Skip to content
arrow_back
ISM-1422policyASD Information Security Manual (ISM)

Prevent Unauthorised Access to Software Source

Ensure only authorised users can access the main software source to keep it secure.

record_voice_over

Plain language

Unauthorised access to your software's main source can be a major risk because it allows outsiders to change, steal, or damage your software. This is crucial to prevent because it could lead to serious issues like financial loss, data breaches, and even loss of customer trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2018

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Unauthorised access to the authoritative source for software is prevented.
policyASD Information Security Manual (ISM)ISM-1422
priority_high

Why it matters

If access to the authoritative source is not restricted, attackers or insiders can modify code or steal IP, leading to compromised integrity, data exposure, and reputational harm.

settings

Operational notes

Enforce least-privilege to source repos (MFA, RBAC), review access regularly, and monitor/audit commits in version control to detect and remove unauthorised changes quickly.

build

Implementation tips

  • System owners should ensure a list of authorised users is maintained and regularly updated. This can be done by identifying who needs access to the software's source based on their job roles and responsibilities, and ensuring only they are on this list.
  • IT teams should set up secure access controls for the software's source. This involves using strong passwords and regularly changing them, and where possible, using multi-factor authentication, which means verifying identity using more than one method.
  • Managers should train staff on the importance of access control. Organise regular sessions to educate staff about the risks of unauthorised access and how to spot suspicious activity.
  • Procurement teams should work with IT to select tools or services that monitor access to the software source. This could include setting up alerts when unusual activity is detected, so any risks are quickly addressed.
  • Security officers should regularly review and audit access logs. This involves checking who accessed the software source and when, to spot any unauthorised access attempts quickly.
fact_check

Audit / evidence tips

  • AskThe authorised user access list: Request to see the document or system record listing everyone who can access the software sourceGoodAn up-to-date list signed off by management
  • AskAccess control policy: Request the document outlining access procedures to the software sourceGoodA policy document that aligns with current best practices
  • AskTo see training records for staff: Request proof of training sessions conducted on access control importanceGoodDocumented records showing completed regular training sessions
  • AskMonitoring and alert records: Request logs or reports on how access to the software source is monitoredGoodA system or log showing active monitoring and timely response to alerts
  • AskTo review recent access logs: Request logs that detail recent access events for the software sourceGoodComprehensive logs with no unexplained anomalies in access patterns
link

Cross-framework mappings

How ISM-1422 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 8.3ISM-1422 requires that unauthorised access to the authoritative source for software, such as the source code repository, is prevented
Annex A 8.4ISM-1422 mandates preventing unauthorised access to the software source to protect its integrity and confidentiality
handshakeSupports(2)expand_less
Annex A 5.18ISM-1422 depends on correctly provisioning and maintaining authorisations to the authoritative software source
Annex A 8.2ISM-1422 necessitates preventing unauthorised access to software sources by controlling high-risk accounts

E8

ControlNotesDetails
handshakeSupports(1)expand_less
E8-RA-ML2.4ISM-1422 focuses on preventing unauthorised access to software sources, including administrative access

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls