---
title: "Guidelines for system management"
source: "https://www.cyber.gov.au/ism/oscal/v2026.09.4/artifacts/ISM_catalog.json"
collection: "asd-ism"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

# Guidelines for system management

Source: https://www.cyber.gov.au/ism/oscal/v2026.09.4/artifacts/ISM_catalog.json
OSCAL release: 2026.09.4
Catalog SHA-256: `237ea09362b8449ed5c5ee85de4725a0468ee73d13af7cf61c26d4e6ac47f12d`
Rendered controls: 61

## System administration

OSCAL sort-id: `catalog[1].group[17].group[1]`

### Overview

#### Context

System administration of cloud services brings unique challenges when compared to system administration of on-premises assets. Importantly, responsibility for system administration of cloud services is often shared between service providers and their customers. As the system administration processes and procedures implemented by service providers are often opaque to their customers, customers should consider a service provider’s control plane to operate within a different security domain.

#### Further information

Further information on system administration can be found in the Australian Signals Directorate’s (ASD) [Secure administration](https://www.cyber.gov.au/business-government/protecting-devices-systems/system-administration/secure-administration) publication.

Further information on change and configuration management plans can be found in the ‘System-specific cyber security documentation’ section of the [Guidelines for cyber security documentation](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-cyber-security-documentation).

Further information on the use of privileged user accounts for system administration activities can be found in the ‘Identity and access management’ section of the [Guidelines for system access](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-system-access).

Further information on network segmentation and segregation can be found in the ‘Network design and configuration’ section of the [Guidelines for networking](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-networking).

### System administration processes and procedures

OSCAL sort-id: `catalog[1].group[17].group[1].group[1]`

#### Overview

A key component of system administration is ensuring that administrative activities are undertaken in a repeatable and accountable manner using system administration processes and procedures. In doing so, requirements for administrative activities may cover:

- configuring applications, operating systems, network devices or networked information technology (IT) equipment
- applying patches, updates or vendor mitigations to applications, drivers, operating systems or firmware
- installing or removing applications, operating systems, network devices or networked IT equipment
- implementing system changes or enhancements
- resolving problems identified by users.

Furthermore, in support of change management processes and procedures, system administrators should document requirements for administrative activities, consider potential security impacts, obtain any necessary approvals, notify any affected parties of disruptions or outages, and maintain system and cyber security documentation.

### ISM-0042

- Revision: 6
- Updated: Dec-22
- Applicability: NC, OS, P, S, TS

#### Statement

System administration processes, and supporting system administration procedures, are developed, implemented and maintained.

### ISM-1211

- Revision: 7
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

System administration activities are performed in accordance with the system’s change and configuration management plan.

### Separate privileged operating environments

OSCAL sort-id: `catalog[1].group[17].group[1].group[2]`

#### Overview

One of the greatest threats to the security of networks is the compromise of privileged user accounts. Providing a separate privileged operating environment for system administrators, in addition to their unprivileged operating environment, makes it much harder for administrative activities and privileged user accounts to be compromised by malicious actors.

Using different physical workstations, with one being a dedicated Secure Admin Workstation, is the most secure approach to separating privileged and unprivileged operating environments for system administrators. However, a trusted and hardened virtualisation-based solution may be sufficient for separating privileged and unprivileged operating environments on the same Secure Admin Workstation. In such cases, privileged operating environments should not be virtualised within unprivileged operating environments.

### ISM-1898

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Secure Admin Workstations are used in the performance of administrative activities.

### ISM-1380

- Revision: 6
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Privileged human users use separate privileged and unprivileged operating environments.

### ISM-1687

- Revision: 0
- Updated: Sep-21
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML2, ML3

#### Statement

Privileged operating environments are not virtualised within unprivileged operating environments.

### ISM-1688

- Revision: 2
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Unprivileged user accounts cannot be used to log on to privileged operating environments.

### ISM-1689

- Revision: 2
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Privileged user accounts (excluding local administrator accounts) cannot be used to log on to unprivileged operating environments.

