Terminate User Sessions and Restart Workstations Daily
Ensure that all user sessions end and computers are restarted every day.
Plain language
Shutting down computers and logging everyone out each day helps protect sensitive information. If someone forgets to log out or quits using their computer, others could access private files, putting the business at risk.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
User sessions are terminated and workstations are restarted at least daily.
Why it matters
Failing to log off users can lead to unauthorised access, risking data breaches and damaging the organisation's reputation.
Operational notes
Ensure routine checks are done to verify daily restarts, maintaining consistency and security across all workstations.
Implementation tips
- IT team should set up automatic shutdowns: Configure computers to log users out and reboot at a specific time every day. This ensures no one stays logged in overnight.
- Managers should communicate the new routine: Explain to staff why daily restarts are important and remind them to save work before leaving. This helps prevent any lost work due to unsaved files.
- System administrators should use scripts: Write simple scripts that force logoff commands on all systems. This keeps the process consistent and automated.
- HR should update the IT policy: Include a section on daily computer restarts and user logouts. This sets clear expectations for employee compliance.
- Office manager should schedule regular checks: Once a week, verify that computers are actually restarting and no sessions remain logged in overnight. This ensures the system is functioning correctly.
Audit / evidence tips
- Askthe policy document: Request the policy that mandates daily logouts and restartsLook atdetails outlining the requirements and responsibilitiesGoodincludes clear policies with version control
- Asklogs of system restarts: Request logs that show when computers shutdown and restarted each dayLook attimestamps that span each evening and early morningGoodshows consistent daily logs
- Askweekly compliance reports: Request reports that confirm the process is followedLook atany discrepancies or missed shutdownsGoodhas zero missed days
- Askcommunication records: Request emails or memos sent to staff about the new routine. Check for clear explanations and instructionsGoodresult includes comprehensive communication logs
- Asksomeone to demonstrate the automated script: Request a demonstration of the script that manages the shutdownsLook atcorrect script execution and successful logoff on multiple test unitsGoodshows the script working flawlessly
Cross-framework mappings
How ISM-0853 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 7.7 | ISM-0853 requires user sessions to be terminated after inactivity and systems to be restarted daily outside business hours | |
handshakeSupports(1)expand_less | ||
| Annex A 5.15 | ISM-0853 requires inactive user sessions to be terminated after an appropriate period of inactivity and for workstations to be restarted ... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.