Access to Tools for Detecting Security Events
Ensure cyber security staff have tools to detect and identify security threats and incidents.
Plain language
This control ensures that your cybersecurity team has the right tools to spot potential security threats before they become real problems. If they lack these tools, issues might go unnoticed, causing harm like data breaches or reputational damage.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Cyber security personnel have access to sufficient tools to facilitate the detection of cyber security events and the identification of cyber security incidents.
Why it matters
Without proper tools, cybersecurity threats can go unnoticed, leading to data breaches, financial loss, and damage to the organisation's reputation.
Operational notes
Regularly review tool configurations and updates to ensure they remain effective against evolving threats. Continuous staff training on these tools is essential.
Implementation tips
- Management should ensure that the IT team is equipped with security monitoring tools. This can be done by budgeting for and acquiring necessary software that allows monitoring of the network and systems effectively.
- The IT team should install and configure these tools. They should set them up to detect unusual activity by tailoring tools to the specific environment and business needs of the organisation.
- Cybersecurity staff should be trained to use the tools effectively. This includes setting up workshops or online courses to ensure they know how to interpret alerts and respond to them appropriately.
- Managers should conduct regular reviews with IT to evaluate the effectiveness of these tools. This can involve checking reports generated by the tools and discussing how the information is being used to enhance security.
- Procurement should liaise with IT to maintain licenses for security tools. This includes keeping track of renewals to ensure continuous access to critical software without interruption.
Audit / evidence tips
- Asklogs or reports generated by the security monitoring toolsLook atthe frequency and types of alerts recordedGoodis detailed logs highlighting potential threats and corresponding actions taken
- Goodall staff have up-to-date training certificates
- Aska list of security tools currently in use. Look to see if their functions align with identifying and detecting threatsGoodis a comprehensive list matching the organisation's threat profile
- Look atdetails on who is responsible for whatGoodhas clear roles, responsibilities, and a schedule for tool maintenance and updates
- Askto see budget records for security tool procurementLook atentries detailing software purchases and renewalsGoodincludes documented purchases matching the tools listed in use
Cross-framework mappings
How ISM-0120 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| Annex A 8.6 | Annex A 8.6 requires monitoring of resource use and subsequent adjustment to prevent performance degradation or outages | |
| Annex A 8.16 | ISM-0120 requires cyber security personnel to have sufficient data sources and tools to monitor systems for key indicators of compromise | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(5)expand_less | ||
extensionDepends on(7)expand_less | ||
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.