Skip to content
arrow_back
search
ISM-0551 policy ASD Information Security Manual (ISM)

Ensure Secure IP Telephony Device Authentication

Ensure only authorised IP phones can register and use the network, blocking unauthorised and unused functionalities.

record_voice_over

Plain language

This control ensures that only the phones you have approved can connect to your office phone network. This is important because if unauthorised devices join the network, they could listen in on private conversations or cause disruptions, much like leaving the door open to anyone who wants to walk in uninvited.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2019

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

IP telephony is configured such that: - IP phones authenticate themselves to the call controller upon registration - auto-registration is disabled and only authorised devices are allowed to access the network - unauthorised devices are blocked by default - all unused and prohibited functionality is disabled.
policy ASD Information Security Manual (ISM) ISM-0551
priority_high

Why it matters

Without IP phone authentication and auto-registration disabled, rogue handsets can register to the call controller, enabling call eavesdropping and network disruption.

settings

Operational notes

Ensure auto-registration is disabled, only authorised phones can register to the call controller, and unknown devices are blocked by default; disable unused/prohibited IP phone functionality.

Mapping detail

Mapping

Direction

Controls