Skip to content

Break Glass Account

What is Break Glass Account?

An emergency access account that bypasses normal access controls during critical situations, with strict monitoring and post-use review procedures.

Information Security

What the standards actually require on break glass account

Requirements naming break glass account across 4 standards, quoted from the control text.

Break glass accounts are only used when normal authentication processes cannot be used.

ISM-1611 · Break glass accounts are only used when normal authentication processes cannot be used.

All ML1 requirements plus: Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated. Privileged access to systems and applications is disabled after 45 days of inactivity.

E8-ADMIN-ML2 · Restrict Administrative Privileges (ML2)

Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.

164.312(a)(2)(ii) · Emergency Access Procedure (Required)

Establish procedures for obtaining necessary ePHI during an emergency. NIST recommends break-glass accounts, time-bounded activation, and full logging.

164.312(a)(2)(ii) · Emergency Access Procedure (Required)

Questions people ask about break glass account

What is Break Glass Account?
An emergency access account that bypasses normal access controls during critical situations, with strict monitoring and post-use review procedures.
Why is Break Glass Account important for compliance?
Break Glass Account is a key concept in Information Security. Understanding break glass account helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Break Glass Account?
Break Glass Account appears in the requirement text of Australian Information Security Manual, ACSC Essential Eight, HIPAA Security Rule, NIST SP 800-66 Rev 2. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Break Glass Account?
Explore our compliance framework pages to see how break glass account applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Break Glass Account applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.