Skip to content
arrow_back
search
ISM-1406 policy ASD Information Security Manual (ISM)

Use SOEs for Workstations and Servers

Use pre-configured software setups for all computers and servers to ensure consistency and security.

record_voice_over

Plain language

Standard Operating Environments (SOEs) mean setting up computers and servers to all use the same, secure software and settings. This matters because it keeps everything consistent and safe, and helps prevent hackers from finding weak spots by always having the latest protective measures in place.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SOEs are used for workstations and servers.
policy ASD Information Security Manual (ISM) ISM-1406
priority_high

Why it matters

Without SOEs, workstations and servers diverge from approved baselines, increasing misconfiguration risk and making patching and compliance harder.

settings

Operational notes

Maintain and version SOE images; patch and harden regularly, and verify deployed builds match the SOE to prevent configuration drift.

Mapping detail

Mapping

Direction

Controls