Skip to content
arrow_back
search
ISM-1812 policy ASD Information Security Manual (ISM)

Restrict Backup Access to Unprivileged Users

Ensure that users without special permissions cannot see other people's backups.

record_voice_over

Plain language

This control makes sure that only users with the proper permissions can see or get into backup files of others. It’s important because if someone without permission can access backups, they might see private information or alter important files without anyone knowing.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Unprivileged user accounts cannot access backups belonging to other user accounts.
policy ASD Information Security Manual (ISM) ISM-1812
priority_high

Why it matters

If unprivileged users can access other users’ backups, confidential data may be disclosed and backup data could be altered, impacting integrity.

settings

Operational notes

Enforce per-user backup ACLs so unprivileged accounts can only view/restore their own backups; regularly audit access and test restore permissions.

Mapping detail

Mapping

Direction

Controls