Skip to content
arrow_back
search
E8-RB-ML3.1 bolt ASD Essential Eight

Unprivileged accounts cannot access their own backups

Ensure basic user accounts are unable to access or manage their backup data.

record_voice_over

Plain language

This control ensures that basic, everyday user accounts in an organisation can't get into or mess with their own backup data. This is important because if an unprivileged user accidentally or purposely tampers with their backups, critical information might be lost or corrupted, especially in situations like ransomware attacks.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Unprivileged accounts cannot access their own backups.
bolt ASD Essential Eight E8-RB-ML3.1
priority_high

Why it matters

Uncontrolled backup access by unprivileged users can lead to loss or corruption of data, increasing recovery time and business disruption during attacks.

settings

Operational notes

Regularly review access controls and audit logs to ensure unprivileged accounts remain isolated from their backups, preventing misuse or tampering.

Mapping detail

Mapping

Direction

Controls