Skip to content
arrow_back
search
ISM-2015 policy ASD Information Security Manual (ISM)

Central Logging of Non-Internet Network API Data Access

All network API data changes not shared online must be logged centrally.

record_voice_over

Plain language

This control means that any time data is changed or accessed through a company's internal systems (not over the internet), these actions need to be recorded centrally. It matters because without keeping track of who accesses or changes important data, a business could be vulnerable to data tampering or breaches, possibly resulting in loss of trust, revenue, or legal issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Network API calls that facilitate modification of data, or access to data not authorised for release into the public domain, but are not accessible over the internet, are centrally logged.
policy ASD Information Security Manual (ISM) ISM-2015
priority_high

Why it matters

Without central logging of internal (non-internet) API calls that access or modify non-public data, unauthorised access or changes may go undetected, harming integrity and compliance.

settings

Operational notes

Ensure internal (non-internet) APIs log centrally: caller identity, endpoint, timestamp and action (read/modify). Review logs and alert on unusual access to non-public data.

Mapping detail

Mapping

Direction

Controls