Skip to content
arrow_back
search
E8-RB-ML2.2 bolt ASD Essential Eight

Privileged accounts cannot modify or delete backups.

Ensure privileged users can't change or remove backups, except backup admins.

record_voice_over

Plain language

This control is about making sure that people with special access to your systems, like IT administrators, can't change or delete your important backups unless they are specifically responsible for backups. This is important because if someone accidentally or deliberately deletes your backups, or if a hacker gets hold of an admin account, you could lose all your data and not be able to recover it.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.
bolt ASD Essential Eight E8-RB-ML2.2
priority_high

Why it matters

If privileged users can delete or alter backups, attackers can remove recovery points, increasing ransomware impact and causing irrecoverable data loss.

settings

Operational notes

Audit backup repository ACLs regularly so only backup administrator accounts can modify or delete backups; alert on any permission changes.

Mapping detail

Mapping

Direction

Controls