Skip to content
arrow_back
search
ISM-0720 policy ASD Information Security Manual (ISM)

Develop and Maintain a Cyber Security Communication Strategy

The CISO creates and updates a strategy to share the organisation's cyber security goals effectively.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) needs to set up a plan to communicate the organisation's cybersecurity goals clearly to everyone involved. This is important because if people don't understand the cybersecurity goals, they might not follow security measures, which can lead to data breaches or other cyber incidents.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees the development, implementation and maintenance of a cyber security communications strategy to assist in communicating the cyber security vision and strategy for their organisation.
policy ASD Information Security Manual (ISM) ISM-0720
priority_high

Why it matters

Without a CISO-led cyber security communications strategy, staff and executives receive inconsistent guidance, delaying response and increasing incident likelihood.

settings

Operational notes

Maintain a CISO-approved comms plan with audiences, channels and cadence; include incident updates, awareness messages, ownership and measures of reach/effectiveness.

Mapping detail

Mapping

Direction

Controls