Criteria for Medical Devices in SECRET and TOP SECRET Areas
Medical devices in secure areas must be safe, approved, and have limited connectivity.
Plain language
If you're bringing medical devices into highly secure areas, they need to be safe and not too connected to the outside world. This matters because if a device has, for example, Wi-Fi or mobile connectivity that can't be disabled, it could be a way in for hackers to access sensitive information or systems.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for physical securitySection
Facilities and SystemsOfficial control statement
Medical devices authorised to be brought into SECRET and TOP SECRET areas meet, at a minimum, the following criteria: - are listed on the Australian Register of Therapeutic Goods - have been prescribed by a legally qualified medical practitioner - have been commercially purchased within Australia - do not have inbuilt cellular connectivity - can operate independently of mobile devices - where possible, have Wi-Fi, Bluetooth and other forms of wireless connectivity disabled when operating within SECRET and TOP SECRET areas.
Why it matters
Improperly managed medical devices can be an entry point for cyber attacks in secure areas, risking sensitive data exposure.
Operational notes
Regular checks of device connectivity settings and staff re-training are necessary to mitigate security risks in sensitive areas.
Implementation tips
- Procurement should ensure that all medical devices intended for secure areas are purchased from Australian suppliers and listed on the Australian Register of Therapeutic Goods. This can be verified by checking the supplier's details and registration against official records.
- Healthcare professionals must prescribe any medical devices for secure areas, ensuring they are necessary and appropriate. Arrange a formal prescription from a registered medical practitioner for any device entering these areas.
- IT teams should verify and disable any wireless capabilities on medical devices when not needed. This involves physically inspecting devices and checking settings for Bluetooth, Wi-Fi, and cellular connectivity.
- Facility managers should regularly audit devices entering secure areas to ensure compliance. Implement a checklist process during entry and exit of devices, documenting their connectivity features and any modifications made.
- Training teams should prepare staff who manage medical devices on the importance of connectivity restrictions in secure areas. Hold regular training sessions and provide clear instructions on procedures and steps to follow.
Audit / evidence tips
- Askthe list of approved medical devices: Request documentation showing all devices allowed into secure areas with detailsLook atproperly listed devices with prescriptions and supplier informationGoodis a comprehensive list with each device meeting the criteria
- Goodincludes detailed logs confirming disabling of unnecessary wireless functions
- Asktraining records of staff handling medical devices: Review training completion certificates or attendance sheetsLook atregular staff engagement and emphasis on security practicesGoodshows a consistent training history with focus on security
- Look atregistration details on the Australian Register of Therapeutic GoodsGooddisplays properly documented verification processes for purchases
- Look atregular maintenance logs indicating compliance with security requirementsGoodincludes checks for device connectivity status and any action taken if non-compliant
Cross-framework mappings
How ISM-2008 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.19 | ISM-2008 requires organisations to authorise medical devices before they enter SECRET/TOP SECRET areas using explicit assurance and suppl... | |
handshakeSupports(3)expand_less | ||
| Annex A 5.1 | ISM-2008 sets a topic-specific rule for SECRET/TOP SECRET environments: only authorised medical devices meeting defined provenance and co... | |
| Annex A 5.12 | ISM-2008 applies additional device-handling and connectivity restrictions specifically in SECRET and TOP SECRET areas, effectively treati... | |
| Annex A 5.31 | ISM-2008 mandates compliance conditions for a regulated class of equipment (medical devices) when used in SECRET/TOP SECRET areas, includ... | |
linkRelated(1)expand_less | ||
| Annex A 7.6 | Annex A 7.6 requires organisations to implement security measures governing work practices within secure areas | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Physical security
See all Guidelines for physical security controls, or browse the full ASD ISM library.