Skip to content
arrow_back
search
ISM-1533 policy ASD Information Security Manual (ISM)

Establish Mobile Device Management Policies

Create and maintain policies to manage and control mobile devices within the organization.

record_voice_over

Plain language

Creating and maintaining a policy to manage mobile devices is like setting ground rules for how these devices are used in your organisation. This matters because without clear rules, mobile devices could become easy targets for cyber attacks or data leaks, leading to loss of sensitive information and potentially harming your business reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A mobile device management policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1533
priority_high

Why it matters

Without an enforced MDM policy, lost or unmanaged mobiles may expose sensitive data and allow unauthorised access to corporate systems.

settings

Operational notes

Review the MDM policy regularly to cover enrolment, PIN/biometrics, encryption, patching, app controls and remote wipe for lost or stolen devices.

Mapping detail

Mapping

Direction

Controls