Latest publications 17 Mar 2025 Preparing for and responding to denial-of-service attacks Although organisations cannot avoid being targeted by denial-of-service attacks, there are a number of measures that organisations can implement to prepare for and potentially reduce the impact if targeted. Preparing for denial-of-service attacks before they occur is by far the best strategy, it is very difficult to respond once they begin and efforts at this stage are unlikely to be effective. 10 Feb 2025 Foundations for modern defensible architecture The Foundations represent the first step to help organisations adopt a ‘modern defensible architecture’ approach, which will enable them to evolve alongside the threat landscape. 10 Feb 2025 Modern defensible architecture Modern defensible architecture is the first step in Australian Signals Directorate (ASD)’s Australian Cyber Security Centre (ACSC)’s push to ensure that secure architecture and design are being considered and applied by organisations in their cybersecurity and resilience planning. All publications Title AudienceIndividuals & familiesSmall & medium businessesOrganisations & Critical InfrastructureGovernment Sort by Sort byDate updated (new to old)Date updated (old to new)Title (A-Z)Title (Z-A) Items per page 61218243036424854606672788490200 06 Oct 2021 Domain Name System security for domain owners This publication provides information on DNS security for domain owners. It also shared helpful strategies to reduce the risk of domain misuse. 06 Oct 2021 Domain Name System security for domain resolvers This publication explores DNS security for recursive resolution servers. It also shares helpful strategies to reduce the risk of DNS resolver subversion or compromise. 06 Oct 2021 Fundamentals of Cross Domain Solutions This publication introduces technical and non-technical audiences to cross domain security principles for securely connecting security domains. 06 Oct 2021 How to combat fake emails Organisations can reduce the likelihood of their domains being used to support fake emails by implementing Sender Policy Framework (SPF) and Domain-based Message Authentication, Reporting and Conformance (DMARC) records in their Domain Name System (DNS) configuration. Using DMARC with DomainKeys Identified Mail (DKIM) to sign emails provides further safety against fake emails. Likewise, organisations can better protect their users against fake emails by ensuring their email systems use and apply SPF, DKIM and DMARC policies on inbound email. 06 Oct 2021 How to manage your security when engaging a Managed Service Provider Understand the actions organisations can take to manage the security risks posed by engaging and authorising network access for managed service providers. 06 Oct 2021 Implementing certificates, TLS, HTTPS and opportunistic TLS Transport Layer Security (TLS) is a widely used encryption protocol which enables parties to communicate securely over the internet. Through the use of certificates and Public Key Infrastructure (PKI), parties can identify each other through a trusted intermediary and establish encrypted tunnels for the secure transfer of information. Pagination Previous page ‹‹ Page 15 Next page ›› Alerts and Advisories Advice, guidance and publications Reports and statistics News Programs Glossary