Handling and security Current

Storing client identity evidence securely

A practical approach, starting from Australia's own baseline security guidance.

Collecting and verifying a client's identity evidence is only useful if it stays secure once you have it. This guide sets out a practical approach, starting from ASD's Essential Eight baseline and adding further practical storage and access steps. It is general information, not legal or IT security advice.

Action plan

1 Apply the relevant Essential Eight controls to where evidence is stored ASD's Essential Eight names the baseline mitigation strategies most firms should already be applying.

The Australian Signals Directorate's Essential Eight sets out eight baseline mitigation strategies for protecting internet-connected systems: patching applications, patching operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, user application hardening, and regular backups. Wherever client identity evidence is stored, check that the relevant controls from this baseline are actually applied to that system.

  • Confirm multi-factor authentication is required to access the system storing identity evidence
  • Confirm the system and its applications are kept patched
  • Confirm regular backups of stored evidence exist and are tested

Done when: The relevant Essential Eight controls have been confirmed for the system storing identity evidence

ACSC: Essential Eight explained
2 Encrypt stored evidence and limit how many copies exist Fewer copies, properly encrypted, is easier to secure than many scattered copies.

Encrypting identity evidence at rest, and keeping it in a single controlled system rather than scattered across email, personal devices, or ad hoc folders, meaningfully reduces the number of places a breach could occur.

  • Store identity evidence in one controlled system rather than email or personal devices
  • Confirm the storage system encrypts data at rest
  • Remove or consolidate stray copies once the controlled record exists

Done when: Identity evidence is held in one encrypted, controlled system with no stray uncontrolled copies

3 Review who can actually access stored evidence Storage security and access control are two different questions worth checking separately.

Storing evidence securely and controlling who can see it are related but separate steps. Once evidence is stored, review who currently has access to it against who actually needs it for their role.

  • List who currently has access to the system storing identity evidence
  • Compare that list against who genuinely needs access for their role
  • Remove access that's no longer needed

Done when: Access to stored identity evidence has been reviewed against genuine role need

See controlling who can access sensitive client records