Skip to content
arrow_back
search
ISM-1250 policy ASD Information Security Manual (ISM)

Limit Server Application User Account Privileges

Server applications have restricted user account access to the server's file system.

record_voice_over

Plain language

Limiting server applications' user account privileges means ensuring that the software running on your server has access only to what it absolutely needs. This is important because if these applications have too much access, they can be exploited by hackers to reach sensitive data, which could lead to data breaches or business disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The user accounts under which server applications run have limited access to their underlying server's file system.
policy ASD Information Security Manual (ISM) ISM-1250
priority_high

Why it matters

Excessive application access can lead to data breaches, as compromised apps can exploit unneeded privileges to access sensitive files.

settings

Operational notes

Audit server app run accounts; remove write/admin rights and restrict file paths to only what the app needs. Recheck after updates or config changes.

Mapping detail

Mapping

Direction

Controls