Skip to content
arrow_back
search
ISM-1955 policy ASD Information Security Manual (ISM)

Regularly Change Compromised Credentials

Change computer account passwords every 30 days or if they're compromised or suspected to be.

record_voice_over

Plain language

This rule is about regularly changing your computer account passwords, especially if they're compromised or might be. It's important because if someone else gets your password, they could access all your sensitive information and misuse it before you even realise there's a problem.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Credentials for computer accounts are changed if they are compromised, they are suspected of being compromised or they have not been changed in the past 30 days.
policy ASD Information Security Manual (ISM) ISM-1955
priority_high

Why it matters

Failure to change compromised or stale computer account credentials can enable unauthorised access, data breaches and service misuse within days.

settings

Operational notes

Change computer account credentials immediately on suspected/confirmed compromise, and enforce rotation so they are changed at least every 30 days (e.g., scheduled tasks with alerts).

Mapping detail

Mapping

Direction

Controls