Skip to content
arrow_back
search
ISM-1814 policy ASD Information Security Manual (ISM)

Prevent Backup Modifications by Unprivileged Users

Only authorised users can change or delete backups, keeping data safe from unauthorised access.

record_voice_over

Plain language

This control ensures that only authorised people can make changes to or delete backups of important data. This matters because if backups are tampered with or deleted by mistake or maliciously, you could lose critical data permanently, which can disrupt your business and cost you money.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Unprivileged user accounts are prevented from modifying and deleting backups.
policy ASD Information Security Manual (ISM) ISM-1814
priority_high

Why it matters

If unprivileged users can alter or delete backups, attackers can erase recovery points, causing permanent data loss and outages.

settings

Operational notes

Restrict backup repositories to backup admins only; use immutable/WORM storage, MFA, and regularly audit delete/modify permissions.

Mapping detail

Mapping

Direction

Controls