Skip to content
arrow_back
search
ISM-1934 policy ASD Information Security Manual (ISM)

Annual Review of DCSync Permissions

Review DCSync user permissions yearly and remove them if no longer needed.

record_voice_over

Plain language

In simple terms, this control is about regularly checking who has the ability to make secretive changes to your organisation's directory of users, like resetting passwords or accessing confidential information. This is important because if someone with these powers no longer needs them, they could accidentally or maliciously cause a data breach or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

User accounts with DCSync permissions are reviewed at least annually, and those without an ongoing requirement for the permissions have them removed.
policy ASD Information Security Manual (ISM) ISM-1934
priority_high

Why it matters

Failure to review DCSync permissions annually may allow unauthorised data access, risking severe breaches and operational disruptions.

settings

Operational notes

Schedule annual audits of DCSync roles and document findings to ensure any unnecessary permissions are swiftly revoked.

Mapping detail

Mapping

Direction

Controls