Skip to content
arrow_back
search
ISM-1552 policy ASD Information Security Manual (ISM)

Secure Web Content with HTTPS Only

Ensure all web content is delivered over a secure HTTPS connection.

record_voice_over

Plain language

This control means that any content from your website must be delivered through a secure connection, specifically HTTPS, which protects data as it moves between your website and its visitors. Using HTTPS is important because it keeps sensitive information, like personal details and payment data, safe from hackers; if not done, your customers could be at risk of identity theft or fraud.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

All web application content is offered exclusively using HTTPS.
policy ASD Information Security Manual (ISM) ISM-1552
priority_high

Why it matters

Without HTTPS, credentials and session cookies can be intercepted or altered in transit, leading to account compromise, data breaches and reputational damage.

settings

Operational notes

Enforce HTTPS-only via HSTS and redirects; monitor TLS certificate expiry; and regularly scan for any HTTP resources/mixed content across web pages and APIs.

Mapping detail

Mapping

Direction

Controls