Skip to content
arrow_back
ISM-2007policyASD Information Security Manual (ISM)

Authorised Medical Device Register for SECRET and TOP SECRET Areas

Keep, maintain and regularly check an approved list of medical devices allowed into SECRET and TOP SECRET areas.

record_voice_over

Plain language

Some areas in your organisation hold information classified as SECRET or TOP SECRET (the two highest levels of government classification). This control says you must create and keep an official list (a register) of every medical device that is allowed into those areas, such as a pacemaker, insulin pump, hearing aid or other personal medical item. Many of these devices contain wireless transmitters, microphones or memory, so an unapproved one could secretly record or leak sensitive information. The register has to be set up, put into use, kept up to date, and checked on a regular basis to make sure it stays accurate.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.
policyASD Information Security Manual (ISM)ISM-2007
priority_high

Why it matters

An unrecorded medical device with a hidden microphone, transmitter or memory could leak SECRET or TOP SECRET information, causing a serious national security breach.

settings

Operational notes

Review the register on a set schedule and whenever staff or devices change, so it always reflects exactly who is permitted to bring which device into classified areas.

build

Implementation tips

  • The security manager creates a single register that records each approved medical device, the person who relies on it, the SECRET or TOP SECRET area it is permitted in, and the date it was authorised.
  • The person needing a medical device in a classified area submits a written request, and a delegated approver checks the device's wireless, recording and storage features before adding it to the register.
  • The facility security officer puts the register into active use by checking devices against it at entry points to SECRET and TOP SECRET areas before anyone is allowed in.
  • The register owner keeps the list current by adding new devices, removing devices for people who have left or changed roles, and updating entries whenever a device is replaced or upgraded.
  • The security team schedules a regular verification (for example every quarter) where they reconcile the register against people actually working in those areas and confirm each listed device is still genuinely required.
fact_check

Audit / evidence tips

  • Askto see the authorised medical device register itselfLook atwhether it covers SECRET and TOP SECRET areas specifically and lists each device with its owner and authorisation dateGoodis a single controlled document that is complete and clearly owned
  • Askwho has authority to approve a medical device for entry into these areasLook ata named role and a documented approval stepGoodshows approvals are made by a delegated officer after assessing the device's risk features
  • Askhow the register is used at the point of entryLook ataccess procedures or guard instructions for classified areasGoodshows staff actually check devices against the register before granting access
  • Askhow the register is kept up to dateLook atrecent entries showing additions and removals when people or devices changeGoodshows the list is living, not a one-off document created years ago
  • Askevidence of the regular verification activityLook atdated reconciliation records, sign-offs or review notesGoodshows scheduled checks confirming every listed device is still authorised and required
link

Cross-framework mappings

How ISM-2007 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.9ISM-2007 requires an authorised, maintained, and regularly verified register of approved medical devices for SECRET and TOP SECRET areas
handshakeSupports(1)expand_less
Annex A 7.2ISM-2007 requires organisations to control medical devices in SECRET and TOP SECRET areas by maintaining and verifying an authorised devi...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for physical security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls