Skip to content
arrow_back
ISM-0120policyASD Information Security Manual (ISM)

Access to Tools for Detecting Security Events

Ensure cyber security staff have tools to detect and identify security threats and incidents.

record_voice_over

Plain language

This control ensures that your cybersecurity team has the right tools to spot potential security threats before they become real problems. If they lack these tools, issues might go unnoticed, causing harm like data breaches or reputational damage.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.
policyASD Information Security Manual (ISM)ISM-0120
priority_high

Why it matters

Without proper tools, cybersecurity threats can go unnoticed, leading to data breaches, financial loss, and damage to the organisation's reputation.

settings

Operational notes

Regularly review tool configurations and updates to ensure they remain effective against evolving threats. Continuous staff training on these tools is essential.

build

Implementation tips

  • Management should ensure that the IT team is equipped with security monitoring tools. This can be done by budgeting for and acquiring necessary software that allows monitoring of the network and systems effectively.
  • The IT team should install and configure these tools. They should set them up to detect unusual activity by tailoring tools to the specific environment and business needs of the organisation.
  • Cybersecurity staff should be trained to use the tools effectively. This includes setting up workshops or online courses to ensure they know how to interpret alerts and respond to them appropriately.
  • Managers should conduct regular reviews with IT to evaluate the effectiveness of these tools. This can involve checking reports generated by the tools and discussing how the information is being used to enhance security.
  • Procurement should liaise with IT to maintain licenses for security tools. This includes keeping track of renewals to ensure continuous access to critical software without interruption.
fact_check

Audit / evidence tips

  • Asklogs or reports generated by the security monitoring toolsLook atthe frequency and types of alerts recordedGoodis detailed logs highlighting potential threats and corresponding actions taken
  • Goodall staff have up-to-date training certificates
  • Aska list of security tools currently in use. Look to see if their functions align with identifying and detecting threatsGoodis a comprehensive list matching the organisation's threat profile
  • Look atdetails on who is responsible for whatGoodhas clear roles, responsibilities, and a schedule for tool maintenance and updates
  • Askto see budget records for security tool procurementLook atentries detailing software purchases and renewalsGoodincludes documented purchases matching the tools listed in use
link

Cross-framework mappings

How ISM-0120 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(2)expand_less
Annex A 8.6Annex A 8.6 requires monitoring of resource use and subsequent adjustment to prevent performance degradation or outages
Annex A 8.16ISM-0120 requires cyber security personnel to have sufficient data sources and tools to monitor systems for key indicators of compromise

E8

ControlNotesDetails
handshakeSupports(5)expand_less
extensionDepends on(7)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for security assurance controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls