Skip to content
arrow_back
search
ISM-1247 policy ASD Information Security Manual (ISM)

Disable or Remove Unneeded Server Features

Remove unnecessary accounts and features from servers to enhance security.

record_voice_over

Plain language

This control is about making sure you only keep what you really need on your servers. If servers have unnecessary accounts and features, they can be weak spots for hackers to exploit, which could lead to data breaches or service disruptions. It's like only keeping the doors and windows you use open and securely locked, while closing ones you don't need to stop burglars from getting in.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unneeded user accounts, components, services and functionality of server applications are disabled or removed.
policy ASD Information Security Manual (ISM) ISM-1247
priority_high

Why it matters

Excess server features expand the attack surface; unnecessary services/components can be exploited to gain unauthorised access, leading to compromise or data breach.

settings

Operational notes

Maintain a hardened baseline: regularly review installed server roles/features, disable or remove anything not required, and verify services/accounts are not left enabled by default.

Mapping detail

Mapping

Direction

Controls