Skip to content
arrow_back
search
ISM-1263 policy ASD Information Security Manual (ISM)

Enforce Unique Accounts for Server Administration

Administrators must use unique accounts to manage each server application.

record_voice_over

Plain language

Each administrator needs to have their own account when managing software on servers. This is important because if everyone shares the same account, you can't track who made changes. Mistakes or malicious actions can then go undetected, putting the entire server at risk by making it hard to figure out who did what.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unique privileged user accounts are used for administering individual server applications.
policy ASD Information Security Manual (ISM) ISM-1263
priority_high

Why it matters

Without unique admin accounts, tracing changes is difficult, increasing the risk of undetected malicious actions and operational disruptions.

settings

Operational notes

Regularly audit privileged accounts to confirm each administrator uses a unique account per server application, and alert on any shared credentials or concurrent logons.

Mapping detail

Mapping

Direction

Controls