Skip to content
arrow_back
E8-RA-ML2.11boltASD Essential Eight

Report cyber incidents to the CISO promptly

Report security incidents to the security officer quickly after finding them.

record_voice_over

Plain language

This control means that whenever there's a suspected cyber security incident, such as a data breach or hacking attempt, it needs to be reported to the Chief Information Security Officer (CISO) or their delegate immediately. This matters because quick reporting allows the organisation to respond swiftly, minimising potential damage and costs.

Framework

ASD Essential Eight

Control effect

Responsive

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

18 June 2026

E8 maturity levels

ML2

Official control statement

Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered.
boltASD Essential EightE8-RA-ML2.11
priority_high

Why it matters

Failure to promptly report incidents to the CISO can delay crisis management, worsening data breaches and increasing recovery costs.

settings

Operational notes

Escalate suspected cyber security incidents to the CISO (or delegate) via the defined process immediately upon discovery, and record time and details.

build

Implementation tips

  • Security Officer: Ensure all staff know who the CISO or their delegate is so they can report incidents quickly.
  • IT Team: Set up a clear and simple procedure for staff to report security incidents, such as a dedicated phone line or email address.
  • System Administrator: Regularly review and test the incident reporting procedure to make sure it's efficient and easy to use.
  • Business Manager: Include a basic overview of what constitutes a cyber incident in staff training sessions so everyone has a clear understanding.
fact_check

Audit / evidence tips

  • AskHow are staff trained to recognise and report cybersecurity incidents?
  • GoodShows regular and comprehensive training sessions have been conducted and documented
  • AskIs there a procedure in place for reporting incidents to the CISO promptly?
  • GoodThe procedure is documented, accessible, and includes clear steps and contact information
link

Cross-framework mappings

How E8-RA-ML2.11 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(2)expand_less
Annex A 5.24E8-RA-ML2.11 calls for prompt incident reporting to the CISO (or delegate)
Annex A 6.8E8-RA-ML2.11 requires prompt incident escalation to the CISO (or delegate)
handshakeSupports(2)expand_less
Annex A 5.23Annex A 5.23 requires lessons from incidents to be used to improve security controls
Annex A 5.26E8-RA-ML2.11 requires incidents to be reported to the CISO promptly for governance

ASD ISM

ControlNotesDetails
layersPartially meets(3)expand_less
ISM-0043E8-RA-ML2.11 requires prompt incident reporting to the CISO (or delegate)
ISM-0142ISM-0142 requires organisations to report the compromise or suspected compromise of cryptographic equipment or associated keying material...
ISM-0576E8-RA-ML2.11 requires reporting cyber incidents to the CISO promptly
sync_altPartially overlaps(5)expand_less
ISM-0140E8-RA-ML2.11 requires cyber security incidents to be reported promptly to the CISO (or delegate) after they occur or are discovered
ISM-0141E8-RA-ML2.11 requires prompt reporting of cyber incidents to the CISO (or delegate) when incidents occur or are discovered
ISM-0733E8-RA-ML2.11 requires cyber security incidents to be reported to the CISO (or delegate) promptly
ISM-1088ISM-1088 requires personnel to rapidly report potential compromise of mobile devices, removable media, or credentials, particularly in ov...
ISM-1803E8-RA-ML2.11 focuses on timely reporting of incidents to the CISO (or delegate)
handshakeSupports(1)expand_less
ISM-1478ISM-1478 requires the CISO to oversee the cyber security program and ensure compliance with cyber security policy and related obligations
extensionDepends on(1)expand_less
ISM-1618ISM-1618 requires that the CISO oversees the organisation’s response to cyber security incidents
linkRelated(1)expand_less
ISM-0123E8-RA-ML2.11 requires cyber security incidents to be reported to the CISO (or delegate)

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Restrict admin privileges controls, or browse the full Essential Eight library.

Mapping detail

Mapping

Direction

Controls