Skip to content
arrow_back
search
E8-RB-ML3.2 bolt ASD Essential Eight

Privileged accounts cannot access their own backups

Ensure accounts with special access cannot view their own backup data.

record_voice_over

Plain language

This control is about making sure that users with special access rights, like managers or IT staff, can't see or touch the backup copies of their own files. This is important because if someone managed to break into these privileged accounts, they could alter or delete backup data, making recovery impossible after a security incident.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Privileged accounts (excluding backup administrator accounts) cannot access their own backups.
bolt ASD Essential Eight E8-RB-ML3.2
priority_high

Why it matters

If privileged accounts can access their own backups, attackers can delete logs, hide breaches, and sabotage recovery using stolen admin credentials.

settings

Operational notes

Limit backup access to designated backup administrator accounts only. Enforce separate credentials, deny self-access, and regularly review backup ACLs and audit logs.

Mapping detail

Mapping

Direction

Controls