Skip to content
arrow_back
search
ISM-1764 policy ASD Information Security Manual (ISM)

Use NIST P-384 Curve for ECDSA Signatures

Use the NIST P-384 or P-521 curves, preferably P-384, for secure digital signatures.

record_voice_over

Plain language

This control is about using a specific type of digital signature to keep online communications safe. It suggests using a secure mathematical curve, known as NIST P-384, when creating digital signatures. If we don't follow this advice, our sensitive messages or transactions could be tampered with or forged, leading to potential security breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using ECDSA for digital signatures, NIST P-384 or P-521 curves are used, preferably the NIST P-384 curve.
policy ASD Information Security Manual (ISM) ISM-1764
priority_high

Why it matters

Without NIST P-384/P-521 for ECDSA, weaker curve choices can reduce signature strength, increasing forgery risk and undermining integrity.

settings

Operational notes

Enforce ECDSA curve policy to use NIST P-384 (preferred) or P-521; audit TLS/cert profiles and app crypto libs to block other curves after upgrades.

Mapping detail

Mapping

Direction

Controls