Skip to content
arrow_back
ISM-1080policyASD Information Security Manual (ISM)

Use AACA or High Assurance Algorithms for Data Encryption

Ensure that data at rest is encrypted using strong cryptographic algorithms like AACA for high security.

record_voice_over

Plain language

Using strong cryptographic algorithms like Advanced Encryption Standard (AES) protects your stored data from unauthorised access. If data isn't well-protected, it could be stolen or altered, leading to potential financial loss or reputational damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

An AACA or high assurance cryptographic algorithm is used when encrypting data at rest.
policyASD Information Security Manual (ISM)ISM-1080
priority_high

Why it matters

Poor encryption can lead to severe data breaches, exposing sensitive business or customer information, thus causing financial and reputational harm.

settings

Operational notes

Regularly update encryption practices as threats evolve, ensuring all team members understand their role in protecting data using approved algorithms.

build

Implementation tips

  • The IT team should identify which data is sensitive and requires encryption. They can start by reviewing the types of data stored and prioritising anything that could harm the business if leaked.
  • Managers should brief staff on the importance of encrypting data at rest and ensure they know how to handle and store sensitive data correctly. This could involve setting clear guidelines and regular team check-ins to reinforce practices.
  • Procurement teams should ensure that any new software or services purchased support high assurance encryption methods. They should verify this by checking documentation or seeking assurances from vendors.
  • System owners should coordinate with IT to apply strong cryptographic algorithms to all stored data. This might involve setting up routines or scripts that automatically encrypt data as it is saved.
  • The IT security team should conduct regular audits of existing systems to verify that data remains encrypted with strong algorithms. They can use tools to scan systems and confirm encryption settings and check logs for any issues.
fact_check

Audit / evidence tips

  • Askencryption policy documents: Request policies that define how and when encryption must be applied to data at restLook atthe inclusion of strong algorithms like AESGoodshould have a clear policy listing approved algorithms
  • Askthe latest report summarising encryption complianceLook atsystem names and encryption statusGoodA report showing all systems compliant with encryption policies
  • AskIT team training records: Verify documentation showing that team members have been trained in encryption techniquesLook atcourse completion certificates or signed attendance recordsGoodwill show recent, relevant training for key staff
  • Askto see how data is encrypted on a system. Ensure strong algorithms are being usedGoodwould show data being automatically encrypted without manual intervention
  • Askvendor documentation: When third-party services are involved, request their encryption compliance documentsLook atproof of high assurance algorithm useGoodwill be certified documentation showing their encryption standards
link

Cross-framework mappings

How ISM-1080 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 8.24ISM-1080 requires that when encrypting media (data at rest), organisations use an ASD-Approved Cryptographic Algorithm (AACA) or other hi...
handshakeSupports(2)expand_less
Annex A 5.33ISM-1080 requires that encryption of media uses an AACA or high assurance algorithm, reducing the likelihood that stored records can be a...
Annex A 8.1ISM-1080 requires use of ASD-approved/high assurance algorithms when encrypting media to protect data at rest from unauthorised access

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cryptography controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls