Skip to content
arrow_back
search
ISM-0724 policy ASD Information Security Manual (ISM)

Implement Cyber Security Metrics and KPIs

The CISO sets up metrics and indicators to measure and track cyber security performance in the organisation.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) sets up ways to measure how well the organisation is protecting itself from cyber threats. This is important because if you don't track your cyber security performance, you might miss weaknesses, which could lead to data breaches, financial loss, or damage to your business's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO implements cyber security measurement metrics and key performance indicators for their organisation.
policy ASD Information Security Manual (ISM) ISM-0724
priority_high

Why it matters

Without cyber security metrics and KPIs, the CISO cannot track control effectiveness or risk trends, leaving gaps unnoticed and delaying response to emerging threats.

settings

Operational notes

Define KPIs with owners, data sources, targets and reporting cadence; review monthly against threat changes, and use results to prioritise remediation and risk decisions.

Mapping detail

Mapping

Direction

Controls