Skip to content
arrow_back
ISM-1869policyASD Information Security Manual (ISM)

Maintain Non-Networked IT Equipment Register

Ensure a non-networked IT equipment list is created and kept up-to-date.

record_voice_over

Plain language

Creating and maintaining a list of IT equipment that isn't connected to the network helps you track what devices you have and ensures they're managed securely. If you don't have this list, you might miss a device that becomes a security risk or gets lost or stolen.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

A non-networked IT equipment register is developed, implemented, maintained and regularly verified.
policyASD Information Security Manual (ISM)ISM-1869
priority_high

Why it matters

Without a maintained registry of non-networked devices, organisations risk unmanaged equipment causing data loss or security breaches.

settings

Operational notes

Regularly review and update the non-networked IT equipment register to quickly identify any missing or unauthorised devices.

build

Implementation tips

  • A designated IT manager should create an initial list of all non-networked IT equipment by conducting a physical audit of the organisation's premises. This involves walking through all office areas and identifying devices such as standalone printers or backup hard drives.
  • An inventory manager should input all collected details like serial numbers and location into a central register. This could be a spreadsheet or a simple database maintained on a secure drive.
  • The office manager should establish a process for updating the register whenever new equipment is purchased or existing equipment is decommissioned. Regular updates can be scheduled alongside monthly budget reviews.
  • The HR team should include a step in the employee onboarding checklist to check and update the register if relevant, such as when a new device is allocated to an employee.
  • The IT manager should conduct a quarterly review to verify the register's accuracy by cross-referencing it with purchase records and conducting a spot-check of equipment locations.
fact_check

Audit / evidence tips

  • Askthe non-networked IT equipment registerLook atit to ensure it lists all stand-alone devices and includes details like serial numbers and locationGoodis a comprehensive, neatly organised list covering all equipment
  • Askrecent updates or changes to the registerLook attimestamps or change logs that show the register is updated regularlyGoodis evidence of recent entries or modifications
  • Look atclearly defined steps and responsible partiesGoodincludes a document that outlines procedures and designated roles
  • Look atchecklists or documentation indicating recent completionGoodincludes evidence of a recent physical equipment audit
  • Askto see training or briefing material used for employees involved in maintaining the registerLook atcontent relevance and delivery recordsGoodis up-to-date training documents with attendance logs
link

Cross-framework mappings

How ISM-1869 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.9ISM-1869 requires an organisation to develop, implement, maintain and regularly verify a register of non-networked IT equipment

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for information technology equipment controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls