Skip to content
arrow_back
search
E8-RB-ML1.5 bolt ASD Essential Eight

Unprivileged accounts cannot access others' backups

Ensure that unprivileged accounts can't access other users' backups.

record_voice_over

Plain language

This control is about making sure that people who don't have special permissions can't see or access other people’s backup files. Imagine if someone in your office could look at your personal emails or documents just because they have access to the backup system—that's a huge privacy risk. By enforcing this control, you prevent unauthorised access and potential data leaks.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Unprivileged accounts cannot access backups belonging to other accounts.
bolt ASD Essential Eight E8-RB-ML1.5
priority_high

Why it matters

If unprivileged users can access other users' backups, sensitive data can be exposed, causing privacy breaches and unauthorised disclosure.

settings

Operational notes

Review backup ACLs regularly and confirm only owners/admins can read others' backup sets; investigate any cross-user access events in logs.

Mapping detail

Mapping

Direction

Controls