Use AACA or High Assurance Algorithms for Data Encryption
Ensure that data at rest is encrypted using strong cryptographic algorithms like AACA for high security.
Plain language
Using strong cryptographic algorithms like Advanced Encryption Standard (AES) protects your stored data from unauthorised access. If data isn't well-protected, it could be stolen or altered, leading to potential financial loss or reputational damage.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cryptographySection
Cryptographic AlgorithmsOfficial control statement
An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.
Why it matters
Poor encryption can lead to severe data breaches, exposing sensitive business or customer information, thus causing financial and reputational harm.
Operational notes
Regularly update encryption practices as threats evolve, ensuring all team members understand their role in protecting data using approved algorithms.
Implementation tips
- The IT team should identify which data is sensitive and requires encryption. They can start by reviewing the types of data stored and prioritising anything that could harm the business if leaked.
- Managers should brief staff on the importance of encrypting data at rest and ensure they know how to handle and store sensitive data correctly. This could involve setting clear guidelines and regular team check-ins to reinforce practices.
- Procurement teams should ensure that any new software or services purchased support high assurance encryption methods. They should verify this by checking documentation or seeking assurances from vendors.
- System owners should coordinate with IT to apply strong cryptographic algorithms to all stored data. This might involve setting up routines or scripts that automatically encrypt data as it is saved.
- The IT security team should conduct regular audits of existing systems to verify that data remains encrypted with strong algorithms. They can use tools to scan systems and confirm encryption settings and check logs for any issues.
Audit / evidence tips
- Askencryption policy documents: Request policies that define how and when encryption must be applied to data at restLook atthe inclusion of strong algorithms like AESGoodshould have a clear policy listing approved algorithms
- Askthe latest report summarising encryption complianceLook atsystem names and encryption statusGoodA report showing all systems compliant with encryption policies
- AskIT team training records: Verify documentation showing that team members have been trained in encryption techniquesLook atcourse completion certificates or signed attendance recordsGoodwill show recent, relevant training for key staff
- Askto see how data is encrypted on a system. Ensure strong algorithms are being usedGoodwould show data being automatically encrypted without manual intervention
- Askvendor documentation: When third-party services are involved, request their encryption compliance documentsLook atproof of high assurance algorithm useGoodwill be certified documentation showing their encryption standards
Cross-framework mappings
How ISM-1080 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 8.24 | ISM-1080 requires that when encrypting media (data at rest), organisations use an ASD-Approved Cryptographic Algorithm (AACA) or other hi... | |
handshakeSupports(2)expand_less | ||
| Annex A 5.33 | ISM-1080 requires that encryption of media uses an AACA or high assurance algorithm, reducing the likelihood that stored records can be a... | |
| Annex A 8.1 | ISM-1080 requires use of ASD-approved/high assurance algorithms when encrypting media to protect data at rest from unauthorised access | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cryptography
See all Guidelines for cryptography controls, or browse the full ASD ISM library.