Skip to content
arrow_back
search
ISM-1953 policy ASD Information Security Manual (ISM)

Ensure Strong Management of Admin Account Credentials

Make sure admin account passwords in each domain are long, unique, and securely managed.

record_voice_over

Plain language

This control is about making sure the administrator accounts used to run your computer networks have passwords that are long, unique, and handled securely. This matters because weak or shared passwords make it easy for hackers to break into your systems, potentially leading to theft of sensitive information or disruption of services.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials for the built-in Administrator account in each domain are long, unique, unpredictable and managed.
policy ASD Information Security Manual (ISM) ISM-1953
priority_high

Why it matters

Weak or reused built-in domain Administrator credentials enable domain compromise, privilege escalation and widespread service disruption.

settings

Operational notes

Ensure each domain’s built-in Administrator password is long, unique and stored in a vault; rotate regularly and after suspected compromise.

Mapping detail

Mapping

Direction

Controls