Skip to content
arrow_back
search
ISM-1175 policy ASD Information Security Manual (ISM)

Restrict Privileged Users from Internet Access

Privileged accounts can't access the internet or web services unless explicitly allowed.

record_voice_over

Plain language

This control ensures that user accounts with high levels of access cannot browse the internet or use online services unless they are given special permission. It's important because these accounts have the 'keys to the kingdom,' so if they get hacked while online, it could lead to a major security breach.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Privileged user accounts (excluding those explicitly authorised to access online services) are prevented from accessing the internet, email and web services.
policy ASD Information Security Manual (ISM) ISM-1175
priority_high

Why it matters

If privileged users access the internet, they become prime targets for attacks, risking credential theft and major breaches.

settings

Operational notes

Regularly audit privileged accounts to confirm they cannot access the internet, email or web services; remove access and investigate exceptions promptly.

Mapping detail

Mapping

Direction

Controls