Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0701Establish Mobile Device Emergency Sanitisation Processes and Procedures

Official control statement

Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.
policyASD Information Security Manual (ISM)ISM-0701

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

The organisation develops, implements and maintains processes and supporting procedures to rapidly sanitise mobile devices in an emergency.

NCOSPASD Information Security ManualGuidelines for enterprise mobility
record_voice_over

What this means in practice

This control ensures your organisation can quickly and completely erase data from a mobile device when an emergency demands it, such as when a device is lost, stolen or seized. It requires both a high-level process and step-by-step procedures that staff can follow under pressure. Keeping these current and tested matters because sensitive information left on an unsecured device can be read by anyone who gains access to it.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2022

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Mobile device emergency sanitisation processes and procedures

priority_high

Why it matters

Without a tested emergency sanitisation capability, a lost, stolen or seized mobile device can expose sensitive organisational data to unauthorised parties.

settings

Operational notes

Review and test the sanitisation process at regular intervals and after any change to the mobile device fleet or management tools, confirming remote wipe still works.

build

Implementation tips

  • Have the security team define the events that trigger emergency sanitisation, such as device loss, theft, compromise or travel to high-risk locations, and record them in the documented process.
  • Configure your mobile device management (MDM) platform so administrators can remotely wipe or factory-reset a device the moment it is reported at risk.
  • Write step-by-step procedures that tell staff and administrators exactly who to contact, what actions to take and in what order when a device needs emergency sanitisation.
  • Enable full-device encryption on all mobile devices so a cryptographic erase renders the stored data unrecoverable within seconds.
  • Test the sanitisation process on sample devices at regular intervals and update the procedures whenever new device types, operating systems or MDM tools are introduced.
fact_check

Audit / evidence tips

  • AskAsk for the documented mobile device emergency sanitisation process and its supporting procedures.Look atThe process and procedure documents, including version numbers and approval or review dates.GoodCurrent, approved documents that cover triggers, responsibilities and the sanitisation method for each type of mobile device in use.
  • AskAsk how a mobile device is sanitised remotely during an emergency.Look atThe MDM configuration and the remote wipe or factory-reset capability for managed devices.GoodMDM settings show remote wipe is enabled and available across all managed mobile devices.
  • AskAsk for evidence that the sanitisation process has been used or tested.Look atIncident records or test logs of emergency sanitisation events.GoodDated records showing devices were successfully sanitised and the outcome was confirmed.
  • AskAsk who is responsible for initiating emergency sanitisation and how they are reached.Look atThe named roles, contact details and escalation steps set out in the procedures.GoodClearly assigned roles with reliably reachable contacts and a defined escalation path.
  • AskAsk how the process and procedures are kept current.Look atThe review history, change log and revision dates of the documents.GoodEvidence of regular review and updates that reflect the current device fleet and management tools.
link

Cross-framework mappings

How ISM-0701 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.1ISM-0701 requires mobile device emergency sanitisation processes and procedures to be developed, implemented and maintained

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls