Skip to content
arrow_back
ISM-1910policyASD Information Security Manual (ISM)

Log Network API Calls for Data Protection

Ensure API calls over the internet that change or access sensitive data are logged centrally.

record_voice_over

Plain language

It's crucial to keep track of when your computer systems make requests for or change important information online. If you don't, you might miss signs of an attack or misuse that could lead to data exposure or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, and are accessible over the internet, are centrally logged.
policyASD Information Security Manual (ISM)ISM-1910
priority_high

Why it matters

Without centrally logging internet-exposed API calls that modify or access sensitive data, breaches may go undetected, enabling theft and reputational harm.

settings

Operational notes

Centrally capture logs for internet-exposed APIs (create/update/delete and sensitive reads), sync time, and routinely alert on anomalous access patterns.

build

Implementation tips

  • IT team should set up central logging: Ensure that all changes to sensitive information made via online requests (network API calls) are recorded in a single place. Use available tools to automatically gather these logs from the systems involved.
  • System admins should define what counts as sensitive data: Clearly identify which types of data are sensitive and need to be logged when accessed or changed. Create a list with examples such as customer information or financial records.
  • Managers should oversee a regular logging review: Schedule routine checks to ensure logs are properly recorded and any anomalies are caught early. Assign someone to be responsible for these regular reviews and establish a simple procedure for them.
  • Procurement should acquire suitable logging tools: Purchase or subscribe to tools that can reliably gather and store logs from all relevant systems and are easy for your IT team to use. Consider tools recommended by the Australian Cyber Security Centre (ACSC).
  • Training coordinators should educate staff: Provide training sessions for relevant staff about the importance of logging and how to handle logs securely. Include practical exercises that show how logs help spot security issues.
fact_check

Audit / evidence tips

  • AskThe central logging configuration: Request documentation that describes the logging setup for API callsGoodShows comprehensive coverage of sensitive actions
  • AskRecent log reviews: Request records showing when recent log reviews were conducted and by whomGoodIncludes regular review dates and documented follow-ups on anomalies
  • AskTo see data classification lists: Request lists or policies that identify sensitive data requiring loggingGoodAligns with your risk assessment and covers all critical data
  • AskStaff training records: Request evidence of training sessions for staff involved in loggingGoodIncludes completed and up-to-date training that covers logging practices
  • AskA demonstration of logging tools: Request a walk-through of how your logging tools work and where logs are locatedGoodShows a tool that effectively centralises logs and is easy for staff to manage
link

Cross-framework mappings

How ISM-1910 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

E8

ControlNotesDetails
handshakeSupports(4)expand_less
E8-AC-ML2.6ISM-1910 requires centrally logging internet-accessible network API calls that modify data or access non-public data
E8-MF-ML2.7ISM-1910 requires centrally logging internet-accessible network API calls that modify data or access non-public data
E8-RA-ML2.8ISM-1910 requires centrally logging internet-accessible network API calls that modify data or access non-public data
E8-AH-ML2.13ISM-1910 requires centrally logging internet-accessible network API calls that modify data or access non-public data
extensionDepends on(1)expand_less
E8-AC-ML2.7ISM-1910 requires centrally logging internet-accessible network API calls that modify data or access non-public data

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls