Skip to content
arrow_back
search
ISM-1373 policy ASD Information Security Manual (ISM)

Ensure TLS Connections do not use Anonymous DH

Do not use Anonymous Diffie-Hellman for secure connections to prevent security vulnerabilities.

record_voice_over

Plain language

This control is about making sure that when your systems talk to each other securely over the internet, they don't use a risky shortcut called Anonymous Diffie-Hellman (DH). If this shortcut is used, it leaves the door open for cybercriminals to sneak in and eavesdrop on your private information. Imagine hiring a security guard who doesn't ask your name or ID; that's what Anonymous DH effectively does.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Anonymous DH is not used for TLS connections.
policy ASD Information Security Manual (ISM) ISM-1373
priority_high

Why it matters

Using Anonymous DH exposes TLS sessions to man-in-the-middle attacks, enabling interception or alteration of sensitive data in transit.

settings

Operational notes

Audit TLS configs to disable ADH/anon cipher suites (e.g., ADH-*) and confirm servers only offer authenticated DHE/ECDHE suites after changes.

Mapping detail

Mapping

Direction

Controls