Skip to content
arrow_back
search
ISM-0846 policy ASD Information Security Manual (ISM)

Application Control Restrictions for Users

Users can't avoid application control except for administrators and emergency accounts.

record_voice_over

Plain language

This control means that only authorised users, like system administrators or special accounts for emergencies, can deactivate or bypass application controls. This is important because allowing regular users to disable security controls could lead to unauthorised software running on your system, which can make your computers vulnerable to attacks and data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

All users (with the exception of local administrator accounts and break glass accounts) cannot disable, bypass or be exempted from application control.
policy ASD Information Security Manual (ISM) ISM-0846
priority_high

Why it matters

Allowing users to bypass application control can enable unauthorised software execution, increasing malware risk and potential data compromise.

settings

Operational notes

Audit who can change application control: only local administrators and break glass accounts, and alert on any exemption or bypass attempts.

Mapping detail

Mapping

Direction

Controls