Skip to content
arrow_back
search
ISM-2018 policy ASD Information Security Manual (ISM)

Secure BGP Routing with RPKI-Registered IP Addresses

Routers reject or down-rank invalid IP address routes to enhance BGP security.

record_voice_over

Plain language

This control is about making sure that the internet routes used to send and receive data are secure and accurate. If this isn't done, your data could be sent through the wrong paths, posing risks like loss of sensitive information or even your website or services being inaccessible. It's like ensuring your mail gets delivered to the right address and not everyone else's mailbox.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Routes for RPKI-registered IP addresses that are advertised from invalid Autonomous Systems, or that are longer than allowed, are rejected or deprioritised by routers that exchange routes via BGP.
policy ASD Information Security Manual (ISM) ISM-2018
priority_high

Why it matters

Without rejecting/deprioritising RPKI-invalid BGP routes (wrong origin AS or too-long prefix), traffic can be hijacked, intercepted or blackholed, causing outages and misrouting.

settings

Operational notes

Maintain ROA-based BGP policy: regularly refresh RPKI cache/ROAs, set routers to reject or deprioritise RPKI-invalid (and max-length exceeded) routes, and alert on validation state changes.

Mapping detail

Mapping

Direction

Controls