Skip to content
arrow_back
search
ISM-0476 policy ASD Information Security Manual (ISM)

Ensuring Strong RSA Modulus for Digital Security

Use a minimum 2048-bit RSA modulus for better security in digital signatures and key transport.

record_voice_over

Plain language

This control is about making sure your digital communications and important data are kept secure by using strong keys for encryption. Imagine if the lock on your front door was weak and easily breakable; similarly, a weak encryption key makes it easier for hackers to steal your information. By using a 2048-bit RSA modulus or, even better, a 3072-bit, you’re essentially adding a strong lock to your digital data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using RSA for digital signatures, and transporting encryption session keys (and similar keys), a modulus of at least 2048 bits is used, preferably 3072 bits.
policy ASD Information Security Manual (ISM) ISM-0476
priority_high

Why it matters

Using RSA keys under 2048 bits for signatures or session key transport can be factored, allowing forgery, decryption of session keys and data compromise.

settings

Operational notes

Inventory RSA use (signing and session key transport), enforce ≥2048-bit modulus (prefer 3072), and rotate/replace any keys below this threshold.

Mapping detail

Mapping

Direction

Controls