Skip to content
arrow_back
ISM-0821policyASD Information Security Manual (ISM)

Advise on Risks of Posting Personal Information Online

Employees should be aware of the dangers of posting their personal info on the internet.

record_voice_over

Plain language

Posting your personal details online can make you vulnerable to cyber criminals and identity theft. If this isn't considered, your personal and professional info might be used against you by scammers or hackers.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Personnel are advised of security risks associated with posting personal information on online services.
policyASD Information Security Manual (ISM)ISM-0821
priority_high

Why it matters

Failing to manage personal info online risks identity theft and financial loss impacting both individuals and the organisation.

settings

Operational notes

Regularly update training and guidelines about online safety to reflect new risks, and encourage staff to report suspicious activities.

build

Implementation tips

  • HR should educate staff through training sessions on the importance of not posting personal information online. This involves creating scenarios where personal info could be misused, and discussing safe online sharing habits.
  • The IT team should develop easy-to-understand guidelines that outline what kind of personal info should never be shared online. Use clear examples that relate to everyday work and personal life.
  • Managers should review employees' understanding during regular check-ins. Encourage them to ask questions on what is considered personal information that should be protected.
  • Executives should prioritise cyber safety in meetings by discussing online behaviour and sharing real-life stories about the risks of posting personal information online. This helps to create a culture of security awareness.
  • The communications team should regularly remind staff via email or newsletter about the risks and give practical safety tips. They can use catchy phrases or stories to make the message memorable.
fact_check

Audit / evidence tips

  • Askthe training materials used for personnel security awarenessLook atcontent that specifically covers risks of posting personal information online. Good content includes interactive elements and practical examples
  • Askto see the documented guidelines provided to staff. Check that they specifically mention types of personal information that are at risk online. Good guidelines use plain language and relatable scenarios
  • Askmanagement for records of check-ins where personal information safety was discussedLook atentries that specifically address online sharing behavioursGoodrecord includes names, dates, and key outcomes discussed
  • Askcopies of reminders or campaigns about online privacyLook atdistribution records and the frequency of communications. Good evidence shows regular intervals and creative, engaging content
  • Look atquestions or comments suggesting employees understand the threats of sharing personal information. Positive feedback indicates effective training
link

Cross-framework mappings

How ISM-0821 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 5.34Annex A 5.34 requires the organisation to meet privacy and PII requirements, including preventing inappropriate disclosure
linkRelated(1)expand_less
Annex A 6.3Annex A 6.3 requires role-relevant information security awareness and regular updates to policies and procedures

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for personnel security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls