Maintain and Verify Managed Service Register
Keep and regularly check a log of managed services.
Plain language
This control is about keeping a detailed log of all third-party services your business uses, like cloud providers or outsourced IT. It's important because without a clear record, you might overlook managing these services securely, leading to data breaches or service disruptions.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Topic
Managed ServicesOfficial control statement
A managed service register is developed, implemented, maintained and regularly verified.
Why it matters
Without a managed service register, unseen risks from third-party services can lead to data breaches, service outages, or compliance failures.
Operational notes
Regularly update and review the managed service register to keep track of all active services and ensure they meet your security requirements.
Implementation tips
- The office manager should create a master list of all managed services used by the business, capturing each service provider's name, services offered, and contract terms. This can be done using a simple spreadsheet.
- The IT team should regularly review the list to confirm that all services are still necessary and meet security needs. They can do this by setting a quarterly reminder to check each service's relevance and update any changes.
- Each department head should report any new services they decide to use. They can submit a form outlining the service's purpose and details to the office manager for inclusion in the register.
- The procurement officer should ensure any new contracts or service agreements include privacy and security terms. They can do this by having a checklist of security requirements to discuss with vendors during the negotiation phase.
- The IT team should periodically conduct spot checks of the managed service register against actual deployed services, looking for any discrepancies. This can involve cross-referencing against network or system inventories.
Audit / evidence tips
- Askthe managed service register: Request the document or system that lists all third-party services in use by the organisation
- Look atcontract terms in the register: Check that security and privacy requirements are documented for each service
- Look atrecent activity: Ensure that the register has been updated within the last quarter to reflect current services
- Aska change log or update history: Verify if there is a record showing who made updates and when, indicating the register is regularly maintained
- Aska sample review meeting reportLook atnotes from the last review meeting that verify the services on the register are still necessary and secure
Cross-framework mappings
How ISM-1736 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(3)expand_less | ||
| Annex A 5.19 | ISM-1736 requires organisations to maintain a current, verified register of managed services | |
| Annex A 5.21 | ISM-1736 requires organisations to maintain and regularly verify a register of managed services | |
| Annex A 5.22 | Annex A 5.22 requires regular monitoring, review and evaluation of supplier services and the management of changes in supplier delivery a... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Procurement and outsourcing
See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.