Skip to content
arrow_back
search
ISM-0490 policy ASD Information Security Manual (ISM)

Ensure S/MIME 3.0 or Later is Used

Only use S/MIME version 3.0 or later for secure email communications.

record_voice_over

Plain language

Imagine sending an important letter through the post. You'd want to make sure only the person it's meant for can open it, right? Using the right version of S/MIME (3.0 or later) for your emails is like sealing that letter - it protects the contents so only the intended person can read it. If you use an older version, it's like sending your letter with a faulty lock, and others could read or even change your message.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Versions of S/MIME earlier than S/MIME version 3.0 are not used for S/MIME connections.
policy ASD Information Security Manual (ISM) ISM-0490
priority_high

Why it matters

Using S/MIME versions earlier than 3.0 can weaken email protection, enabling message interception, downgrade attacks, or tampering.

settings

Operational notes

Configure mail clients/servers to require S/MIME v3.0+ only; disable older S/MIME options and confirm in client/server settings.

Mapping detail

Mapping

Direction

Controls