Skip to content
arrow_back
ISM-1245policyASD Information Security Manual (ISM)

Remove Temporary Files After Server Installation

Ensure temporary files are deleted after installing server applications to maintain system security.

record_voice_over

Plain language

After you install server software, it creates temporary files that help with the setup. If you don't delete these files, they could be used by attackers to harm your servers, potentially leading to data breaches or server breakdowns.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

All temporary installation files created during server application installation processes are removed after server applications have been installed.
policyASD Information Security Manual (ISM)ISM-1245
priority_high

Why it matters

If temporary files are not deleted, they could expose servers to attacks, risking data breaches or server failures that disrupt business operations.

settings

Operational notes

Regularly monitor server installations to ensure temporary files are consistently deleted to reduce security risks. Keep staff trained and agreements up-to-date.

build

Implementation tips

  • The IT team should identify temporary files created during server installations. This can be done by checking installation logs or software documentation to locate where these files are usually stored.
  • System administrators should configure automatic scripts to remove temporary files post-installation. Using file management tools, they can set up scheduled tasks to clean up after installations.
  • Managers should ensure IT staff are trained on recognising and managing installation files. Hold training sessions with clear examples of what these files look like and the risks of not deleting them.
  • Procurement teams should include deletion clauses in software purchase agreements. Ensure agreements require vendors to document all temporary files their software creates and how to securely remove them.
  • The IT security officer should periodically review server setups to ensure this control is followed. They can perform spot checks on recently installed servers to confirm temporary files are routinely deleted.
fact_check

Audit / evidence tips

  • Askdocumented procedures on temporary file managementLook atclear steps on identifying and deleting these filesGoodincludes specific file paths and deletion methods
  • Request examples of recent server installations including post-installation steps. Check if temporary files were identified and deleted. Good evidence includes logs showing the cleanup was performed.
  • Asktraining records verifying IT staff understand temporary file risksLook atattendance logs and training materialGoodshows regular and comprehensive training sessions
  • Look atclauses requiring the deletion of installation filesGoodshows these requirements are clearly stated and enforced
  • Aska review report from the IT security officer's spot checksLook atthe findings on temporary file deletions. Good reports include specific incidents, corrections made, and future recommendations
link

Cross-framework mappings

How ISM-1245 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.19ISM-1245 requires all temporary installation files and logs created during server application installation to be removed after installation

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls