Skip to content
arrow_back
search
ISM-1647 policy ASD Information Security Manual (ISM)

Disable Privileged Access After 12 Months

Privileged system access is disabled if not revalidated within a year.

record_voice_over

Plain language

This control means that if someone has special access to important systems or resources, it needs to be checked and confirmed at least once a year. If it's not reviewed and confirmed, their access is turned off. This is crucial to ensure that only the right people can access sensitive information and systems, preventing potential misuse or accidental damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Privileged access to systems and their resources are disabled after 12 months unless revalidated.
policy ASD Information Security Manual (ISM) ISM-1647
priority_high

Why it matters

Failing to regularly revalidate privileged access risks unauthorised access, leading to data breaches or system misuse by former employees.

settings

Operational notes

Run a 12‑monthly review of privileged accounts; disable any not revalidated, record approvals, and remove access promptly when staff change roles or leave.

Mapping detail

Mapping

Direction

Controls