Skip to content
arrow_back
search
ISM-1759 policy ASD Information Security Manual (ISM)

Ensure Strong Encryption with Diffie-Hellman

Use a minimum 3072-bit modulus for secure Diffie-Hellman key exchanges.

record_voice_over

Plain language

This control is about using strong encryption to keep our private information safe when it's being shared online. Imagine you're sending a secret message in a locked box; this is like ensuring the lock on that box is really difficult to pick. If we don't use strong enough encryption, it's like using a weak lock, and someone could intercept and read our message, exposing sensitive data or personal information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using DH for agreeing on encryption session keys, a modulus of at least 3072 bits is used, preferably 3072 bits.
policy ASD Information Security Manual (ISM) ISM-1759
priority_high

Why it matters

Using weak Diffie-Hellman keys invites attackers to decrypt sensitive communications, risking data breaches and loss of confidential information.

settings

Operational notes

Regularly verify DH groups use a minimum 3072-bit modulus in TLS/VPN configs, and update cryptographic libraries when standards change.

Mapping detail

Mapping

Direction

Controls