Separate Personal and Work Accounts for Online Services
Keep your personal and work user accounts separate when using online services.
Plain language
Keeping your work and personal accounts separate online means using different usernames and passwords for each. This matters because mixing them up can lead to mishaps like sharing work information by mistake, or security breaches if one account is hacked.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for personnel securityOfficial control statement
Personnel are advised to maintain separate personal user accounts from any work user accounts they use for online services.
Why it matters
Mixing personal and work accounts can lead to accidental data leaks or unauthorised access, risking business confidentiality and security.
Operational notes
Regularly remind employees about the importance of keeping work and personal accounts separate and check compliance with established policies.
Implementation tips
- HR should ensure all employees understand the importance of separating personal and work accounts. They can do this by organising workshops or training sessions explaining the risks and benefits of this separation.
- IT teams should create distinct processes for account creation and access control for work accounts. This can be done by setting up clear procedures and guidelines for employees to follow when accessing work systems.
- Managers should encourage their teams to use separate browsers or devices for personal and work activities. This helps reduce the risk of data leaks by keeping work and personal browsing histories and cookies separate.
- System administrators should regularly audit user accounts to ensure no overlap between personal and work accounts exists. This includes keeping logs of account activity and regularly reviewing these logs.
- Security officers should implement policies that clearly define and enforce the separation of personal and work accounts. They can draft these policies and communicate them effectively through regular updates and email reminders.
Audit / evidence tips
- Askthe account management policy document. Look whether it includes clear guidelines for maintaining separate personal and work accountsGooddetailed policies that outline the need for and methods of separation
- Askto see logs of recent account audits conducted by ITLook atevidence of account segregation reviewsGoodlogs showing regular checks with no findings of overlap
- Look atattendance records and feedback formsGoodcomprehensive session records and positive feedback on understanding
- Aska demonstration of account setup proceduresLook atdistinct processes for work accountsGooda step-by-step process that segregates personal from work account setup
- Look atdocumentation on follow-up actions and policies revisedGoodincident reports with clear corrective action and policy updates
Cross-framework mappings
How ISM-1146 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.10 | ISM-1146 advises personnel to keep separate work and personal online accounts to reduce cross-contamination and account compromise risks | |
handshakeSupports(1)expand_less | ||
| Annex A 6.3 | ISM-1146 advises personnel to maintain separate work and personal online accounts for online services | |
linkRelated(1)expand_less | ||
| Annex A 6.7 | Annex A 6.7 requires security measures for personnel working remotely to protect organisational information accessed or processed offsite | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Personnel security
See all Guidelines for personnel security controls, or browse the full ASD ISM library.