Skip to content
arrow_back
search
ISM-1612 policy ASD Information Security Manual (ISM)

Restricted Use of Break Glass Accounts for Emergencies

Use special accounts only for approved emergency activities to maintain system security.

record_voice_over

Plain language

Break glass accounts are special user accounts used only in emergencies, like when there’s a critical system issue, and normal login methods fail. If these accounts are misused, it could lead to security vulnerabilities, as they often bypass normal security checks. Restricting their use helps prevent unauthorised access to sensitive systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Break glass accounts are only used for specific authorised activities.
policy ASD Information Security Manual (ISM) ISM-1612
priority_high

Why it matters

Misuse of break glass accounts can bypass normal controls, enabling unauthorised privileged access and increasing the likelihood of serious breaches.

settings

Operational notes

Log and review all break glass account use; restrict to approved emergency activities, require approval, and investigate any unexpected access immediately.

Mapping detail

Mapping

Direction

Controls