Skip to content
arrow_back
search
ISM-1707 policy ASD Information Security Manual (ISM)

Restrict Backup Modifications by Privileged Users

Only backup admins can modify or delete backups; others are restricted.

record_voice_over

Plain language

This control ensures that only backup administrators can change or delete important backup files. It's like keeping the keys to a locked safe - if everyone has access, it’s easy for someone to accidentally or intentionally delete essential files, which could lead to losing vital data or backups when they're needed most.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.
policy ASD Information Security Manual (ISM) ISM-1707
priority_high

Why it matters

Without this control, privileged users could delete backups, risking permanent data loss and crippling business recovery efforts.

settings

Operational notes

Regularly audit backup admin permissions to prevent unauthorised privilege escalation and protect backup integrity.

Mapping detail

Mapping

Direction

Controls