Skip to content
arrow_back
search
ISM-1614 policy ASD Information Security Manual (ISM)

Manage Emergency Account Access Changes

Change break glass account passwords after emergency access.

record_voice_over

Plain language

In a nutshell, this control is about changing the passwords for special emergency accounts—called 'break glass accounts'—after they've been used by someone other than the person who normally manages them. This is crucial because if passwords aren't updated, it leaves the door open for potential misuse or unauthorised access to sensitive systems, which could lead to data breaches or disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Break glass account credentials are changed by the account custodian after they are accessed by any other party.
policy ASD Information Security Manual (ISM) ISM-1614
priority_high

Why it matters

Without changing break glass credentials after use, prior holders can re-enter systems, increasing the chance of unauthorised access, breaches and disruption.

settings

Operational notes

After any break glass use, the account custodian must reset the password immediately, record the change in logs/tickets, and confirm access is returned to a known state.

Mapping detail

Mapping

Direction

Controls