Skip to content
arrow_back
search
ISM-0445 policy ASD Information Security Manual (ISM)

Dedicated Accounts for Privileged User Activities

Privileged users must have separate accounts for administrative tasks to enhance security.

record_voice_over

Plain language

This control is about making sure that people who manage important computer systems use special, dedicated accounts only for tasks that require high-level access. This matters because if these special accounts are misused or compromised, a hacker could gain control of critical systems, leading to data theft, system outages, or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Privileged users are assigned a dedicated privileged user account to be used solely for duties requiring privileged access.
policy ASD Information Security Manual (ISM) ISM-0445
priority_high

Why it matters

Without dedicated privileged accounts, a compromised standard user account can be abused for admin actions, enabling data exfiltration and service disruption.

settings

Operational notes

Use separate privileged accounts only for admin tasks; block email/web use on them and monitor logons to detect unauthorised privileged use.

Mapping detail

Mapping

Direction

Controls