Skip to content
arrow_back
search
ISM-1772 policy ASD Information Security Manual (ISM)

Use Secure Pseudorandom Functions for IPsec Connections

Use secure methods for IPsec connections to ensure data integrity and security.

record_voice_over

Plain language

This control is about making sure the way we secure our Internet data links is as strong as possible. If we don't use the best methods for securing these data links, which are recommended by experts, our sensitive information may be exposed to cyber threats or data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

PRF_HMAC_SHA2_256, PRF_HMAC_SHA2_384 or PRF_HMAC_SHA2_512 is used for IPsec connections, preferably PRF_HMAC_SHA2_512.
policy ASD Information Security Manual (ISM) ISM-1772
priority_high

Why it matters

Using weak or non-approved IPsec PRFs can allow key derivation attacks, reducing tunnel integrity/confidentiality and risking data exposure.

settings

Operational notes

Verify IPsec proposals use PRF_HMAC_SHA2_256/384/512 (prefer 512); reject weaker PRFs and regularly audit configuration drift.

Mapping detail

Mapping

Direction

Controls