Skip to content
arrow_back
search
ISM-0141 policy ASD Information Security Manual (ISM)

Report Cyber Incidents Promptly to Designated Contacts

Service providers must report cyber incidents quickly to a specified contact as part of their contract.

record_voice_over

Plain language

This control means that if a company providing you service experiences any cyber incidents, they must let you know right away. It's important because if they don't, unidentified issues could spread, harming your business, damaging your reputation, or leading to data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The requirement for service providers to report cyber security incidents to a designated point of contact as soon as possible after they occur or are discovered is documented in contractual arrangements with service providers.
policy ASD Information Security Manual (ISM) ISM-0141
priority_high

Why it matters

Delayed incident reporting by service providers can lead to unchecked breaches, escalating damage and costs, and reputation loss due to incomplete response efforts.

settings

Operational notes

Include incident reporting timeframes and a designated contact in service contracts. Exercise reporting channels with providers to confirm prompt notification.

Mapping detail

Mapping

Direction

Controls