mapping detail

Mapping

Direction

Controls