Skip to content
arrow_back
search
ISM-1246 policy ASD Information Security Manual (ISM)

Apply Strict Server Application Hardening Guidelines

Servers are secured using the most restrictive guidance from ASD and vendors to protect against vulnerabilities.

record_voice_over

Plain language

This control is about strengthening the security of server applications by following strict guidelines to reduce the risk of cyber attacks. If server applications are not properly secured, they can be vulnerable to hackers, potentially leading to data breaches and serious disruptions to your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Server applications are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
policy ASD Information Security Manual (ISM) ISM-1246
priority_high

Why it matters

Without strict server application hardening (ASD/vendor baselines), default settings and weak services may be exploited, enabling unauthorised access or outages.

settings

Operational notes

Maintain ASD and vendor hardening baselines for each server app; review updates and, where guidance conflicts, implement the most restrictive settings.

Mapping detail

Mapping

Direction

Controls