Skip to content
arrow_back
search
ISM-1811 policy ASD Information Security Manual (ISM)

Secure and Resilient Data Backup Retention

Ensure backups of data and applications are stored safely and can withstand issues.

record_voice_over

Plain language

Making sure data backups are safe and can handle unexpected problems is crucial for any organisation. If these backups aren't secure or can't be relied upon when needed, you risk losing important information due to system failures, cyber attacks, or even natural disasters.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Backups of data, applications and settings are retained in a secure and resilient manner.
policy ASD Information Security Manual (ISM) ISM-1811
priority_high

Why it matters

Inadequate backup retention increases risk of data loss after ransomware, system failure or disaster, causing extended outages and costly recovery.

settings

Operational notes

Define retention periods and immutable/offsite copies; encrypt and access-control backups; regularly test restores and review retention as systems change.

Mapping detail

Mapping

Direction

Controls