Skip to content
arrow_back
search
ISM-1742 policy ASD Information Security Manual (ISM)

Destroy Un-sanitizable IT Equipment Safely

If IT equipment can't be cleaned properly, it must be destroyed to ensure security.

record_voice_over

Plain language

Sometimes, old computers or gadgets can't be properly wiped clean of sensitive data. In that case, it's important to physically destroy them so nobody can retrieve personal or business data. If we don't, this information could fall into the wrong hands, leading to privacy breaches or financial harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IT equipment that cannot be sanitised is destroyed.
policy ASD Information Security Manual (ISM) ISM-1742
priority_high

Why it matters

Failure to destroy unsanitiseable IT equipment may expose sensitive data via recovered media, causing reportable breaches and financial loss.

settings

Operational notes

Maintain a register of unsanitiseable assets and require vendor-certified physical destruction (e.g., shredding) with witnessed chain-of-custody records.

Mapping detail

Mapping

Direction

Controls