Skip to content
arrow_back
E8-RB-ML3.2boltASD Essential Eight

Privileged accounts cannot access their own backups

Ensure accounts with special access cannot view their own backup data.

record_voice_over

Plain language

This control is about making sure that users with special access rights, like managers or IT staff, can't see or touch the backup copies of their own files. This is important because if someone managed to break into these privileged accounts, they could alter or delete backup data, making recovery impossible after a security incident.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

Regular backups

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML3

Official control statement

Privileged accounts (excluding backup administrator accounts) cannot access their own backups.
boltASD Essential EightE8-RB-ML3.2
priority_high

Why it matters

If privileged accounts can access their own backups, attackers can delete logs, hide breaches, and sabotage recovery using stolen admin credentials.

settings

Operational notes

Limit backup access to designated backup administrator accounts only. Enforce separate credentials, deny self-access, and regularly review backup ACLs and audit logs.

build

Implementation tips

    fact_check

    Audit / evidence tips

    • AskCan you show how privileged access to backup data is restricted?GoodAccess controls clearly prevent privileged accounts from accessing their own backups
    • AskWhat measures are in place to prevent unauthorised access?GoodLogs indicate no instances of privileged accounts accessing their own backups
    • AskHow often are access controls reviewed?GoodAccess controls are reviewed monthly and any issues are promptly addressed
    link

    Cross-framework mappings

    How E8-RB-ML3.2 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

    ASD ISM

    ControlNotesDetails
    layersPartially meets(1)expand_less
    ISM-1928E8-RB-ML3.2 requires privileged accounts (excluding backup administrator accounts) cannot access their own backups to reduce the risk of ...
    sync_altPartially overlaps(1)expand_less
    ISM-1813ISM-1813 requires that unprivileged user accounts cannot access their own backup data
    handshakeSupports(2)expand_less
    ISM-1708ISM-1708 requires that backup administrator accounts are prevented from modifying or deleting backups during their retention period
    ISM-1811E8-RB-ML3.2 mandates that privileged accounts (excluding backup administrator accounts) cannot access their own backups
    linkRelated(1)expand_less
    ISM-1706E8-RB-ML3.2 requires that privileged accounts (other than backup administrator accounts) are unable to access their own backups

    These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

    See all Regular backups controls, or browse the full Essential Eight mitigation strategies library.

    Mapping detail

    Mapping

    Direction

    Controls