Encrypt All Data Stored on Media Using ASD-Approved Cryptography
All data held on storage media must be encrypted using cryptography approved by the Australian Signals Directorate (ASD).
Plain language
This control means every piece of information saved on your storage media (such as laptop hard drives, USB sticks, external drives, backup tapes and memory cards) must be scrambled using encryption that the Australian Signals Directorate (ASD), the government's cyber security agency, has approved. Encryption turns readable data into a coded form that no one can open without the right key. That way, if a device or drive is lost, stolen or thrown out, the information on it stays unreadable and protected.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
All data stored on media is encrypted using ASD-approved cryptography.
Why it matters
If data stored on media is not encrypted with ASD-approved cryptography, a lost or stolen laptop, USB stick or backup drive exposes readable sensitive information, causing a data breach.
Operational notes
Re-check encryption coverage whenever new media or devices are added, and confirm the chosen cryptographic methods are still listed as ASD-approved as the Information Security Manual is updated.
Implementation tips
- The IT team should turn on full-disk encryption (for example BitLocker on Windows or FileVault on macOS) on every laptop, desktop and server, choosing an encryption setting that uses an ASD-approved method such as AES (Advanced Encryption Standard).
- The IT team should configure all USB sticks, external drives, backup tapes and memory cards so they are automatically encrypted before any data is written to them, blocking the use of unencrypted removable media.
- A manager or IT lead should keep a written list that maps each type of storage media the organisation uses to the specific ASD-approved encryption product or setting protecting it, so nothing is left unencrypted.
- The IT team should store and back up the encryption keys and recovery keys in a secure, separate location (such as a key management system or locked safe) so encrypted data can still be recovered if a device fails.
- Procurement and IT staff should check the current ASD Information Security Manual and Evaluated Products list before buying or enabling any encryption tool, confirming the cryptographic algorithm is still ASD-approved.
Audit / evidence tips
- Aska list of all storage media types in use (laptops, servers, USB drives, backup media) and the encryption applied to eachLook atwhether every entry shows an ASD-approved algorithm such as AESGoodaccounts for all media with no unencrypted gaps
- Askthe IT team to demonstrate encryption on a sample deviceLook atthe device settings or management console showing encryption is active and which algorithm is usedGoodshows full-disk encryption switched on and confirmed as ASD-approved
- Askwhich specific cryptographic products or settings are used and how they were confirmed as ASD-approvedLook atreferences to the current ASD Information Security Manual or Evaluated Products listGoodcites the exact approved standard, not a vague claim
- Askhow removable media like USB sticks and external drives are handledLook atpolicy and technical controls that force encryption on removable mediaGoodshows unencrypted removable media is blocked or automatically encrypted
- Askhow encryption keys are managed and recoveredLook atevidence of secure key storage and a recovery processGoodshows keys are protected separately and data can be recovered without weakening the encryption
Cross-framework mappings
How ISM-1059 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 7.10 | ISM-1059 mandates encryption of all data stored on media as a fundamental security measure | |
handshakeSupports(1)expand_less | ||
| Annex A 5.33 | Annex A 5.33 requires protection of records against unauthorised access and unauthorised release as well as loss and falsification | |
extensionDepends on(1)expand_less | ||
| Annex A 8.24 | ISM-1059 requires encryption for all data on media, implying the need for effective cryptographic key management | |
linkRelated(1)expand_less | ||
| Annex A 8.1 | Annex A 8.1 requires organisations to protect information stored on, processed by, or accessible via user endpoint devices | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Media
See all Guidelines for media controls, or browse the full ASD ISM library.