Skip to content
arrow_back
search
ISM-1249 policy ASD Information Security Manual (ISM)

Limit Server Application User Privileges

Server apps must run separately with only the necessary permissions to operate.

record_voice_over

Plain language

This control is about making sure that any software running on your server doesn't have more power than it needs. If an application has too many permissions, a hacker could exploit these and cause damage or access sensitive information. By keeping permissions to the bare minimum, we limit what harm can be done if there's a breach.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Server applications are configured to run as a separate user account with the minimum privileges needed to perform their functions.
policy ASD Information Security Manual (ISM) ISM-1249
priority_high

Why it matters

If server apps run with excessive privileges or shared accounts, an attacker can escalate access, alter data, or disrupt services.

settings

Operational notes

Run each server application under its own dedicated account; review granted rights and group memberships regularly and remove any no longer required.

Mapping detail

Mapping

Direction

Controls