Seek Legal Advice for Personal Device Access
Consult lawyers before allowing personal devices to access organisation's systems or data to prevent legal issues.
Plain language
Before letting employees use their personal phones or computers to access your organisation's data, it's wise to seek legal advice. This can prevent you from running into legal issues down the track, like accidental data breaches or loss of sensitive information.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for enterprise mobilitySection
Enterprise MobilityOfficial control statement
Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.
Why it matters
Without legal advice, there's a risk of legal responsibility if personal devices cause security breaches, risking data leaks or financial penalties.
Operational notes
Regularly review and update policies on personal device use ensuring legal advice remains current and relevant as laws and technology change.
Implementation tips
- General Manager should consult with a lawyer to understand legal responsibilities and potential risks when employees use personal devices for work. Schedule a meeting with a local solicitor experienced in cybersecurity and workplace law.
- HR should update the employee handbook to include clear guidelines on the use of personal devices, based on legal advice received. Write the guidelines in plain language and provide examples of acceptable and unacceptable device use.
- IT Manager should implement a policy where any personal device must be registered and secure before accessing any company data. Use a simple checklist to ensure devices have basic security controls, like passwords and app restrictions.
- Procurement should collaborate with IT and legal experts to decide on acceptable technologies that personal devices must have to access corporate systems. Have a criteria list that includes recommended software and security apps.
- Leadership should organise training sessions to educate staff about the risks and responsibilities of using their devices for work. Use case studies or role-play exercises to engage employees and reinforce the importance of compliance.
Audit / evidence tips
- Askthe policy documentation on personal device useLook atwhether it includes a section on legal compliance and security requirementsGoodThe document is current, detailed, and legally vetted
- Look atcommunication such as emails or meeting notes confirming the legal advice was soughtGoodA dated and signed document summarising legal guidance
- Askthe list of personal devices that have access to company systemsLook atregistration details and security compliance of each deviceGoodAn up-to-date record showing compliant devices only
- Look atthe relevance and clarity of the contentGoodMaterials explain risks, responsibilities, and are regularly updated
- Askevidence of policy awareness among staff, such as signed acknowledgmentsLook atcompleteness and whether every staff member is coveredGoodEvery employee has acknowledged in writing, and records are regularly updated
Cross-framework mappings
How ISM-1297 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.20 | ISM-1297 requires organisations to change or disable default accounts on network devices to reduce the risk of unauthorised access using ... | |
handshakeSupports(3)expand_less | ||
| Annex A 8.2 | ISM-1297 requires organisations to change or disable default accounts on network devices so privileged or built-in access cannot be obtai... | |
| Annex A 8.21 | ISM-1297 requires organisations to change or disable default accounts on network devices to prevent straightforward compromise via known ... | |
| Annex A 8.32 | ISM-1297 requires organisations to change or disable default accounts on network devices, which is a common configuration change that mus... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Enterprise mobility
See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.