Skip to content
arrow_back
search
ISM-1654 policy ASD Information Security Manual (ISM)

Disable or Remove Internet Explorer 11

Ensure Internet Explorer 11 is not used to enhance system security.

record_voice_over

Plain language

Disabling or removing Internet Explorer 11 (IE11) means ensuring that people in your organisation can’t use this outdated software. This is important because IE11 no longer gets security updates, making your system vulnerable to cyber attacks if people continue to use it.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Internet Explorer 11 is disabled or removed.
policy ASD Information Security Manual (ISM) ISM-1654
priority_high

Why it matters

If Internet Explorer 11 remains enabled, its legacy attack surface can be exploited to deliver malware or enable unauthorised access and data loss.

settings

Operational notes

Confirm IE11 is removed/disabled via GPO/Intune and feature management; block iexplore.exe launch, and provide supported browser alternatives to users.

Mapping detail

Mapping

Direction

Controls