Skip to content
arrow_back
search
ISM-0665 policy ASD Information Security Manual (ISM)

Verification Required for Exporting Secret Data

Only verified and authorised people or services can handle SECRET or TOP SECRET data exports.

record_voice_over

Plain language

This control ensures that only people or services with special approval can handle very sensitive information when it's sent outside the organisation. This is important because if the wrong person gains access, it could lead to data theft, financial loss, or damage to the organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Aug 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Trustworthy sources for SECRET and TOP SECRET systems are limited to people and services that have been verified and authorised as such by the chief information security officer.
policy ASD Information Security Manual (ISM) ISM-0665
priority_high

Why it matters

If trustworthy export sources aren’t verified and authorised by the CISO, SECRET/TOP SECRET data can be exfiltrated to untrusted people/services, enabling espionage and major damage.

settings

Operational notes

Maintain a CISO-approved register of verified and authorised people/services permitted to export SECRET/TOP SECRET data, and review access and verification evidence after role or service changes.

Mapping detail

Mapping

Direction

Controls