### ISM-1958

- Revision: 1
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

User accounts with DCSync permissions cannot be used to log on to unprivileged operating environments.

### Administrative infrastructure

OSCAL sort-id: `catalog[1].group[17].group[1].group[3]`

#### Overview

The security of administrative activities can be improved by segregating administrative infrastructure from the wider network and the internet. In doing so, the use of a jump server (also known as a jump host or jump box) that allows only necessary ports and services to be used can be an effective way of simplifying and securing administrative activities. Specifically, a jump server can provide filtering of network management traffic while also acting as a focal point to perform multi-factor authentication; store and manage administrative tools; and perform logging, monitoring and alerting activities. In addition, using separate jump servers for the administration of critical servers (such as Microsoft Active Directory Domain Services domain controllers, Microsoft Active Directory Certificate Services servers, Microsoft Active Directory Federation Services servers and Microsoft Entra Connect servers), high-value servers (such as Domain Name System servers, database servers, email servers, file servers and web servers) and regular servers can further assist in protecting these assets.

### ISM-1385

- Revision: 4
- Updated: Jun-23
- Applicability: NC, OS, P, S, TS

#### Statement

Administrative infrastructure is segregated from the wider network and the internet.

### ISM-1750

- Revision: 0
- Updated: Mar-22
- Applicability: NC, OS, P, S, TS

#### Statement

Administrative infrastructure for critical servers, high-value servers and regular servers is segregated from each other.

### ISM-1386

- Revision: 5
- Updated: Mar-22
- Applicability: NC, OS, P, S, TS

#### Statement

Network management traffic can only originate from administrative infrastructure.

### ISM-1387

- Revision: 2
- Updated: Sep-21
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML2, ML3

#### Statement

Administrative activities are conducted through jump servers.

### ISM-1899

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS

#### Statement

Network devices that do not belong to administrative infrastructure cannot initiate connections with administrative infrastructure.

### Administrative tools

OSCAL sort-id: `catalog[1].group[17].group[1].group[4]`

#### Overview

Legitimate remote monitoring and management (RMM) tools and remote access tools are frequently abused by malicious actors as they are digitally signed, often permitted by application control rulesets and provide interactive access that blends with normal system administration activities. As such, an organisation should develop, enforce and maintain a list of authorised RMM tools and remote access tools, to prevent the execution of those that are not authorised, to the extent possible, and monitor for any unusual or unexpected network activity associated with their use.

### ISM-2149

- Revision: 0
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

A list of authorised RMM tools and remote access tools is developed, enforced and maintained.

### ISM-2150

- Revision: 0
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

Network connections for unauthorised RMM tools and remote access tools are blocked at gateways.

### Software registers

OSCAL sort-id: `catalog[1].group[17].group[1].group[5]`

#### Overview

Maintaining accurate software registers assists an organisation in managing its systems and maintaining awareness of the software installed on them, including applications, drivers, firmware and operating systems. Software registers can support change and configuration management, vulnerability management, cyber security incident response and software lifecycle management. This includes monitoring trustworthy sources for information about relevant vulnerabilities, patches, updates and cessation of support.

### ISM-1493

- Revision: 7
- Updated: Jun-26
- Applicability: NC, OS, P, S, TS

#### Statement

Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.

### ISM-1643

- Revision: 0
- Updated: Jun-21
- Applicability: NC, OS, P, S, TS

#### Statement

Software registers contain versions and patch histories of applications, drivers, operating systems and firmware.

## System maintenance

OSCAL sort-id: `catalog[1].group[17].group[2]`

### Overview

#### Further information

Further information on system patching can be found in ASD’s [Patching applications and operating systems](https://www.cyber.gov.au/business-government/protecting-devices-systems/system-administration/patching-applications-and-operating-systems) publication.

Further information on patching evaluated products can be found in the ‘Evaluated product usage’ section of the [Guidelines for evaluated products](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-evaluated-products).

