Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2131Quarterly Certificate Template Reviews to Remediate Misconfigurations

Check every certificate template at least quarterly for settings that would let someone gain higher privileges or request certificates they should not have, and fix what you find.

record_voice_over

Plain language

A certificate template is the set of rules a certificate authority uses when it issues a certificate: who is allowed to request one, what the certificate can be used for, whether the requester can choose the name that goes in it, and whether a manager has to approve it. Templates tend to be created once and then forgotten, while the people, groups and systems around them change. This control asks you to open up every template at least once every three months and look specifically for two kinds of problem. The first is a setting that could enable privilege escalation, for example a template that lets an ordinary user obtain a certificate that works for logon or authentication as a more powerful account. The second is a setting that allows unauthorised certificate enrolment, for example enrol permissions granted to a broad group, or an approval step that has been switched off. Anything you find has to be remediated, not just noted. It matters because a badly configured template is a quiet, durable path for an attacker who already has a foothold. Instead of cracking passwords, they simply request a certificate the template was never meant to give them and then use it to authenticate as someone else. Because the certificate is valid and issued by your own authority, this can look entirely legitimate to the systems that trust it. A regular review is how you catch that drift before someone else does.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Microsoft Active Directory Certificate Services

Official control statement

Certificate templates are reviewed at least every three months to identify and remediate misconfigurations that could enable privilege escalation or unauthorised certificate enrolment.
policyASD Information Security Manual (ISM)ISM-2131
priority_high

Why it matters

If templates are not reviewed on a regular cycle, misconfigurations accumulate unnoticed. An attacker with low-privileged access could use an over-permissive template to enrol for a certificate that authenticates them as a privileged account, giving them a persistent, hard-to-detect route to domain or system compromise. Unauthorised enrolment can also produce valid certificates for people or devices that should never have received them, undermining every service that trusts the certificate authority. The longer the gap between reviews, the longer such a path stays open.

settings

Operational notes

Treat the review as a recurring calendar task owned by the certificate or identity team, scheduled so that no more than three months pass between completed reviews. Keep a current inventory of templates so the review has a known scope and nothing is skipped.

For each template, the reviewer checks who holds enrol and auto-enrol permissions, who can modify the template itself, which purposes and extended key usages it allows (particularly anything usable for authentication), whether requesters can supply their own subject name, whether manager or CA approval is required, and whether the template is still needed at all. Findings are recorded and either fixed on the spot or raised as a change with a due date. Fixes are verified at the following review.

Templates that are unused should be considered for removal, since they still carry risk while published. Any new template or change to an existing one made between reviews should be examined at the next review so the cycle stays complete.

build

Implementation tips

  • The certificate services owner sets a recurring review task, no more than three months apart, in the team's work calendar or ticketing system, and assigns a named reviewer and an approver for each cycle.
  • The reviewer exports the full list of certificate templates and their settings from each certificate authority (using the CA management console or command-line tooling) so every template is covered and the export can be kept as a record.
  • The reviewer works through a fixed checklist per template covering enrol and auto-enrol permissions, who can edit the template, allowed purposes and extended key usages (especially authentication), whether the requester can supply the subject name, and whether approval is required, marking each item as acceptable or a finding.
  • For each finding, the certificate services team applies the fix (tightening permissions, removing an unsafe usage, requiring approval, or unpublishing an unneeded template) through normal change control and records the before and after settings.
  • At the start of each review, the reviewer re-checks that all findings from the previous cycle were remediated and confirms any templates created or changed since then are included in the current cycle.
fact_check

Audit / evidence tips

  • AskAsk for the schedule or ticket history showing when certificate template reviews were carried out over the last year.Look atCheck the dates of completed reviews and the gaps between them.GoodReviews are completed with no more than three months between them, and each has a named reviewer and a completion date.
  • AskAsk for the template inventory or export used as the scope of the most recent review.Look atCompare it with the templates currently published on the certificate authority.GoodEvery template on the CA appears in the review scope, including recently added ones.
  • AskAsk for the checklist or working notes from a recent review.Look atConfirm it examines enrol permissions, template modification rights, allowed purposes, subject name supply and approval settings for each template.GoodEach template has a recorded assessment against those settings, with findings clearly marked.
  • AskAsk for the list of findings raised in the last two reviews and the changes made in response.Look atTrace each finding to a change record or configuration change that fixed it.GoodEvery finding has a documented fix, a date and someone who verified it, rather than being left open.
  • AskAsk to see the current settings of one or two templates that were flagged in a previous review.Look atCheck the live configuration matches the remediated state described in the review record.GoodThe live template reflects the fix, showing the review actually changed the configuration.
link

Cross-framework mappings

How ISM-2131 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.9ISM-2131 requires certificate templates to be reviewed at least quarterly to identify and remediate misconfigurations that could enable p...
sync_altPartially overlaps(1)expand_less
Annex A 8.8ISM-2131 requires certificate templates to be reviewed at least quarterly to find and fix misconfigurations that could allow privilege es...
handshakeSupports(1)expand_less
Annex A 5.18ISM-2131 requires routine review and remediation of certificate template settings to prevent unauthorised certificate enrolment and escal...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls