Skip to content
arrow_back
search
ISM-1866 policy ASD Information Security Manual (ISM)

Prevent Storage of Classified Data on Private Devices

Prevent employees from storing classified data on their personal devices when accessing sensitive systems.

record_voice_over

Plain language

This control is about making sure employees don't save classified information on their personal devices. If they do, there's a risk that sensitive data could be exposed or lost if their device is lost, stolen, or hacked.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

OS, P

ISM last updated

Mar 2026

Control Stack last updated

24 Mar 2026

E8 maturity levels

N/A

Official control statement

Personnel using privately-owned mobile devices or desktop computers to access OFFICIAL: Sensitive or PROTECTED systems or data are prevented from storing classified data on their privately-owned mobile devices and desktop computers.
policy ASD Information Security Manual (ISM) ISM-1866
priority_high

Why it matters

If personal devices store classified data, it risks exposure through theft, loss, or a cyberattack, potentially leading to significant data breaches.

settings

Operational notes

Regularly update and enforce policies to prevent employees from even unintentionally storing sensitive data on their personal devices. Stay vigilant in monitoring.

Mapping detail

Mapping

Direction

Controls