Skip to content
arrow_back
search
ISM-1945 policy ASD Information Security Manual (ISM)

Remove Enrollee Supplies Subject Flag from Templates

Ensure certificate templates do not allow users to supply their own subject information.

record_voice_over

Plain language

This control ensures that when people apply for digital certificates, which are like digital ID cards, they can't fill in their own personal information. It’s important because if this step isn’t followed, someone might pretend to be someone else, leading to potential fraud or security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT flag is removed from certificate templates.
policy ASD Information Security Manual (ISM) ISM-1945
priority_high

Why it matters

If users can supply subject details in templates, certificates can be issued with spoofed identities, enabling unauthorised access to systems and data.

settings

Operational notes

Periodically review certificate templates and confirm CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT is removed, so enrollee-supplied subject names cannot be used.

Mapping detail

Mapping

Direction

Controls