Skip to content
arrow_back
ISM-1984policyASD Information Security Manual (ISM)

Encrypt Event Logs in Transit Using ASD Cryptography

Event logs must be encrypted with approved methods before being sent to a central logging system.

record_voice_over

Plain language

This control means making sure that as your organisation's event logs travel from various sources to a central system, they are encrypted using methods approved by the Australian Signals Directorate (ASD). This matters because if logs aren't encrypted, sensitive data could be intercepted and misused by cybercriminals.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.
policyASD Information Security Manual (ISM)ISM-1984
priority_high

Why it matters

If logs aren't encrypted in transit, sensitive information could be intercepted, leading to data breaches and reputational damage.

settings

Operational notes

Ensure encryption protocols are current and consistent across all systems. Regularly review ASD guidelines for any updates.

build

Implementation tips

  • IT team should ensure all event logs sent over the internet are encrypted. They can do this by setting up secure connections using ASD-approved encryption methods like Transport Layer Security (TLS).
  • System administrators should regularly review and update the encryption protocols. Check manuals and online resources from ASD for the latest guidelines on encryption standards.
  • Managers should schedule training sessions for staff on the importance of encrypting event logs. Use simple training materials that explain what event logs are and why protecting them in transit is critical.
  • Procurement should verify that any new logging systems or tools support ASD-approved encryption. Request confirmation from vendors that their products meet these standards before purchase.
  • The compliance officer should document the encryption process in a security policy. This should include the encryption methods used, who is responsible for implementation, and how often it's reviewed.
fact_check

Audit / evidence tips

  • Askthe network security policy: Request the document that outlines how event log data is protected during transmission
  • Look atthe encryption configuration settings: Verify that ASD-approved protocols like TLS are enabled
  • GoodA documented policy showing encryption standards, settings for TLS in network configurations, and personnel responsible for compliance
  • Askthe list of log sources and destinations: This should show where logs originate and where they are sent within the organisation
  • Look atthe log transport pathway documentation: Check it details encrypted pathways and methods in use
  • GoodDocumentation showing log sources/destinations, encryption methods, and periodic reviews by the IT team
  • Aska training schedule: Ensure there are regular sessions on encryption practices
  • Look atthe training materials and attendance records: Confirm they cover ASD-approved encryption methods
  • GoodCurrent training materials and participant lists showing regular training sessions
  • Askabout the vendor selection process for logging tools: Inquire if ASD-approved encryption was a requirement
  • Look atpurchase documents for new logging tools: These should specify encryption standards were a criteria
  • GoodDocumentation of vendor assessments showing compliance with encryption standards at the time of purchase
link

Cross-framework mappings

How ISM-1984 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.24ISM-1984 requires a specific cryptographic use case: encrypt event log traffic while it is in transit to a centralised logging facility
handshakeSupports(3)expand_less
Annex A 5.28ISM-1984 requires event logs to be encrypted in transit to a centralised logging facility, helping preserve the integrity and confidentia...
Annex A 8.15ISM-1984 requires that event logs forwarded to a centralised event logging facility are encrypted in transit to protect them against inte...
Annex A 8.20ISM-1984 requires encryption in transit for event logs sent over networks to a centralised event logging facility, directly reducing the ...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for security assurance controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls