Skip to content
arrow_back
search
ISM-0589 policy ASD Information Security Manual (ISM)

Limit Document Sensitivity on MFDs Based on Network Classification

Multifunction devices should not scan or copy documents that are more sensitive than the network they are connected to can handle.

record_voice_over

Plain language

This control means making sure that office machines like printers and copiers (called Multifunction Devices, or MFDs) don't handle documents that are too sensitive for the network they're on. This matters because if a document is more sensitive than the network's security level, it could fall into the wrong hands, causing data breaches or revealing private information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

MFDs are not used to scan or copy documents above the sensitivity or classification of networks they are connected to.
policy ASD Information Security Manual (ISM) ISM-0589
priority_high

Why it matters

If an MFD scans/copies above its connected network classification, sensitive content can traverse lower networks and be stored on the device, causing data spills.

settings

Operational notes

Configure MFD scan/copy limits to the connected network classification; disable higher-class modes and restrict scan-to paths (email/SMB/USB) to same-class destinations.

Mapping detail

Mapping

Direction

Controls