Skip to content
arrow_back
search
ISM-1620 policy ASD Information Security Manual (ISM)

Ensure Privileged Accounts are Secured in AD

Privileged user accounts must belong to a special security group for extra protection.

record_voice_over

Plain language

This control is about making sure people with special access to important parts of your computer system are grouped together for extra security. If you don't do this, these privileged accounts might be easier targets for hackers, which could allow them to access sensitive information and cause serious harm to your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Privileged user accounts are members of the Protected Users security group.
policy ASD Information Security Manual (ISM) ISM-1620
priority_high

Why it matters

If privileged AD accounts are not in Protected Users, credentials can be more easily stolen or reused, enabling elevated access and wider compromise.

settings

Operational notes

Regularly audit Protected Users membership in Active Directory and remove unauthorised accounts; ensure privileged users are added and exceptions are documented.

Mapping detail

Mapping

Direction

Controls