Register for RF and IR Devices in Secret Areas
Maintain a register of RF and IR devices for secure areas to ensure authorised use.
Plain language
Keeping a record of all RF (radio frequency) and IR (infrared) devices in secure areas helps ensure that only authorised devices are used. If this isn't done, unauthorised devices could be used to eavesdrop or steal sensitive information, potentially causing significant damage.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for physical securitySection
Facilities and SystemsOfficial control statement
An authorised RF and IR device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.
Why it matters
Lack of a device register could lead to unauthorised eavesdropping or data breaches, exposing sensitive information and causing potential harm.
Operational notes
Regularly review and update the RF and IR device register to ensure only authorised devices operate in secure areas, maintaining strong security posture.
Implementation tips
- The security manager should create a register of authorised RF and IR devices. Start by listing all devices currently in use in designated secret areas, including details like model, serial number, and owner.
- IT staff should work with security personnel to update the device register regularly. Set a routine schedule to check for new or removed devices, ensuring the register stays current and accurate.
- Managers should inform staff about the importance of reporting new devices. Use team meetings or emails to remind staff to report any new RF or IR devices intended for use in secure areas.
- Procurement teams should coordinate with IT before buying new RF or IR devices. They must ensure each device matches security requirements before it's added to the register.
- Conduct routine training sessions to remind employees of the security protocols. Security officers should explain the risks of unregistered devices and how to report them correctly.
Audit / evidence tips
- Askthe RF and IR device register: Verify it is up-to-date with details like device type, serial number, and owner nameLook atinclusion of recent entries and removalsGoodA detailed, current register showing all devices authorised for secure areas
- Look atlogs showing when and how often checks of the register occurGoodConsistent records showing regular checks conducted on a monthly or quarterly basis
- Askto see records of employee training on device reporting: Review attendance sheets or training materialsGoodDocumented proof of regular training, with clear agendas and participant lists
- Askto see procurement protocols for new devices: Check the procedure aligns with ensuring all devices are registered before introduction to secure areasGoodWritten procedure showing compatibility check and register update step
- GoodReports detailing handling of past incidents, showing effective resolution and updates to the register
Cross-framework mappings
How ISM-1543 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.9 | ISM-1543 requires an authorised RF and IR device register for SECRET and TOP SECRET areas to be developed, maintained, and regularly veri... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Physical security
See all Guidelines for physical security controls, or browse the full ASD ISM library.