Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2104Do Not Post Security Clearance and Briefing Details Online

Staff are told not to post their security clearance or briefing details on unapproved online services and to report it when such information appears.

record_voice_over

Plain language

This control is about keeping details of your security clearance and any security briefings off websites, apps and social media that your organisation has not approved. If someone reveals what level of clearance they hold or what they were briefed on, it can tell outsiders who to target and what secrets your organisation holds. Staff also need to speak up and report it whenever they notice this kind of information has been posted, whether by themselves or someone else.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Personnel are advised not to post information about their security clearance and briefings on unauthorised online services, and to report cases where such information is posted.
policyASD Information Security Manual (ISM)ISM-2104
priority_high

Why it matters

If staff post their security clearance or briefing details on unapproved sites, attackers learn who holds sensitive access and what secrets exist, making them prime targets for social engineering or espionage.

settings

Operational notes

Reinforce the rule whenever briefings are held and review reported cases periodically to confirm postings are removed and lessons are fed back into awareness training.

build

Implementation tips

  • The security manager should write a short, plain-English rule that states personnel must not post their security clearance level or details of any security briefings on unauthorised online services, and should include this rule in the staff handbook and induction pack.
  • The awareness training team should add a specific module showing real examples of what counts as a security clearance or briefing detail (for example posting 'just got my Secret clearance' on a public profile) so staff recognise what they must not share.
  • The IT or security team should set up a simple, well-publicised reporting channel (such as a dedicated email address or an item on the helpdesk form) so anyone who spots clearance or briefing information posted online can report it quickly.
  • Line managers should remind their teams before and after any security briefing that the content of that briefing must not be discussed or posted on unapproved websites, apps or social media.
  • The HR team should have new starters who hold a clearance sign an acknowledgement that they understand they must not post clearance or briefing details online and that they will report any cases they see.
fact_check

Audit / evidence tips

  • Askthe written policy or staff guidance that tells personnel not to post security clearance and briefing details on unauthorised online servicesLook atwhether it names clearance level and briefing content specifically and whether it is easy for staff to findGoodis a current, approved document that clearly states the rule and where it lives
  • Askhow staff are made aware of this ruleLook atinduction materials, awareness training slides and any signed acknowledgementsGoodshows the rule is taught with concrete examples and that staff have confirmed they understand it
  • Askhow someone reports a case where clearance or briefing information has been posted onlineLook atthe reporting channel (email address, form or hotline) and whether staff actually know it existsGoodis a named, monitored channel that staff can describe without hesitation
  • Askto see records of any reports that have been made and what happened nextLook atthe log of reported postings and the actions taken to get them removed or escalatedGoodshows reports are captured, acted on promptly and closed out
  • Askhow the organisation defines an 'unauthorised' online service versus an approved oneLook atany list of approved platforms or guidance distinguishing the twoGoodmakes the boundary clear enough that staff know what is and is not allowed
link

Cross-framework mappings

How ISM-2104 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 6.3ISM-2104 provides a specific piece of security guidance: do not post security clearance and briefing details online and report if it occurs
sync_altPartially overlaps(1)expand_less
Annex A 5.10ISM-2104 requires personnel not to post security clearance and briefing details on unauthorised online services and to report when this o...
handshakeSupports(1)expand_less
Annex A 5.26ISM-2104 directs personnel behaviour to prevent disclosure of security clearance/briefing details and requires reporting when such disclo...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for personnel security controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls