Skip to content
arrow_back
search
ISM-1595 policy ASD Information Security Manual (ISM)

Ensure Initial User Credentials Are Changed

Users must change their initial passwords the first time they log in to enhance security.

record_voice_over

Plain language

When someone gets a new user account, they are given initial login details. It’s crucial for security to change this initial password the first time they log in. If users don't update their password, it could be easy for someone else to guess it, potentially allowing them unauthorized access to the system and sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials provided to users are changed on first use.
policy ASD Information Security Manual (ISM) ISM-1595
priority_high

Why it matters

Failure to change initial passwords increases the risk of unauthorised access, potentially leading to data breaches and system compromise.

settings

Operational notes

Configure IAM/AD to force a password change at first sign-in and block shared/default credentials; monitor new accounts to confirm the change occurs promptly.

Mapping detail

Mapping

Direction

Controls