Skip to content
arrow_back
search
ISM-1946 policy ASD Information Security Manual (ISM)

Restrict Write Access to Certificate Templates

Ensure regular users can't change certificate templates to maintain security.

record_voice_over

Plain language

This control is about making sure that regular users in your organisation can't change the templates used to create digital certificates. These certificates are crucial for secure communication in your IT systems. If unauthorised people can change them, they might create fake certificates that compromise your security, leading to data breaches or system misuse.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Unprivileged user accounts do not have write access to certificate templates.
policy ASD Information Security Manual (ISM) ISM-1946
priority_high

Why it matters

Unauthorised template changes could lead to fraudulent certificates, compromising secure communications and exposing systems to data breaches.

settings

Operational notes

Audit certificate template ACLs and AD CS role assignments regularly so only privileged admins can write or publish templates; remove any unprivileged write access.

Mapping detail

Mapping

Direction

Controls