Skip to content
arrow_back
search
ISM-1615 policy ASD Information Security Manual (ISM)

Testing Break Glass Accounts Post Credential Change

Ensure emergency accounts work properly after changing their passwords.

record_voice_over

Plain language

Break glass accounts are special accounts that give emergency access to critical systems. We need to make sure these accounts work correctly after their passwords are changed, because if they don't, you might be locked out when you most need access during an emergency.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Break glass accounts are tested after credentials are changed.
policy ASD Information Security Manual (ISM) ISM-1615
priority_high

Why it matters

If break glass accounts aren’t tested after credential changes, emergency access may fail, causing lockouts and delaying critical recovery actions.

settings

Operational notes

After any break glass credential change, perform a controlled login test, confirm access paths work, and record the test outcome and date.

Mapping detail

Mapping

Direction

Controls