Skip to content
arrow_back
search
ISM-1412 policy ASD Information Security Manual (ISM)

Web Browser Hardening with Strict Guidelines

Web browsers must be set with the strictest security settings per ASD and vendor guides.

record_voice_over

Plain language

This control means that your web browser – the program you use to browse the internet – should have the highest level of security settings according to guidelines from both the Australian Signals Directorate (ASD) and the makers of the browser. This is crucial because if your web browser isn't secure, it can be an easy way for hackers to get into your computer, leading to data theft or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Web browsers are hardened using ASD and vendor hardening guidance, with the most restrictive guidance taking precedence when conflicts occur.
policy ASD Information Security Manual (ISM) ISM-1412
priority_high

Why it matters

Without ASD/vendor browser hardening (most restrictive applied), weak defaults can enable drive‑by attacks, credential theft and unauthorised data access via the browser.

settings

Operational notes

Regularly audit browser policies against ASD and vendor baselines, applying the most restrictive setting where guidance conflicts, and rapidly update configs for new advisories.

Mapping detail

Mapping

Direction

Controls