Skip to content
arrow_back
search
ISM-1584 policy ASD Information Security Manual (ISM)

Prevent Unauthorised Changes to Security Settings

Ensure non-admin users cannot change or disable security settings on operating systems.

record_voice_over

Plain language

This control is about making sure that everyday users can't mess with important security settings on their computers. It matters because if anyone could change these settings, they might accidentally or intentionally turn off protections that keep your data safe and secure.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unprivileged users are prevented from bypassing, disabling or modifying security functionality of operating systems.
policy ASD Information Security Manual (ISM) ISM-1584
priority_high

Why it matters

If unprivileged users can change OS security settings, protections may be disabled, enabling malware execution or unauthorised access.

settings

Operational notes

Restrict OS security setting changes to admins via GPO/MDM, and monitor/audit events for attempts to disable or bypass controls.

Mapping detail

Mapping

Direction

Controls