Use Encrypted Cordless Systems for Sensitive Conversations
Do not use cordless phones for sensitive talks unless they use ASD-approved encryption.
Plain language
Cordless phones can be tricky for confidential conversations because anyone nearby with the right equipment could listen in. If you have to use them, make sure they're set up to encrypt calls so others can't eavesdrop on sensitive information.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Section
Telephone SystemsOfficial control statement
Cordless telephone handsets and headsets are not used for sensitive or classified conversations unless all communications are encrypted using ASD-approved cryptography.
Why it matters
Without encryption, unauthorised individuals could intercept your conversations, leading to data breaches or loss of confidentiality.
Operational notes
Regularly check for and apply firmware updates to ensure your cordless phone systems maintain the necessary encryption standards.
Implementation tips
- IT team should review current cordless phone systems to check if they use encryption. Check the manual or contact the manufacturer to verify what kind of security features are included.
- The procurement manager should only purchase cordless phone systems with ASD-approved encryption. Refer to the list of approved systems from the Australian Signals Directorate (ASD) for guidance.
- Office managers should train staff on using encrypted phone systems to handle sensitive calls. Arrange a short informational session demonstrating how to use these features.
- System administrators should regularly update the firmware of cordless phone systems. Check for updates on the manufacturer's website or contact their support to ensure encryption modules are up-to-date.
- Legal advisors should work with the IT team to develop a policy regarding the use of encrypted cordless phones. Draft a clear policy document that defines when encryption is necessary for phone calls.
Audit / evidence tips
- Askthe list of cordless phone systems in use: Request a record showing the types and models of phones currently used within the organisationLook atdetails on encryption capabilitiesGoodwould show only ASD-approved systems being used for sensitive conversations
- Askattendance records or training materials that cover the use of encrypted phone systemsLook atdates and employee signatures who attendedGoodprovides thorough coverage of proper use
- Askto see the procurement records for phone systems: Request purchase orders or invoices specifying the models of cordless systems bought. Examine these for any ASD-approved encryption verificationGoodconfirms all new systems meet this control's encryption standard
- Askthe company's telecommunications policyLook atsections that address the use of cordless phones and encryptionGoodpolicy explicitly mentions when and how encrypted systems must be used
- Askrecords that detail when phone systems were last updated. Check that updates occurred in a timely manner and specifically whether they included any security patches related to encryption
Cross-framework mappings
How ISM-0233 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.24 | ISM-0233 requires that cordless telephone handsets and headsets are not used for sensitive or classified conversations unless the communi... | |
handshakeSupports(1)expand_less | ||
| Annex A 5.12 | ISM-0233 mandates encryption (or non-use) of cordless handsets/headsets for sensitive or classified conversations | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Communications systems
See all Guidelines for communications systems controls, or browse the full ASD ISM library.