Skip to content
arrow_back
search
ISM-1139 policy ASD Information Security Manual (ISM)

Require Latest Version of TLS for Security

Ensure only the latest TLS version is used to secure connections.

record_voice_over

Plain language

This control is about making sure that when information is sent over the internet, it's kept safe and private. We do this by using the latest version of a security protocol called TLS (Transport Layer Security). If we don't, hackers could intercept and access sensitive information like credit card numbers or personal details.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Only the latest version of TLS is used for TLS connections.
policy ASD Information Security Manual (ISM) ISM-1139
priority_high

Why it matters

Allowing non-latest TLS versions (e.g., TLS 1.0/1.1) can enable downgrade attacks and weaker ciphers, exposing data in transit to compromise.

settings

Operational notes

Verify servers/clients only negotiate the latest TLS version supported; disable TLS 1.0/1.1, restrict cipher suites, and regularly test with TLS scanners.

Mapping detail

Mapping

Direction

Controls