Skip to content
arrow_back
search
ISM-0947 policy ASD Information Security Manual (ISM)

Sanitise Media After Data Transfers Between Domains

Clean rewriteable media after transferring data between systems of different security levels.

record_voice_over

Plain language

When you move files using a USB stick or another rewritable disk between computers with different security levels, like from a personal laptop to a work computer with sensitive information, you need to wipe it clean afterwards. This is important because if you don’t, the disk could carry confidential data to places it shouldn't, risking a data leak or security breach.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When transferring data manually between two systems belonging to different security domains, rewritable media is sanitised after each data transfer.
policy ASD Information Security Manual (ISM) ISM-0947
priority_high

Why it matters

If rewritable media isn’t sanitised after each cross-domain manual transfer, residual data can leak between domains and be accessed unauthorised.

settings

Operational notes

After every manual transfer between security domains, sanitise rewritable media using an approved method and record completion to prevent residual data carryover.

Mapping detail

Mapping

Direction

Controls