Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2096Separate Organisational and Personal Mobile Data

Ensure mobile devices keep work and personal apps and data separate.

record_voice_over

Plain language

This control ensures that work and personal apps and data on mobile devices are kept separate. If you don't do this, sensitive company data can accidentally leak or be accessed by unauthorised users through personal apps.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Mobile devices are configured to enforce separation between organisational and personal mobile applications and data.
policyASD Information Security Manual (ISM)ISM-2096
priority_high

Why it matters

Mixing work and personal data on mobile devices can lead to data breaches, regulatory violations, and damage to company reputation.

settings

Operational notes

Regularly remind staff to check they are using work apps only within work profiles to maintain security. Frequent verification of MDM settings helps ensure compliance.

build

Implementation tips

  • Managers should require staff to install a work profile on their mobiles. This is independent from their personal profile, ensuring company apps and data stay separate and secure.
  • IT teams should configure mobile device management (MDM) systems to enforce data separation. This involves setting rules that keep work emails, files, and apps apart from personal ones.
  • System administrators should provide guidelines and support to staff. They can explain how to install and use company-approved apps in the work profile to prevent data sharing with personal apps.
  • HR should inform employees during onboarding about the importance of separating work and personal data on mobiles. They can provide easy-to-follow steps and visual guides.
  • Compliance officers should regularly review device settings to ensure separation rules are applied. They might check settings during routine tech check-ins with staff.
fact_check

Audit / evidence tips

  • Askthe mobile management policy documentation. Look to see if it specifies how work and personal data should be kept separateGoodshows clear processes for ensuring data is not shared between profiles
  • Look athow many devices have work profiles set up compared to total devicesGoodis a high percentage indicating effective deployment
  • Aska demonstration on how data separation is enforced on a sample mobile device. Look to see that work and personal apps cannot access each other's dataGoodshows total app and data isolation
  • Look atattendee lists and training materialsGoodincludes regular training sessions with signed attendance
  • Askcompliance or audit records checking the effectiveness of data separationLook atany findings and remediation actions takenGoodidentifies few findings and prompt corrective actions
link

Cross-framework mappings

How ISM-2096 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 6.7ISM-2096 requires mobile devices to be configured so organisational applications and data are kept separate from personal applications an...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls