Skip to content
arrow_back
search
ISM-1840 policy ASD Information Security Manual (ISM)

Prevent Reversible Encryption of User Passwords

User account passwords must not be stored in a way that allows them to be easily decrypted.

record_voice_over

Plain language

This control is about making sure that user passwords are stored in a way that they can't be easily deciphered, which means avoiding methods where passwords can be undone into plain text. This matters because if passwords are stored insecurely, someone who gains access to them can easily use or misuse user accounts, leading to data breaches, financial loss, or damage to the organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User account passwords do not use reversible encryption.
policy ASD Information Security Manual (ISM) ISM-1840
priority_high

Why it matters

If passwords are stored with reversible encryption, a breach could expose passwords and enable credential reuse and account takeover across systems.

settings

Operational notes

Regularly confirm password storage uses strong one-way hashing (e.g., bcrypt/Argon2) with unique salts, and audit systems to ensure no reversible encryption is enabled.

Mapping detail

Mapping

Direction

Controls