PROTECTED is a handling classification. It is not, in itself, a cryptographic specification.
The misconception runs roughly like this: if a system handles PROTECTED information, the system must encrypt that information end-to-end, at rest and in transit, using a fixed list of approved algorithms, and meeting that bar is what makes it “PROTECTED-grade”. The framing is intuitive. It is also wrong on both ends.
The classification itself comes from the PSPF and describes the sensitivity of the information and the consequences of its compromise. It governs who may access it, where it may be processed, how it must be marked, and how it must be transported between environments. Encryption is one mechanism that may serve those obligations. It is not the obligation itself.
The cryptographic obligations are set by the ISM, not the classification label. The Guidelines for Cryptography specify approved algorithms, key lengths, and use cases — and the ISM is explicit that some controls apply only when data is outside its normal protective boundary. PROTECTED data inside a physically secure, ASD-assessed enclave with strong access control may not require the same cryptographic envelope as the same data leaving that enclave across a public network.
The trap for SaaS vendors sits in the gap between those two ideas. A vendor can pour engineering effort into AES-256 at rest, TLS 1.3 in transit, customer-managed keys, hardware security modules — and still fail an assessment because the access controls, audit logging, personnel vetting, or jurisdictional controls around the data don’t meet the rest of the obligation. Encryption hardens the container. It does not satisfy the handling rules.
The corollary is also true. A system that meets the handling rules through other compensating controls — physically segregated network, vetted personnel, restricted endpoints — may not need the maximal cryptographic posture the marketing brochure implies. The assessor’s job is to read the controls in context, not to tick “AES present”.
Takeaway. Before you optimise for encryption, read the ISM control set in scope. The label tells you what the data is. The controls tell you what you actually have to do with it.
Published by TrustedZone news automation on 2026-05-20 AEST. Director rollback.