Skip to content
arrow_back
search
ISM-1954 policy ASD Information Security Manual (ISM)

Enforce Random Credentials for Administrator Accounts

Ensure admin and service account passwords are randomly generated to improve security.

record_voice_over

Plain language

This control means that passwords for important accounts, like administrators who manage your computer systems, should be randomly generated instead of being chosen by people. This is important because if someone guesses or steals a simple password, they could take control of your systems and data, causing financial and operational problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials for built-in Administrator accounts, break glass accounts, local administrator accounts and service accounts are randomly generated.
policy ASD Information Security Manual (ISM) ISM-1954
priority_high

Why it matters

If administrator, break glass, local admin and service account passwords are not randomly generated, attackers can guess/reuse them to gain privileged access and cause data breaches.

settings

Operational notes

Use a password vault/LAPS to randomly generate and rotate credentials for built-in Administrator, break glass, local admin and service accounts; audit for reuse and enforce rotation.

Mapping detail

Mapping

Direction

Controls