Skip to content
arrow_back
ISM-0469policyASD Information Security Manual (ISM)

Use Approved Cryptographic Protocols When Encrypting Data In Transit

When data moves across networks, encrypt it using an approved (AACP) or high assurance cryptographic protocol so it cannot be read in transit.

record_voice_over

Plain language

When your business sends information across a network (for example, over the internet or between offices), that data should be scrambled using a trusted, government-approved method so outsiders cannot read it on the way. This control says you must use an AACP (ASD-Approved Cryptographic Protocol: a protocol the Australian Signals Directorate has vetted) or, for very sensitive material, a "high assurance" protocol that meets an even stronger standard. Using the right protocol means that even if someone intercepts the traffic, all they see is unreadable gibberish.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

19 June 2026

E8 maturity levels

N/A

Official control statement

An AACP or high assurance cryptographic protocol is used when encrypting data in transit.
policyASD Information Security Manual (ISM)ISM-0469
priority_high

Why it matters

If data in transit is not protected with an approved protocol, attackers can intercept and read sensitive information such as logins, customer records or financial details as it crosses the network.

settings

Operational notes

Approved protocol lists and supported versions change over time, so review enabled protocols and cipher settings periodically and retire any that the ASD no longer approves.

build

Implementation tips

  • The IT manager or IT provider should make an inventory of every place data travels across a network (websites, email, file transfers, remote access, links between offices) and confirm each one uses an ASD-Approved Cryptographic Protocol (AACP) such as a current version of TLS (Transport Layer Security, the technology behind the padlock in a browser).
  • The person managing your servers and websites should disable old, weak protocols (for example, older SSL and early TLS versions) and configure systems to only accept current approved versions, then test the configuration with a free protocol-checking tool.
  • For any information that is highly classified or especially sensitive, the security officer should identify whether a high assurance cryptographic protocol is required and arrange the specific ASD-evaluated product needed, rather than relying on a standard commercial protocol.
  • The IT team should set up automatic certificate renewal and protocol updates so encryption does not silently lapse, and keep a dated record of which protocol version each system is running.
  • The business owner should add a clause to contracts with cloud and IT suppliers requiring that data in transit is protected using an AACP or high assurance protocol, and ask each supplier to confirm this in writing.
fact_check

Audit / evidence tips

  • Aska list of all network connections that carry business data and the protocol used for eachLook atwhether each entry names an ASD-Approved Cryptographic Protocol (such as a supported TLS version) rather than a generic 'encrypted' labelGoodis a complete, current inventory mapping every data-in-transit path to a named approved protocol
  • Askto see the configuration or a scan report for a public-facing website or serviceLook atevidence that weak protocols (older SSL, early TLS) are disabled and only current approved versions are enabledGoodis a recent third-party or tool-generated scan showing only approved protocols accepted
  • Askhow the organisation decides when a high assurance cryptographic protocol is needed instead of a standard approved oneLook ata documented link between data sensitivity or classification and the protocol chosenGoodreferences the data's classification and names the specific high assurance product used
  • Askrecords of how encryption certificates and protocol versions are kept currentLook atrenewal logs, automated update settings, and dates of the last reviewGoodshows certificates that have not expired and a routine process for keeping protocols up to date
  • Asksuppliers and cloud providers to confirm what protocol protects data in transit to and from their serviceLook atwritten confirmation or contract clauses naming an AACP or high assurance protocolGoodis a signed statement or contract term specifying the approved protocol in use
link

Cross-framework mappings

How ISM-0469 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.20ISM-0469 requires that an ASD-Approved Cryptographic Protocol (or high assurance cryptographic protocol) is used to protect data when it ...
sync_altPartially overlaps(1)expand_less
Annex A 8.24ISM-0469 requires the use of ASD-Approved Cryptographic Protocols (or high assurance cryptographic protocols) to protect data communicate...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cryptography controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls