Maintain Register of Authorised Recording Devices in SECRET and TOP SECRET Areas
Keep a maintained, regularly verified register of every photographic and video recording device authorised to be used in SECRET and TOP SECRET areas.
Plain language
Cameras, video recorders and phones with cameras are normally a serious risk in your most sensitive areas (those classified SECRET and TOP SECRET), because they can capture protected information. This control says that for the small number of recording devices you do allow into those areas, you must keep an official list (a register) that records each one. You build that register, put it into use, keep it up to date, and regularly check it is still accurate so that no unapproved recording device ends up in a high-security area unnoticed.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for physical securitySection
Facilities and SystemsOfficial control statement
An authorised photographic and video recording device register for SECRET and TOP SECRET areas is developed, implemented, maintained and regularly verified.
Why it matters
If unauthorised cameras or video recorders go undetected in SECRET or TOP SECRET areas, classified information can be photographed and leaked, causing a serious national security breach.
Operational notes
Treat the register as a living record: update it the moment a device is added, reassigned or retired, and run scheduled verification checks so it stays accurate between formal reviews.
Implementation tips
- The site security manager creates a written register that lists every photographic and video recording device approved for use in SECRET and TOP SECRET areas, capturing for each one a unique identifier (such as a serial or asset number), the device type, who it is assigned to, and the date it was authorised.
- The person who approves access decides and documents the rules for granting authorisation, so a device is only added to the register after a named approver signs off, and any phone, camera or recorder not on the register is treated as prohibited in those areas.
- The security team puts the register into day-to-day use by checking devices against it at entry points to SECRET and TOP SECRET areas, and by removing or updating an entry the moment a device is reassigned, returned or decommissioned.
- The register owner schedules regular verification (for example quarterly) where they physically reconcile the listed devices against what is actually present and authorised, and records the date, who performed it, and any discrepancies found and fixed.
- Management stores the register securely with controlled access, keeps previous versions, and assigns a named owner responsible for keeping it accurate so it does not drift out of date between checks.
Audit / evidence tips
- Askto see the actual register of authorised photographic and video recording devices for SECRET and TOP SECRET areasLook atwhether each entry has a unique identifier, device type and authorisation detailGoodis a complete, current register rather than an informal or partial list
- Askwho authorises a device to be added and request the approval recordsLook atnamed approvers and dated sign-offs tied to each deviceGoodshows authorisation happens before a device is allowed in, not retrospectively
- Askhow the register is used at the point of entry to high-security areasLook atentry-control procedures or logs that reference checking devices against the registerGoodshows the register actively prevents unlisted devices from entering
- Askevidence of the regular verification activityLook atdated reconciliation records showing devices were physically checked against the register and any mismatches resolvedGoodshows verification is routine and recent, not a one-off
- Askhow the register is kept current when devices change hands or are retiredLook ata named owner, version history and update timestampsGoodshows entries are amended promptly and old devices are removed
Cross-framework mappings
How ISM-2069 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
linkRelated(1)expand_less | ||
| Annex A 7.6 | Annex A 7.6 requires the design and implementation of security measures that control and protect work within secure areas | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Physical security
See all Guidelines for physical security controls, or browse the full ASD ISM library.