Skip to content
arrow_back
search
ISM-1073 policy ASD Information Security Manual (ISM)

Ensure Provider Contracts for System Access

Service providers need a contract before accessing or managing your systems.

record_voice_over

Plain language

This control ensures that before allowing a service provider to access or manage your organisation's systems, there must be a formal contract in place. This is important because without a contract, your business might be at risk of data breaches, misuse of systems, or unexpected costs if something goes wrong.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

An organisation's systems are not accessed or administered by a service provider unless a contractual arrangement exists between the organisation and the service provider to do so.
policy ASD Information Security Manual (ISM) ISM-1073
priority_high

Why it matters

Without a contract, a provider may access/administer systems without defined security obligations, increasing breach and liability risk.

settings

Operational notes

Require written contracts before provider system access, defining scope, security clauses, and offboarding; review regularly for changes.

Mapping detail

Mapping

Direction

Controls