Skip to content
arrow_back
search
ISM-0554 policy ASD Information Security Manual (ISM)

Secure Two-Way Authentication for Video Calls

Video calls must use secure two-way authentication to ensure calls are encrypted and cannot be reused.

record_voice_over

Plain language

This control is about making sure that your video calls are extra secure by using a method that checks both sides before letting the call begin, and it ensures that these calls can’t be tampered with or listened to by anyone else. This is important because if you don’t secure your video calls, sensitive information you share could be stolen or misused, putting your business or personal conversations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

An encrypted and non-replayable two-way authentication scheme is used for call authentication and authorisation.
policy ASD Information Security Manual (ISM) ISM-0554
priority_high

Why it matters

Without secure two-way authentication, attackers can spoof participants or replay call setup messages, exposing sensitive business or personal information during video calls.

settings

Operational notes

Regularly test mutual authentication on video calls and validate anti-replay protections (nonces/timestamps) to ensure call setup messages cannot be reused or spoofed.

Mapping detail

Mapping

Direction

Controls