Further information on managing risks associated with legacy IT can be found in ASD’s [Managing the risks of legacy IT: Executive guidance](https://www.cyber.gov.au/business-government/protecting-devices-systems/legacy-technology-management/managing-the-risks-of-legacy-it-executive-guidance) and [Managing the risks of legacy IT: Practitioner guidance](https://www.cyber.gov.au/business-government/protecting-devices-systems/legacy-technology-management/managing-the-risks-of-legacy-it-practitioner-guidance) publications.

Further information on cessation of support for Microsoft Windows operating systems, including potential compensating security controls for use beyond their cessation date for support, can be found in ASD’s [End of support for Microsoft Windows and Microsoft Windows Server](https://www.cyber.gov.au/business-government/protecting-devices-systems/legacy-technology-management/end-of-support-for-microsoft-windows-and-microsoft-windows-server) publication.

Further information on hardening user applications can be found in the ‘User application hardening’ section of the [Guidelines for system hardening](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-system-hardening).

Further information on hardening server applications can be found in the ‘Server application hardening’ section of the [Guidelines for system hardening](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-system-hardening).

### Patch management processes and procedures

OSCAL sort-id: `catalog[1].group[17].group[2].group[1]`

#### Overview

Applying patches or updates is critical to ensuring the ongoing security of applications, drivers, operating systems and firmware. In doing so, it is important that patches or updates are applied consistently and in a secure manner. For example, by using a centralised and managed approach that maintains the integrity of patches or updates and confirms that they have been applied successfully.

### ISM-1143

- Revision: 9
- Updated: Dec-22
- Applicability: NC, OS, P, S, TS

#### Statement

Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.

### ISM-0298

- Revision: 8
- Updated: Mar-22
- Applicability: NC, OS, P, S, TS

#### Statement

A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.

### Mitigating known vulnerabilities

OSCAL sort-id: `catalog[1].group[17].group[2].group[2]`

#### Overview

When patches or updates are released by vendors for vulnerabilities, an organisation should apply them in a timeframe commensurate with the likelihood of attempted exploitation by malicious actors. For example, by prioritising patches or updates for vulnerabilities in online services as well as operating systems of internet-facing servers and internet-facing network devices. This is especially important when vulnerabilities are assessed as critical by vendors or working exploits exist.

If no patches or updates are available for vulnerabilities, mitigation advice from vendors, trustworthy authorities or security researchers may provide some protection until patches or updates are made available. Such mitigation advice may be published in conjunction with, or soon after, announcements made relating to vulnerabilities. Mitigation advice may cover how to disable or block access to vulnerable functionality, how to reconfigure vulnerable functionality, or how to detect attempted or successful exploitation of vulnerable functionality.

If a patch or update is released for high assurance IT equipment, ASD will assess the patch or update. Subsequently, if the patch or update is approved for deployment, ASD will provide guidance on the methods and timeframes in which it is to be applied.

### ISM-1876

- Revision: 0
- Updated: Sep-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1690

- Revision: 2
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1691

- Revision: 2
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.

### ISM-1692

- Revision: 2
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1901

- Revision: 1
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1693

- Revision: 3
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML2, ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.

### ISM-1877

- Revision: 0
- Updated: Sep-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1694

- Revision: 2
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1695

- Revision: 2
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.

### ISM-1696

- Revision: 1
- Updated: Sep-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1902

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1878

- Revision: 1
- Updated: Jun-24
- Applicability: NC, OS, P, S, TS

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1751

- Revision: 4
- Updated: Jun-24
- Applicability: NC, OS, P, S, TS

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1879

- Revision: 1
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1697

- Revision: 2
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-1903

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.

### ISM-1904

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.

### ISM-0300

- Revision: 10
- Updated: Jun-24
- Applicability: S, TS

#### Statement

Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.

