Remove Temporary Files After Server Installation
Ensure temporary files are deleted after installing server applications to maintain system security.
Plain language
After you install server software, it creates temporary files that help with the setup. If you don't delete these files, they could be used by attackers to harm your servers, potentially leading to data breaches or server breakdowns.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Server Application HardeningOfficial control statement
All temporary installation files created during server application installation processes are removed after server applications have been installed.
Why it matters
If temporary files are not deleted, they could expose servers to attacks, risking data breaches or server failures that disrupt business operations.
Operational notes
Regularly monitor server installations to ensure temporary files are consistently deleted to reduce security risks. Keep staff trained and agreements up-to-date.
Implementation tips
- The IT team should identify temporary files created during server installations. This can be done by checking installation logs or software documentation to locate where these files are usually stored.
- System administrators should configure automatic scripts to remove temporary files post-installation. Using file management tools, they can set up scheduled tasks to clean up after installations.
- Managers should ensure IT staff are trained on recognising and managing installation files. Hold training sessions with clear examples of what these files look like and the risks of not deleting them.
- Procurement teams should include deletion clauses in software purchase agreements. Ensure agreements require vendors to document all temporary files their software creates and how to securely remove them.
- The IT security officer should periodically review server setups to ensure this control is followed. They can perform spot checks on recently installed servers to confirm temporary files are routinely deleted.
Audit / evidence tips
- Askdocumented procedures on temporary file managementLook atclear steps on identifying and deleting these filesGoodincludes specific file paths and deletion methods
- Request examples of recent server installations including post-installation steps. Check if temporary files were identified and deleted. Good evidence includes logs showing the cleanup was performed.
- Asktraining records verifying IT staff understand temporary file risksLook atattendance logs and training materialGoodshows regular and comprehensive training sessions
- Look atclauses requiring the deletion of installation filesGoodshows these requirements are clearly stated and enforced
- Aska review report from the IT security officer's spot checksLook atthe findings on temporary file deletions. Good reports include specific incidents, corrections made, and future recommendations
Cross-framework mappings
How ISM-1245 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.19 | ISM-1245 requires all temporary installation files and logs created during server application installation to be removed after installation | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.