Skip to content
arrow_back
ISM-1939policyASD Information Security Manual (ISM)

Minimise Members in Privileged Security Groups

Limit the number of users in highly privileged security groups like Domain Admins to enhance security.

record_voice_over

Plain language

This control is about keeping the list of people who have the most powerful access to your organisation's digital systems as small as possible. It matters because if too many people have high-level access, the risk of accidental or malicious damage to your data or systems increases.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The number of user accounts that are members of the Domain Admins, Enterprise Admins or other highly privileged security groups is minimised.
policyASD Information Security Manual (ISM)ISM-1939
priority_high

Why it matters

Having too many members in privileged groups can increase the risk of data breaches or system failures due to misuse or errors.

settings

Operational notes

Regularly review and minimise membership in privileged security groups to limit exposure. Ensure any access changes are well-documented and authorised.

build

Implementation tips

  • System owners should review the list of users with high-level access. This involves regularly checking who is in groups like Domain Admins and removing any who don't absolutely need this level of access.
  • IT managers should work with HR to ensure that departing employees are promptly removed from privileged groups. They should set up a process where HR notifies IT immediately when someone leaves the organisation.
  • Managers should periodically meet with IT to assess the necessity of privileged access for each role. Hold these meetings quarterly and discuss any changes in job responsibilities that might affect access needs.
  • IT teams should implement a request-and-approval process for granting privileged access. Require written justification for any new additions to privileged groups and approval from a senior manager.
  • Audit teams should establish a monitoring system to log and review all activity done by privileged accounts. Use tools that provide alerts for unusual activity to catch potential misuse quickly.
fact_check

Audit / evidence tips

  • Askthe current list of members in Domain Admins and similar groupsLook atthe job roles of each member listedGoodshows only essential personnel, aligned with their roles
  • Look atthe timestamps and who authorised changesGoodwill show timely updates and appropriate approvals
  • Askrecords of quarterly access reviews by IT and managersLook atmeeting notes or review checklistsGoodprovides documentation showing thoughtful review with actions taken
  • Look atdetailed steps and HR-IT collaborationGooddescribes a clear, prompt process with roles and responsibilities
  • Asklogs on activities performed by privileged accountsLook atlogged events for anything unusualGoodshows regular log reviews with no unexplained, unusual access
link

Cross-framework mappings

How ISM-1939 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
linkRelated(1)expand_less
Annex A 8.2Annex A 8.2 requires privileged access rights to be restricted and managed, including limiting who holds highly privileged permissions

E8

ControlNotesDetails
layersPartially meets(1)expand_less
handshakeSupports(5)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls