Skip to content
arrow_back
search
ISM-0252 policy ASD Information Security Manual (ISM)

Annual Cyber Security Awareness for Personnel

All staff receive yearly training on using and protecting systems, and reporting incidents.

record_voice_over

Plain language

Cyber security awareness training is like giving everyone in your organisation the knowledge they need to safely use and protect computers and data. It's important because if staff aren't aware of cyber threats and how to report them, your organisation could be at risk of data breaches, financial loss, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Cyber security awareness training is undertaken annually by all personnel and covers: - the purpose of the cyber security awareness training - security appointments and contacts - authorised use of systems and their resources - protection of systems and their resources - reporting of cyber security incidents and suspected compromises of systems and their resources.
policy ASD Information Security Manual (ISM) ISM-0252
priority_high

Why it matters

Without annual cyber security awareness training, personnel may misuse systems, miss incident reporting steps and contacts, and increase risk of compromise and data loss.

settings

Operational notes

Deliver and track annual training for all personnel, covering purpose, contacts, authorised use, protection of resources, and how to report incidents and suspected compromises.

Mapping detail

Mapping

Direction

Controls