Cyber Security Steering Committee Coordination
The CISO aligns cyber security with business by regularly meeting with a dedicated committee of key executives.
Plain language
This control ensures the Chief Information Security Officer (CISO) meets with a group of key business and security leaders regularly to align the organisation's security efforts with its business goals. Without this coordination, security measures might neglect critical business areas, leading to potential data breaches or operational disruptions.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.
Why it matters
Without regular alignment, security strategies might miss business-critical areas, leading to data breaches or operational issues.
Operational notes
Maintain an updated contact list for committee members and ensure everyone stays informed of upcoming meetings and actions required.
Implementation tips
- The CISO should form a steering committee consisting of key executives from both the business and cyber security teams. Invite these individuals to ensure that the group reflects a balance of security needs and business priorities.
- Meeting organiser should schedule regular meetings, ideally monthly, where the agenda includes updates on security threats, status of current security measures, and alignment with business objectives. Ensure each meeting has clear minutes and action items.
- Each committee member should prepare reports on risk areas and challenges in their respective functions before meetings. This involves identifying pressing security issues that could affect business operations.
- The CISO should review the effectiveness of current policies and strategies with the committee. Use this review process to flag new risks and reassess security priorities based on business changes.
- Assign a dedicated note-taker to document meeting discussions and decisions. Ensure these minutes cover key points such as agreed actions, responsibilities, and timelines for follow-ups.
Audit / evidence tips
- Askpast meeting agendas: Check that agendas address both security and business objectivesGoodagenda should clearly show a balance between security strategies and business needs
- Request meeting minutes for at least the last six months: Verify that the minutes capture discussion points and decisions. Good minutes include assigned action items and deadlines.
- Askto see the list of committee membersLook atdiversity in roles, including business and security leadsGoodlist reflects a balance of people from different areas within the organisation
- Goodlog will list clear initiatives and evidence of alignment with business strategy
- Askapproved reports on security status updates: Examine these reports for accuracy and relevance to business strategies. Good reports provide insightful analyses on how security measures impact business operations
Cross-framework mappings
How ISM-0725 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.2 | Annex A 5.2 requires information security roles and responsibilities to be defined and allocated according to organisational needs | |
handshakeSupports(3)expand_less | ||
| Annex A 5.1 | ISM-0725 requires the CISO to align cyber security and business strategies through a regular, formal executive steering committee/advisor... | |
| Annex A 5.4 | Annex A 5.4 requires management to ensure personnel apply information security in line with organisational policies and procedures | |
| Annex A 5.35 | ISM-0725 requires the CISO to coordinate cyber security and business alignment via a formal, regularly meeting cyber security steering co... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.