Inspect IT Equipment Post-Maintenance for Unauthorised Changes
After maintenance, check IT equipment to ensure no unapproved changes were made.
Plain language
Whenever your IT equipment is fixed or serviced, it's crucial to check that no unauthorised changes were made. This is important because unauthorised changes can introduce vulnerabilities or unwanted software, risking your business's security and privacy.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Following maintenance or repairs to IT equipment, it is inspected to confirm that it retains its approved configuration and that no unauthorised modifications have been made.
Why it matters
Unauthorised changes to IT equipment can lead to security breaches, compromising sensitive data and disrupting business operations.
Operational notes
Regularly update your equipment checklist to reflect authorised settings. Ensure post-maintenance inspections are thorough and consistent.
Implementation tips
- IT team should establish a checklist: Create a checklist of key configuration settings for each piece of IT equipment to compare before and after maintenance. Ensure configurations match approved settings.
- Designate a responsible staff member: Have a specific person responsible for inspecting equipment after any external repairs. This person should be familiar with what configurations are authorised.
- Use system logs: Encourage the IT team to review system logs for unexpected changes immediately after maintenance. Logs can indicate if unauthorised software was installed.
- Engage a trusted external party: If maintenance is performed by outsiders, consider hiring a trusted IT consultant to verify no unauthorised changes were made post-maintenance.
- Document inspection process: Create a simple report form for documenting each post-maintenance inspection. Ensure it logs who performed the check, date, time, and findings.
Audit / evidence tips
- Askthe checklist of approved configurations: Request the document used for pre- and post-maintenance checksLook atwhether it covers all critical settingsGoodwill be a comprehensive and up-to-date list
- Askrecent inspection reports: Review reports from the last few maintenance checksLook atdetails of the checks, including dates and personnelGoodis a series of reports showing who did what, when
- Asksystem log reviews: Request logs that show checks for unauthorised changes after maintenanceLook atlogs close to the maintenance eventGoodshows logs reviewed with no anomalies
- Askmaintenance provider records: Request records of who performed maintenanceLook atsigned agreements on post-service checksGoodis documentation of authorised vendors and agreed procedures
- Askevidence of training: Request info on who is trained to perform post-maintenance checksLook attraining materials and attendance recordsGoodincludes recent training sessions covering equipment inspection
Cross-framework mappings
How ISM-1598 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.9 | ISM-1598 requires IT equipment to be inspected after maintenance or repair to confirm it still matches the approved configuration and has... | |
sync_altPartially overlaps(2)expand_less | ||
| Annex A 7.13 | ISM-1598 requires inspection of IT equipment after maintenance/repair to ensure integrity of the approved configuration and identify unau... | |
| Annex A 8.32 | ISM-1598 requires verifying, after maintenance, that IT equipment retains its approved configuration and has not been changed without aut... | |
handshakeSupports(1)expand_less | ||
| Annex A 8.19 | ISM-1598 requires post-maintenance inspection to confirm systems remain in their approved configuration and no unauthorised modifications... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Information technology equipment
See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.