Skip to content
arrow_back
search
ISM-1453 policy ASD Information Security Manual (ISM)

Ensure PFS is Enabled for TLS Connections

TLS connections must be set up to protect past data even if the server's private key is compromised.

record_voice_over

Plain language

This control is about using something called Perfect Forward Secrecy (PFS) to protect data transferred online. It ensures that even if someone gets hold of the keys used to secure these transfers, they can't access past data. Without PFS, if a hacker steals a key, they could unlock all your previous communications, risking a breach of private or sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Perfect Forward Secrecy (PFS) is used for TLS connections.
policy ASD Information Security Manual (ISM) ISM-1453
priority_high

Why it matters

Without PFS, a stolen TLS private key can decrypt previously captured sessions, exposing historical sensitive data and enabling major breaches.

settings

Operational notes

Audit TLS to allow only ECDHE/DHE suites (PFS) and disable RSA key exchange. Re-test after updates to ensure forward secrecy remains enabled.

Mapping detail

Mapping

Direction

Controls