Skip to content
arrow_back
search
ISM-2014 policy ASD Information Security Manual (ISM)

Ensure API Client Authentication and Authorization

Check and confirm who can use certain non-internet APIs to access restricted data.

record_voice_over

Plain language

This control is about making sure that only the right people and systems can access your business data through internal APIs, which are tools for letting different software programs talk to each other. If this isn't done properly, unauthorised users might gain access to sensitive data, leading to data breaches or leaks that could harm your business reputation and financial health.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Authentication and authorisation of clients is performed when clients call network APIs that facilitate access to data not authorised for release into the public domain but are not accessible over the internet.
policy ASD Information Security Manual (ISM) ISM-2014
priority_high

Why it matters

Weak API client authentication/authorisation can allow unauthorised internal callers to access non-public data via network APIs, causing disclosure and compromise.

settings

Operational notes

Enforce strong client authentication (e.g., mTLS/OAuth), validate scopes/roles per API, and regularly review access logs for unauthorised internal API calls.

Mapping detail

Mapping

Direction

Controls