Advise on Risks of Posting Personal Information Online
Employees should be aware of the dangers of posting their personal info on the internet.
Plain language
Posting your personal details online can make you vulnerable to cyber criminals and identity theft. If this isn't considered, your personal and professional info might be used against you by scammers or hackers.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for personnel securityOfficial control statement
Personnel are advised of security risks associated with posting personal information on online services.
Why it matters
Failing to manage personal info online risks identity theft and financial loss impacting both individuals and the organisation.
Operational notes
Regularly update training and guidelines about online safety to reflect new risks, and encourage staff to report suspicious activities.
Implementation tips
- HR should educate staff through training sessions on the importance of not posting personal information online. This involves creating scenarios where personal info could be misused, and discussing safe online sharing habits.
- The IT team should develop easy-to-understand guidelines that outline what kind of personal info should never be shared online. Use clear examples that relate to everyday work and personal life.
- Managers should review employees' understanding during regular check-ins. Encourage them to ask questions on what is considered personal information that should be protected.
- Executives should prioritise cyber safety in meetings by discussing online behaviour and sharing real-life stories about the risks of posting personal information online. This helps to create a culture of security awareness.
- The communications team should regularly remind staff via email or newsletter about the risks and give practical safety tips. They can use catchy phrases or stories to make the message memorable.
Audit / evidence tips
- Askthe training materials used for personnel security awarenessLook atcontent that specifically covers risks of posting personal information online. Good content includes interactive elements and practical examples
- Askto see the documented guidelines provided to staff. Check that they specifically mention types of personal information that are at risk online. Good guidelines use plain language and relatable scenarios
- Askmanagement for records of check-ins where personal information safety was discussedLook atentries that specifically address online sharing behavioursGoodrecord includes names, dates, and key outcomes discussed
- Askcopies of reminders or campaigns about online privacyLook atdistribution records and the frequency of communications. Good evidence shows regular intervals and creative, engaging content
- Look atquestions or comments suggesting employees understand the threats of sharing personal information. Positive feedback indicates effective training
Cross-framework mappings
How ISM-0821 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 5.34 | Annex A 5.34 requires the organisation to meet privacy and PII requirements, including preventing inappropriate disclosure | |
linkRelated(1)expand_less | ||
| Annex A 6.3 | Annex A 6.3 requires role-relevant information security awareness and regular updates to policies and procedures | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Personnel security
See all Guidelines for personnel security controls, or browse the full ASD ISM library.