Skip to content
arrow_back
ISM-1974policyASD Information Security Manual (ISM)

Securing Non-Classified IT Equipment in Secure Rooms

Non-classified IT equipment should be placed in secure rooms to prevent unauthorized physical access.

record_voice_over

Plain language

This control is about making sure that non-classified IT equipment like servers or network gear is kept in secure rooms. This is important to prevent unauthorised people from physically accessing them, which could lead to data breaches, equipment damage, or disruptions in service.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC

ISM last updated

Dec 2024

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Non-classified servers, network devices and cryptographic equipment are secured in suitably secure server rooms or communications rooms.
policyASD Information Security Manual (ISM)ISM-1974
priority_high

Why it matters

Without secure server/comms rooms, unauthorised access to servers, network or cryptographic gear can enable tampering, outages and data compromise.

settings

Operational notes

Restrict and log entry to server/comms rooms; review access lists regularly; ensure racks/cabinets are locked and equipment is physically secured.

build

Implementation tips

  • Facility managers should identify server or communications rooms that need enhanced security. Start by listing all equipment that needs such protection and assess current security measures for each location.
  • IT teams should ensure secure access control to these rooms. They can do this by installing key card systems or biometric locks which monitor and restrict access to authorised personnel only.
  • Office managers should regularly review the list of authorised personnel. They should schedule monthly reviews and update access rights based on changes in staff roles or employment status.
  • The security team should install surveillance cameras in and around the secure rooms. Ensure cameras cover all entry points and maintain regular checks to verify recordings are stored properly and accessible if needed.
  • An external security consultant should conduct annual audits of the physical security measures. This includes assessing any potential vulnerabilities in the physical security controls and making recommendations for improvement.
fact_check

Audit / evidence tips

  • AskThe list of rooms designated as secureGoodA comprehensive list with clear identification measures for securing each room
  • AskLogs showing who accessed the secure rooms in the last monthGoodDetailed logs that match access rights, with no unauthorised entries
  • AskThe maintenance records of surveillance equipmentGoodRecent and regular maintenance records that show cameras are operational
  • AskThe list of people authorised to access secure roomsGoodA controlled list with justified, regularly updated permissions
  • AskThe security audit report conducted by an external consultantGoodA thorough report with clear findings and evidence of follow-up actions
link

Cross-framework mappings

How ISM-1974 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 7.1ISM-1974 requires non-classified servers, network devices, and cryptographic equipment to be secured in suitably secure server rooms or c...
Annex A 7.3Annex A 7.3 requires an organisation-wide approach to designing and implementing physical security for offices, rooms and facilities
sync_altPartially overlaps(1)expand_less
Annex A 7.8Annex A 7.8 requires that equipment is securely placed and physically protected
handshakeSupports(1)expand_less
Annex A 7.4Annex A 7.4 requires continuous monitoring of premises to detect unauthorised physical access
extensionDepends on(1)expand_less
Annex A 7.2ISM-1974 requires non-classified servers, network devices, and cryptographic equipment to be secured in suitably secure server rooms or c...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for physical security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls