Skip to content
arrow_back
search
ISM-2048 policy ASD Information Security Manual (ISM)

Restrict Non-Admins from Changing Permissions

Non-admin users can't change their own permissions or privileges in software with multiple user roles.

record_voice_over

Plain language

This control means that people who aren't administrators shouldn't be able to change their own permissions in software that has different user roles. It's important because if non-administrators could change their own permissions, they might get access to sensitive information they shouldn't see.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Where software supports multiple user roles, non-administrative users are prevented from altering their profile permissions or privileges.
policy ASD Information Security Manual (ISM) ISM-2048
priority_high

Why it matters

If non-admin users can alter their own permissions, they may self-escalate privileges, access restricted data, and tamper with system settings, causing a breach or outage.

settings

Operational notes

Verify non-admin roles cannot edit their own role memberships or privileges; routinely review access controls and test that permission-change functions are restricted to administrators.

Mapping detail

Mapping

Direction

Controls