Skip to content
arrow_back
ISM-2092policyASD Information Security Manual (ISM)

Enforce Fine-Grained Permissions for AI Applications

Implement access controls to precisely limit what users can do with AI applications.

record_voice_over

Plain language

This control ensures that only the right people can do specific things with AI applications, preventing misuse or data breaches. It's like having a lock and key system so not everyone can wander into critical areas in your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Access control policies are implemented to enforce fine-grained permissions for AI applications.
policyASD Information Security Manual (ISM)ISM-2092
priority_high

Why it matters

Without proper permissions, sensitive AI data could be misused or leaked, leading to financial and reputational harm.

settings

Operational notes

Regularly review and update user permissions to reflect changing roles, ensuring data remains secure and accessible only to authorised users.

build

Implementation tips

  • Managers should identify who needs access to AI systems and for what purposes. Make a simple list of team members and their roles to define who genuinely requires access to sensitive functions.
  • IT staff should configure user accounts with specific permissions. Use software tools to set limitations on who can view, change, or delete information in the AI applications.
  • HR teams should maintain updated records of user roles and any changes. Regularly review and update these records as people join, leave, or change roles within the organisation.
  • The IT team should implement periodic review meetings with department heads. Schedule these quarterly to reassess who should have access based on any new projects or organisational changes.
  • Data protection officers should train staff on the importance of these permissions. Conduct workshops using real-world scenarios to explain why limits are in place and how they protect the business.
fact_check

Audit / evidence tips

  • Askuser access lists for AI applications: Request documentation detailing current user access settings for each AI systemLook atwho has access and at what levelGoodshows intentional permission assignments aligned with job roles
  • Request a list of permission change logs: Ensure you acquire records showing changes made to user permissions over time. Check for both the frequency and reasons for these changes. Good records have a clear history of changes with justifications.
  • Askminutes from access review meetingsLook atthe scope of discussion and decisions madeGoodwill include action items and confirmations of necessary or revoked accesses
  • Look atthe number of participants and training contentGoodlog shows regular and comprehensive training sessions
  • Look atreports on any detected improper access attemptsGoodwill include an alert mechanism and response records
link

Cross-framework mappings

How ISM-2092 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(3)expand_less
Annex A 5.15ISM-2092 requires organisations to implement access control policies that enforce fine-grained permissions specifically for artificial in...
Annex A 5.18ISM-2092 requires fine-grained permissioning for AI applications, ensuring only authorised users can use AI capabilities in line with policy
Annex A 8.3ISM-2092 requires restricting AI application use through fine-grained permissions enforced by access control policies
handshakeSupports(1)expand_less
Annex A 8.5ISM-2092 requires enforcing fine-grained permissions for AI applications, which relies on the ability to correctly identify and authentic...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for software development controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls