Skip to content
arrow_back
search
ISM-0443 policy ASD Information Security Manual (ISM)

Restrict Temporary Access to Secure Systems

Temporary access is not allowed for systems handling highly sensitive information.

record_voice_over

Plain language

This control is about ensuring that systems which handle very sensitive information shouldn't have temporary access granted to them. The reason for this is simple: if you allow short-term access to these systems, there's a risk someone could misuse that access and expose critical information. Keeping these systems secure helps protect against data leaks and potential financial or reputational harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Temporary access is not granted to systems that process, store or communicate caveated or sensitive compartmented information.
policy ASD Information Security Manual (ISM) ISM-0443
priority_high

Why it matters

Granting temporary access to systems handling caveated or sensitive compartmented information can enable unauthorised disclosure and compromise of classified operations.

settings

Operational notes

Enforce policy that no temporary accounts or time-bound access are issued for caveated/SCI systems; audit account creation and approvals to detect exceptions.

Mapping detail

Mapping

Direction

Controls