Skip to content
arrow_back
search
ISM-1370 policy ASD Information Security Manual (ISM)

Ensure Only Server-Initiated TLS Renegotiation

Only the server can start secure renegotiation for TLS connections to maintain security.

record_voice_over

Plain language

This control means that only the server, and not the user’s computer, can start or restart a secure connection. This is crucial because if a user’s device could start this process, a hacker might trick the connection into becoming less secure, putting sensitive information at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Only server-initiated secure renegotiation is used for TLS connections.
policy ASD Information Security Manual (ISM) ISM-1370
priority_high

Why it matters

Without server-controlled TLS renegotiation, systems face increased risk of DoS or connection hijacking, leading to potential data breaches.

settings

Operational notes

Configure TLS to reject client-initiated renegotiation and allow only server-initiated secure renegotiation; verify with TLS scanners after changes.

Mapping detail

Mapping

Direction

Controls