Skip to content
arrow_back
search
ISM-1596 policy ASD Information Security Manual (ISM)

Avoid Reusing Credentials Across Systems

Users should not use the same passwords on different systems for better security.

record_voice_over

Plain language

This control is about not using the same password for different accounts or systems. It's important because if someone gets access to one password, they could break into all your accounts and do serious harm, like stealing money or sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials are not reused by users across different systems.
policy ASD Information Security Manual (ISM) ISM-1596
priority_high

Why it matters

Reusing passwords increases the risk of credential stuffing, potentially causing financial loss or compromise of sensitive data across multiple systems.

settings

Operational notes

Require unique passwords per system and promote password managers to generate/store strong credentials; block known-breached passwords to reduce reuse.

Mapping detail

Mapping

Direction

Controls