### Cessation of support

OSCAL sort-id: `catalog[1].group[17].group[2].group[3]`

#### Overview

When applications, operating systems, network devices and networked IT equipment reach their cessation date for support, and become legacy IT, an organisation will find it increasingly difficult to protect them against vulnerabilities as patches, updates and other forms of support will no longer be made available by vendors. As such, unsupported applications, operating systems, network devices and networked IT equipment should be removed or replaced.

In planning for cessation of support, it is important to note that while vendors generally advise the cessation date for support of operating systems well in advance, some applications, network devices and networked IT equipment may cease to receive support immediately after newer versions are released.

Finally, when the immediate removal or replacement of unsupported applications, operating systems, network devices or networked IT equipment is not possible, compensating security controls should be implemented until such time that they can be removed or replaced.

### ISM-1905

- Revision: 0
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Online services that are no longer supported by vendors are removed.

### ISM-1704

- Revision: 3
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

### ISM-0304

- Revision: 8
- Updated: Jun-25
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

### ISM-1501

- Revision: 1
- Updated: Sep-21
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Operating systems that are no longer supported by vendors are replaced.

### ISM-1753

- Revision: 2
- Updated: Dec-24
- Applicability: NC, OS, P, S, TS

#### Statement

Internet-facing network devices that are no longer supported by vendors are replaced.

### ISM-1981

- Revision: 0
- Updated: Dec-24
- Applicability: NC, OS, P, S, TS

#### Statement

Non-internet-facing network devices that are no longer supported by vendors are replaced.

### ISM-1982

- Revision: 0
- Updated: Dec-24
- Applicability: NC, OS, P, S, TS

#### Statement

Networked IT equipment that is no longer supported by vendors is replaced.

### ISM-1809

- Revision: 3
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

When applications, operating systems, network devices or networked IT equipment that are no longer supported by vendors cannot be immediately removed or replaced, compensating security controls are implemented until such time that they can be removed or replaced.

## Data backup and restoration

OSCAL sort-id: `catalog[1].group[17].group[3]`

### Overview

#### Further information

Further information on [digital preservation planning](https://www.naa.gov.au/information-management/legislation/digital-preservation-planning) and [data retention](https://www.naa.gov.au/information-management/records-authorities/types-records-authorities/afda-express-version-2-functions) is available from the National Archives of Australia.

Further information on the [retention of records created using artificial intelligence](https://www.naa.gov.au/information-management/manage-information-assets/types-information/information-management-records-created-using-artificial-intelligence-ai-technologies) is also available from the National Archives of Australia.

Further information on the collection and retention of personal information can be found in the Office of the Australian Information Commissioner’s [Australian Privacy Principles](https://www.oaic.gov.au/privacy/australian-privacy-principles) and the associated [Australian Privacy Principles guidelines](https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines).

Further information on business continuity and disaster recovery planning can be found in the ‘Chief information security officer’ section of the [Guidelines for cyber security roles](https://www.cyber.gov.au/business-government/asds-cyber-security-frameworks/ism/cyber-security-guidelines/guidelines-for-cyber-security-roles).

### Digital preservation policy

OSCAL sort-id: `catalog[1].group[17].group[3].group[1]`

#### Overview

Developing, implementing and maintaining a digital preservation policy, as part of digital continuity planning, can assist in ensuring the long-term integrity and availability of data is maintained, especially when taking into account the potential for data degradation and removable media, hardware and software obsolescence.

### ISM-1510

- Revision: 2
- Updated: Dec-22
- Applicability: NC, OS, P, S, TS

#### Statement

A digital preservation policy is developed, implemented and maintained.

### Data backup and restoration processes and procedures

OSCAL sort-id: `catalog[1].group[17].group[3].group[2]`

#### Overview

Having data backup and restoration processes and procedures is an important part of business continuity and disaster recovery planning. Such activities will also form an integral part of an overarching digital preservation policy.

### ISM-1547

- Revision: 2
- Updated: Dec-22
- Applicability: NC, OS, P, S, TS

#### Statement

Data backup processes, and supporting data backup procedures, are developed, implemented and maintained.

