Skip to content
arrow_back
search
ISM-1705 policy ASD Information Security Manual (ISM)

Restrict Access to User Account Backups

Only backup administrators can access backups; other privileged users cannot access backups of different accounts.

record_voice_over

Plain language

This control ensures that only backup administrators can access user account backups, meaning other staff with special access can't view or change these backups. This is important to prevent sensitive information from being misused or stolen by someone who shouldn't have access to it.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.
policy ASD Information Security Manual (ISM) ISM-1705
priority_high

Why it matters

If privileged users can access other users’ backups, sensitive data may be exposed and integrity and confidentiality compromised.

settings

Operational notes

Regularly review backup ACLs so only backup administrator accounts can access other users’ backups; log and alert on unauthorised access attempts.

Mapping detail

Mapping

Direction

Controls