Skip to content
arrow_back
search
ISM-1059 policy ASD Information Security Manual (ISM)

Ensure All Data on Media is Encrypted

All data stored on devices must be secure and not readable to protect it from unauthorized access.

record_voice_over

Plain language

This control means that any data stored on devices such as computers, USB sticks, or external drives should be encrypted. This is crucial because if someone unauthorised gets their hands on these devices, they can't read or misuse the data, protecting sensitive information from being exposed.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

All data stored on media is encrypted.
policy ASD Information Security Manual (ISM) ISM-1059
priority_high

Why it matters

If data on media isn't encrypted, a stolen or lost device could expose sensitive info, leading to data breaches and reputational damage.

settings

Operational notes

Regularly verify encryption is enabled on removable media and endpoints; enforce full-disk encryption and block unencrypted USB storage where possible.

Mapping detail

Mapping

Direction

Controls