Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 2166MACsec Secure Association Lifetime Limited To Under Four Hours

Configure MACsec links so each secure association is replaced in under four hours (14400 seconds), limiting how long any one set of session keys stays in use on the link.

record_voice_over

Plain language

MACsec encrypts traffic between two directly connected network devices at the Ethernet layer. The encryption keys it uses are held in a "secure association" (SA), and the SA lifetime is how long one set of keys is used before the devices roll to a fresh one. This control requires that the SA lifetime on MACsec connections is set to less than four hours (14400 seconds). Keys that live for a long time give an attacker more time to collect traffic and more material encrypted under the same key. If a key is ever compromised, everything protected by it during its lifetime is exposed. Rekeying more often shrinks that window: the volume of data under any one key is smaller, and a compromised key becomes useless sooner. In short, a shorter SA lifetime limits how much traffic an attacker could ever decrypt from a single key.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2026

Control Stack last updated

05 Sept 2026

E8 maturity levels

N/A

Topic

Media Access Control Security

Official control statement

A secure association lifetime of less than four hours (14400 seconds) is used for MACsec connections.
policyASD Information Security Manual (ISM)ISM-2166
priority_high

Why it matters

If MACsec SA lifetimes are left at long or unlimited values, a single set of session keys protects hours or days of link traffic. A key compromise, a cryptographic weakness or a captured traffic stream then exposes far more data than it should, and the organisation cannot demonstrate that its encrypted links meet the ISM's rekeying expectation.

settings

Operational notes

Treat the SA lifetime as a standard setting in the MACsec configuration template used for switches, routers and any other devices that terminate MACsec links. Network engineers should set the rekey interval (often expressed as a timer in seconds or minutes in vendor configuration) to a value below 14400 seconds and confirm that both ends of each link agree, since a mismatch can cause rekey failures or link flaps.

Day to day, watch for configuration drift: firmware upgrades, device replacements and copied configurations can silently reintroduce a vendor default that exceeds four hours. Include the SA lifetime in configuration compliance checks and in the change-approval checklist for any new or modified MACsec link. When troubleshooting MACsec links, do not "fix" instability by lengthening the lifetime beyond the limit; resolve the underlying key agreement issue instead.

build

Implementation tips

  • Network engineers should inventory every MACsec connection in the environment and record the currently configured secure association lifetime or rekey interval for each end of each link.
  • Network engineers should set the MACsec SA lifetime (rekey timer) on every MACsec-capable device to a value below 14400 seconds, using the vendor's timer or key-lifetime parameter, and apply it consistently at both ends of each link.
  • The network architecture owner should update the standard MACsec configuration template and build guide so the sub-four-hour lifetime is applied automatically to any new MACsec link.
  • Network operations should add an automated configuration compliance check (for example a script or network configuration manager rule) that flags any MACsec interface whose SA lifetime is 14400 seconds or higher.
  • The change manager should add a checklist item to MACsec-related changes, firmware upgrades and device replacements requiring the SA lifetime to be verified against the four-hour limit before the change is closed.
fact_check

Audit / evidence tips

  • AskAsk for the list of all MACsec connections and the configured secure association lifetime for each end.Look atCheck that every link is listed and that a lifetime value is recorded for both devices on each link.GoodEvery MACsec link shows a lifetime below 14400 seconds at both ends, with no gaps or unknown values.
  • AskAsk for running configuration exports from a sample of MACsec-enabled devices.Look atFind the MACsec or MKA policy section and read the rekey timer or key lifetime parameter.GoodThe configured value is explicitly set below four hours rather than relying on an unstated vendor default.
  • AskAsk for the standard MACsec configuration template or build guide.Look atLook for the SA lifetime setting and the value it prescribes.GoodThe template mandates a lifetime under 14400 seconds so new links inherit the setting automatically.
  • AskAsk for output from the configuration compliance tool or script that checks MACsec settings.Look atCheck whether the SA lifetime is one of the checked parameters and review recent results.GoodRecent checks cover the lifetime, and any device found above the limit was remediated with a record of the fix.
  • AskAsk for change records for recent MACsec changes, firmware upgrades or device replacements.Look atLook for evidence that the SA lifetime was verified after the change.GoodChange records show the lifetime was confirmed below four hours before closure, demonstrating the setting survives routine changes.
link

Cross-framework mappings

How ISM-2166 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 8.20ISM-2166 requires configuring MACsec so each secure association (and its session keys) is replaced in under four hours to reduce exposure...
Annex A 8.24ISM-2166 requires regular MACsec secure association rekeying (under four hours), directly limiting cryptographic key lifetime for MACsec ...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for networking controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls