Skip to content
arrow_back
search
ISM-0675 policy ASD Information Security Manual (ISM)

Ensure Data Exports are Digitally Signed

Data from SECRET and TOP SECRET systems must be signed by a trusted source before export.

record_voice_over

Plain language

When sensitive data needs to be moved from secure systems, it's crucial that this data is 'signed' by a trusted source to confirm it hasn't been tampered with. This is like getting a stamped seal of authenticity, ensuring that what you send is exactly what you meant to, and helps prevent leaks and misuse of sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Aug 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Data authorised for export from SECRET and TOP SECRET systems is digitally signed by a trustworthy source.
policy ASD Information Security Manual (ISM) ISM-0675
priority_high

Why it matters

If SECRET/TOP SECRET exports are not digitally signed, recipients cannot verify integrity or source, enabling tampering and potentially compromising national security.

settings

Operational notes

Digitally sign all SECRET/TOP SECRET exports with trusted keys; validate signatures on receipt and manage certificate/keys to maintain a trustworthy signing source.

Mapping detail

Mapping

Direction

Controls