Skip to content
arrow_back
search
ISM-1404 policy ASD Information Security Manual (ISM)

Disabling Inactive User Access After 45 Days

If a user doesn't use their system access for 45 days, it's disabled to keep the system secure.

record_voice_over

Plain language

Every 45 days, if someone hasn't used their access to a system, it gets turned off. This helps protect your organisation by making sure only active and engaged users can access important systems, reducing the risk of unauthorised access if an account is forgotten or abandoned.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unprivileged access to systems and their resources are disabled after 45 days of inactivity.
policy ASD Information Security Manual (ISM) ISM-1404
priority_high

Why it matters

If inactive unprivileged accounts aren’t disabled after 45 days, stale credentials can be exploited for unauthorised access and data compromise.

settings

Operational notes

Review last logon/activity regularly and automatically disable unprivileged user accounts after 45 days of inactivity, with documented reactivation approval.

Mapping detail

Mapping

Direction

Controls