Skip to content
arrow_back
search
ISM-0039 policy ASD Information Security Manual (ISM)

Develop and Maintain a Cyber Security Strategy

Ensure there is a continuous and effective plan for safeguarding cyber activities and data.

record_voice_over

Plain language

Having a cyber security strategy means having a plan for keeping your digital stuff safe from cyber threats. This matters because without a plan, your important data could be vulnerable to hackers who might steal information, disrupt your business, or cause you financial harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A cyber security strategy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-0039
priority_high

Why it matters

Without a cyber security strategy, security activity becomes ad hoc, funding is misdirected, and risk decisions are inconsistent, increasing breach likelihood.

settings

Operational notes

Review the cyber security strategy at least annually and after major change; align to business goals, risk appetite and governance, and track delivery of planned initiatives.

Mapping detail

Mapping

Direction

Controls