Skip to content
arrow_back
search
ISM-1824 policy ASD Information Security Manual (ISM)

Prevent Changes to PDF Application Security Settings

Users are restricted from changing security settings in PDF applications.

record_voice_over

Plain language

This control means that people using PDF applications at work cannot change the security settings. This matters because if someone tampers with these settings, it could make sensitive documents easier to steal or tamper with, which might expose personal or business information to unauthorized people.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

PDF application security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1824
priority_high

Why it matters

Allowing users to change PDF security settings can enable copying, printing or editing of protected PDFs, increasing the risk of sensitive data exposure.

settings

Operational notes

Lock PDF application security settings using GPO/MDM and prevent local overrides; periodically verify settings and report any user-changeable options.

Mapping detail

Mapping

Direction

Controls