Skip to content
arrow_back
search
E8-RB-ML2.1 bolt ASD Essential Eight

Prevent privileged accounts from accessing others' backups

Ensure only backup administrators can access all backup data.

record_voice_over

Plain language

This control is about making sure that only the backup administrators can access all the backup data, including those from other privileged accounts. This is important to prevent unauthorised access to sensitive data and to protect it from being tampered with or deleted, which could cause major disruptions to the business.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged accounts (excluding backup administrator accounts) cannot access backups belonging to other accounts.
bolt ASD Essential Eight E8-RB-ML2.1
priority_high

Why it matters

If privileged accounts can access other users' backups, they can extract sensitive data or delete/alter backups, undermining recovery and causing disruption.

settings

Operational notes

Regularly review backup repository ACLs so only backup administrator accounts can access others' backups; alert on privileged access and verify exemptions.

Mapping detail

Mapping

Direction

Controls