Authorised Medical Device Register for SECRET and TOP SECRET Areas
Keep, maintain and regularly check an approved list of medical devices allowed into SECRET and TOP SECRET areas.
Plain language
Some areas in your organisation hold information classified as SECRET or TOP SECRET (the two highest levels of government classification). This control says you must create and keep an official list (a register) of every medical device that is allowed into those areas, such as a pacemaker, insulin pump, hearing aid or other personal medical item. Many of these devices contain wireless transmitters, microphones or memory, so an unapproved one could secretly record or leak sensitive information. The register has to be set up, put into use, kept up to date, and checked on a regular basis to make sure it stays accurate.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for physical securitySection
Facilities and SystemsOfficial control statement
An authorised medical device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.
Why it matters
An unrecorded medical device with a hidden microphone, transmitter or memory could leak SECRET or TOP SECRET information, causing a serious national security breach.
Operational notes
Review the register on a set schedule and whenever staff or devices change, so it always reflects exactly who is permitted to bring which device into classified areas.
Implementation tips
- The security manager creates a single register that records each approved medical device, the person who relies on it, the SECRET or TOP SECRET area it is permitted in, and the date it was authorised.
- The person needing a medical device in a classified area submits a written request, and a delegated approver checks the device's wireless, recording and storage features before adding it to the register.
- The facility security officer puts the register into active use by checking devices against it at entry points to SECRET and TOP SECRET areas before anyone is allowed in.
- The register owner keeps the list current by adding new devices, removing devices for people who have left or changed roles, and updating entries whenever a device is replaced or upgraded.
- The security team schedules a regular verification (for example every quarter) where they reconcile the register against people actually working in those areas and confirm each listed device is still genuinely required.
Audit / evidence tips
- Askto see the authorised medical device register itselfLook atwhether it covers SECRET and TOP SECRET areas specifically and lists each device with its owner and authorisation dateGoodis a single controlled document that is complete and clearly owned
- Askwho has authority to approve a medical device for entry into these areasLook ata named role and a documented approval stepGoodshows approvals are made by a delegated officer after assessing the device's risk features
- Askhow the register is used at the point of entryLook ataccess procedures or guard instructions for classified areasGoodshows staff actually check devices against the register before granting access
- Askhow the register is kept up to dateLook atrecent entries showing additions and removals when people or devices changeGoodshows the list is living, not a one-off document created years ago
- Askevidence of the regular verification activityLook atdated reconciliation records, sign-offs or review notesGoodshows scheduled checks confirming every listed device is still authorised and required
Cross-framework mappings
How ISM-2007 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.9 | ISM-2007 requires an authorised, maintained, and regularly verified register of approved medical devices for SECRET and TOP SECRET areas | |
handshakeSupports(1)expand_less | ||
| Annex A 7.2 | ISM-2007 requires organisations to control medical devices in SECRET and TOP SECRET areas by maintaining and verifying an authorised devi... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Physical security
See all Guidelines for physical security controls, or browse the full ASD ISM library.