Skip to content
arrow_back
search
ISM-1597 policy ASD Information Security Manual (ISM)

Ensuring Credential Input Obscurity

Passwords and personal credentials are hidden when entered in systems to enhance security.

record_voice_over

Plain language

When you enter a password or personal details into a system, this control ensures that information isn't visible to anyone nearby. This matters because if someone can see your credentials as you type, they could misuse them to access sensitive information or systems they shouldn't.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials are obscured as they are entered into systems.
policy ASD Information Security Manual (ISM) ISM-1597
priority_high

Why it matters

If credential entry fields are not masked (e.g., password dots), shoulder-surfers or screen recording can capture credentials and enable unauthorised access.

settings

Operational notes

Verify all login and admin forms mask passwords/PINs, including remote sessions; test after updates, and audit configurations to prevent plaintext entry display.

Mapping detail

Mapping

Direction

Controls