Skip to content
arrow_back
search
ISM-0661 policy ASD Information Security Manual (ISM)

User Accountability for Data Transfers

Users are responsible for the data they move between systems.

record_voice_over

Plain language

The rule here is simple: if you're moving data between different systems, it's your responsibility to ensure it's done properly and securely. If done improperly, you risk exposing sensitive information or allowing unauthorised folks to get their hands on it, which could lead to financial losses and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Users transferring data to and from systems are held accountable for data transfers they perform.
policy ASD Information Security Manual (ISM) ISM-0661
priority_high

Why it matters

Without user accountability for data transfers, unauthorised exfiltration and leaks can go undetected, increasing breach impact and loss of client trust.

settings

Operational notes

Enable per-user transfer logging and regularly review logs to trace each upload/download to a user and investigate anomalies.

Mapping detail

Mapping

Direction

Controls