Skip to content
arrow_back
search
ISM-0043 policy ASD Information Security Manual (ISM)

Develop Cyber Security Incident Response Plans

Systems must have a plan for handling and reporting cyber security incidents to ensure quick and effective responses.

record_voice_over

Plain language

A cyber security incident response plan means having a clear plan for what to do if something goes wrong with your computers or data. This is important because without one, you might not know how to quickly fix issues like data breaches or hacking, leading to more damage, loss of trust, and potential legal issues.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Systems have a cyber security incident response plan that covers the following: - guidelines on what constitutes a cyber security incident - the types of cyber security incidents likely to be encountered and the expected response to each type - how to report cyber security incidents, internally to an organisation and externally to relevant authorities - other parties which need to be informed in the event of a cyber security incident - the authority, or authorities, responsible for investigating and responding to cyber security incidents - the criteria by which an investigation of a cyber security incident would be requested from a law enforcement agency, the Australian Signals Directorate or other relevant authority - the steps necessary to ensure the integrity of evidence relating to a cyber security incident - system contingency measures or a reference to such details if they are located in a separate document.
policy ASD Information Security Manual (ISM) ISM-0043
priority_high

Why it matters

Without a documented incident response plan, incident detection, reporting and evidence handling are delayed, increasing business impact and risking missed external reporting obligations.

settings

Operational notes

Review and exercise the incident response plan; confirm roles/authorities, internal/external reporting paths, incident types and responses, and steps to preserve evidence integrity.

Mapping detail

Mapping

Direction

Controls