Skip to content
arrow_back
search
ISM-1549 policy ASD Information Security Manual (ISM)

Develop and Maintain Media Management Policy

Create and update a policy to manage media handling effectively.

record_voice_over

Plain language

A media management policy is like a rulebook for how everyone in your organisation should handle items such as USB drives, CDs, or DVDs that store information. It matters because without proper guidance, sensitive information could be lost, damaged, or stolen, leading to serious problems like data breaches or reputational harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A media management policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1549
priority_high

Why it matters

Without a media management policy, removable media (e.g., USBs) may be used or disposed of insecurely, causing data leakage and reputational harm.

settings

Operational notes

Review and reissue the media management policy at least annually, covering approved media types, labelling, storage, transport, sanitisation and disposal.

Mapping detail

Mapping

Direction

Controls