Skip to content
arrow_back
search
ISM-1603 policy ASD Information Security Manual (ISM)

Disabling Vulnerable Authentication Methods

Turn off login methods that can be tricked into accepting false entries.

record_voice_over

Plain language

This control is about turning off ways to log in that can easily be tricked. If we don't do this, someone could pretend to be you and get into your systems, causing chaos by stealing information or messing things up.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication methods susceptible to replay attacks are disabled.
policy ASD Information Security Manual (ISM) ISM-1603
priority_high

Why it matters

If replay-susceptible authentication methods remain enabled, attackers can capture and reuse credentials to impersonate users, causing breaches and disruption.

settings

Operational notes

Audit and disable replay-susceptible methods (e.g., NTLMv1, PAP, CHAP); enforce MFA and modern protocols like Kerberos, TLS, and SCRAM.

Mapping detail

Mapping

Direction

Controls