Skip to content
arrow_back
search
ISM-1706 policy ASD Information Security Manual (ISM)

Prevent Backup Access by Privileged Users

Privileged users cannot access their own data backups; only backup administrators can.

record_voice_over

Plain language

This control means that people with special access, known as privileged users, should not be able to look at or retrieve data from their own backup files. This matters because if someone has bad intentions, they could misuse this access to manipulate data or hide certain changes, which could harm your business's integrity and trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.
policy ASD Information Security Manual (ISM) ISM-1706
priority_high

Why it matters

If privileged users can access their own backups, they can alter or delete evidence, conceal misuse and compromise integrity, auditability and compliance.

settings

Operational notes

Enforce access controls so only backup administrator accounts can read/restore backups; routinely review ACLs and logs to detect and fix any privileged-user access.

Mapping detail

Mapping

Direction

Controls