Skip to content
arrow_back
ISM-1942policyASD Information Security Manual (ISM)

Domain Computers Group Privilege Restriction

The Domain Computers group should not have any privileged access to maintain security.

record_voice_over

Plain language

This control ensures that computers in a network don't have special access to sensitive areas. If this isn't done, malicious people could exploit those computers to steal data or cause harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The Domain Computers security group is not a member of any privileged or highly privileged security groups.
policyASD Information Security Manual (ISM)ISM-1942
priority_high

Why it matters

Without this control, computers in the network could be hijacked to access sensitive information, leading to security breaches and data loss.

settings

Operational notes

Regularly review and update security group policies to maintain restrictions on the Domain Computers group, preventing unauthorised access.

build

Implementation tips

  • IT team should review the membership of the Domain Computers group. Use user management tools to ensure it doesn't have privileged access.
  • System owner must confirm that no computers have been added to high-level groups. Check configurations monthly and document findings.
  • IT administrator should use monitoring tools to track changes. Set alerts for any change to the Domain Computers group's permissions.
  • Managers should request regular security briefings from IT. Discuss the importance of keeping computers out of privileged groups and understand potential impacts.
  • Audit staff should schedule routine checks. Use checklists to verify Domain Computers is limited to non-privileged access.
fact_check

Audit / evidence tips

  • Aska listing of current security group membershipsLook atgroup memberships to ensure Domain Computers isn't part of privileged groupsGoodA list showing Domain Computers in only basic access groups
  • GoodLogs showing change history with authorised approvals
  • Askto see permissions granted to the Domain Computers groupLook atexcessive permissions beyond standard computer needsGoodAccess levels appropriate only for basic machine operations
  • Look atspecific mention of Domain Computer group restrictionsGoodPolicy clearly stating Domain Computers cannot join privileged groups
  • Aska recent internal audit report on access management. Examine findings related to Domain ComputersGoodAudit confirms no unauthorised privileged group access
link

Cross-framework mappings

How ISM-1942 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.2ISM-1942 requires that the Active Directory **Domain Computers** group is not a member of any privileged or highly-privileged security gr...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls