Skip to content
arrow_back
search
ISM-2049 policy ASD Information Security Manual (ISM)

Enforcing Re-authentication After Permission Changes

Users must log in again if their account permissions change.

record_voice_over

Plain language

If a user's access levels or passwords change, they have to log in again to confirm their identity. This is important because if someone’s permissions are updated, like giving them more access or changing their username, it could mean a security risk if it’s not really them or their access isn’t needed anymore.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When user permissions or credentials are changed, software forces all impacted users to re-authenticate.
policy ASD Information Security Manual (ISM) ISM-2049
priority_high

Why it matters

If users aren’t forced to re-authenticate after permission or credential changes, old sessions may retain access and enable unauthorised activity.

settings

Operational notes

Expire sessions and require immediate re-authentication for all affected accounts whenever permissions, roles, passwords or MFA settings change.

Mapping detail

Mapping

Direction

Controls