Skip to content
arrow_back
ISM-2008policyASD Information Security Manual (ISM)

Criteria for Medical Devices in SECRET and TOP SECRET Areas

Medical devices in secure areas must be safe, approved, and have limited connectivity.

record_voice_over

Plain language

If you're bringing medical devices into highly secure areas, they need to be safe and not too connected to the outside world. This matters because if a device has, for example, Wi-Fi or mobile connectivity that can't be disabled, it could be a way in for hackers to access sensitive information or systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Medical devices authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Australian Register of Therapeutic Goods - have been prescribed by a legally qualified medical practitioner - have been commercially purchased within Australia - do not have inbuilt cellular connectivity - can operate independently of mobile devices - where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas.
policyASD Information Security Manual (ISM)ISM-2008
priority_high

Why it matters

Improperly managed medical devices can be an entry point for cyber attacks in secure areas, risking sensitive data exposure.

settings

Operational notes

Regular checks of device connectivity settings and staff re-training are necessary to mitigate security risks in sensitive areas.

build

Implementation tips

  • Procurement should ensure that all medical devices intended for secure areas are purchased from Australian suppliers and listed on the Australian Register of Therapeutic Goods. This can be verified by checking the supplier's details and registration against official records.
  • Healthcare professionals must prescribe any medical devices for secure areas, ensuring they are necessary and appropriate. Arrange a formal prescription from a registered medical practitioner for any device entering these areas.
  • IT teams should verify and disable any wireless capabilities on medical devices when not needed. This involves physically inspecting devices and checking settings for Bluetooth, Wi-Fi, and cellular connectivity.
  • Facility managers should regularly audit devices entering secure areas to ensure compliance. Implement a checklist process during entry and exit of devices, documenting their connectivity features and any modifications made.
  • Training teams should prepare staff who manage medical devices on the importance of connectivity restrictions in secure areas. Hold regular training sessions and provide clear instructions on procedures and steps to follow.
fact_check

Audit / evidence tips

  • Askthe list of approved medical devices: Request documentation showing all devices allowed into secure areas with detailsLook atproperly listed devices with prescriptions and supplier informationGoodis a comprehensive list with each device meeting the criteria
  • Goodincludes detailed logs confirming disabling of unnecessary wireless functions
  • Asktraining records of staff handling medical devices: Review training completion certificates or attendance sheetsLook atregular staff engagement and emphasis on security practicesGoodshows a consistent training history with focus on security
  • Look atregistration details on the Australian Register of Therapeutic GoodsGooddisplays properly documented verification processes for purchases
  • Look atregular maintenance logs indicating compliance with security requirementsGoodincludes checks for device connectivity status and any action taken if non-compliant
link

Cross-framework mappings

How ISM-2008 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 5.19ISM-2008 requires organisations to authorise medical devices before they enter SECRET/TOP SECRET areas using explicit assurance and suppl...
handshakeSupports(3)expand_less
Annex A 5.1ISM-2008 sets a topic-specific rule for SECRET/TOP SECRET environments: only authorised medical devices meeting defined provenance and co...
Annex A 5.12ISM-2008 applies additional device-handling and connectivity restrictions specifically in SECRET and TOP SECRET areas, effectively treati...
Annex A 5.31ISM-2008 mandates compliance conditions for a regulated class of equipment (medical devices) when used in SECRET/TOP SECRET areas, includ...
linkRelated(1)expand_less
Annex A 7.6Annex A 7.6 requires organisations to implement security measures governing work practices within secure areas

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for physical security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls