Skip to content
arrow_back
search
ISM-1969 policy ASD Information Security Manual (ISM)

Preventing Accidental Execution of Malicious Code

Ensure malicious code cannot accidentally run by treating it before storage or communication.

record_voice_over

Plain language

This control is about making sure that bad software, which can harm your computers and steal your information, doesn't run by accident. It's important because if this harmful code does run, it can disrupt your business, damage your reputation, and cost a lot of money to fix.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Malicious code, when stored or communicated, is treated beforehand to prevent accidental execution.
policy ASD Information Security Manual (ISM) ISM-1969
priority_high

Why it matters

Failure to pre-treat malicious code can lead to accidental execution, resulting in data breaches, operational disruption, and financial loss.

settings

Operational notes

Sanitise or quarantine captured malware samples (e.g., password-protect archives) before storing or sharing to prevent execution.

Mapping detail

Mapping

Direction

Controls