Skip to content
arrow_back
search
ISM-1875 policy ASD Information Security Manual (ISM)

Monthly Network Scans for Clear-Text Credentials

Monthly scans check for passwords or credentials that are not encrypted.

record_voice_over

Plain language

This control is about running regular checks on your computer network to make sure no passwords or login details are lying around in plain view. If these details aren't protected, cyber criminals could easily access your systems, leading to data theft or unauthorised access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Networks are scanned at least monthly to identify any credentials that are being stored in the clear.
policy ASD Information Security Manual (ISM) ISM-1875
priority_high

Why it matters

Storing clear-text credentials can lead to unauthorised access, credential reuse, data breaches, and loss of trust.

settings

Operational notes

Run at least monthly scans to detect clear-text credentials in files, configs and logs; remediate findings and re-scan to confirm.

Mapping detail

Mapping

Direction

Controls