Skip to content
arrow_back
search
ISM-1369 policy ASD Information Security Manual (ISM)

Ensure TLS Connections Use AES-GCM Encryption

Use AES-GCM to securely encrypt information sent over TLS connections.

record_voice_over

Plain language

This control is about making sure the information you send over the internet is hard for others to read, by using a type of encryption called AES-GCM. This matters because if your data isn't properly protected, cybercriminals could intercept and misuse sensitive information, such as customer details or financial data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

AES-GCM is used for encryption of TLS connections.
policy ASD Information Security Manual (ISM) ISM-1369
priority_high

Why it matters

If TLS does not use AES-GCM, weaker ciphers may be negotiated, increasing the risk of traffic decryption or tampering and data exposure.

settings

Operational notes

Regularly review server/client TLS cipher suites to ensure AES-GCM is enabled and preferred; monitor config changes and disable legacy CBC/RC4 suites.

Mapping detail

Mapping

Direction

Controls