Skip to content
arrow_back
search
ISM-0817 policy ASD Information Security Manual (ISM)

Reporting Suspicious Online Contact Awareness

Staff learn to recognise and report suspicious online contact.

record_voice_over

Plain language

This control is about making sure that everyone in your organisation knows how to spot and report any suspicious contact they might experience online, like strange emails from unknown sources. It matters because ignoring these signs can lead to serious issues like data breaches, which can harm your reputation and cost you time and money to fix.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Personnel are advised of what suspicious contact via online services is and how to report it.
policy ASD Information Security Manual (ISM) ISM-0817
priority_high

Why it matters

Failing to report suspicious online contact promptly can lead to exposure of sensitive information, resulting in data breaches and reputational damage.

settings

Operational notes

Train staff to recognise suspicious online contact (e.g., probing, grooming, unusual requests) and require prompt reporting via the security incident channel.

Mapping detail

Mapping

Direction

Controls