Skip to content
arrow_back
search
ISM-0383 policy ASD Information Security Manual (ISM)

Change Default OS User Accounts During Setup

Change or disable default OS user accounts during setup to enhance security.

record_voice_over

Plain language

When you first set up a new computer or server, it often comes with a default user account that everyone knows about. If you don't change or remove this account, a hacker can easily break in and take over your system without much effort.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Default user accounts or credentials for operating systems, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
policy ASD Information Security Manual (ISM) ISM-0383
priority_high

Why it matters

If default OS accounts/credentials remain unchanged, attackers can guess or reuse known defaults to gain unauthorised access, leading to compromise and data loss.

settings

Operational notes

During build and after major upgrades, confirm all default or pre-configured OS accounts are renamed, disabled or removed, and that any default passwords are changed.

Mapping detail

Mapping

Direction

Controls