Skip to content
arrow_back
search
ISM-0477 policy ASD Information Security Manual (ISM)

Separate RSA Key Pairs for Different Functions

Use separate RSA key pairs for signing and key transportation to enhance security.

record_voice_over

Plain language

This guideline is about using different sets of RSA keys for different tasks like signing messages and exchanging encryption keys. It's important because using the same key for multiple purposes can make your system vulnerable to attacks, where someone could fake messages or improperly access secure information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using RSA for digital signatures, and for transporting encryption session keys (and similar keys), a different key pair is used for digital signatures and transporting encryption session keys.
policy ASD Information Security Manual (ISM) ISM-0477
priority_high

Why it matters

Using the same RSA keys for multiple functions increases the risk of key compromise, allowing attackers to forge signatures or decrypt sensitive communications.

settings

Operational notes

Audit RSA key usage to ensure separate key pairs are dedicated to signing vs key transport; label keys by purpose and prevent reuse across functions.

Mapping detail

Mapping

Direction

Controls