Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1137Request Risk Assessment for Emanation Security

Official control statement

System owners deploying SECRET or TOP SECRET systems within fixed facilities contact ASD for an emanation security risk assessment.
policyASD Information Security Manual (ISM)ISM-1137

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

System owners must ask for a security risk assessment when setting up SECRET or TOP SECRET systems.

record_voice_over

What this means in practice

When setting up classified systems rated as SECRET or TOP SECRET, you need to check with the Australian Signals Directorate for potential security risks from electromagnetic emissions. This is important because data can be intercepted through electromagnetic signals if not properly protected.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Proactive

Classifications

S, TS

ISM last updated

Mar 2026

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Emanation security risk assessments

priority_high

Why it matters

Without proper assessment, classified information might leak via electromagnetic signals, risking national security and sensitive data exposure.

settings

Operational notes

Keep communication lines open with ASD for updates on best practices. Regularly review and refresh training to keep team knowledge current.

build

Implementation tips

  • System owners should identify all systems within the organisation that handle SECRET or TOP SECRET information. Make a comprehensive list of these systems, noting down the types of information they handle and their physical locations in your facilities.
  • System owners need to contact the ASD to request an emanation security threat assessment for each system identified. Visit the ASD website to find the appropriate contact information or seek guidance from your organisation's security advisor if available.
  • Owners should coordinate with their IT team to gather technical details and prepare for the ASD assessment. Ensure that you have documented how the systems are set up, including any measures already in place to prevent emissions leaks.
  • The IT team should accompany the system owner during the ASD assessment. This allows for detailed discussions about existing security controls and provides an opportunity to ask for any immediate advice or feedback from the ASD experts.
  • After the assessment, system owners should work with the IT team to implement any recommendations provided by the ASD. Develop a follow-up action plan that prioritises critical actions and set timelines for completion, keeping records of all steps taken.
fact_check

Audit / evidence tips

  • AskA copy of the list of systems handling SECRET or TOP SECRET informationLook atWhether this list is comprehensive and includes details about each system and their locationsGoodIncludes a dated list, reviewed recently, that accurately reflects current systems
  • Look atEmails, letters, or meeting notes confirming the assessment request. Good evidence is documented proof of the request with a response from ASD, if available
  • AskAny security reports issued by the ASD after their assessments. Review whether the reports identify specific risks and offer actionable recommendationsGoodReport will clearly outline potential risks and suggest practical solutions or improvements
  • Look atWhether it includes specific steps to address each of the ASD recommendations with assigned responsibilities and timelinesGoodAction plan is well-structured with a timeline and accountability for follow-up
  • Look atUpdates in IT systems, photographs, or other physical evidence of changed security measures. A successful implementation includes validated changes ensuring risk mitigations are effective
link

Cross-framework mappings

How ISM-1137 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 7.1ISM-1137 necessitates contacting ASD for an emanation security threat assessment for high-security systems
Annex A 7.6ISM-1137 requires system owners of SECRET or TOP SECRET systems to contact ASD for an emanation threat assessment
extensionDepends on(1)expand_less
Annex A 5.5ISM-1137 requires system owners deploying SECRET or TOP SECRET systems in fixed facilities to contact ASD for an emanation security threa...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for communications infrastructure controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls