Skip to content
arrow_back
search
ISM-0142 policy ASD Information Security Manual (ISM)

Report Cryptographic Equipment Compromises Promptly

Notify security officers quickly if cryptographic equipment or keys might be compromised.

record_voice_over

Plain language

This control is about reporting immediately if you think the devices or codes that protect your organisation's electronic information might have been compromised. This matters because if a malicious actor gains access to your secure communications or data, they could steal sensitive information, causing significant harm to your business's reputation and operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The compromise or suspected compromise of cryptographic equipment or associated keying material is reported to the chief information security officer, or one of their delegates, as soon as possible after it occurs.
policy ASD Information Security Manual (ISM) ISM-0142
priority_high

Why it matters

Failure to promptly report compromised cryptographic equipment or keying material can allow continued exposure of protected data and unauthorised access.

settings

Operational notes

Train staff to recognise crypto equipment/key compromise indicators and report immediately to the CISO (or delegate) using defined incident channels.

Mapping detail

Mapping

Direction

Controls