Skip to content
arrow_back
ISM-1059policyASD Information Security Manual (ISM)

Encrypt All Data Stored on Media Using ASD-Approved Cryptography

All data held on storage media must be encrypted using cryptography approved by the Australian Signals Directorate (ASD).

record_voice_over

Plain language

This control means every piece of information saved on your storage media (such as laptop hard drives, USB sticks, external drives, backup tapes and memory cards) must be scrambled using encryption that the Australian Signals Directorate (ASD), the government's cyber security agency, has approved. Encryption turns readable data into a coded form that no one can open without the right key. That way, if a device or drive is lost, stolen or thrown out, the information on it stays unreadable and protected.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

All data stored on media is encrypted using ASD-approved cryptography.
policyASD Information Security Manual (ISM)ISM-1059
priority_high

Why it matters

If data stored on media is not encrypted with ASD-approved cryptography, a lost or stolen laptop, USB stick or backup drive exposes readable sensitive information, causing a data breach.

settings

Operational notes

Re-check encryption coverage whenever new media or devices are added, and confirm the chosen cryptographic methods are still listed as ASD-approved as the Information Security Manual is updated.

build

Implementation tips

  • The IT team should turn on full-disk encryption (for example BitLocker on Windows or FileVault on macOS) on every laptop, desktop and server, choosing an encryption setting that uses an ASD-approved method such as AES (Advanced Encryption Standard).
  • The IT team should configure all USB sticks, external drives, backup tapes and memory cards so they are automatically encrypted before any data is written to them, blocking the use of unencrypted removable media.
  • A manager or IT lead should keep a written list that maps each type of storage media the organisation uses to the specific ASD-approved encryption product or setting protecting it, so nothing is left unencrypted.
  • The IT team should store and back up the encryption keys and recovery keys in a secure, separate location (such as a key management system or locked safe) so encrypted data can still be recovered if a device fails.
  • Procurement and IT staff should check the current ASD Information Security Manual and Evaluated Products list before buying or enabling any encryption tool, confirming the cryptographic algorithm is still ASD-approved.
fact_check

Audit / evidence tips

  • Aska list of all storage media types in use (laptops, servers, USB drives, backup media) and the encryption applied to eachLook atwhether every entry shows an ASD-approved algorithm such as AESGoodaccounts for all media with no unencrypted gaps
  • Askthe IT team to demonstrate encryption on a sample deviceLook atthe device settings or management console showing encryption is active and which algorithm is usedGoodshows full-disk encryption switched on and confirmed as ASD-approved
  • Askwhich specific cryptographic products or settings are used and how they were confirmed as ASD-approvedLook atreferences to the current ASD Information Security Manual or Evaluated Products listGoodcites the exact approved standard, not a vague claim
  • Askhow removable media like USB sticks and external drives are handledLook atpolicy and technical controls that force encryption on removable mediaGoodshows unencrypted removable media is blocked or automatically encrypted
  • Askhow encryption keys are managed and recoveredLook atevidence of secure key storage and a recovery processGoodshows keys are protected separately and data can be recovered without weakening the encryption
link

Cross-framework mappings

How ISM-1059 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 7.10ISM-1059 mandates encryption of all data stored on media as a fundamental security measure
handshakeSupports(1)expand_less
Annex A 5.33Annex A 5.33 requires protection of records against unauthorised access and unauthorised release as well as loss and falsification
extensionDepends on(1)expand_less
Annex A 8.24ISM-1059 requires encryption for all data on media, implying the need for effective cryptographic key management
linkRelated(1)expand_less
Annex A 8.1Annex A 8.1 requires organisations to protect information stored on, processed by, or accessible via user endpoint devices

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for media controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls