Skip to content
arrow_back
search
ISM-1571 policy ASD Information Security Manual (ISM)

Verify Security Compliance in Service Contracts

Contracts with service providers must include clauses that allow security compliance checks.

record_voice_over

Plain language

This control ensures that when you hire a service provider, your contract with them includes a clause that lets you check if they're doing their job securely. If you don't have this right, you might not be able to spot or fix problems when the provider's security fails, which could lead to data breaches or other serious issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The right to verify compliance with security requirements is documented in contractual arrangements with service providers.
policy ASD Information Security Manual (ISM) ISM-1571
priority_high

Why it matters

Without a contractual right to verify/audit service providers, noncompliance may go undetected, increasing breach risk and legal exposure.

settings

Operational notes

Ensure contracts explicitly grant rights to verify/audit security compliance (including evidence access). Schedule periodic audits and review attestations or reports.

Mapping detail

Mapping

Direction

Controls