Skip to content
arrow_back
ISM-1085policyASD Information Security Manual (ISM)

Encrypt Sensitive Data Over Public Networks

Mobile devices must encrypt sensitive data sent over public networks using approved cryptography.

record_voice_over

Plain language

This control means that any sensitive information sent from mobile devices over public Wi-Fi, like at a cafe or airport, needs to be encrypted using safe methods approved by the Australian Signals Directorate (ASD). This is important because if your information isn't protected, it can be intercepted by others, leading to data theft and potential harm to your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Mobile devices encrypt all sensitive or classified data communicated over public network infrastructure using ASD-approved cryptography.
policyASD Information Security Manual (ISM)ISM-1085
priority_high

Why it matters

Failing to encrypt data on public networks can result in data breaches, leading to financial loss and damage to your reputation.

settings

Operational notes

Consistently monitor mobile devices to ensure they maintain compliance with encryption standards, adapting policies and training as needed.

build

Implementation tips

  • IT team should configure mobile devices to automatically use encryption when sending data over the internet. This can be done by ensuring all mobile apps use secure communication protocols.
  • Managers should educate staff on the importance of using secure networks and ensuring their apps are updated to the latest versions, which often include security improvements.
  • Procurement officers should ensure that devices purchased have the capability to support ASD-approved encryption standards, by checking with vendors before purchase.
  • System administrators should regularly audit device settings to verify encryption protocols are in place and functioning correctly. This involves checking device settings or using management software to automate compliance checks.
  • Training coordinators should arrange for regular training sessions for employees to understand what encryption is and why they must ensure their devices comply with these requirements.
fact_check

Audit / evidence tips

  • Askthe list of mobile devices used across the organisation: Check if the list matches the inventory of devices, including details about their encryption capabilities
  • Look atspecifications about the encryption standards used and ASD approval detailsGoodpolicy clearly states which protocols are mandatory
  • Asklogs or reports from mobile device management software: Review them for entries showing compliance with encryption settings. Good records show regular checks and any issues flagged and resolved
  • Request training attendance records: Ensure staff involved in data handling have attended encryption and security training. Good records will have names, dates, and training details.
  • Aska demonstration of encryption on a sample mobile device: Observe if the sample device complies with the policy and check encryption settings. Good demonstration shows secure configuration
link

Cross-framework mappings

How ISM-1085 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.24ISM-1085 requires mobile devices to encrypt sensitive or classified data when communicating over public network infrastructure
handshakeSupports(2)expand_less
Annex A 8.12ISM-1085 requires mobile devices to encrypt sensitive or classified data when communicated over public network infrastructure to reduce e...
Annex A 8.20ISM-1085 requires mobile devices to encrypt sensitive or classified data when it is communicated over public network infrastructure

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for enterprise mobility controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls