Skip to content
arrow_back
search
ISM-0547 policy ASD Information Security Manual (ISM)

Secure Protocols for Video and IP Telephony

Video and IP calls must use secure protocols to keep communications private and safe.

record_voice_over

Plain language

This control is about making sure that the video and voice calls your organisation makes online are secure. If the protocols used aren't secure, sensitive information could be stolen or conversations could be intercepted by unauthorised people.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 May 2026

E8 maturity levels

N/A

Official control statement

Video conferencing and IP telephony calls are conducted using a secure real-time transport protocol.
policy ASD Information Security Manual (ISM) ISM-0547
priority_high

Why it matters

Unsecure video and IP calls risk data breaches through eavesdropping, leading to potential loss of sensitive information or reputational damage.

settings

Operational notes

Audit video/IP telephony to enforce SRTP/DTLS-SRTP, disable insecure RTP, and verify encryption settings remain current after updates or changes.

build

Implementation tips

  • Organisation managers should prioritise the use of secure communication software. Ensure the software for video calls or IP telephony is configured to employ secure protocols like Secure Real-time Transport Protocol (SRTP) and these settings are checked regularly.
  • IT teams should update and patch video conferencing and telephony applications regularly. Plan for updates by scheduling checks weekly and consult vendor update notices to keep security features current.
  • HR should train staff on the importance of secure communications. Conduct workshops to explain why using secure protocols is necessary and how to ensure their systems are set up correctly before starting a call.
  • System administrators should regularly review system logs for any unusual activities in communication applications. Set a routine to analyse logs weekly for failed access attempts or unauthorised usage, indicating potential security breaches.
fact_check

Audit / evidence tips

  • AskNetwork configuration documents: Request documentation showing the communication applications' network setup GoodDocument will clearly indicate active secure protocols
  • AskTo review the software update logs GoodLog will show consistent updates, especially of security patches, occurring within a reasonable timeframe following release
  • AskVendor certifications or agreements: These should outline the security guarantees of the communication software GoodWill include a certificate or vendor statement confirming compliance
  • AskTo see staff training records: Review records for training sessions about secure communication usage GoodIncludes recent attendance records, showing most of the relevant staff attended training within the past year
  • AskLogs of communication sessions: Review how logs are monitored for security GoodLog shows no unusual activities or flags any suspicious patterns that were followed up on appropriately
link

Cross-framework mappings

How ISM-0547 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

link_off

No cross-framework mappings recorded yet.

Mapping detail

Mapping

Direction

Controls