Skip to content
arrow_back
search
ISM-0498 policy ASD Information Security Manual (ISM)

Ensure Short Lifetimes for IPsec Associations

IPsec connections should expire in less than four hours to maintain security.

record_voice_over

Plain language

Shortening the lifetime of an IPsec connection to under four hours is like changing the locks on your doors every few hours to keep potential burglars at bay. It ensures the data moving across the internet between your systems remains secure, reducing the risk of cyber attackers gaining access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A security association lifetime of less than four hours (14400 seconds) is used for IPsec connections.
policy ASD Information Security Manual (ISM) ISM-0498
priority_high

Why it matters

If an IPsec security association lifetime exceeds four hours, a compromised key can be used longer, increasing the chance of traffic decryption or tampering.

settings

Operational notes

Configure IPsec SA lifetimes to <14400 seconds (4 hours) on both peers, and regularly verify tunnel rekeying and expiry via device logs/config audits.

Mapping detail

Mapping

Direction

Controls