ISM-0157

Data communicated over network infrastructure in areas not authorised for the processing of such data is encrypted as if it was communicated through unsecured spaces.

Topic
Network infrastructure
Applicable to
all

History

Priority
must
Dec 2021
Removed
The recommendation that cryptographic products have completed an ASD Cryptographic Evaluation before being used for the protection of data at rest or in transit has been replaced with a recommendation for the use of cryptographic products that have been evaluated and certified under the Common Criteria against a Protection Profile.
2015
Agencies communicating sensitive or classified information over public network infrastructureor over infrastructure in unsecured spaces (Zone One security areas) must use encryptionapproved for communicating such information over public network infrastructure.
2010
Agencies communicating classified information over public network infrastructure or over infrastructure inunsecured spaces must use encryption to lower requirements to that for unclassified and public networks.
2008
Agencies communicating classified information over uncontrolled public network infrastructure or through uncontrolled areas must use encryption to lower the storage and processing requirements to that of an UNCLASSIFIED level.