Skip to content
arrow_back
ISM-0820policyASD Information Security Manual (ISM)

Avoid Posting Work Data on Unauthorised Online Services

Staff should not share work info on unauthorised sites and must report if such info is found online.

record_voice_over

Plain language

This control is about keeping your organisation's information safe by not letting employees share work-related data on unauthorised online platforms. Imagine if sensitive projects or client details end up where they shouldn't; this could damage your reputation, cause financial loss, or even legal trouble.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Personnel are advised not to post work-related information on unauthorised online services, and to report cases where such information is posted.
policyASD Information Security Manual (ISM)ISM-0820
priority_high

Why it matters

If work data ends up on unauthorised sites, it can cause major losses like reputational damage, financial hits, and legal issues for your organisation.

settings

Operational notes

Regularly update your authorised online services list and keep the conversation open about data safety to prevent mishaps.

build

Implementation tips

  • Managers should create a clear list of authorised online services that staff can use for work-related purposes. Hold a team meeting to explain this list and ensure everyone understands what's allowed.
  • HR should include a section on appropriate online sharing in the employee handbook. Provide examples of authorised vs unauthorised services, and update this information regularly.
  • IT teams should monitor internet traffic to help identify if work data is being shared on unauthorised services. Use simple tools that flag unusual data sharing patterns, and investigate promptly.
  • Supervisors should routinely discuss safe online behaviours during team meetings. Encourage staff to ask if they're unsure about which services are safe for work data.
  • Business owners should encourage a culture where employees feel comfortable reporting accidental data sharing. Set up an anonymous reporting system if necessary, and reward proactive behaviour.
fact_check

Audit / evidence tips

  • Askthe employee handbook: Check for a section that details authorised online servicesLook atthe clarity and currency of the informationGoodhandbook has a specific list and recent review date
  • Request logs of internet traffic monitoring: Examine any flags for unauthorised data sharing. Verify whether there are follow-ups on these flags. Correct implementation shows regular checks and issue resolutions.
  • Askto see the training recordsLook atsessions on online service usage and reporting procedures. Check for attendance and content coverage. Good records show regular training with high staff participation
  • Look atexamples of identified cases of unauthorised data sharing. Check for documentation of incident handling and resolution. Thorough documentation indicates proper adherence to policies
  • Askrecords of reported incidentsLook atanonymised documentation of employee-reported issues related to unauthorised sharing. Good documentation shows acceptance of reports and actions taken
link

Cross-framework mappings

How ISM-0820 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.4ISM-0820 sets a specific personnel behaviour expectation: do not post work information to unauthorised online services and report if it h...
handshakeSupports(2)expand_less
Annex A 6.4Annex A 6.4 requires organisations to formalise and communicate disciplinary actions for information security policy violations
Annex A 6.6ISM-0820 focuses on preventing unauthorised disclosure by advising personnel not to post work information to unauthorised online services...
linkRelated(1)expand_less
Annex A 6.8Annex A 6.8 requires defined mechanisms for reporting information security events and suspected weaknesses promptly

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for personnel security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls