Skip to content
arrow_back
search
ISM-1825 policy ASD Information Security Manual (ISM)

Ensure Security Configuration Is Immutable by Users

Users cannot modify the security settings of security products.

record_voice_over

Plain language

This control means that users shouldn't be able to change the security settings on software that protects your systems, like antivirus programs or firewalls. This is important because if users could alter these settings, they might accidentally weaken the protection, making it easier for hackers to access sensitive information or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security product security settings cannot be changed by users.
policy ASD Information Security Manual (ISM) ISM-1825
priority_high

Why it matters

If users can change security product settings, they may disable protections, allowing malware, breaches, or data theft to occur.

settings

Operational notes

Restrict admin rights and enforce tamper protection so end users cannot modify security product policies; alert on attempted changes and review exceptions.

Mapping detail

Mapping

Direction

Controls