Use Approved Cryptographic Protocols When Encrypting Data In Transit
When data moves across networks, encrypt it using an approved (AACP) or high assurance cryptographic protocol so it cannot be read in transit.
Plain language
When your business sends information across a network (for example, over the internet or between offices), that data should be scrambled using a trusted, government-approved method so outsiders cannot read it on the way. This control says you must use an AACP (ASD-Approved Cryptographic Protocol: a protocol the Australian Signals Directorate has vetted) or, for very sensitive material, a "high assurance" protocol that meets an even stronger standard. Using the right protocol means that even if someone intercepts the traffic, all they see is unreadable gibberish.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
19 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cryptographySection
Cryptographic ProtocolsOfficial control statement
An AACP or high assurance cryptographic protocol is used when encrypting data in transit.
Why it matters
If data in transit is not protected with an approved protocol, attackers can intercept and read sensitive information such as logins, customer records or financial details as it crosses the network.
Operational notes
Approved protocol lists and supported versions change over time, so review enabled protocols and cipher settings periodically and retire any that the ASD no longer approves.
Implementation tips
- The IT manager or IT provider should make an inventory of every place data travels across a network (websites, email, file transfers, remote access, links between offices) and confirm each one uses an ASD-Approved Cryptographic Protocol (AACP) such as a current version of TLS (Transport Layer Security, the technology behind the padlock in a browser).
- The person managing your servers and websites should disable old, weak protocols (for example, older SSL and early TLS versions) and configure systems to only accept current approved versions, then test the configuration with a free protocol-checking tool.
- For any information that is highly classified or especially sensitive, the security officer should identify whether a high assurance cryptographic protocol is required and arrange the specific ASD-evaluated product needed, rather than relying on a standard commercial protocol.
- The IT team should set up automatic certificate renewal and protocol updates so encryption does not silently lapse, and keep a dated record of which protocol version each system is running.
- The business owner should add a clause to contracts with cloud and IT suppliers requiring that data in transit is protected using an AACP or high assurance protocol, and ask each supplier to confirm this in writing.
Audit / evidence tips
- Aska list of all network connections that carry business data and the protocol used for eachLook atwhether each entry names an ASD-Approved Cryptographic Protocol (such as a supported TLS version) rather than a generic 'encrypted' labelGoodis a complete, current inventory mapping every data-in-transit path to a named approved protocol
- Askto see the configuration or a scan report for a public-facing website or serviceLook atevidence that weak protocols (older SSL, early TLS) are disabled and only current approved versions are enabledGoodis a recent third-party or tool-generated scan showing only approved protocols accepted
- Askhow the organisation decides when a high assurance cryptographic protocol is needed instead of a standard approved oneLook ata documented link between data sensitivity or classification and the protocol chosenGoodreferences the data's classification and names the specific high assurance product used
- Askrecords of how encryption certificates and protocol versions are kept currentLook atrenewal logs, automated update settings, and dates of the last reviewGoodshows certificates that have not expired and a routine process for keeping protocols up to date
- Asksuppliers and cloud providers to confirm what protocol protects data in transit to and from their serviceLook atwritten confirmation or contract clauses naming an AACP or high assurance protocolGoodis a signed statement or contract term specifying the approved protocol in use
Cross-framework mappings
How ISM-0469 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.20 | ISM-0469 requires that an ASD-Approved Cryptographic Protocol (or high assurance cryptographic protocol) is used to protect data when it ... | |
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.24 | ISM-0469 requires the use of ASD-Approved Cryptographic Protocols (or high assurance cryptographic protocols) to protect data communicate... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cryptography
See all Guidelines for cryptography controls, or browse the full ASD ISM library.