Skip to content
arrow_back
search
E8-AH-ML1.4 bolt ASD Essential Eight

Web browser security settings locked down to users

Users should not be able to change web browser security settings.

record_voice_over

Plain language

This control means that regular users shouldn't be able to change the security settings in their web browsers. It's important because if people can alter security settings, they might accidentally or intentionally make the browser less secure, leaving the business open to hackers and viruses.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Web browser security settings cannot be changed by users.
bolt ASD Essential Eight E8-AH-ML1.4
priority_high

Why it matters

Allowing users to modify browser security settings increases risk of data breaches and malware, undermining central security controls.

settings

Operational notes

Use GPO/MDM-enforced browser policies to lock security settings. Regularly audit policy compliance and block local overrides to prevent unauthorised changes.

Mapping detail

Mapping

Direction

Controls