Skip to content
arrow_back
search
ISM-1330 policy ASD Information Security Manual (ISM)

Limit PMK Caching Duration on Wireless Networks

Ensure that stored authentication data for networks isn't kept for more than a day.

record_voice_over

Plain language

This control is about making sure that when a device connects to your Wi-Fi network, the information that proves it is allowed to connect isn't stored for more than 24 hours. This matters because if an unauthorised person gets hold of this information, they could easily access your wireless network and misuse your data or resources.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The PMK caching period is not set to greater than 1440 minutes (24 hours).
policy ASD Information Security Manual (ISM) ISM-1330
priority_high

Why it matters

If PMK caching exceeds 24 hours, compromised credentials can keep working longer, enabling unauthorised WLAN access and raising breach risk.

settings

Operational notes

Check WLC/AP PMK caching is set to 1440 minutes (24 hours) or less, and review after firmware changes or template updates.

Mapping detail

Mapping

Direction

Controls