Skip to content
arrow_back
search
ISM-1395 policy ASD Information Security Manual (ISM)

Ensuring Data Protection by Service Providers

Service providers must protect any entrusted data adequately.

record_voice_over

Plain language

Service providers, like the companies that handle your data or host your website, need to keep your information safe. If they don’t, your data could be misused, lost, or fall into the wrong hands, causing harm to your business or personal reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Service providers, including any subcontractors, provide an appropriate level of protection for any data entrusted to them or their services.
policy ASD Information Security Manual (ISM) ISM-1395
priority_high

Why it matters

Inadequate data protection by service providers can lead to data breaches, damaging reputation and risking client trust and legal action.

settings

Operational notes

Audit service providers and subcontractors (contracts, SLAs, attestations) to verify controls for handling, storage and disposal of your data meet requirements.

Mapping detail

Mapping

Direction

Controls