Skip to content
arrow_back
search
ISM-0565 policy ASD Information Security Manual (ISM)

Email Security for Protective Markings

Email servers stop and track emails with wrong markings to prevent mistakes.

record_voice_over

Plain language

This control is about making sure that emails are properly marked so that sensitive information isn't sent to the wrong person by mistake. If emails are not marked correctly, it could lead to serious privacy breaches or sensitive information getting into the wrong hands.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Email servers are configured to block, log and report emails with inappropriate protective markings.
policy ASD Information Security Manual (ISM) ISM-0565
priority_high

Why it matters

If email servers don’t block, log and report incorrect protective markings, sensitive content may be misrouted or disclosed to unauthorised recipients.

settings

Operational notes

Tune transport rules to detect mismatched protective markings; review logs and alerts regularly and investigate reported emails to correct sender behaviour.

Mapping detail

Mapping

Direction

Controls