Skip to content
arrow_back
search
ISM-1613 policy ASD Information Security Manual (ISM)

Central Logging of Break Glass Account Usage

Logging is used to track and monitor the use of emergency access accounts.

record_voice_over

Plain language

This control is about keeping track of when and how emergency access accounts, also known as 'break glass accounts', are used. This is important because these accounts have high-level access to your systems, which, if misused, could lead to serious security breaches or data loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Use of break glass accounts is centrally logged.
policy ASD Information Security Manual (ISM) ISM-1613
priority_high

Why it matters

Without central logging of break glass account use, misuse may go undetected, delaying incident response and enabling data breaches and unauthorised changes.

settings

Operational notes

Centrally log all break glass use to the SIEM; alert on use, capture timestamp, account, source and actions, and review records after each event.

Mapping detail

Mapping

Direction

Controls