Skip to content
arrow_back
search
ISM-1957 policy ASD Information Security Manual (ISM)

Ensure CA Servers Use Hardware Security Modules

Microsoft AD CS private keys need a hardware module for secure storage.

record_voice_over

Plain language

This control means that the private keys for your Microsoft Active Directory Certificate Services (AD CS) servers need to be stored in a specially designed hardware device, known as a hardware security module (HSM). It's important because HSMs make it much harder for hackers to steal these keys, which are like the master keys to your network's security systems. Without this protection, your organisation is at risk of serious security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Private keys for Microsoft AD CS CA servers are protected by a hardware security module.
policy ASD Information Security Manual (ISM) ISM-1957
priority_high

Why it matters

Without HSMs securing CA server keys, attackers could forge certificates, undermining trust and compromising sensitive communications.

settings

Operational notes

Regularly check HSM logs for anomalies and ensure key backups are securely managed to mitigate loss or hardware failure risks.

Mapping detail

Mapping

Direction

Controls