Skip to content
arrow_back
search
ISM-0380 policy ASD Information Security Manual (ISM)

Disable Unneeded OS Accounts and Services

Remove or turn off unnecessary user accounts and services on operating systems to improve security.

record_voice_over

Plain language

This control is about shutting down or removing user accounts and services on computer systems that aren't needed. Doing this helps protect your business from hackers who might use these unused accounts or services to break into your systems and cause trouble, like stealing information or disrupting your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unneeded user accounts, components, services and functionality of operating systems are disabled or removed.
policy ASD Information Security Manual (ISM) ISM-0380
priority_high

Why it matters

Leaving unused OS accounts or services enabled creates unnecessary entry points, increasing the likelihood of privilege misuse, compromise and outages.

settings

Operational notes

Regularly review OS accounts and running services; disable or remove default, unused or legacy items, and verify only required services start at boot to minimise attack surface.

Mapping detail

Mapping

Direction

Controls