Skip to content
arrow_back
search
ISM-1311 policy ASD Information Security Manual (ISM)

Prevent Use of Insecure SNMP Versions on Networks

Avoid using SNMP versions 1 and 2, as they are insecure for network management.

record_voice_over

Plain language

This control is about ensuring that your network doesn't use old, unsafe methods to manage devices, specifically versions 1 and 2 of something called the Simple Network Management Protocol (SNMP). If these outdated versions are used, hackers can easily snoop on or change your network data, leading to information theft or network disruption.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SNMP version 1 and SNMP version 2 are not used on networks.
policy ASD Information Security Manual (ISM) ISM-1311
priority_high

Why it matters

If SNMPv1/v2 are used, attackers can sniff community strings and modify device settings via unauthenticated or weakly protected SNMP traffic.

settings

Operational notes

Scan and audit network devices to confirm SNMPv1/v2 are disabled; allow only SNMPv3 with authentication and encryption, and remove legacy configs.

Mapping detail

Mapping

Direction

Controls