Skip to content
arrow_back
search
ISM-1974 policy ASD Information Security Manual (ISM)

Securing Non-Classified IT Equipment in Secure Rooms

Non-classified IT equipment should be placed in secure rooms to prevent unauthorized physical access.

record_voice_over

Plain language

This control is about making sure that non-classified IT equipment like servers or network gear is kept in secure rooms. This is important to prevent unauthorised people from physically accessing them, which could lead to data breaches, equipment damage, or disruptions in service.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
policy ASD Information Security Manual (ISM) ISM-1974
priority_high

Why it matters

Without secure server/comms rooms, unauthorised access to servers, network or cryptographic gear can enable tampering, outages and data compromise.

settings

Operational notes

Restrict and log entry to server/comms rooms; review access lists regularly; ensure racks/cabinets are locked and equipment is physically secured.

Mapping detail

Mapping

Direction

Controls