Skip to content
arrow_back
ISM-0694policyASD Information Security Manual (ISM)

Block Privately Owned Devices From SECRET and TOP SECRET Systems

Personally owned mobile devices and desktop computers must never be used to access SECRET or TOP SECRET systems or the data held in them.

record_voice_over

Plain language

This control means that personal phones, tablets and home computers (any device owned by an individual rather than the organisation) are not allowed to connect to or open systems and information classified as SECRET or TOP SECRET. SECRET and TOP SECRET are the two highest government security classifications, used for information that could cause serious or exceptionally grave damage if exposed. Personal devices cannot be properly checked, locked down or monitored, so allowing them near such sensitive systems creates an unacceptable risk of leaks.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Privately owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data.
policyASD Information Security Manual (ISM)ISM-0694
priority_high

Why it matters

If a personal phone or home computer connects to SECRET or TOP SECRET systems, highly classified information can leak through an uncontrolled device, causing serious or exceptionally grave national security damage.

settings

Operational notes

Keep the device register current as hardware is added or retired, and re-check the technical and physical blocks whenever the classified systems or their network change.

build

Implementation tips

  • The IT or security manager should configure the SECRET and TOP SECRET systems so they only accept connections from a register of organisation-owned, hardened devices, and reject any device not on that list.
  • The system owner should publish a written policy stating plainly that no privately owned mobile device or desktop computer may access SECRET or TOP SECRET systems or data, and have all staff who use these systems sign it.
  • IT administrators should issue government or organisation-owned devices to anyone who needs to work with SECRET or TOP SECRET material, so staff never have a reason to reach for a personal device.
  • The security team should physically separate the areas and networks where SECRET and TOP SECRET systems live, controlling entry so personal phones and laptops cannot be plugged in or connected.
  • Managers should run a clear-desk and device-check routine before staff enter SECRET or TOP SECRET work areas, collecting or excluding personal devices at the door.
fact_check

Audit / evidence tips

  • Askthe access control configuration or device register for the SECRET and TOP SECRET systemsLook atwhether only organisation-owned devices are listed and whether unknown devices are actively blockedGoodshows a maintained allow-list and evidence that non-listed devices are refused connection
  • Askthe written policy banning privately owned devices from these systemsLook atwhether it names both mobile devices and desktop computers and both SECRET and TOP SECRET classificationsGoodis a current, signed-off policy that staff have acknowledged
  • Askhow staff are given the tools to do classified workLook atissue records for organisation-owned devices assigned to relevant usersGoodshows every user of these systems has an official device, removing any need for a personal one
  • Askevidence of the controls that stop personal devices physically connectingLook atnetwork port controls, entry procedures and any device-detection logsGoodshows layered measures (technical and physical) rather than relying on staff goodwill alone
  • Askany records of attempted or actual access by unauthorised personal devicesLook atthe logs and how each event was handledGoodshows either no such events or prompt detection and follow-up where one occurred
link

Cross-framework mappings

How ISM-0694 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 5.15ISM-0694 mandates that privately-owned devices are not permitted to access SECRET and TOP SECRET systems or data
Annex A 8.3ISM-0694 requires an explicit prohibition on privately-owned devices accessing SECRET and TOP SECRET systems or data
handshakeSupports(2)expand_less
Annex A 8.20ISM-0694 requires preventing privately-owned devices from accessing SECRET and TOP SECRET systems or data
Annex A 8.22ISM-0694 requires that privately-owned mobile devices and desktop computers do not access SECRET and TOP SECRET systems or data
extensionDepends on(1)expand_less
Annex A 5.12ISM-0694 enforces an access restriction specifically tied to SECRET and TOP SECRET classifications and to privately-owned devices
linkRelated(1)expand_less
Annex A 6.7Annex A 6.7 addresses protecting information when personnel work remotely, including controlling which devices can access organisational ...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls