Skip to content
arrow_back
search
ISM-1260 policy ASD Information Security Manual (ISM)

Secure Server Applications by Changing Default Credentials

Change or remove default user accounts and passwords in server apps to enhance security from the start.

record_voice_over

Plain language

This control is about changing the default usernames and passwords on your server applications. It matters because hackers often know these defaults and can easily gain access to your system if they aren't changed, leading to potential data breaches or outages.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Default user accounts or credentials for server applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
policy ASD Information Security Manual (ISM) ISM-1260
priority_high

Why it matters

If default accounts or passwords remain, attackers can log in easily, take over the server application and access or alter sensitive data.

settings

Operational notes

During install, change/disable/remove all default and pre-configured accounts; routinely scan apps for default logins and rotate credentials after upgrades.

Mapping detail

Mapping

Direction

Controls