Encrypt Sensitive Data Over Public Networks
Mobile devices must encrypt sensitive data sent over public networks using approved cryptography.
Plain language
This control means that any sensitive information sent from mobile devices over public Wi-Fi, like at a cafe or airport, needs to be encrypted using safe methods approved by the Australian Signals Directorate (ASD). This is important because if your information isn't protected, it can be intercepted by others, leading to data theft and potential harm to your business.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for enterprise mobilitySection
Mobile Device ManagementOfficial control statement
Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
Why it matters
Failing to encrypt data on public networks can result in data breaches, leading to financial loss and damage to your reputation.
Operational notes
Consistently monitor mobile devices to ensure they maintain compliance with encryption standards, adapting policies and training as needed.
Implementation tips
- IT team should configure mobile devices to automatically use encryption when sending data over the internet. This can be done by ensuring all mobile apps use secure communication protocols.
- Managers should educate staff on the importance of using secure networks and ensuring their apps are updated to the latest versions, which often include security improvements.
- Procurement officers should ensure that devices purchased have the capability to support ASD-approved encryption standards, by checking with vendors before purchase.
- System administrators should regularly audit device settings to verify encryption protocols are in place and functioning correctly. This involves checking device settings or using management software to automate compliance checks.
- Training coordinators should arrange for regular training sessions for employees to understand what encryption is and why they must ensure their devices comply with these requirements.
Audit / evidence tips
- Askthe list of mobile devices used across the organisation: Check if the list matches the inventory of devices, including details about their encryption capabilities
- Look atspecifications about the encryption standards used and ASD approval detailsGoodpolicy clearly states which protocols are mandatory
- Asklogs or reports from mobile device management software: Review them for entries showing compliance with encryption settings. Good records show regular checks and any issues flagged and resolved
- Request training attendance records: Ensure staff involved in data handling have attended encryption and security training. Good records will have names, dates, and training details.
- Aska demonstration of encryption on a sample mobile device: Observe if the sample device complies with the policy and check encryption settings. Good demonstration shows secure configuration
Cross-framework mappings
How ISM-1085 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.24 | ISM-1085 requires mobile devices to encrypt sensitive or classified data when communicating over public network infrastructure | |
handshakeSupports(2)expand_less | ||
| Annex A 8.12 | ISM-1085 requires mobile devices to encrypt sensitive or classified data when communicated over public network infrastructure to reduce e... | |
| Annex A 8.20 | ISM-1085 requires mobile devices to encrypt sensitive or classified data when it is communicated over public network infrastructure | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Enterprise mobility
See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.