Skip to content
arrow_back
search
ISM-1883 policy ASD Information Security Manual (ISM)

Restrict Privileged Access to Necessary Service Duties

Only necessary access is allowed for users to perform their duties online.

record_voice_over

Plain language

This control means that only people who need special access to important parts of your online services to do their job should have it. It’s important because too many people with access can lead to mistakes or intentional harm, like data theft or system damage, which can cost money and damage your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Privileged user accounts explicitly authorised to access online services are strictly limited to only what is required for users and services to undertake their duties.
policy ASD Information Security Manual (ISM) ISM-1883
priority_high

Why it matters

Over-privileged accounts for online services increase misuse and compromise risk, enabling unauthorised changes or data access beyond service duties.

settings

Operational notes

Regularly review privileged access for online services and remove unneeded roles/permissions so accounts only have access required for service duties.

Mapping detail

Mapping

Direction

Controls