Skip to content
arrow_back
search
ISM-1297 policy ASD Information Security Manual (ISM)

Change Default Credentials on Network Devices

Ensure default accounts on network devices are changed or disabled for security.

record_voice_over

Plain language

This control is about changing or removing default usernames and passwords on network devices like routers and switches. It's important because if you leave them as the default, hackers can easily break into your network since these credentials are often publicly known.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Legal advice is sought prior to allowing privately-owned mobile devices and desktop computers to access systems or data.
policy ASD Information Security Manual (ISM) ISM-1297
priority_high

Why it matters

Without seeking legal advice, allowing BYOD can expose sensitive data to unauthorised access and lead to regulatory non-compliance.

settings

Operational notes

Document a BYOD approval workflow that requires recorded legal advice before privately-owned devices can access systems or data, with periodic review of that advice.

Mapping detail

Mapping

Direction

Controls