Encrypt Backups of Microsoft AD Servers
Ensure backups of Microsoft AD servers are encrypted and only accessible by admins.
Plain language
This rule ensures that backups of your important Microsoft server systems are kept safe by encrypting them. This matters because if unencrypted backups fall into the wrong hands, sensitive information could be exposed, risking your business's privacy and integrity.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Server Application HardeningOfficial control statement
Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.
Why it matters
If backups aren't encrypted, sensitive data could be stolen, leading to breaches that harm your reputation and financial standing.
Operational notes
Regularly review user access to backups and update encryption practices to comply with the latest security standards.
Implementation tips
- The IT team should ensure backups are encrypted: They can do this by using encryption software that's approved by the Australian Signals Directorate. Regularly update the encryption software to maintain its effectiveness.
- System administrators should limit access: Only designated backup administrator accounts should be able to access these backups. They can use user permission settings to achieve this.
- IT managers should conduct regular training: Hold training sessions for backup admins on the importance of encryption and correct access procedures. Ensure they understand the potential risks of non-compliance.
- The IT department must regularly audit backup storage: Check that all encrypted backups are stored securely and cannot be accessed by unauthorized users. Use secure locations or cloud storage with encryption.
- Senior management should review access logs: Regularly inspect logs to ensure that only authorised personnel are accessing backups. This could be done monthly to ensure compliance and spot any irregular activities.
Audit / evidence tips
- Askthe encryption software documentation: Request to see which software is used and if it's approved by the Australian Signals DirectorateLook atversion numbers and update schedulesGoodCurrent approval and up-to-date versions
- Askaccess logs to backup systems: Request the logs showing who accessed backups in the last six monthsLook atanomalies or unauthorised accessGoodLogs showing access only by authorised admin accounts
- Askthe list of backup admin accounts: Request a current list of accounts with backup accessLook atthe roles and approval for each account holderGoodClearly defined roles limited to necessary personnel
- Askabout the location of stored backups: Check where physical or cloud-based backups are storedLook atsecure physical locations or cloud encryption evidenceGoodSecure, controlled access locations confirmed
- Asktraining records: Check records of training sessions for backup administratorsLook atdates, attendance, and content relevanceGoodRegular training sessions with mandatory attendance and specific content covered
Cross-framework mappings
How ISM-1928 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 8.13 | Annex A 8.13 requires organisations to maintain backup copies of information, software and systems and to test them against a backup policy | |
E8
| Control | Notes | Details |
|---|---|---|
layersPartially meets(2)expand_less | ||
sync_altPartially overlaps(2)expand_less | ||
handshakeSupports(1)expand_less | ||
linkRelated(1)expand_less | ||
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.