Skip to content
arrow_back
search
ISM-1818 policy ASD Information Security Manual (ISM)

Client Authentication for Network API Access

Ensure clients are verified before they change data through network APIs on the internet.

record_voice_over

Plain language

This control ensures that only verified users can change important data when using network applications visible on the internet. If this isn't done, unauthorised people or hackers could alter your data, leading to loss of trust, potential financial loss, and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data and are accessible over the internet.
policy ASD Information Security Manual (ISM) ISM-1818
priority_high

Why it matters

Without client authentication for internet-accessible APIs that modify data, unauthorised parties could change records, causing breaches, financial loss and reputational damage.

settings

Operational notes

Review API logs for failed tokens and unusual client IDs; ensure only authenticated, authorised clients can call internet-facing data-modifying endpoints.

Mapping detail

Mapping

Direction

Controls