Skip to content
arrow_back
search
ISM-1994 policy ASD Information Security Manual (ISM)

Use Correct Hashing for ML-DSA Pre-hashed Variants

Ensure stronger hashes like SHA-384 or SHA-512 are used with ML-DSA digital signatures for added security.

record_voice_over

Plain language

This control is about making sure your digital signatures are extra secure by using strong hashing methods like SHA-384 or SHA-512 before signing. By doing this, you protect sensitive data from being tampered with or faked, which is crucial in maintaining trust and preventing fraud.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When the pre-hashed variants of ML-DSA-65 and ML-DSA-87 are used, at least SHA-384 and SHA-512 respectively are used for pre-hashing.
policy ASD Information Security Manual (ISM) ISM-1994
priority_high

Why it matters

If ML-DSA-65/87 pre-hashed variants use weaker than SHA-384/SHA-512, signature forgery and integrity failures become more likely.

settings

Operational notes

Verify configurations and libraries: ML-DSA-65 pre-hash uses SHA-384 and ML-DSA-87 pre-hash uses SHA-512; test during updates.

Mapping detail

Mapping

Direction

Controls