Skip to content
arrow_back
search
ISM-1293 policy ASD Information Security Manual (ISM)

Decryption of Files for Content Filtering

Files are decrypted at gateways to ensure they're safe before passing through.

record_voice_over

Plain language

This control is about making sure that any files coming into or leaving your organisation are safe by decrypting them at your gateways to check their contents. It matters because if you don't check these files, harmful content could enter your systems or sensitive information could leave without your knowledge, leading to data breaches or losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Encrypted files imported or exported via gateways or CDSs are decrypted in order to undergo content filtering checks.
policy ASD Information Security Manual (ISM) ISM-1293
priority_high

Why it matters

Without decrypting files for content filtering, malicious payloads can traverse gateways/CDSs unnoticed, causing data breaches and information leakage.

settings

Operational notes

Configure gateways/CDSs to decrypt inbound and outbound encrypted files before content filtering, and maintain key/certificate handling so inspection remains effective.

build

Implementation tips

  • Managers should ensure policies are in place so that all encrypted files passing through your organisation's gateways are decrypted. This can be done by writing clear procedures for the IT team to follow, stating that decryption is mandatory before any file passes through.
  • IT teams should set up the necessary software and hardware at gateways to automatically decrypt files. This involves selecting software that can integrate with existing systems and setting it up to ensure all incoming and outgoing files are decrypted and scanned.
  • System administrators should regularly monitor and update decryption tools to ensure they handle the latest types of encryption. They can schedule routine checks to install updates and patches that keep the tools effective against new encryption methods.
  • Compliance officers should conduct regular training sessions with staff to ensure they understand why decrypted files are checked. This could involve workshops explaining the risks of unfiltered files and how to spot concerning signs.
  • Security officers should create a system for securely storing logs of decrypted files to track when and who decrypted them. They can set up an organised filing process, ensuring only authorised staff have access to these logs.
fact_check

Audit / evidence tips

  • AskThe decryption policy document: Request the document outlining procedures for decrypting files at gateways GoodIncludes a detailed procedure with responsible personnel identified
  • GoodShows logs that are regularly maintained and accurately record all decryption activities
  • AskA demonstration of the tool used for decryption: Look to see the tool in action, including how it integrates and works in real-time GoodDemonstration shows that all types of encrypted files are correctly decrypted
  • GoodRecord shows that staff training is frequent and comprehensive, with clear indications of increased awareness
  • AskTo see update and maintenance logs for decryption tools GoodIncludes a consistent schedule of maintenance and actions taken to address any detected issues
link

Cross-framework mappings

How ISM-1293 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

Control Notes Details
handshake Supports (1) expand_less
Annex A 8.12 ISM-1293 requires encrypted files passing through gateways or CDSs to be decrypted so they can undergo content filtering checks

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

Mapping detail

Mapping

Direction

Controls