Skip to content
arrow_back
search
ISM-0718 policy ASD Information Security Manual (ISM)

CISO Reporting to Board on Cyber Security

The CISO must regularly update the board or executive committee on cyber security issues.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) should regularly update the board or executive committee about cybersecurity issues and strategies. This is important because if the organisation's leadership isn't aware of cyber risks, they can't make informed decisions to protect the company from financial loss or reputational harm due to security breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO regularly reports directly to their organisation's board of directors or executive committee on cyber security matters.
policy ASD Information Security Manual (ISM) ISM-0718
priority_high

Why it matters

Without direct CISO reporting to the board, cyber risk may be under‑reported, delaying investment decisions and worsening breach impact and governance outcomes.

settings

Operational notes

Schedule regular CISO briefings to the board/executive committee covering top risks, incidents, metrics, and funded remediation decisions aligned to risk appetite.

Mapping detail

Mapping

Direction

Controls