Skip to content
arrow_back
ISM-1738policyASD Information Security Manual (ISM)

Verify Compliance with Security Requirements

Regularly ensure service providers are following the security agreements in their contracts.

record_voice_over

Plain language

This control is about checking that service providers are doing what they promised in terms of security. It's important because if they slip up, your data and systems could be at risk, leading to data breaches or service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The right to verify compliance with security requirements documented in contractual arrangements with service providers is regularly exercised.
policyASD Information Security Manual (ISM)ISM-1738
priority_high

Why it matters

If providers aren't following security agreements, you risk data breaches, financial loss, and damaged reputation.

settings

Operational notes

Regular communication with service providers ensures they remain aware of their security obligations. Keep track of compliance issues and follow-ups.

build

Implementation tips

  • Procurement teams should review contracts with service providers to ensure they include clear security obligations. Make sure these are specific about what security measures the provider must take.
  • IT managers should schedule regular compliance checks with each service provider. Use a checklist based on the security terms in the contract and conduct these checks quarterly.
  • Assign an employee to be the main point of contact for service providers. This person should keep track of communications and follow up on any security issues identified.
  • Security leaders should conduct training sessions for staff involved with contract management. Focus on recognising security needs and how to enforce them through contracts.
  • Business managers should review reports from compliance checks. Ensure that any issues are followed up and that providers are held accountable for improving their security posture.
fact_check

Audit / evidence tips

  • Askthe last compliance check report with service providersLook atdetails on what was checked and what issues were foundGoodthe report includes a checklist, findings, and corrective actions with timelines
  • Goodeach contract has a dedicated section on security obligations with explicit terms
  • Askevidence of communication between the organisation and service providers about security issuesLook atdocumented emails or meeting minutesGooda series of emails or minutes showing issues raised and addressed
  • Asktraining records of staff involved in managing provider contractsLook atdetails on date, content, and attendeesGoodrecent training records demonstrating that relevant staff attended and understood contract security requirements
  • Look ata clear plan with dates and responsible personsGooda documented plan showing regular intervals and assigned employees for each check
link

Cross-framework mappings

How ISM-1738 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.20Annex A 5.20 requires relevant information security requirements to be established and agreed with each supplier based on the relationshi...
sync_altPartially overlaps(4)expand_less
Annex A 5.19ISM-1738 mandates regular verification of service provider compliance with contracted security requirements
Annex A 5.21ISM-1738 requires regular, ongoing verification of service providers against contractual security requirements
Annex A 5.22Annex A 5.22 requires organisations to monitor and evaluate supplier practices and service delivery, including managing change
Annex A 5.36Annex A 5.36 requires organisations to regularly review compliance with information security policies, rules and standards
handshakeSupports(2)expand_less
Annex A 8.21Annex A 8.21 requires that security requirements for network services are identified and that implemented mechanisms and service levels a...
Annex A 8.30Annex A 8.30 requires directing, monitoring and reviewing outsourced system development activities on an ongoing basis

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for procurement and outsourcing controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls