Skip to content
arrow_back
search
ISM-1553 policy ASD Information Security Manual (ISM)

Disable TLS Compression for Security

TLS connections should not use compression to prevent security risks.

record_voice_over

Plain language

This control is about turning off a feature called TLS compression in secure online connections. It matters because if TLS compression is on, it might let cyber attackers steal sensitive information like passwords or credit card numbers by exploiting weaknesses in the way data is compressed. This could lead to data breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

TLS compression is disabled for TLS connections.
policy ASD Information Security Manual (ISM) ISM-1553
priority_high

Why it matters

If TLS compression is used, attackers might exploit CRIME-like vulnerabilities to steal sensitive data, risking financial and reputational damage.

settings

Operational notes

Regularly verify TLS configuration does not allow compression (e.g., openssl/nmap scans) after patches or upgrades, as some updates can re-enable it.

Mapping detail

Mapping

Direction

Controls