Skip to content
arrow_back
search
ISM-0714 policy ASD Information Security Manual (ISM)

Appointment of CISO for Cyber Security Leadership

Ensure a CISO is appointed to lead and guide the organisation's cyber security efforts.

record_voice_over

Plain language

This control is about appointing someone as the Chief Information Security Officer (CISO) to lead and oversee all the cyber security tasks in an organisation. It matters because without a dedicated leader to focus on keeping your digital information safe, your organisation is like a ship without a captain, which can easily run into trouble from cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering information technology and operational technology).
policy ASD Information Security Manual (ISM) ISM-0714
priority_high

Why it matters

Without an appointed CISO, cyber security leadership is unclear across IT/OT, causing fragmented priorities, slower decisions, and higher breach likelihood.

settings

Operational notes

Formally appoint a CISO with clear remit over cyber security for both IT and OT, defined decision rights, and regular reporting to executives and key stakeholders.

Mapping detail

Mapping

Direction

Controls