Encrypt Database and Web Server Communications
Data exchanged between database and web servers must use approved encryption methods.
Plain language
This control ensures that any data exchanged between your web servers and database servers is securely encrypted. If this isn't done, sensitive information like customer data or company secrets could be intercepted by cybercriminals, leading to financial and reputational damage.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for database systemsSection
Database ServersOfficial control statement
Data communicated between database servers and web servers is encrypted using Australian Signals Directorate-approved cryptography.
Why it matters
Unencrypted data between servers could be intercepted, leading to breaches of confidential information and damaging trust with customers.
Operational notes
Regularly review and renew encryption certificates, and ensure team members understand and follow current ASD-approved encryption practices.
Implementation tips
- The IT team should select encryption methods approved by the Australian Signals Directorate (ASD). Check the latest ASD guidelines to ensure the encryption technology is current and complies with standards.
- System owners need to work with their IT team to ensure all data communications between web and database servers are encrypted. They can verify this by ensuring encryption settings are correctly enabled on all relevant systems.
- Managers should ensure regular staff training is conducted to raise awareness about the importance of encrypting data. Training should cover how encryption protects sensitive information from unauthorised access.
- The IT team should regularly update encryption certificates to prevent expired certificates from causing data vulnerabilities. Set reminders for certificate renewal and ensure system configurations are adjusted accordingly.
- System administrators should routinely monitor server logs for any unencrypted data transmissions. They should configure alerts to detect and respond to any anomalies or failures in encryption protocols.
Audit / evidence tips
- Askdocumentation on encryption methods usedLook atwhether the methods are ASD-approvedGoodis up-to-date records referencing ASD guidelines
- Goodresult shows active encryption settings matching ASD standards
- Askto see records of staff training sessions about data encryptionLook atattendance records and training materials. Good evidence would show recent training relevant to the control being discussed
- Goodshows few, if any, unaddressed issues in logs
- Askdetails on encryption certificate management processesLook atexpiry dates and how renewal is managedGoodprocess includes reminders for renewals well before expiry dates
Cross-framework mappings
How ISM-1277 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
| Annex A 5.14 | ISM-1277 requires that data communicated between database servers and web servers is encrypted to protect it in transit | |
| Annex A 8.24 | ISM-1277 requires encryption of data in transit specifically between web servers and database servers | |
handshakeSupports(2)expand_less | ||
| Annex A 8.9 | ISM-1277 requires encryption for traffic between database servers and web servers to prevent interception or tampering in transit | |
| Annex A 8.22 | ISM-1277 requires that communications between web servers and database servers are encrypted, typically using secure channels such as TLS | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Database systems
See all Guidelines for database systems controls, or browse the full ASD ISM library.