Skip to content
arrow_back
search
ISM-1590 policy ASD Information Security Manual (ISM)

Mandate Credential Changes Upon Compromise

Change user account credentials if they're compromised or potentially insecure.

record_voice_over

Plain language

This control is about making sure that sensitive information used to access systems—like passwords—gets changed if it's thought to be compromised or not secure. This is important because if someone else gets access to these credentials, they could pretend to be an authorised user and breach your systems, leading to data loss or other serious problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials for user accounts are changed if: - they are compromised - they are suspected of being compromised - they are discovered stored on networks in the clear - they are discovered being transferred across networks in the clear - membership of a shared user account changes.
policy ASD Information Security Manual (ISM) ISM-1590
priority_high

Why it matters

Not changing credentials after compromise, suspected compromise, cleartext exposure, or shared account membership changes can enable unauthorised access and data breaches.

settings

Operational notes

Monitor for credential compromise indicators (alerts, leaked passwords), cleartext storage/transfer, and shared account membership changes; reset affected credentials immediately.

Mapping detail

Mapping

Direction

Controls