Skip to content
arrow_back
search
ISM-1813 policy ASD Information Security Manual (ISM)

Prevent Unauthorised User Access to Backup Data

Ensure that regular user accounts cannot view or restore their own backup files for security reasons.

record_voice_over

Plain language

This control ensures that regular users can't access, view, or restore the backup files of their own data. This matters because if anyone could see or modify their backups, it could lead to sensitive information being accidentally shared or altered, which could harm the entire organisation by making data unreliable or exposing it to competitors.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Unprivileged user accounts cannot access their own backups.
policy ASD Information Security Manual (ISM) ISM-1813
priority_high

Why it matters

If unprivileged users can access their own backups, they could recover deleted data and exfiltrate sensitive information outside normal access controls.

settings

Operational notes

Ensure backup repositories and restore tools are restricted to privileged roles; test that standard user accounts cannot list, read or restore their own backups.

Mapping detail

Mapping

Direction

Controls