Skip to content
arrow_back
ISM-0869policyASD Information Security Manual (ISM)

Encrypt Storage on Mobile Devices

Mobile devices must use ASD-approved encryption for both internal and external storage.

record_voice_over

Plain language

This control ensures that mobile phones and tablets use government-approved techniques to lock away their data. Without proper encryption, if a device is lost or stolen, sensitive information could be at risk of exposure, leading to privacy breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Mobile devices encrypt their internal storage and any removable media using ASD-approved cryptography.
policyASD Information Security Manual (ISM)ISM-0869
priority_high

Why it matters

Without encryption, lost or stolen mobile devices may lead to data breaches, endangering sensitive information and causing financial and reputational damage.

settings

Operational notes

Regularly update encryption policies and tools to reflect any new standards or threats to ensure ongoing protection of stored data.

build

Implementation tips

  • The IT team should ensure all company-issued mobile devices have encryption enabled on their internal storage. This can be done by checking the device settings and confirming encryption status.
  • Procurement should verify that any new devices support ASD-approved encryption before purchasing. They can do this by consulting device specifications or seeking assurances from suppliers.
  • Managers should request regular checks from the IT team to ensure that any removable storage, like SD cards, is also using proper encryption methods. This can be part of routine device audits.
  • HR should educate employees about the importance of using encryption and how it protects company data. This can be included as part of the induction program or regular cybersecurity training sessions.
  • The IT team should use mobile device management (MDM) tools to enforce encryption policies. These tools can ensure devices remain compliant with encryption standards and alert the team if issues arise.
fact_check

Audit / evidence tips

  • Askthe device encryption policy document: Request the written policy outlining how and why encryption is applied to devicesLook atspecifics on encryption standards and enforcement mechanismsGoodComprehensive policy with references to ASD-approved encryption
  • Aska recent encryption status report: Request a report generated by the IT team or MDM tool showing current encryption status of all devicesLook atthe report for compliance with encryption policiesGoodreport shows all devices are compliant with no exceptions
  • Asktraining records: Request records showing employee training on the importance of encryptionLook atattendance records and training materialsGoodDocumented training with employee attendance and up-to-date materials
  • Askprocurement checklists: Request documentation showing the process for verifying device compliance before purchaseLook atitems related to encryption capability assessmentsGoodDocumented checks confirming all devices have necessary encryption support
  • Askan audit trail from the MDM system: Request logs that show when devices were checked for encryption complianceLook atrecent entries indicating monitoring of this controlGoodLogs showing regular checks with no outstanding compliance issues
link

Cross-framework mappings

How ISM-0869 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(1)expand_less
Annex A 8.24ISM-0869 involves encrypting storage on mobile devices, a specific application of cryptography
linkRelated(1)expand_less
Annex A 8.1Annex A 8.1 requires protection of information stored on and accessible via user endpoint devices

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls