Skip to content
arrow_back
search
ISM-1748 policy ASD Information Security Manual (ISM)

Prevent Changes to Email Client Security Settings

Users are not allowed to change the security settings on their email clients.

record_voice_over

Plain language

This control means that people using email programs at your business aren't allowed to change security settings like spam filters or encryption options. It's crucial because if these settings are altered, it might leave your business open to cyber threats such as phishing or data leaks, risking your privacy and finances.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Email client security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1748
priority_high

Why it matters

If users can change email client security settings, they may disable protections, increasing phishing risk, malware delivery, and data leakage.

settings

Operational notes

Enforce policy controls to lock email client security settings; routinely verify configs and record the approved secure baseline settings.

Mapping detail

Mapping

Direction

Controls