Skip to content
arrow_back
search
ISM-2013 policy ASD Information Security Manual (ISM)

Ensure Client Authentication for Internal Network APIs

Make sure apps inside your network check who accesses them and what they can do, before allowing data changes.

record_voice_over

Plain language

This control requires you to make sure that anyone accessing apps within your company's internal network is verified and granted the right level of access before they can change any data. This is important because if unauthorised people can make changes, it could lead to data breaches or loss that could harm your business operations and reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication and authorisation of clients is performed when clients call network APIs that facilitate modification of data but are not accessible over the internet.
policy ASD Information Security Manual (ISM) ISM-2013
priority_high

Why it matters

Unauthorised calls to internal network APIs could allow data modification, leading to fraud, service disruption, and reputational damage.

settings

Operational notes

Require client authentication/authorisation (e.g., mTLS or signed tokens) for internal write APIs; review service accounts/keys and alert on failed auth attempts.

Mapping detail

Mapping

Direction

Controls