Skip to content
arrow_back
search
ISM-1861 policy ASD Information Security Manual (ISM)

Enable Local Security Authority Protection

Ensure the system has measures to secure login details against unauthorized access.

record_voice_over

Plain language

This control is about making sure that your computer systems have a strong lock on your login information to prevent unauthorised access. If you don't protect these login details, someone could break into your system and potentially steal sensitive information, causing both reputational and financial harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Local Security Authority protection functionality is enabled.
policy ASD Information Security Manual (ISM) ISM-1861
priority_high

Why it matters

If LSA protection is not enabled, malware can dump LSASS credentials, enabling unauthorised access and lateral movement.

settings

Operational notes

Verify LSA protection is enabled (RunAsPPL) after patching or upgrades, and alert if LSASS protection is disabled.

Mapping detail

Mapping

Direction

Controls