Skip to content
arrow_back
ISM-1574policyASD Information Security Manual (ISM)

Data Portability in Service Contracts

Ensure service contracts cover data portability for backups, migration, and decommissioning.

record_voice_over

Plain language

This control is about making sure that your business data can be easily moved or backed up when using services like cloud storage. It's important because if your provider goes down or if you switch services, you want your data safe and away from being stuck or lost.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The storage of data in a portable manner that enables backups, service migration and service decommissioning without any loss of data is documented in contractual arrangements with service providers.
policyASD Information Security Manual (ISM)ISM-1574
priority_high

Why it matters

Without data portability, your business risks losing access to crucial information, facing operational delays, and financial losses if you change or leave a service provider.

settings

Operational notes

Regularly review and update service contracts to ensure they include terms that facilitate easy data portability and conformity with legal standards.

build

Implementation tips

  • Procurement teams should ensure that contracts with service providers include clear clauses about data portability. Do this by specifying how and when data can be extracted or transferred during and after the contract.
  • IT managers should work with service vendors to test data migration and backup processes. They can create small test data sets to perform a mock transfer, ensuring compatibility with other systems.
  • Legal teams should review all service agreements for compliance with data portability requirements. They should check that there are no hidden fees or barriers that prevent easy data transfer.
  • Managers should establish a regular review schedule for service contracts to assess data portability clauses. This can be done annually to ensure that the clauses still meet business needs and legal requirements.
  • Operational staff should maintain an inventory of systems and services to track where data resides. Use this inventory to ensure you know how data can be retrieved or moved if needed.
fact_check

Audit / evidence tips

  • Askthe service contract agreements: Request to see documents that outline data portability clauses with service providersLook atsections detailing how and when data can be migrated or backed upGoodincludes clear, non-restrictive terms about data transfer rights
  • Askevidence of successful data migration tests: Request reports or logs of any recent data migration or backup tests performedLook atdetails on the timing and success of the data transfersGoodshows no data loss and documents how the process was completed
  • Askthe inventory of data assets used in service contracts: Review how data assets are listed and managedLook atcomprehensive details about data location and portability optionsGoodinventory provides clarity on all data managed by third-party services
  • Askperiodic review meeting records: Request minutes or reports from meetings held to discuss contract reviewsLook atwhat actions were taken concerning data portabilityGoodincludes documented discussions and decisions made on maintaining or improving portability
  • Asklegal compliance checks: Request documentation of legal reviews for service contractsLook atevidence of compliance with Australian regulations related to data transferGoodincludes legal sign-offs and compliance confirmations
link

Cross-framework mappings

How ISM-1574 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 5.14ISM-1574 requires contractual arrangements with service providers to document portable data storage arrangements that support backups, se...
Annex A 8.10ISM-1574 requires service agreements to document how data can be migrated and decommissioned without loss, which typically includes speci...
handshakeSupports(2)expand_less
Annex A 5.19ISM-1574 requires organisations to document data portability expectations (backup, migration, and decommissioning without data loss) in c...
Annex A 8.13ISM-1574 requires supplier contracts to document portable storage arrangements that enable backups and restoration/migration without losi...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls