Skip to content
arrow_back
search
ISM-2044 policy ASD Information Security Manual (ISM)

Prevent Default Credentials in Software Installations

Ensure software does not come with default passwords; new credentials are set during installation.

record_voice_over

Plain language

Setting up software with default passwords is risky because hackers can easily guess or find these common passwords online, just like a skeleton key that opens many doors. To stay secure, it’s crucial to create unique passwords for each new software installation, preventing unauthorised access and potential data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Software has no default credentials; however, if credentials are required, they are created on first install by the installing organisation.
policy ASD Information Security Manual (ISM) ISM-2044
priority_high

Why it matters

Default credentials let attackers guess or reuse logins to gain unauthorised access, leading to data compromise and service disruption.

settings

Operational notes

On first install, create unique admin credentials (no vendor defaults), store them in a password manager, and verify all default accounts are removed/disabled.

Mapping detail

Mapping

Direction

Controls