Skip to content
arrow_back
ISM-1928policyASD Information Security Manual (ISM)

Encrypt Backups of Microsoft AD Servers

Ensure backups of Microsoft AD servers are encrypted and only accessible by admins.

record_voice_over

Plain language

This rule ensures that backups of your important Microsoft server systems are kept safe by encrypting them. This matters because if unencrypted backups fall into the wrong hands, sensitive information could be exposed, risking your business's privacy and integrity.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Backups of Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are encrypted using ASD-approved cryptography, stored securely and only accessible to backup administrator accounts.
policyASD Information Security Manual (ISM)ISM-1928
priority_high

Why it matters

If backups aren't encrypted, sensitive data could be stolen, leading to breaches that harm your reputation and financial standing.

settings

Operational notes

Regularly review user access to backups and update encryption practices to comply with the latest security standards.

build

Implementation tips

  • The IT team should ensure backups are encrypted: They can do this by using encryption software that's approved by the Australian Signals Directorate. Regularly update the encryption software to maintain its effectiveness.
  • System administrators should limit access: Only designated backup administrator accounts should be able to access these backups. They can use user permission settings to achieve this.
  • IT managers should conduct regular training: Hold training sessions for backup admins on the importance of encryption and correct access procedures. Ensure they understand the potential risks of non-compliance.
  • The IT department must regularly audit backup storage: Check that all encrypted backups are stored securely and cannot be accessed by unauthorized users. Use secure locations or cloud storage with encryption.
  • Senior management should review access logs: Regularly inspect logs to ensure that only authorised personnel are accessing backups. This could be done monthly to ensure compliance and spot any irregular activities.
fact_check

Audit / evidence tips

  • Askthe encryption software documentation: Request to see which software is used and if it's approved by the Australian Signals DirectorateLook atversion numbers and update schedulesGoodCurrent approval and up-to-date versions
  • Askaccess logs to backup systems: Request the logs showing who accessed backups in the last six monthsLook atanomalies or unauthorised accessGoodLogs showing access only by authorised admin accounts
  • Askthe list of backup admin accounts: Request a current list of accounts with backup accessLook atthe roles and approval for each account holderGoodClearly defined roles limited to necessary personnel
  • Askabout the location of stored backups: Check where physical or cloud-based backups are storedLook atsecure physical locations or cloud encryption evidenceGoodSecure, controlled access locations confirmed
  • Asktraining records: Check records of training sessions for backup administratorsLook atdates, attendance, and content relevanceGoodRegular training sessions with mandatory attendance and specific content covered
link

Cross-framework mappings

How ISM-1928 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.13Annex A 8.13 requires organisations to maintain backup copies of information, software and systems and to test them against a backup policy

E8

ControlNotesDetails
layersPartially meets(2)expand_less
sync_altPartially overlaps(2)expand_less
handshakeSupports(1)expand_less
linkRelated(1)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system hardening controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls