Skip to content
arrow_back
search
ISM-1746 policy ASD Information Security Manual (ISM)

Restrict File System Permission Changes

Only authorised users can change file permissions for approved applications to maintain system security.

record_voice_over

Plain language

This control ensures that only people who are allowed to do so can change the permissions for important files and folders on your computer or server. This is important because if the wrong person changes these permissions, it could make sensitive information vulnerable to being seen or altered by unauthorised people, leading to potential data breaches or system malfunctions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When implementing application control using path rules, only approved users can change file system permissions for approved files and folders.
policy ASD Information Security Manual (ISM) ISM-1746
priority_high

Why it matters

If unapproved users can change permissions on approved paths, they can grant access to protected files, enabling data theft or service disruption.

settings

Operational notes

When using path rules, restrict chmod/ACL changes to approved admin groups; review permission change rights and audit logs on approved folders regularly.

Mapping detail

Mapping

Direction

Controls