Skip to content
arrow_back
search
ISM-0735 policy ASD Information Security Manual (ISM)

Secure Facilities for Classified Systems

Classified systems are kept in secure locations fitting their classification level.

record_voice_over

Plain language

This control is about making sure that classified systems—those that handle sensitive information—are stored in locations that match their security needs. Imagine if you kept your life savings under a mattress instead of in a secure bank; unprotected systems are just as vulnerable, risking data breaches and serious consequences for your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
policy ASD Information Security Manual (ISM) ISM-0735
priority_high

Why it matters

Without CISO oversight of security awareness training, personnel might mishandle classified systems, raising the risk of data breaches and operational disruptions.

settings

Operational notes

Have the CISO approve the awareness plan and review completion rates, test results and incident trends quarterly; update modules to address identified gaps.

Mapping detail

Mapping

Direction

Controls