Skip to content
arrow_back
search
ISM-1611 policy ASD Information Security Manual (ISM)

Use Break Glass Accounts Only in Emergencies

Break glass accounts should be used only if normal login methods fail.

record_voice_over

Plain language

A 'break glass' account is like an emergency key that should be used only if the usual way of getting into a computer system is not working. It's important because if you can use this emergency access too easily or often, it could let people sneak in who shouldn't be there, putting your organisation's sensitive information at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Break glass accounts are only used when normal authentication processes cannot be used.
policy ASD Information Security Manual (ISM) ISM-1611
priority_high

Why it matters

Excessive use of break glass accounts can lead to unauthorised access, compromising sensitive data and weakening overall security posture.

settings

Operational notes

Audit and review break glass use regularly; ensure each use is logged, monitored, and justified as an emergency.

Mapping detail

Mapping

Direction

Controls