In modern days cloud computing has found its application to a great extent. People are sure that it will be the future technology that occupies digital world, but the security related issues need to be overcome. By using cloud computing, users can access their data from remote servers through internet. Cloud computing provides cheaper and faster services to users. At the same time there is security issues associated with cloud such as data loss, abuse of data, cyber security attacks and so on. While off-shoring sensitive data through third party cloud servers, access control ensures that an unauthenticated person cannot access data without user's knowledge. This research paper proposes a Data security and User centric access control framework which provides two levels of security and multilayer access control mechanism by using key exchange. This mechanism allows user to store shuffled and encrypted data in a cloud server which is only accessed by the authenticated users. A novel key management mechanism is used to achieve multilayer access control. User centric access control makes this mechanism more vigorous because there is no need for third party auditors and key service providers. All the communications and key transactions are only between the owner of the data, consumer of the data and the cloud host. This proposed framework (ISADA) gives a better solution for broken access control under horizontal privilege escalation.