Skip to content
arrow_back
search
ISM-1454 policy ASD Information Security Manual (ISM)

Enhancing Security with Encrypted RADIUS Communications

Ensure RADIUS server communications are encrypted for increased security.

record_voice_over

Plain language

This control requires using encryption to protect information sent between devices that verify user identities (called authenticators) and your central RADIUS server, which handles user logins. It's important because, without this encryption, sensitive information like passwords could be intercepted by hackers while in transit, putting your network at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Communications between authenticators and a RADIUS server are encapsulated with an additional layer of encryption using RADIUS over Internet Protocol Security or RADIUS over Transport Layer Security.
policy ASD Information Security Manual (ISM) ISM-1454
priority_high

Why it matters

Without RADIUS over IPsec/TLS, RADIUS packets can be intercepted, exposing credentials and enabling unauthorised network access and compromise.

settings

Operational notes

Configure and verify RADIUS over TLS (RadSec) or IPsec between authenticators and the RADIUS server; regularly validate certificates, cipher suites and trust chains.

Mapping detail

Mapping

Direction

Controls