Skip to content
arrow_back
ISM-1074policyASD Information Security Manual (ISM)

Controlling Access to Critical IT Infrastructure

Ensure keys to server and communication rooms are securely managed.

record_voice_over

Plain language

This control is about keeping the keys to important areas like server rooms secure so that only authorised people can access them. If we don't keep these keys safe, unauthorised people might enter these critical areas, potentially damaging equipment, stealing data, or causing service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2024

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Keys or equivalent access mechanisms to server rooms, communications rooms and security containers are appropriately controlled.
policyASD Information Security Manual (ISM)ISM-1074
priority_high

Why it matters

Poor control of access keys could allow unauthorised entry to critical infrastructure, leading to data theft, sabotage, or severe operational disruptions.

settings

Operational notes

Audit server room and comms room key registers regularly; revoke access for leavers and investigate missing keys immediately.

build

Implementation tips

  • The facility manager should implement a key logging system to track who takes keys and when. This can be done by setting up a sign-in/sign-out sheet or using an electronic key management system to record these transactions.
  • The IT manager should assign a responsible person to oversee server room access. They need to ensure that only authorised personnel are listed and given access, updating the list as roles change within the organisation.
  • HR should conduct regular training for staff on the importance of securing key access. This involves setting up brief sessions to inform staff about why key control is critical and how misuse can impact the organisation.
  • Security personnel should perform regular checks to make sure keys are stored securely when not in use. This involves routine inspections of the storage facility, ensuring it remains locked and only accessible to authorised staff.
  • The manager in charge of security should have a protocol for lost or misplaced keys. This includes a prompt reporting mechanism, reviewing access logs, and changing locks or updating access mechanisms if a key is compromised.
fact_check

Audit / evidence tips

  • AskThe current list of authorised personnel with access to server and communication roomsGoodIs a current, dated list with justified access for each person
  • AskRecords of key issuance and returnsGoodIs a comprehensive log with names, dates, and times of when keys were issued and returned
  • AskTo see the training records on key management for staffGoodProgram will have regular sessions (at least annually) and show that all relevant staff were trained
  • AskSecurity inspection reports for the storage location of the keysGoodIs dated inspection logs with follow-up actions noted for any issues found
  • AskAbout the procedure for handling lost keysGoodProcedure will show prompt steps taken, with a risk assessment and mitigation plan documented
link

Cross-framework mappings

How ISM-1074 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 7.1ISM-1074 requires keys or equivalent access mechanisms to server rooms, communications rooms and security containers to be appropriately ...
sync_altPartially overlaps(2)expand_less
Annex A 7.2Annex A 7.2 requires organisations to protect secure areas through controlled entry and access points
Annex A 7.8Annex A 7.8 requires equipment to be positioned and protected to reduce unauthorised access and physical harm
linkRelated(1)expand_less
Annex A 7.5Annex A 7.5 requires safeguards that protect infrastructure from physical threats and environmental events

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for physical security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls