Skip to content
arrow_back
search
ISM-1218 policy ASD Information Security Manual (ISM)

Sanitise Overseas IT Equipment Handling Sensitive Data

Overseas IT equipment with sensitive data must be sanitised where it is located.

record_voice_over

Plain language

When your business uses IT equipment overseas that handles very sensitive Australian data, it's important to clean out or 'sanitise' that data before the equipment leaves its location. This matters because if this data is not properly removed, it could fall into the wrong hands, leading to data breaches that can harm your business's reputation and result in legal consequences.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IT equipment, including associated media, that is located overseas and has processed, stored or communicated AUSTEO or AGAO data, is sanitised in situ.
policy ASD Information Security Manual (ISM) ISM-1218
priority_high

Why it matters

Without in-situ sanitisation overseas, AUSTEO/AGAO data on equipment or media may be recovered, enabling unauthorised disclosure and damaging Australian interests.

settings

Operational notes

Ensure overseas equipment/media that handled AUSTEO/AGAO is sanitised in situ before reuse, repair, return or disposal, and keep records of the method, date and verifier.

Mapping detail

Mapping

Direction

Controls