Skip to content
arrow_back
search
ISM-1910 policy ASD Information Security Manual (ISM)

Log Network API Calls for Data Protection

Ensure API calls over the internet that change or access sensitive data are logged centrally.

record_voice_over

Plain language

It's crucial to keep track of when your computer systems make requests for or change important information online. If you don't, you might miss signs of an attack or misuse that could lead to data exposure or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.
policy ASD Information Security Manual (ISM) ISM-1910
priority_high

Why it matters

Without centrally logging internet-exposed API calls that modify or access sensitive data, breaches may go undetected, enabling theft and reputational harm.

settings

Operational notes

Centrally capture logs for internet-exposed APIs (create/update/delete and sensitive reads), sync time, and routinely alert on anomalous access patterns.

Mapping detail

Mapping

Direction

Controls