Skip to content
arrow_back
search
ISM-1277 policy ASD Information Security Manual (ISM)

Encrypt Data Between Database and Web Servers

Ensure data between database and web servers is kept secure by encrypting it.

record_voice_over

Plain language

This control means that the information sent between your database and website needs to be scrambled so it can't be read by anyone except those authorised to see it. It's important because if someone can intercept this information, they could see sensitive customer data, financial details, or even damage your reputation if the data is exposed.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Data communicated between database servers and web servers is encrypted.
policy ASD Information Security Manual (ISM) ISM-1277
priority_high

Why it matters

If database-to-web traffic is not encrypted, attackers can intercept credentials and query results, causing data exposure and breach reporting.

settings

Operational notes

Enforce TLS (preferably mTLS) on DB connections from web servers, validate certificates, and alert on any plaintext DB ports or failed TLS handshakes.

Mapping detail

Mapping

Direction

Controls