Skip to content
arrow_back
search
ISM-0701 policy ASD Information Security Manual (ISM)

CISO Management of Cyber Security Personnel

The Chief Information Security Officer (CISO) manages cyber security staff in the organisation.

record_voice_over

Plain language

This control means that the Chief Information Security Officer (CISO) is responsible for leading and managing the people who ensure cyber security in an organisation. It matters because without someone effectively overseeing these experts, security efforts can become disorganised, leaving the organisation vulnerable to cyber threats that could disrupt operations or compromise sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Mobile device emergency sanitisation processes, and supporting mobile device emergency sanitisation procedures, are developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-0701
priority_high

Why it matters

Without mobile device emergency sanitisation processes, lost or stolen devices may expose sensitive data, causing reportable breaches and operational harm.

settings

Operational notes

Test and maintain mobile emergency sanitisation (e.g., remote wipe) procedures, including triggers, responsibilities, logging, and periodic drills on new device models.

Mapping detail

Mapping

Direction

Controls