Skip to content
arrow_back
search
ISM-1852 policy ASD Information Security Manual (ISM)

Limit Unprivileged Access to Essential Functions

Users can only access what they need to do their work, nothing extra.

record_voice_over

Plain language

This control is about ensuring that employees and software have access only to the systems and information they need to do their jobs—nothing more. If people can access more than they should, it increases the risk of mistakes or intentional harm, like data breaches or loss of sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unprivileged access to systems and their resources is limited to only what is required for users and services to undertake their duties.
policy ASD Information Security Manual (ISM) ISM-1852
priority_high

Why it matters

Excess access can lead to data breaches or loss by enabling users to retrieve, alter or delete sensitive info beyond their job needs.

settings

Operational notes

Apply least privilege with RBAC: restrict default access, approve exceptions, and review user/service permissions regularly to remove unnecessary rights.

Mapping detail

Mapping

Direction

Controls