Develop and Verify Database Register
Maintain an up-to-date list of databases and check it regularly to ensure accuracy.
Plain language
Keeping a current list of databases and checking it regularly ensures you know where your important information sits. If you overlook this, you might miss a vulnerability that hackers could exploit, leading to potential data breaches.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
A database register is developed, implemented, maintained and regularly verified.
Why it matters
An outdated database register could lead to data breaches, risking confidential data and the organisation's reputation.
Operational notes
Regular checks of the database register help ensure it stays up-to-date, reflecting new additions and changes promptly.
Implementation tips
- Business owners should appoint a responsible person or team to maintain the database register. They should gather details about each database, such as its location, purpose, and who can access it, and record this in a shared document.
- IT staff should schedule regular updates to the database register. They can set a monthly reminder to check with database managers if there have been any changes or if any new databases need to be added.
- HR should work with IT to educate employees on why maintaining an accurate database register is crucial. They can organise short training sessions to explain how every employee's actions contribute to overall data security.
- Database managers should verify the register's entries weekly to ensure accuracy. This involves cross-checking with actual databases by referring to system configurations and confirming they align with the register.
- Auditors should provide oversight by reviewing the entire register quarterly. They should compare it against any contracts or vendor agreements to ensure nothing has been omitted.
Audit / evidence tips
- Askthe latest version of the database registerLook atthe entries for each database, including details like location, purpose, and responsible personnelGoodA comprehensive list with all relevant details filled out and dates of last review
- Look atattendance or distribution lists showing who received informationGoodDocumented training sessions or emails reaching relevant staff
- Asklogs of register updates or changes over the past monthsLook attimestamps and notes on what was modifiedGoodClear log entries showing regular updates and specific changes made with timestamps
- Aska list of new databases added in the past six monthsLook atmatching entries in the register and any supporting documentationGoodEach new database has an entry in the register with consistent supporting documents
- Look atsigned-off audit reports or review notesGoodDated reports with sign-offs from the auditing staff confirming all entries are verified
Cross-framework mappings
How ISM-1243 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.9 | Annex A 5.9 requires an inventory of information and associated assets, including ownership | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Database systems
See all Guidelines for database systems controls, or browse the full ASD ISM library.