Skip to content
arrow_back
search
ISM-0459 policy ASD Information Security Manual (ISM)

Implement Full or Partial Disk Encryption for Data Protection

Encrypt all or parts of a drive to ensure data cannot be accessed without the correct permissions.

record_voice_over

Plain language

This control is about using encryption to protect the information stored on your computer's drives. Encryption is like putting your data in a locked box - without the correct key, even if someone gets their hands on the box, they can't see what's inside. If you don't encrypt your drives, someone who steals your computer or gains unauthorised access could read your private information or sensitive business data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Full disk encryption, or partial encryption where access controls will only allow writing to the encrypted partition, is implemented when encrypting data at rest.
policy ASD Information Security Manual (ISM) ISM-0459
priority_high

Why it matters

Without disk encryption, lost or stolen devices expose sensitive data, risking data breaches and severe reputational damage.

settings

Operational notes

Regularly verify recovery keys and escrow them securely; confirm FDE/partition encryption is enabled and cannot write to any unencrypted volumes.

Mapping detail

Mapping

Direction

Controls