Skip to content
arrow_back
search
ISM-0717 policy ASD Information Security Manual (ISM)

CISO Oversight of Cyber Security Personnel

The CISO is in charge of managing the organisation's cyber security staff.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) is responsible for overseeing the cyber security team at their organisation. This ensures that the team is well-trained and prepared to handle threats, reducing the risk of data breaches that could harm the organisation's reputation and financial standing.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees the management of cyber security personnel within their organisation.
policy ASD Information Security Manual (ISM) ISM-0717
priority_high

Why it matters

Without CISO oversight, cyber security personnel may be mismanaged, reducing accountability and resourcing and increasing likelihood of missed threats and major incidents.

settings

Operational notes

Define the CISO’s accountability for cyber security personnel: set roles, reporting lines and KPIs; review workload, resourcing and training regularly; and address capability gaps promptly.

Mapping detail

Mapping

Direction

Controls