Skip to content
arrow_back
search
ISM-1804 policy ASD Information Security Manual (ISM)

Include Break Clauses in Cloud Service Contracts

Contracts must have clauses that allow termination if security requirements aren't met by service providers.

record_voice_over

Plain language

Imagine you're relying on a company to securely manage your important files in the cloud. What happens if they fail to protect your data? This control means you can end your contract if they don't meet their security promises. It’s important because having this safety net helps you avoid bigger issues if things go wrong.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Break clauses associated with failure to meet security requirements are documented in contractual arrangements with service providers.
policy ASD Information Security Manual (ISM) ISM-1804
priority_high

Why it matters

Without break clauses tied to unmet security requirements, you may be locked into a non-compliant cloud provider, extending breach exposure and increasing legal and reputational risk.

settings

Operational notes

Review cloud contracts to ensure break clauses explicitly cover failure to meet security requirements, define triggers/evidence, and specify termination or remediation timeframes.

Mapping detail

Mapping

Direction

Controls