Skip to content
arrow_back
search
ISM-2093 policy ASD Information Security Manual (ISM)

Restrict Access to AI Data with Role-Based Controls

Access to sensitive AI data is restricted using roles to ensure only authorised personnel can view it.

record_voice_over

Plain language

This control ensures that only the right people can access sensitive data used in artificial intelligence systems by assigning different roles to different people. If not done, there’s a risk of unauthorised people gaining access, which could lead to data breaches, misuse of information, or even financial and reputational damage to your organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Role-based access controls are implemented for artificial intelligence applications to restrict access to sensitive data.
policy ASD Information Security Manual (ISM) ISM-2093
priority_high

Why it matters

Without role-based access, unauthorised access to AI data can lead to breaches, data misuse, and significant financial or reputational harm.

settings

Operational notes

Regularly review and update roles to ensure access aligns with current duties, preventing data exposure through outdated permissions.

Mapping detail

Mapping

Direction

Controls