Avoid Posting Work Data on Unauthorised Online Services
Staff should not share work info on unauthorised sites and must report if such info is found online.
Plain language
This control is about keeping your organisation's information safe by not letting employees share work-related data on unauthorised online platforms. Imagine if sensitive projects or client details end up where they shouldn't; this could damage your reputation, cause financial loss, or even legal trouble.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for personnel securityOfficial control statement
Personnel are advised not to post work-related information on unauthorised online services, and to report cases where such information is posted.
Why it matters
If work data ends up on unauthorised sites, it can cause major losses like reputational damage, financial hits, and legal issues for your organisation.
Operational notes
Regularly update your authorised online services list and keep the conversation open about data safety to prevent mishaps.
Implementation tips
- Managers should create a clear list of authorised online services that staff can use for work-related purposes. Hold a team meeting to explain this list and ensure everyone understands what's allowed.
- HR should include a section on appropriate online sharing in the employee handbook. Provide examples of authorised vs unauthorised services, and update this information regularly.
- IT teams should monitor internet traffic to help identify if work data is being shared on unauthorised services. Use simple tools that flag unusual data sharing patterns, and investigate promptly.
- Supervisors should routinely discuss safe online behaviours during team meetings. Encourage staff to ask if they're unsure about which services are safe for work data.
- Business owners should encourage a culture where employees feel comfortable reporting accidental data sharing. Set up an anonymous reporting system if necessary, and reward proactive behaviour.
Audit / evidence tips
- Askthe employee handbook: Check for a section that details authorised online servicesLook atthe clarity and currency of the informationGoodhandbook has a specific list and recent review date
- Request logs of internet traffic monitoring: Examine any flags for unauthorised data sharing. Verify whether there are follow-ups on these flags. Correct implementation shows regular checks and issue resolutions.
- Askto see the training recordsLook atsessions on online service usage and reporting procedures. Check for attendance and content coverage. Good records show regular training with high staff participation
- Look atexamples of identified cases of unauthorised data sharing. Check for documentation of incident handling and resolution. Thorough documentation indicates proper adherence to policies
- Askrecords of reported incidentsLook atanonymised documentation of employee-reported issues related to unauthorised sharing. Good documentation shows acceptance of reports and actions taken
Cross-framework mappings
How ISM-0820 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.4 | ISM-0820 sets a specific personnel behaviour expectation: do not post work information to unauthorised online services and report if it h... | |
handshakeSupports(2)expand_less | ||
| Annex A 6.4 | Annex A 6.4 requires organisations to formalise and communicate disciplinary actions for information security policy violations | |
| Annex A 6.6 | ISM-0820 focuses on preventing unauthorised disclosure by advising personnel not to post work information to unauthorised online services... | |
linkRelated(1)expand_less | ||
| Annex A 6.8 | Annex A 6.8 requires defined mechanisms for reporting information security events and suspected weaknesses promptly | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Personnel security
See all Guidelines for personnel security controls, or browse the full ASD ISM library.