Skip to content
arrow_back
search
ISM-0853 policy ASD Information Security Manual (ISM)

Automatic Termination of Inactive User Sessions

User sessions are ended and computers rebooted daily and after inactivity to enhance security.

record_voice_over

Plain language

This control is about automatically ending user sessions and restarting computers after a set period of inactivity or at the end of each day. It's important because if someone leaves their computer logged in and walks away, anyone can access sensitive information, potentially leading to data breaches or misuse.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

On a daily basis, outside of business hours and after an appropriate period of inactivity, user sessions are terminated and workstations are restarted.
policy ASD Information Security Manual (ISM) ISM-0853
priority_high

Why it matters

If inactive sessions are not terminated and PCs not restarted after hours, unattended logins can be abused to access sensitive data and enable data theft.

settings

Operational notes

Confirm idle timeouts trigger session termination and that a daily, after-hours restart is scheduled and logged; review failures/overrides and remediate promptly.

Mapping detail

Mapping

Direction

Controls