Skip to content
arrow_back
search
ISM-1708 policy ASD Information Security Manual (ISM)

Prevent Backup Modifications During Retention

Backup administrators cannot change or delete backups until the retention period ends.

record_voice_over

Plain language

This control means that once backups are created, no one is allowed to change or delete them until a certain amount of time has passed. This is important because if backups could be changed or erased too early, you might lose important data that you need to recover from disasters or unexpected problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Backup administrator accounts are prevented from modifying and deleting backups during their retention period.
policy ASD Information Security Manual (ISM) ISM-1708
priority_high

Why it matters

Backup modifications during retention risk data loss, undermining recovery efforts post-incident and increasing operational and reputational damage.

settings

Operational notes

Implement immutability for backups to prevent changes. Scheduled audits ensure backup integrity and the effectiveness of role-based restrictions.

Mapping detail

Mapping

Direction

Controls