Skip to content
arrow_back
search
ISM-1711 policy ASD Information Security Manual (ISM)

Ensure User Identity Confidentiality in EAP-TLS

Use available methods to keep user identities private when using EAP-TLS for wireless network authentication.

record_voice_over

Plain language

This control is about making sure that when people log into a Wi-Fi network using EAP-TLS (a secure login method), their identities are kept private. It's important because if someone's identity gets exposed, hackers can steal their information or impersonate them to access sensitive parts of the network.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User identity confidentiality is used if available with EAP-TLS implementations.
policy ASD Information Security Manual (ISM) ISM-1711
priority_high

Why it matters

Without EAP-TLS identity confidentiality, user identities may be exposed in 802.1X exchanges, enabling targeted attacks and aiding unauthorised access attempts.

settings

Operational notes

Verify EAP-TLS is configured for identity privacy (e.g., anonymous outer identity) and routinely test captures to confirm real user IDs are not disclosed during authentication.

Mapping detail

Mapping

Direction

Controls