Skip to content
arrow_back
search
E8-RB-ML1.6 bolt ASD Essential Eight

Prevent unprivileged accounts from modifying and deleting backups

Ensure non-admin users cannot change or remove backup files.

record_voice_over

Plain language

This control is about making sure that regular staff members can't change or delete important backup files. Just think about how bad it would be if a virus or a mistake wiped out all your company's critical data. These backups are your safety net, and you want only trusted staff to have the power to alter them.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1

Official control statement

Unprivileged accounts are prevented from modifying and deleting backups.
bolt ASD Essential Eight E8-RB-ML1.6
priority_high

Why it matters

Without this control, insiders or malware could modify or delete backups, preventing recovery after ransomware or outages and causing major data loss.

settings

Operational notes

Restrict backup delete/modify rights to backup admins only; enforce separate accounts/MFA and regularly audit permissions to keep backups immutable.

Mapping detail

Mapping

Direction

Controls