Skip to content
arrow_back
search
ISM-1304 policy ASD Information Security Manual (ISM)

Secure Network Devices by Changing Default Credentials

During setup, change or remove default login details for network devices to enhance security.

record_voice_over

Plain language

Changing the default username and password on network devices, like routers or modems, is crucial to prevent unauthorised access to your network. If someone with bad intentions finds out these default settings, they could easily get into your system, interfere with operations, or steal sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Default user accounts or credentials for network devices, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
policy ASD Information Security Manual (ISM) ISM-1304
priority_high

Why it matters

If default device accounts are left unchanged, attackers can log in using known defaults and take control of routers/switches, enabling network compromise and data loss.

settings

Operational notes

During initial setup, change or disable all default and pre-configured accounts on network devices; periodically verify configs and review logs for repeated failed/default-credential attempts.

Mapping detail

Mapping

Direction

Controls