Skip to content
arrow_back
search
ISM-0864 policy ASD Information Security Manual (ISM)

Prevent Modifications to Security Settings on Mobile Devices

Mobile devices ensure users cannot change or disable security features once set up.

record_voice_over

Plain language

This control ensures that once security settings are configured on a mobile device, they cannot be turned off or changed by someone not authorised to do so. This is important to prevent accidental or intentional weakening of security, which could expose sensitive information or lead to data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Mobile devices prevent personnel from disabling or modifying security functionality once provisioned.
policy ASD Information Security Manual (ISM) ISM-0864
priority_high

Why it matters

If users can disable or alter provisioned mobile security features, devices can become non-compliant, enabling unauthorised access and data leakage.

settings

Operational notes

Use MDM to enforce non-removable security profiles and restrict user changes; regularly review compliance reports to confirm key settings remain locked.

Mapping detail

Mapping

Direction

Controls