Skip to content
arrow_back
search
ISM-1745 policy ASD Information Security Manual (ISM)

Enable Security Features for System Protection

Ensure essential security features are active to protect the system during startup.

record_voice_over

Plain language

This control is about activating security features on your computer systems before anything else starts up, to keep them safe and secure every time you turn them on. If these protections are not active, your system could be vulnerable to viruses or tampering before your usual defences kick in, putting your data and operations at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Early Launch Antimalware, Secure Boot, Trusted Boot and Measured Boot functionality is enabled.
policy ASD Information Security Manual (ISM) ISM-1745
priority_high

Why it matters

If ELAM, Secure Boot, Trusted Boot and Measured Boot are not enabled, boot-time malware or rootkits can tamper with startup, bypassing defences and risking compromise.

settings

Operational notes

Periodically confirm ELAM, Secure Boot, Trusted Boot and Measured Boot are enabled in UEFI/OS, and review boot attestation or event logs for unexpected boot changes.

Mapping detail

Mapping

Direction

Controls