Skip to content
arrow_back
search
ISM-1508 policy ASD Information Security Manual (ISM)

Limit Privileged Access to Essential Duties Only

Only grant system privileges necessary for users to perform their job roles.

record_voice_over

Plain language

This control is about making sure that only the people who need access to important systems to do their jobs can get it. It's crucial because having too many people with unnecessary access can lead to mistakes, intentional harm, or data breaches, compromising your business's security.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Privileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
policy ASD Information Security Manual (ISM) ISM-1508
priority_high

Why it matters

Excess privileged access increases breach and insider-threat risk by enabling unauthorised changes to critical systems and sensitive data.

settings

Operational notes

Review privileged accounts and role mappings regularly; remove admin rights not required for duties and tightly control service account privileges to prevent privilege creep.

Mapping detail

Mapping

Direction

Controls