ASD ISM 1137Request Risk Assessment for Emanation Security
Official control statement
System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security risk assessment.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
System owners must ask for a security risk assessment when setting up SECRET or TOP SECRET systems.
What this means in practice
When setting up classified systems rated as SECRET or TOP SECRET, you need to check with the Australian Signals Directorate for potential security risks from electromagnetic emissions. This is important because data can be intercepted through electromagnetic signals if not properly protected.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Proactive
Classifications
S, TS
ISM last updated
Mar 2026
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Section
Emanation securityTopic
Emanation security risk assessments
Why it matters
Without proper assessment, classified information might leak via electromagnetic signals, risking national security and sensitive data exposure.
Operational notes
Keep communication lines open with ASD for updates on best practices. Regularly review and refresh training to keep team knowledge current.
Implementation tips
- System owners should identify all systems within the organisation that handle SECRET or TOP SECRET information. Make a comprehensive list of these systems, noting down the types of information they handle and their physical locations in your facilities.
- System owners need to contact the ASD to request an emanation security threat assessment for each system identified. Visit the ASD website to find the appropriate contact information or seek guidance from your organisation's security advisor if available.
- Owners should coordinate with their IT team to gather technical details and prepare for the ASD assessment. Ensure that you have documented how the systems are set up, including any measures already in place to prevent emissions leaks.
- The IT team should accompany the system owner during the ASD assessment. This allows for detailed discussions about existing security controls and provides an opportunity to ask for any immediate advice or feedback from the ASD experts.
- After the assessment, system owners should work with the IT team to implement any recommendations provided by the ASD. Develop a follow-up action plan that prioritises critical actions and set timelines for completion, keeping records of all steps taken.
Audit / evidence tips
- AskA copy of the list of systems handling SECRET or TOP SECRET informationLook atWhether this list is comprehensive and includes details about each system and their locationsGoodIncludes a dated list, reviewed recently, that accurately reflects current systems
- Look atEmails, letters, or meeting notes confirming the assessment request. Good evidence is documented proof of the request with a response from ASD, if available
- AskAny security reports issued by the ASD after their assessments. Review whether the reports identify specific risks and offer actionable recommendationsGoodReport will clearly outline potential risks and suggest practical solutions or improvements
- Look atWhether it includes specific steps to address each of the ASD recommendations with assigned responsibilities and timelinesGoodAction plan is well-structured with a timeline and accountability for follow-up
- Look atUpdates in IT systems, photographs, or other physical evidence of changed security measures. A successful implementation includes validated changes ensuring risk mitigations are effective
Cross-framework mappings
How ISM-1137 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 7.1 | ISM-1137 necessitates contacting ASD for an emanation security threat assessment for high-security systems | |
| Annex A 7.6 | ISM-1137 requires system owners of SECRET or TOP SECRET systems to contact ASD for an emanation threat assessment | |
extensionDepends on(1)expand_less | ||
| Annex A 5.5 | ISM-1137 requires system owners deploying SECRET or TOP SECRET systems in fixed facilities to contact ASD for an emanation security threa... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Communications infrastructure
See all Guidelines for communications infrastructure controls, or browse the full ASD ISM library.