Skip to content
arrow_back
search
ISM-0725 policy ASD Information Security Manual (ISM)

Coordinate Cyber Security Steering Committees

The CISO ensures cyber security and business strategies align by holding regular meetings with key executives.

record_voice_over

Plain language

A cyber security steering committee ensures that your business goals align with your cyber security strategies by bringing together key business and security leaders. If this doesn't happen, your company might face unnecessary risks because your security measures aren't keeping up with business decisions, possibly leading to data breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising of key cyber security and business executives, which meets formally and on a regular basis.
policy ASD Information Security Manual (ISM) ISM-0725
priority_high

Why it matters

Without an executive cyber security steering committee, cyber priorities can drift from business needs, delaying risk decisions and funding and increasing exposure to major incidents.

settings

Operational notes

Establish a steering committee of key cyber and business executives; meet regularly with minutes, risk/prioritisation decisions, owners and due dates tracked to closure.

Mapping detail

Mapping

Direction

Controls