Skip to content
arrow_back
search
ISM-1783 policy ASD Information Security Manual (ISM)

Secure BGP with Valid ROA for IP Addresses

Ensure public IP addresses are protected by valid Route Origin Authorisation records to enhance security.

record_voice_over

Plain language

This control is about making sure that the routes your internet traffic takes are secure and correctly identified. Without this, there's a risk that hackers can misdirect or intercept your online communications, potentially leading to data theft or service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Public IP addresses controlled by, or used by, an organisation are signed by valid ROA records.
policy ASD Information Security Manual (ISM) ISM-1783
priority_high

Why it matters

If valid ROAs are not maintained for organisation public prefixes, BGP routes can be hijacked, redirecting traffic and causing outages or compromise.

settings

Operational notes

Routinely validate ROAs for all public prefixes, monitor RPKI status, renew before expiry, and set maxLength to match announced prefixes and planned changes.

Mapping detail

Mapping

Direction

Controls