Block Privately Owned Devices From SECRET and TOP SECRET Systems
Personally owned mobile devices and desktop computers must never be used to access SECRET or TOP SECRET systems or the data held in them.
Plain language
This control means that personal phones, tablets and home computers (any device owned by an individual rather than the organisation) are not allowed to connect to or open systems and information classified as SECRET or TOP SECRET. SECRET and TOP SECRET are the two highest government security classifications, used for information that could cause serious or exceptionally grave damage if exposed. Personal devices cannot be properly checked, locked down or monitored, so allowing them near such sensitive systems creates an unacceptable risk of leaks.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for enterprise mobilitySection
Enterprise MobilityOfficial control statement
Privately owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data.
Why it matters
If a personal phone or home computer connects to SECRET or TOP SECRET systems, highly classified information can leak through an uncontrolled device, causing serious or exceptionally grave national security damage.
Operational notes
Keep the device register current as hardware is added or retired, and re-check the technical and physical blocks whenever the classified systems or their network change.
Implementation tips
- The IT or security manager should configure the SECRET and TOP SECRET systems so they only accept connections from a register of organisation-owned, hardened devices, and reject any device not on that list.
- The system owner should publish a written policy stating plainly that no privately owned mobile device or desktop computer may access SECRET or TOP SECRET systems or data, and have all staff who use these systems sign it.
- IT administrators should issue government or organisation-owned devices to anyone who needs to work with SECRET or TOP SECRET material, so staff never have a reason to reach for a personal device.
- The security team should physically separate the areas and networks where SECRET and TOP SECRET systems live, controlling entry so personal phones and laptops cannot be plugged in or connected.
- Managers should run a clear-desk and device-check routine before staff enter SECRET or TOP SECRET work areas, collecting or excluding personal devices at the door.
Audit / evidence tips
- Askthe access control configuration or device register for the SECRET and TOP SECRET systemsLook atwhether only organisation-owned devices are listed and whether unknown devices are actively blockedGoodshows a maintained allow-list and evidence that non-listed devices are refused connection
- Askthe written policy banning privately owned devices from these systemsLook atwhether it names both mobile devices and desktop computers and both SECRET and TOP SECRET classificationsGoodis a current, signed-off policy that staff have acknowledged
- Askhow staff are given the tools to do classified workLook atissue records for organisation-owned devices assigned to relevant usersGoodshows every user of these systems has an official device, removing any need for a personal one
- Askevidence of the controls that stop personal devices physically connectingLook atnetwork port controls, entry procedures and any device-detection logsGoodshows layered measures (technical and physical) rather than relying on staff goodwill alone
- Askany records of attempted or actual access by unauthorised personal devicesLook atthe logs and how each event was handledGoodshows either no such events or prompt detection and follow-up where one occurred
Cross-framework mappings
How ISM-0694 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 5.15 | ISM-0694 mandates that privately-owned devices are not permitted to access SECRET and TOP SECRET systems or data | |
| Annex A 8.3 | ISM-0694 requires an explicit prohibition on privately-owned devices accessing SECRET and TOP SECRET systems or data | |
handshakeSupports(2)expand_less | ||
| Annex A 8.20 | ISM-0694 requires preventing privately-owned devices from accessing SECRET and TOP SECRET systems or data | |
| Annex A 8.22 | ISM-0694 requires that privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data | |
extensionDepends on(1)expand_less | ||
| Annex A 5.12 | ISM-0694 enforces an access restriction specifically tied to SECRET and TOP SECRET classifications and to privately-owned devices | |
linkRelated(1)expand_less | ||
| Annex A 6.7 | Annex A 6.7 addresses protecting information when personnel work remotely, including controlling which devices can access organisational ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Enterprise mobility
See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.