Skip to content
arrow_back
search
ISM-1770 policy ASD Information Security Manual (ISM)

Utilise Strong AES Encryption Algorithms

When encrypting with AES, use stronger versions like AES-192 or preferably AES-256 for better security.

record_voice_over

Plain language

This control is about using strong encryption to protect your data when it is being stored or sent over the internet. By choosing a stronger form of encryption like AES-256, you make it much harder for hackers to access your sensitive information. If you don't do this, your data could be stolen, leading to financial loss, reputational damage, or privacy breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using AES for encryption, AES-192 or AES-256 is used, preferably AES-256.
policy ASD Information Security Manual (ISM) ISM-1770
priority_high

Why it matters

Using weak AES encryption can expose sensitive data to breaches, resulting in financial loss and eroded trust.

settings

Operational notes

Regularly audit systems and crypto libraries to ensure AES-256 (or at least AES-192) is enforced for all AES use, and block any AES-128 configurations.

Mapping detail

Mapping

Direction

Controls