Skip to content
arrow_back
search
ISM-0475 policy ASD Information Security Manual (ISM)

Use P-384 Curve for Secure Digital Signatures

Ensure stronger digital signature security by using ECDSA with a key size of at least 224 bits, ideally the P-384 curve.

record_voice_over

Plain language

This control is about using a specific method for signing digital documents to ensure they are authentic and haven't been altered. It's important because if digital signatures aren't strong, someone could fake documents, leading to security breaches and potential fraud.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using ECDSA for digital signatures, a base point order and key size of at least 224 bits is used, preferably the P-384 curve.
policy ASD Information Security Manual (ISM) ISM-0475
priority_high

Why it matters

Using ECDSA with too-small keys or weaker curves can enable signature forgery, undermining integrity and trust in signed data and documents.

settings

Operational notes

Regularly verify that ECDSA uses at least a 224-bit key, aiming for P-384, to maintain signature strength and stay compliant.

Mapping detail

Mapping

Direction

Controls