Skip to content
arrow_back
search
ISM-0232 policy ASD Information Security Manual (ISM)

Encrypt External Traffic for Sensitive Calls

Sensitive phone calls should be encrypted to prevent eavesdropping when using outside systems.

record_voice_over

Plain language

This control is about making sure that any phone conversations involving sensitive information, like confidential business discussions or private client details, are protected from eavesdropping. This is important because if someone manages to listen in, they could misuse the information for financial gain or cause damage by leaking private details.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Telephone systems used for sensitive or classified conversations encrypt all traffic that passes over external systems.
policy ASD Information Security Manual (ISM) ISM-0232
priority_high

Why it matters

Without encrypting external calls, sensitive conversations can be intercepted, risking exposure of confidential data and potential business losses.

settings

Operational notes

Regularly verify external call encryption (e.g., SIP over TLS and SRTP) on trunks and gateways, and confirm no fallback to unencrypted signalling or media.

Mapping detail

Mapping

Direction

Controls