Skip to content
arrow_back
search
ISM-1806 policy ASD Information Security Manual (ISM)

Change Default User Credentials During Setup

Change or remove default user accounts when setting up applications to enhance security.

record_voice_over

Plain language

When setting up new software or systems, it's important to change or remove any user accounts or passwords that come pre-installed. Hackers often know these default accounts and can use them to break into your system, putting your information at risk. By changing them, you're adding an extra layer of security right from the start.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Default user accounts or credentials for user applications, including for any pre-configured user accounts, are changed, disabled or removed during initial setup.
policy ASD Information Security Manual (ISM) ISM-1806
priority_high

Why it matters

If default credentials remain unchanged, attackers can log in using publicly known vendor defaults, leading to unauthorised access and data breaches.

settings

Operational notes

During commissioning, change or disable all vendor default accounts (including built-in and pre-configured users) and verify with periodic account audits and login tests.

Mapping detail

Mapping

Direction

Controls