Skip to content
arrow_back
search
ISM-1771 policy ASD Information Security Manual (ISM)

Use AES Encryption for IPsec Connections

AES encryption, especially ENCR_AES_GCM_16, is recommended for securing internet protocol connections.

record_voice_over

Plain language

This control is about using a type of online lock called AES encryption to protect your internet connections from being accessed by criminals. If you don't use this encryption, your sensitive information, like customer data or confidential business emails, could be intercepted by malicious actors, leading to breaches that could damage your reputation and result in financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

AES is used for encrypting IPsec connections, preferably ENCR_AES_GCM_16.
policy ASD Information Security Manual (ISM) ISM-1771
priority_high

Why it matters

If IPsec is not encrypted with AES (preferably ENCR_AES_GCM_16), attackers can intercept or alter in-transit traffic, exposing sensitive data.

settings

Operational notes

Regularly review IPsec proposals/SA settings to ensure AES is used, preferably ENCR_AES_GCM_16, and remove weaker ciphers from all peers.

Mapping detail

Mapping

Direction

Controls