Skip to content
arrow_back
search
ISM-2017 policy ASD Information Security Manual (ISM)

Ensure DNS Traffic is Encrypted When Supported

DNS data is encrypted whenever possible for added security.

record_voice_over

Plain language

When you browse the internet, your computer needs to find the address of the site you are visiting. This is done through a system called DNS, which stands for Domain Name System. If DNS traffic is not encrypted, hackers could potentially see where you are going online and redirect you to fake sites, which means your data and privacy could be at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

DNS traffic is encrypted by clients and servers wherever supported.
policy ASD Information Security Manual (ISM) ISM-2017
priority_high

Why it matters

Without encrypted DNS traffic, attackers can intercept queries, exposing sensitive data and redirecting users to malicious sites, impacting trust and privacy.

settings

Operational notes

Regularly verify DNS encryption support and keep DNS over HTTPS/TLS configured and updated across clients and resolvers in line with current best practice.

Mapping detail

Mapping

Direction

Controls