### ISM-1548

- Revision: 2
- Updated: Dec-22
- Applicability: NC, OS, P, S, TS

#### Statement

Data restoration processes, and supporting data restoration procedures, are developed, implemented and maintained.

### Performing and retaining backups

OSCAL sort-id: `catalog[1].group[17].group[3].group[3]`

#### Overview

To mitigate the security risk of losing system availability or data as part of a ransomware attack, or other form of destructive attack, backups of data, applications and settings should be performed and retained in accordance with an organisation’s business criticality and business continuity requirements. In doing so, backups of all data, applications and settings should be synchronised to enable restoration to a common point in time. Furthermore, it is essential that all backups are retained in a secure and resilient manner. This will ensure that should a system fall victim to a ransomware attack, or other form of destructive attack, data will not be lost and, if necessary, systems can be quickly restored.

### ISM-1511

- Revision: 4
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Backups of data, applications and settings are performed and retained in accordance with business criticality and business continuity requirements.

### ISM-1810

- Revision: 1
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Backups of data, applications and settings are synchronised to enable restoration to a common point in time.

### ISM-1811

- Revision: 1
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Backups of data, applications and settings are retained in a secure and resilient manner.

### Backup access

OSCAL sort-id: `catalog[1].group[17].group[3].group[4]`

#### Overview

To mitigate the security risk of unauthorised access to backups, an organisation should ensure that access to backups is controlled by using appropriate access controls.

### ISM-1812

- Revision: 1
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Unprivileged user accounts cannot access backups belonging to other user accounts.

### ISM-1813

- Revision: 1
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Unprivileged user accounts cannot access their own backups.

### ISM-1705

- Revision: 2
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML2, ML3

#### Statement

Privileged user accounts (excluding backup administrator accounts) cannot access backups belonging to other user accounts.

### ISM-1706

- Revision: 2
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Privileged user accounts (excluding backup administrator accounts) cannot access their own backups.

### Backup modification and deletion

OSCAL sort-id: `catalog[1].group[17].group[3].group[5]`

#### Overview

To mitigate the security risk of backups being accidentally or maliciously modified or deleted, an organisation should ensure that backups are sufficiently protected from unauthorised modification and deletion by using appropriate access controls during their retention period. Furthermore, as malicious actors routinely seek to access backup infrastructure using credentials harvested from production environments, backup infrastructure should be segregated from such environments and use a separate authentication mechanism for administrative access.

### ISM-1814

- Revision: 1
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Unprivileged user accounts are prevented from modifying and deleting backups.

### ISM-1707

- Revision: 2
- Updated: Sep-24
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML2, ML3

#### Statement

Privileged user accounts (excluding backup administrator accounts) are prevented from modifying and deleting backups.

### ISM-1708

- Revision: 2
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML3

#### Statement

Backup administrator accounts are prevented from modifying and deleting backups during their retention period.

### ISM-2151

- Revision: 0
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

Backups are stored using a technically enforced immutability mechanism that prevents their modification or deletion for the duration of their retention period.

### ISM-2152

- Revision: 0
- Updated: Sep-26
- Applicability: NC, OS, P, S, TS

#### Statement

Backup infrastructure, including backup servers, repositories and management consoles, is segregated from production environments and uses a separate authentication mechanism for administrative access.

### Testing restoration of backups

OSCAL sort-id: `catalog[1].group[17].group[3].group[6]`

#### Overview

To ensure that backups can be restored when the need arises, and that any dependencies can be identified and managed beforehand, it is important that the restoration of data, applications and settings from backups to a common point in time is tested in a coordinated manner as part of disaster recovery exercises.

### ISM-1515

- Revision: 4
- Updated: Dec-23
- Applicability: NC, OS, P, S, TS
- Essential Eight: ML1, ML2, ML3

#### Statement

Restoration of data, applications and settings from backups to a common point in time is tested as part of disaster recovery exercises.
