Skip to content
arrow_back
search
ISM-1817 policy ASD Information Security Manual (ISM)

Secure API Access with Authentication and Authorisation

Ensure only authorised clients can access sensitive data via network APIs over the internet.

record_voice_over

Plain language

This control ensures that only people who are supposed to access certain sensitive information through internet-based systems can do so. It's like having a bouncer at the door of a club, checking IDs to make sure only the right people get in. If this isn't done, unauthorised access could lead to data leaks or breaches, damaging a business's reputation and finances.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain and are accessible over the internet.
policy ASD Information Security Manual (ISM) ISM-1817
priority_high

Why it matters

If API clients are not authenticated and authorised, internet-exposed APIs may leak non-public data to unauthorised users, causing breaches and loss of trust.

settings

Operational notes

Implement strong client authentication and authorisation (e.g., OAuth2/OIDC, JWT validation). Review scopes/claims, rotate keys, and monitor internet-facing API access.

Mapping detail

Mapping

Direction

Controls