Skip to content
arrow_back
search
ISM-1778 policy ASD Information Security Manual (ISM)

Quarantine Security-Noncompliant Data for Review

Noncompliant data is quarantined for review before system entry when imported manually.

record_voice_over

Plain language

When adding data to your company's systems by hand, it's important to hold back any information that doesn't pass security checks for closer inspection. This matters because if risky data slips through, it could lead to data breaches, affecting your business financially and damaging its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When manually importing data to systems, all data that fails security checks is quarantined until reviewed and subsequently approved or not approved for release.
policy ASD Information Security Manual (ISM) ISM-1778
priority_high

Why it matters

If quarantined import data that fails security checks is not reviewed and approved before release, malware or sensitive data may be introduced, causing unauthorised access and reputational/financial damage.

settings

Operational notes

For manual imports, ensure all items failing security checks are automatically quarantined, logged, and only released after a documented security review and explicit approval or rejection.

Mapping detail

Mapping

Direction

Controls