Skip to content
arrow_back
search
E8-AH-ML2.10 bolt ASD Essential Eight

PDF software security settings cannot be changed by users

Prevent users from changing PDF software security settings to enhance safety.

record_voice_over

Plain language

This control makes sure that people in the organisation can't change any security settings in the software used to read PDF documents. This is important because if someone could change these settings, it might make it easier for hackers to sneak in harmful software through PDFs.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Application hardening

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

PDF software security settings cannot be changed by users.
bolt ASD Essential Eight E8-AH-ML2.10
priority_high

Why it matters

If users can change PDF reader security settings, protections may be lowered, enabling malicious PDFs to run code or exfiltrate data.

settings

Operational notes

Enforce and lock PDF reader security preferences via central policy; disable risky features (e.g., JavaScript) and alert on config drift.

Mapping detail

Mapping

Direction

Controls