Skip to content
arrow_back
search
ISM-1972 policy ASD Information Security Manual (ISM)

Security Assessments for Top Secret Cloud Services

Cloud providers' secret services need security checks every two years by authorised assessors.

record_voice_over

Plain language

Cloud service providers storing top secret information must get a detailed security check every two years by specific authorised assessors. This is crucial because it helps catch any security weaknesses that could lead to loss or theft of highly sensitive information, which can cause severe national security issues or significant financial and reputational damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Outsourced cloud service providers and their TOP SECRET cloud services, including sensitive compartmented information cloud services, undergo a security assessment by ASD assessors (or their delegates), using the latest release of the ISM available prior to the beginning of the security assessment (or a subsequent release), at least every 24 months.
policy ASD Information Security Manual (ISM) ISM-1972
priority_high

Why it matters

Missing the required 24-month ASD security assessments can leave TOP SECRET cloud services non-compliant and allow compromises to go undetected, risking national security.

settings

Operational notes

Schedule ASD (or delegate) assessments at least every 24 months for TOP SECRET cloud services, and confirm assessors use the latest ISM release available before the assessment starts.

Mapping detail

Mapping

Direction

Controls