Skip to content
arrow_back
search
ISM-1738 policy ASD Information Security Manual (ISM)

Ensure Regular Verification of Service Provider Security

Organisations must regularly check that service providers meet agreed security standards.

record_voice_over

Plain language

You need to regularly check that your service providers are keeping up their end of the deal when it comes to security. This is important because if they slip up, it could mean data leaks, financial loss, or damage to your reputation. Without these regular check-ins, you could be caught off guard by security issues that harm your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The right to verify compliance with security requirements documented in contractual arrangements with service providers is exercised on a regular and ongoing basis.
policy ASD Information Security Manual (ISM) ISM-1738
priority_high

Why it matters

If provider compliance isn’t regularly verified against contract security requirements, control gaps can persist, leading to data compromise and loss of trust.

settings

Operational notes

Maintain an ongoing schedule to exercise contractual audit/assurance rights (e.g., attestations or audits), and record evidence, findings and remediation actions.

Mapping detail

Mapping

Direction

Controls