Skip to content
arrow_back
search
ISM-1470 policy ASD Information Security Manual (ISM)

Disable Unneeded Software Functions and Services

Turn off or remove unnecessary parts and services of common software to improve security.

record_voice_over

Plain language

This control is about turning off or removing parts of software that you're not using, like certain features in a web browser or email program. It matters because if you don't do this, you might accidentally leave the door open for hackers or malware, potentially leading to data being stolen or your computers being taken over.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unneeded components, services and functionality of office productivity suites, web browsers, email clients, PDF applications and security products are disabled or removed.
policy ASD Information Security Manual (ISM) ISM-1470
priority_high

Why it matters

Leaving unnecessary software functions enabled increases the attack surface, exposing exploitable vulnerabilities and enabling malware or unauthorised access.

settings

Operational notes

Regularly audit office, browser, email and PDF app settings; disable/remove unused add-ons, services and features, and prevent re-enabling without approval.

Mapping detail

Mapping

Direction

Controls