Skip to content
arrow_back
search
ISM-1000 policy ASD Information Security Manual (ISM)

Utilising Perfect Forward Secrecy for IPsec

Use PFS to ensure past IPsec keys can't be used if current ones are compromised.

record_voice_over

Plain language

Perfect Forward Secrecy (PFS) is like changing the locks every time someone opens the door, ensuring that if a key is stolen, it can't be used to unlock the door in the future. This is important for securing communications because if someone gets hold of your current security keys, they won't be able to access past messages, keeping your sensitive information safe.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

PFS is used for IPsec connections.
policy ASD Information Security Manual (ISM) ISM-1000
priority_high

Why it matters

Without IPsec PFS, a compromised key can allow decryption of previously captured VPN traffic, exposing sensitive data.

settings

Operational notes

Ensure IPsec VPNs use PFS in phase 2 (ESP). Periodically verify IKE/IPsec proposals and rekey settings enforce PFS.

Mapping detail

Mapping

Direction

Controls