Skip to content
arrow_back
search
ISM-0123 policy ASD Information Security Manual (ISM)

Report Cyber Security Incidents Promptly

Inform the chief information security officer quickly after any cyber incident is found.

record_voice_over

Plain language

When a cyber security problem is spotted, you need to tell the head of IT security about it right away. This is crucial because if you wait too long, the problem could grow, potentially stealing sensitive data or shutting down your systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.
policy ASD Information Security Manual (ISM) ISM-0123
priority_high

Why it matters

Delayed reporting of cyber incidents can lead to prolonged exposure, escalating damage, and increased data breach costs for the organisation.

settings

Operational notes

Define incident triggers and timeframes, and ensure staff can report to the CISO or delegates 24/7 via a monitored channel with escalation paths and contact details.

Mapping detail

Mapping

Direction

Controls