Skip to content
arrow_back
search
ISM-1737 policy ASD Information Security Manual (ISM)

Maintain a Comprehensive Managed Service Register

Keep a detailed register of all managed services, including providers, purpose, data sensitivity, assessment schedules, and contacts.

record_voice_over

Plain language

This control is about keeping an organised list of all the outside services you use for things like cloud storage or IT support. It matters because if you don’t know who is managing your important data and when their security was last checked, you might miss a critical issue that could lead to a data breach or service interruption.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A managed service register contains the following for each managed service: - managed service provider's name - managed service's name - purpose for using the managed service - sensitivity or classification of data involved - due date for the next security assessment of the managed service - contractual arrangements for the managed service - point of contact for users of the managed service - 24/7 contact details for the managed service provider.
policy ASD Information Security Manual (ISM) ISM-1737
priority_high

Why it matters

Without a managed service register, provider contacts, contracts and assessment due dates are missed, raising unmanaged service and data breach risk.

settings

Operational notes

Keep a register per service: provider, purpose, data classification, contract, user POC, 24/7 contacts, and next assessment due date; update on change.

Mapping detail

Mapping

Direction

Controls