Skip to content
arrow_back
search
ISM-1585 policy ASD Information Security Manual (ISM)

Prevent User Changes to Browser Security Settings

Users cannot modify web browser security settings to ensure consistent protection.

record_voice_over

Plain language

This control means that employees and users in an organisation cannot change the security settings of their web browsers. This is important because if users can reduce security settings, they might expose the organisation to online threats like viruses or hackers, leading to data breaches or loss of sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Web browser security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1585
priority_high

Why it matters

If users can change browser security settings, they may disable protections (e.g. safe browsing, blocking) leading to phishing, malware and data theft.

settings

Operational notes

Enforce locked-down browser security settings via Group Policy/MDM; routinely verify policies prevent user changes and remediate any local overrides.

Mapping detail

Mapping

Direction

Controls