Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2009Restrict Medical Devices in SECRET and TOP SECRET Areas

Official control statement

Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
policyASD Information Security Manual (ISM)ISM-2009

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Ensure unauthorised medical devices are not brought into SECRET and TOP SECRET areas.

STSASD Information Security ManualGuidelines for physical security
Control Stack classificationPreventativeSecure facilities and areas
record_voice_over

What this means in practice

This control ensures that medical devices which have not been authorised are kept out of SECRET and TOP SECRET areas. Many medical devices contain microphones, cameras, wireless radios or storage that could capture or leak classified information, so they cannot be brought in freely. Anyone who needs a medical device in these areas must have it checked and approved beforehand. This protects highly sensitive information from accidental or deliberate compromise.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

S, TS

ISM last updated

Mar 2025

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Bringing medical devices into facilities

priority_high

Why it matters

Without this control, medical devices carrying hidden radios, cameras or storage could enter SECRET and TOP SECRET areas and covertly capture or exfiltrate classified information.

settings

Operational notes

Review medical device authorisations regularly and revoke them promptly when a device or its holder changes.

build

Implementation tips

  • Security officers should document a policy that prohibits medical devices in SECRET and TOP SECRET areas unless each device is individually authorised.
  • Establish an authorisation process so that staff formally request approval for any required medical device before taking it into these areas.
  • The authorising authority should assess each requested medical device for wireless, recording and storage capabilities before granting approval, and record the decision.
  • Display clear signage at every entry point to SECRET and TOP SECRET areas stating that unauthorised medical devices are not permitted.
  • Brief personnel and visitors during security inductions on the medical device restriction and the process for requesting an exemption.
fact_check

Audit / evidence tips

  • AskAsk for the policy governing medical devices in SECRET and TOP SECRET areas.Look atThe documented security policy or standard operating procedures for those areas.GoodA current policy that explicitly prohibits unauthorised medical devices in SECRET and TOP SECRET areas and defines an approval process.
  • AskAsk how requests to bring a medical device into these areas are assessed and approved.Look atThe authorisation workflow and records of assessed device requests.GoodDocumented assessments that consider wireless, recording and storage risks, each with a named approver and a dated decision.
  • AskAsk what controls stop unauthorised medical devices from entering these areas.Look atPhysical entry controls, entry-point signage, and induction or briefing material.GoodSignage at entry points plus induction records showing that personnel are informed of the restriction.
  • AskAsk for a record of medical devices currently authorised in these areas.Look atThe register or log of approved medical devices and the individuals holding them.GoodAn up-to-date register listing each authorised device, its holder, and the basis for approval.
  • AskAsk how compliance with the restriction is monitored and enforced.Look atInspection, spot-check or incident records relating to medical devices in these areas.GoodEvidence of periodic checks and recorded actions taken whenever an unauthorised device is found.
link

Cross-framework mappings

How ISM-2009 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 7.6ISM-2009 requires that unauthorised medical devices are not brought into SECRET and TOP SECRET areas, reducing the risk that devices with...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for physical security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls