Encrypt Network Data with ASD-Approved Cryptography
Ensure all data over networks is encrypted using approved methods.
Plain language
This control ensures that all the data sent over networks is scrambled so that only people who are meant to see it can read it. This is important because if data isn't protected like this, anyone snooping around on the network could easily steal sensitive information, like customer details or business secrets.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
All data communicated over network infrastructure is encrypted using ASD-approved cryptography.
Why it matters
Without encryption, sensitive information could be intercepted, leading to data breaches and loss of customer trust, harming business reputation and finances.
Operational notes
Regularly review and update the encryption standards based on ASD latest guidelines to ensure ongoing network data protection.
Implementation tips
- IT team should ensure that all data transmitted over the network is encrypted. This involves using software and tools that apply Australian Signals Directorate (ASD)-approved cryptographic methods to scramble data during transmission.
- Procurement should work with the IT department to purchase network devices and software that support ASD-approved encryption standards. They should check product specifications and seek vendor confirmations.
- Office managers should collaborate with IT staff to conduct regular training sessions for employees on the importance of network security and the role of encryption. Use simple analogies to explain how encryption protects data.
- AskIT to configure tools like Virtual Private Networks (VPNs) that encrypt data traffic for remote workers
- System owners should conduct periodic audits to ensure compliance with encryption policies. This can involve reviewing security settings with IT to confirm data encryption protocols are properly set up.
Audit / evidence tips
- Askthe network encryption policy documentLook atthe specified encryption methods and whether they are ASD-approvedGoodclear examples of approved cryptographic protocols
- Gooddetailed logs showing encryption settings being active and compliant
- Asktraining records on encryption practicesLook atattendance and topics coveredGoodwell-documented sessions with a focus on explaining the need for encryption
- Look atevidence from IT that data is sent securelyGoodIT showing data capture from a packet inspector displaying encrypted data
- Look athow encryption compliance is assessedGoodan audit report highlighting areas of compliance and any actions to address gaps
Cross-framework mappings
How ISM-1781 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.20 | ISM-1781 requires all data communicated over network infrastructure to be encrypted to protect confidentiality and reduce interception risk | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Networking
See all Guidelines for networking controls, or browse the full ASD ISM library.