Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2164Set MACsec Connectivity Association Lifetime Below 24 Hours

Configure every MACsec link so its connectivity association expires and re-keys in under 24 hours (less than 86400 seconds), rather than persisting indefinitely.

record_voice_over

Plain language

MACsec (Media Access Control Security) encrypts traffic on a network link between two devices, such as a switch and a router or a switch and a server. When the two ends agree to protect a link, they form a connectivity association (CA): a security relationship that governs the keys used to encrypt and authenticate the traffic on that link. This control requires that a connectivity association is not allowed to live for a full day. Its lifetime must be set to less than 24 hours, which is less than 86400 seconds, so that the association is renewed and fresh keying material is established at least once a day. Why it matters: the longer a single connectivity association and its keys are in use, the more encrypted traffic is protected under the same material, and the more valuable and exposed that material becomes. If an attacker recovers or misuses the keys for a link, a short lifetime limits how much traffic they can decrypt and how long they can keep exploiting the association before it is replaced. Keeping the lifetime under a day caps that exposure window and keeps link encryption fresh across the network.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Media Access Control Security

Official control statement

A connectivity association lifetime of less than 24 hours (86400 seconds) is used for MACsec connections.
policyASD Information Security Manual (ISM)ISM-2164
priority_high

Why it matters

If MACsec connectivity associations are left at a default or unlimited lifetime, or set to 24 hours or more, a compromised or weakened association stays valid for far longer than intended. An attacker who obtains the keying material can decrypt or tamper with link traffic for the whole time the association persists, and large volumes of traffic are protected by the same keys, increasing the value of any successful attack. The organisation also fails to meet this ISM control, which is likely to be raised as a finding in an ISM or IRAP assessment of the network.

settings

Operational notes

In practice this is a configuration setting on the network devices that terminate MACsec links (typically switches, routers and, where used, host adapters). The lifetime value must be strictly below 86400 seconds; a value of exactly 86400 does not meet the control, so teams commonly choose a figure comfortably lower to avoid edge cases.

Network engineers should treat the lifetime as part of the standard MACsec build: it belongs in the device configuration template or baseline so that every new MACsec link inherits a compliant value, and it should be checked whenever a link is stood up, a device is replaced, or a configuration is restored from backup. Both ends of a link should be reviewed, since a lifetime is set per device and a mismatch or an unconfigured peer can leave one side non-compliant. Periodic configuration audits, whether by script, network management tooling or manual review, should confirm the value has not drifted back to a vendor default.

build

Implementation tips

  • Network engineering team: inventory every MACsec-protected link in the environment, recording the devices at both ends, so that the lifetime setting can be verified on each device that terminates a connectivity association.
  • Network engineering team: set the MACsec connectivity association lifetime on each of those devices to a value below 86400 seconds using the vendor's MACsec or MKA configuration commands, and confirm the value is applied on both peers of each link.
  • Network architecture or standards owner: add the sub-24-hour lifetime to the organisation's network device configuration baseline and templates, so any new MACsec link is deployed with a compliant value rather than a vendor default.
  • Network operations team: after applying the setting, verify on a sample of links that the connectivity association actually renews within the configured period by checking the device's MACsec or MKA session status or logs over more than one lifetime cycle.
  • Network operations team: build a scheduled configuration compliance check (script or network management tool) that reads the MACsec lifetime from every MACsec-enabled device and flags any device where the value is missing, 86400 seconds or higher, or differs between the two ends of a link.
fact_check

Audit / evidence tips

  • AskAsk for the list of MACsec-protected links and the devices that terminate them.Look atCheck that the list covers all MACsec links in scope and names both peer devices for each link, so the lifetime can be traced to every endpoint.GoodA complete, current inventory exists and each link can be matched to specific device configurations.
  • AskAsk for the running configuration of a sample of MACsec-enabled devices from both ends of several links.Look atLocate the connectivity association or MKA lifetime setting and confirm the configured value in seconds.GoodEvery sampled device shows a lifetime strictly below 86400 seconds, and the two peers of each link are consistent.
  • AskAsk for the network device configuration baseline or template used for MACsec deployments.Look atCheck whether the sub-24-hour lifetime is written into the baseline rather than relying on engineers to set it by hand.GoodThe baseline mandates a specific value below 86400 seconds and new MACsec links are built from it.
  • AskAsk for MACsec or MKA session status output or logs covering more than a day for a sample of links.Look atCheck that connectivity associations are being renewed within the configured lifetime rather than persisting past 24 hours.GoodSession records show re-keying or association renewal occurring at intervals under 24 hours.
  • AskAsk for the results of the most recent configuration compliance check covering MACsec lifetimes.Look atReview what the check tests, how often it runs, and how exceptions such as devices at a vendor default were handled.GoodA recurring check exists, it tests for values below 86400 seconds on every MACsec device, and any deviations were corrected and recorded.
link

Cross-framework mappings

How ISM-2164 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 8.20ISM-2164 requires each MACsec link to use a connectivity association lifetime under 24 hours to enforce regular re-keying
Annex A 8.24ISM-2164 requires a MACsec connectivity association to expire and re-key in less than 24 hours, which is a specific key/association lifet...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for networking controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls