Skip to content
arrow_back
search
ISM-1648 policy ASD Information Security Manual (ISM)

Disabling Inactive Privileged Access to Systems

Access with special privileges is disabled if not used for 45 days to enhance system security.

record_voice_over

Plain language

This control is about turning off special access rights to systems if they haven't been used in 45 days. It matters because people with special privileges can make big changes or access sensitive information. If their access isn't switched off when they're not using it, it could be a way for hackers to cause damage if those accounts get hacked.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Privileged access to systems and their resources are disabled after 45 days of inactivity.
policy ASD Information Security Manual (ISM) ISM-1648
priority_high

Why it matters

If inactive privileged access is not disabled after 45 days, dormant admin accounts can be hijacked to gain elevated access and compromise systems.

settings

Operational notes

Run a weekly report of privileged account activity and automatically disable privileged access after 45 days of inactivity; alert owners at 30/40 days.

Mapping detail

Mapping

Direction

Controls