Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1297Seek Legal Advice for Personal Device Access

Official control statement

Legal advice is sought prior to allowing privately owned mobile devices and desktop computers to access systems or data.
policyASD Information Security Manual (ISM)ISM-1297

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Consult lawyers before allowing personal devices to access organisation's systems or data to prevent legal issues.

NCOSPASD Information Security ManualGuidelines for enterprise mobility
record_voice_over

What this means in practice

Before letting employees use their personal phones or computers to access your organisation's data, it's wise to seek legal advice. This can prevent you from running into legal issues down the track, like accidental data breaches or loss of sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Privately owned mobile devices and desktop computers

priority_high

Why it matters

Without legal advice, there's a risk of legal responsibility if personal devices cause security breaches, risking data leaks or financial penalties.

settings

Operational notes

Regularly review and update policies on personal device use ensuring legal advice remains current and relevant as laws and technology change.

build

Implementation tips

  • General Manager should consult with a lawyer to understand legal responsibilities and potential risks when employees use personal devices for work. Schedule a meeting with a local solicitor experienced in cyber security and workplace law.
  • HR should update the employee handbook to include clear guidelines on the use of personal devices, based on legal advice received. Write the guidelines in plain language and provide examples of acceptable and unacceptable device use.
  • IT Manager should implement a policy where any personal device must be registered and secure before accessing any company data. Use a simple checklist to ensure devices have basic security controls, like passwords and app restrictions.
  • Procurement should collaborate with IT and legal experts to decide on acceptable technologies that personal devices must have to access corporate systems. Have a criteria list that includes recommended software and security apps.
  • Leadership should organise training sessions to educate staff about the risks and responsibilities of using their devices for work. Use case studies or role-play exercises to engage employees and reinforce the importance of compliance.
fact_check

Audit / evidence tips

  • Askthe policy documentation on personal device useLook atwhether it includes a section on legal compliance and security requirementsGoodThe document is current, detailed, and legally vetted
  • Look atcommunication such as emails or meeting notes confirming the legal advice was soughtGoodA dated and signed document summarising legal guidance
  • Askthe list of personal devices that have access to company systemsLook atregistration details and security compliance of each deviceGoodAn up-to-date record showing compliant devices only
  • Look atthe relevance and clarity of the contentGoodMaterials explain risks, responsibilities, and are regularly updated
  • Askevidence of policy awareness among staff, such as signed acknowledgmentsLook atcompleteness and whether every staff member is coveredGoodEvery employee has acknowledged in writing, and records are regularly updated
link

Cross-framework mappings

How ISM-1297 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.31ISM-1297 requires legal advice to be sought before privately owned mobile devices and desktop computers are allowed to access systems or ...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls