Skip to content
arrow_back
search
ISM-1255 policy ASD Information Security Manual (ISM)

Restrict Database User Access Based on Duties

Users can only access or change database information if it's part of their job.

record_voice_over

Plain language

This control is about ensuring that people can only access the database information they need to do their job. It matters because if everyone can access everything, it could lead to mistakes, data leaks, or intentional harm to the business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Database users' ability to access, insert, modify and remove database contents is restricted based on their work duties.
policy ASD Information Security Manual (ISM) ISM-1255
priority_high

Why it matters

Unrestricted database access can enable unauthorised viewing or changes to records, increasing insider misuse, data breach risk, and operational disruption.

settings

Operational notes

Use role-based access to grant only required database CRUD privileges per duty, and review/recertify roles after job changes and at least quarterly.

Mapping detail

Mapping

Direction

Controls