Skip to content
arrow_back
search
ISM-0652 policy ASD Information Security Manual (ISM)

Quarantine Suspicious Files for Review

Files flagged as risky are held until checked and cleared or blocked.

record_voice_over

Plain language

This control means that if a file looks suspicious, it gets set aside so someone can take a closer look before it's allowed to continue. This matters because it helps prevent harmful files, like viruses or ransomware, from getting into your computer systems and causing damage or stealing your information.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Files identified by content filtering checks as suspicious are quarantined until reviewed and subsequently approved or not approved for release.
policy ASD Information Security Manual (ISM) ISM-0652
priority_high

Why it matters

Without quarantining suspicious files flagged by content filtering, malware (e.g. ransomware) may be released to users, causing outages or data compromise.

settings

Operational notes

Route quarantined files to a defined reviewer queue, set SLAs for review, and only release items after approval; track backlog to avoid business delays.

Mapping detail

Mapping

Direction

Controls