Skip to content
arrow_back
ISM-0714policyASD Information Security Manual (ISM)

Appoint a CISO to Lead Cyber Security Across IT and OT

The organisation must appoint a Chief Information Security Officer (CISO) who provides cyber security leadership and guidance. This leadership role must cover both Information Technology (IT, the systems that handle data, email and business applications) and Operational Technology (OT, the systems that monitor or control physical equipment, such as machinery, building services or industrial processes). The CISO is the named senior person accountable for setting direction, coordinating effort and advising the organisation on protecting both of these environments.

record_voice_over

Plain language

A CISO, short for Chief Information Security Officer, is the senior person put in charge of an organisation's cyber security. This control says you must actually appoint someone to that role and give them responsibility for leading and advising on security. Importantly, their remit has to stretch across two different worlds. The first is IT (Information Technology), which is the everyday computing you would recognise: laptops, servers, email, databases and business software. The second is OT (Operational Technology), which is the technology that runs physical things, for example industrial control systems, manufacturing machinery, power and water equipment, or building systems like lifts and air conditioning. These OT systems were often built before cyber threats were common and can be easy to overlook. Without one clearly named leader covering both, security effort tends to be fragmented. Different teams make their own decisions, gaps appear between the IT and OT environments, and no single person is accountable for the overall picture. That makes the organisation an easier target for criminals who want to steal data or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2024

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

A CISO is appointed to provide cyber security leadership and guidance for their organisation (covering IT and OT).
policyASD Information Security Manual (ISM)ISM-0714
priority_high

Why it matters

Without an appointed CISO covering IT and OT, security effort fragments, gaps appear between systems, and no one is accountable for the whole.

settings

Operational notes

Keep the CISO appointment current; reconfirm the named person and their IT and OT remit whenever the role changes hands or the organisation restructures.

build

Implementation tips

  • Senior leadership or the board formally appoints a named individual to the CISO role, recording the appointment in writing so there is no doubt about who holds the position.
  • The person responsible for the appointment writes the CISO role description so it explicitly states accountability for cyber security across both the IT (Information Technology) and OT (Operational Technology) environments, not IT alone.
  • The CISO sets the cyber security direction and provides guidance to the organisation by issuing security priorities, advising leadership on risk, and being the go-to authority that other teams escalate security decisions to.
  • The organisation gives the CISO the authority and reporting line needed to lead, for example a direct line to executive leadership, so their guidance carries weight and is not overruled at lower levels.
  • Where the organisation runs OT systems such as industrial control systems, machinery or building services, the CISO actively engages the teams that operate them so OT security is led with the same attention as IT security.
fact_check

Audit / evidence tips

  • AskWho is your appointed Chief Information Security Officer (CISO) and when were they appointed?Look atA written appointment record, contract or board minute naming the individual and the dateGoodA current, signed and dated document naming a specific person in the CISO role
  • AskWhat does the CISO's role description say they are accountable for?Look atA role description or charter that names cyber security leadership as a core dutyGoodA documented role that clearly assigns responsibility for leading and advising on the organisation's cyber security
  • AskDoes the CISO's remit cover Operational Technology (OT) as well as IT?Look atExplicit wording in the role description or strategy referencing OT, industrial control systems or physical-equipment systemsGoodThe CISO's scope is stated to cover both IT and OT, with evidence of involvement in OT security
  • AskHow does the CISO provide leadership and guidance to the rest of the organisation?Look atExamples such as security strategy documents, advice to executives, or decisions the CISO has signed offGoodDated artefacts showing the CISO actively setting direction and being consulted on security matters
  • AskWho does the CISO report to and what authority do they hold?Look atAn organisation chart or reporting line showing seniority and access to executive leadershipGoodA reporting line that gives the CISO genuine authority to lead security across the whole organisation
link

Cross-framework mappings

How ISM-0714 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 5.2Annex A 5.2 requires information security roles and responsibilities to be defined and allocated according to organisational needs
Annex A 5.24Annex A 5.24 requires planning and preparation for incident management, including defining roles and responsibilities
handshakeSupports(2)expand_less
Annex A 5.4Annex A 5.4 requires management to make sure personnel follow established information security policies, topic-specific policies and proc...
Annex A 6.2Annex A 6.2 requires employment contractual agreements to clearly state information security responsibilities for personnel and the organ...

E8

ControlNotesDetails
linkRelated(2)expand_less
E8-AC-ML2.9ISM-0714 requires the organisation to appoint a CISO to provide cyber security leadership and guidance
E8-AH-ML2.16ISM-0714 requires appointing a CISO to lead and guide cyber security across IT and OT

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls