ASD ISM 2009Restrict Medical Devices in SECRET and TOP SECRET Areas
Official control statement
Unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Ensure unauthorised medical devices are not brought into SECRET and TOP SECRET areas.
What this means in practice
This control ensures that medical devices which have not been authorised are kept out of SECRET and TOP SECRET areas. Many medical devices contain microphones, cameras, wireless radios or storage that could capture or leak classified information, so they cannot be brought in freely. Anyone who needs a medical device in these areas must have it checked and approved beforehand. This protects highly sensitive information from accidental or deliberate compromise.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Preventative
Classifications
S, TS
ISM last updated
Mar 2025
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for physical securitySection
Facilities and systemsTopic
Bringing medical devices into facilities
Why it matters
Without this control, medical devices carrying hidden radios, cameras or storage could enter SECRET and TOP SECRET areas and covertly capture or exfiltrate classified information.
Operational notes
Review medical device authorisations regularly and revoke them promptly when a device or its holder changes.
Implementation tips
- Security officers should document a policy that prohibits medical devices in SECRET and TOP SECRET areas unless each device is individually authorised.
- Establish an authorisation process so that staff formally request approval for any required medical device before taking it into these areas.
- The authorising authority should assess each requested medical device for wireless, recording and storage capabilities before granting approval, and record the decision.
- Display clear signage at every entry point to SECRET and TOP SECRET areas stating that unauthorised medical devices are not permitted.
- Brief personnel and visitors during security inductions on the medical device restriction and the process for requesting an exemption.
Audit / evidence tips
- AskAsk for the policy governing medical devices in SECRET and TOP SECRET areas.Look atThe documented security policy or standard operating procedures for those areas.GoodA current policy that explicitly prohibits unauthorised medical devices in SECRET and TOP SECRET areas and defines an approval process.
- AskAsk how requests to bring a medical device into these areas are assessed and approved.Look atThe authorisation workflow and records of assessed device requests.GoodDocumented assessments that consider wireless, recording and storage risks, each with a named approver and a dated decision.
- AskAsk what controls stop unauthorised medical devices from entering these areas.Look atPhysical entry controls, entry-point signage, and induction or briefing material.GoodSignage at entry points plus induction records showing that personnel are informed of the restriction.
- AskAsk for a record of medical devices currently authorised in these areas.Look atThe register or log of approved medical devices and the individuals holding them.GoodAn up-to-date register listing each authorised device, its holder, and the basis for approval.
- AskAsk how compliance with the restriction is monitored and enforced.Look atInspection, spot-check or incident records relating to medical devices in these areas.GoodEvidence of periodic checks and recorded actions taken whenever an unauthorised device is found.
Cross-framework mappings
How ISM-2009 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 7.6 | ISM-2009 requires that unauthorised medical devices are not brought into SECRET and TOP SECRET areas, reducing the risk that devices with... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Physical security
See all Guidelines for physical security controls, or browse the full ASD ISM library.