Skip to content
arrow_back
search
ISM-1823 policy ASD Information Security Manual (ISM)

Prevent Users from Changing Security Settings in Apps

Users can't change security settings in office software, keeping configurations secure.

record_voice_over

Plain language

This control means that users in your organisation shouldn't be able to change the security settings in office software like Microsoft Word or Excel. It's important because if users could change these settings, they might, whether intentionally or accidentally, weaken the protections that keep your business data safe from cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Office productivity suite security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1823
priority_high

Why it matters

If users can change Office app security settings, protections like macro blocking and protected view may be disabled, increasing data exposure and malware risk.

settings

Operational notes

Enforce Office policy (e.g., Group Policy/Intune) so users cannot modify security options such as macro settings, Protected View, or trusted locations; audit regularly.

Mapping detail

Mapping

Direction

Controls