Appoint a CISO to Lead Cyber Security Across IT and OT
The organisation must appoint a Chief Information Security Officer (CISO) who provides cyber security leadership and guidance. This leadership role must cover both Information Technology (IT, the systems that handle data, email and business applications) and Operational Technology (OT, the systems that monitor or control physical equipment, such as machinery, building services or industrial processes). The CISO is the named senior person accountable for setting direction, coordinating effort and advising the organisation on protecting both of these environments.
Plain language
A CISO, short for Chief Information Security Officer, is the senior person put in charge of an organisation's cyber security. This control says you must actually appoint someone to that role and give them responsibility for leading and advising on security. Importantly, their remit has to stretch across two different worlds. The first is IT (Information Technology), which is the everyday computing you would recognise: laptops, servers, email, databases and business software. The second is OT (Operational Technology), which is the technology that runs physical things, for example industrial control systems, manufacturing machinery, power and water equipment, or building systems like lifts and air conditioning. These OT systems were often built before cyber threats were common and can be easy to overlook. Without one clearly named leader covering both, security effort tends to be fragmented. Different teams make their own decisions, gaps appear between the IT and OT environments, and no single person is accountable for the overall picture. That makes the organisation an easier target for criminals who want to steal data or disrupt operations.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2024
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).
Why it matters
Without an appointed CISO covering IT and OT, security effort fragments, gaps appear between systems, and no one is accountable for the whole.
Operational notes
Keep the CISO appointment current; reconfirm the named person and their IT and OT remit whenever the role changes hands or the organisation restructures.
Implementation tips
- Senior leadership or the board formally appoints a named individual to the CISO role, recording the appointment in writing so there is no doubt about who holds the position.
- The person responsible for the appointment writes the CISO role description so it explicitly states accountability for cyber security across both the IT (Information Technology) and OT (Operational Technology) environments, not IT alone.
- The CISO sets the cyber security direction and provides guidance to the organisation by issuing security priorities, advising leadership on risk, and being the go-to authority that other teams escalate security decisions to.
- The organisation gives the CISO the authority and reporting line needed to lead, for example a direct line to executive leadership, so their guidance carries weight and is not overruled at lower levels.
- Where the organisation runs OT systems such as industrial control systems, machinery or building services, the CISO actively engages the teams that operate them so OT security is led with the same attention as IT security.
Audit / evidence tips
- AskWho is your appointed Chief Information Security Officer (CISO) and when were they appointed?Look atA written appointment record, contract or board minute naming the individual and the dateGoodA current, signed and dated document naming a specific person in the CISO role
- AskWhat does the CISO's role description say they are accountable for?Look atA role description or charter that names cyber security leadership as a core dutyGoodA documented role that clearly assigns responsibility for leading and advising on the organisation's cyber security
- AskDoes the CISO's remit cover Operational Technology (OT) as well as IT?Look atExplicit wording in the role description or strategy referencing OT, industrial control systems or physical-equipment systemsGoodThe CISO's scope is stated to cover both IT and OT, with evidence of involvement in OT security
- AskHow does the CISO provide leadership and guidance to the rest of the organisation?Look atExamples such as security strategy documents, advice to executives, or decisions the CISO has signed offGoodDated artefacts showing the CISO actively setting direction and being consulted on security matters
- AskWho does the CISO report to and what authority do they hold?Look atAn organisation chart or reporting line showing seniority and access to executive leadershipGoodA reporting line that gives the CISO genuine authority to lead security across the whole organisation
Cross-framework mappings
How ISM-0714 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.2 | Annex A 5.2 requires information security roles and responsibilities to be defined and allocated according to organisational needs | |
| Annex A 5.24 | Annex A 5.24 requires planning and preparation for incident management, including defining roles and responsibilities | |
handshakeSupports(2)expand_less | ||
| Annex A 5.4 | Annex A 5.4 requires management to make sure personnel follow established information security policies, topic-specific policies and proc... | |
| Annex A 6.2 | Annex A 6.2 requires employment contractual agreements to clearly state information security responsibilities for personnel and the organ... | |
E8
| Control | Notes | Details |
|---|---|---|
linkRelated(2)expand_less | ||
| E8-AC-ML2.9 | ISM-0714 requires the organisation to appoint a CISO to provide cyber security leadership and guidance | |
| E8-AH-ML2.16 | ISM-0714 requires appointing a CISO to lead and guide cyber security across IT and OT | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.