Skip to content
arrow_back
search
ISM-1749 policy ASD Information Security Manual (ISM)

Limit Cached Credentials to Single Logon

Users' credentials are stored only for their last login to enhance security.

record_voice_over

Plain language

This control means that when you log into your work computer or system, it will only remember details from your last login. This is important because if a hacker gains access to your computer, they'll only find your most recent login details, reducing the chance they can get into other systems or services with older credentials.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Cached credentials are limited to one previous logon.
policy ASD Information Security Manual (ISM) ISM-1749
priority_high

Why it matters

Failure to limit cached credentials risks unauthorised access using older logins, exposing sensitive data and escalating potential breaches.

settings

Operational notes

Set Windows 'CachedLogonsCount' to 1 via policy and audit the setting regularly to detect configuration drift.

Mapping detail

Mapping

Direction

Controls