Skip to content
arrow_back
search
ISM-1402 policy ASD Information Security Manual (ISM)

Protecting Stored Credentials with Security Measures

Store credentials securely using a password manager, hardware module, or by enhancing them with techniques before saving.

record_voice_over

Plain language

Storing credentials safely is like locking away your most important keys and passwords so only you can access them. If this isn't done, your sensitive information like bank details or personal data could be at risk of being stolen, leading to potential financial loss or identity theft.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials stored on systems are protected by a password manager; a hardware security module; or by salting, hashing and stretching them before storage within a database.
policy ASD Information Security Manual (ISM) ISM-1402
priority_high

Why it matters

If credentials aren’t stored in a password manager, HSM, or salted/hashed/stretched in a database, attackers can recover passwords and gain unauthorised access.

settings

Operational notes

Ensure stored credentials are only kept in an approved password manager or HSM; for databases, verify salting plus strong hashing and stretching parameters and review them periodically.

Mapping detail

Mapping

Direction

Controls