Encrypt Event Logs in Transit Using ASD Cryptography
Event logs must be encrypted with approved methods before being sent to a central logging system.
Plain language
This control means making sure that as your organisation's event logs travel from various sources to a central system, they are encrypted using methods approved by the Australian Signals Directorate (ASD). This matters because if logs aren't encrypted, sensitive data could be intercepted and misused by cybercriminals.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for security assuranceSection
Security MonitoringOfficial control statement
Event logs sent to a centralised event logging facility are encrypted in transit using Australian Signals Directorate (ASD)-approved cryptography.
Why it matters
If logs aren't encrypted in transit, sensitive information could be intercepted, leading to data breaches and reputational damage.
Operational notes
Ensure encryption protocols are current and consistent across all systems. Regularly review ASD guidelines for any updates.
Implementation tips
- IT team should ensure all event logs sent over the internet are encrypted. They can do this by setting up secure connections using ASD-approved encryption methods like Transport Layer Security (TLS).
- System administrators should regularly review and update the encryption protocols. Check manuals and online resources from ASD for the latest guidelines on encryption standards.
- Managers should schedule training sessions for staff on the importance of encrypting event logs. Use simple training materials that explain what event logs are and why protecting them in transit is critical.
- Procurement should verify that any new logging systems or tools support ASD-approved encryption. Request confirmation from vendors that their products meet these standards before purchase.
- The compliance officer should document the encryption process in a security policy. This should include the encryption methods used, who is responsible for implementation, and how often it's reviewed.
Audit / evidence tips
- Askthe network security policy: Request the document that outlines how event log data is protected during transmission
- Look atthe encryption configuration settings: Verify that ASD-approved protocols like TLS are enabled
- GoodA documented policy showing encryption standards, settings for TLS in network configurations, and personnel responsible for compliance
- Askthe list of log sources and destinations: This should show where logs originate and where they are sent within the organisation
- Look atthe log transport pathway documentation: Check it details encrypted pathways and methods in use
- GoodDocumentation showing log sources/destinations, encryption methods, and periodic reviews by the IT team
- Aska training schedule: Ensure there are regular sessions on encryption practices
- Look atthe training materials and attendance records: Confirm they cover ASD-approved encryption methods
- GoodCurrent training materials and participant lists showing regular training sessions
- Askabout the vendor selection process for logging tools: Inquire if ASD-approved encryption was a requirement
- Look atpurchase documents for new logging tools: These should specify encryption standards were a criteria
- GoodDocumentation of vendor assessments showing compliance with encryption standards at the time of purchase
Cross-framework mappings
How ISM-1984 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.24 | ISM-1984 requires a specific cryptographic use case: encrypt event log traffic while it is in transit to a centralised logging facility | |
handshakeSupports(3)expand_less | ||
| Annex A 5.28 | ISM-1984 requires event logs to be encrypted in transit to a centralised logging facility, helping preserve the integrity and confidentia... | |
| Annex A 8.15 | ISM-1984 requires that event logs forwarded to a centralised event logging facility are encrypted in transit to protect them against inte... | |
| Annex A 8.20 | ISM-1984 requires encryption in transit for event logs sent over networks to a centralised event logging facility, directly reducing the ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.