Skip to content
arrow_back
search
ISM-0702 policy ASD Information Security Manual (ISM)

Using Cryptographic Sanitisation on Mobile Devices

Ensures cryptographic keys are erased on SECRET or TOP SECRET devices in emergencies.

record_voice_over

Plain language

If you have a mobile device that contains highly sensitive information, like national security secrets, it’s vital to be able to quickly erase encryption keys in an emergency. This is important because keeping these keys on the device means someone could unlock and access that sensitive information if they got their hands on it.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

If a cryptographic zeroise or sanitise function is provided for cryptographic keys on a SECRET or TOP SECRET mobile device, the function is used as part of mobile device emergency sanitisation processes and procedures.
policy ASD Information Security Manual (ISM) ISM-0702
priority_high

Why it matters

Failing to zeroise keys swiftly can expose SECRET/TOP SECRET data if a mobile device is lost or stolen, risking national security.

settings

Operational notes

Regularly test the cryptographic zeroise/sanitise function on the device and ensure it is embedded in emergency sanitisation procedures for rapid use.

Mapping detail

Mapping

Direction

Controls