Skip to content
arrow_back
ISM-0725policyASD Information Security Manual (ISM)

Cyber Security Steering Committee Coordination

The CISO aligns cyber security with business by regularly meeting with a dedicated committee of key executives.

record_voice_over

Plain language

This control ensures the Chief Information Security Officer (CISO) meets with a group of key business and security leaders regularly to align the organisation's security efforts with its business goals. Without this coordination, security measures might neglect critical business areas, leading to potential data breaches or operational disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The CISO coordinates cyber security and business alignment through a cyber security steering committee or advisory board, comprising key cyber security and business executives, which meets formally and regularly.
policyASD Information Security Manual (ISM)ISM-0725
priority_high

Why it matters

Without regular alignment, security strategies might miss business-critical areas, leading to data breaches or operational issues.

settings

Operational notes

Maintain an updated contact list for committee members and ensure everyone stays informed of upcoming meetings and actions required.

build

Implementation tips

  • The CISO should form a steering committee consisting of key executives from both the business and cyber security teams. Invite these individuals to ensure that the group reflects a balance of security needs and business priorities.
  • Meeting organiser should schedule regular meetings, ideally monthly, where the agenda includes updates on security threats, status of current security measures, and alignment with business objectives. Ensure each meeting has clear minutes and action items.
  • Each committee member should prepare reports on risk areas and challenges in their respective functions before meetings. This involves identifying pressing security issues that could affect business operations.
  • The CISO should review the effectiveness of current policies and strategies with the committee. Use this review process to flag new risks and reassess security priorities based on business changes.
  • Assign a dedicated note-taker to document meeting discussions and decisions. Ensure these minutes cover key points such as agreed actions, responsibilities, and timelines for follow-ups.
fact_check

Audit / evidence tips

  • Askpast meeting agendas: Check that agendas address both security and business objectivesGoodagenda should clearly show a balance between security strategies and business needs
  • Request meeting minutes for at least the last six months: Verify that the minutes capture discussion points and decisions. Good minutes include assigned action items and deadlines.
  • Askto see the list of committee membersLook atdiversity in roles, including business and security leadsGoodlist reflects a balance of people from different areas within the organisation
  • Goodlog will list clear initiatives and evidence of alignment with business strategy
  • Askapproved reports on security status updates: Examine these reports for accuracy and relevance to business strategies. Good reports provide insightful analyses on how security measures impact business operations
link

Cross-framework mappings

How ISM-0725 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 5.2Annex A 5.2 requires information security roles and responsibilities to be defined and allocated according to organisational needs
handshakeSupports(3)expand_less
Annex A 5.1ISM-0725 requires the CISO to align cyber security and business strategies through a regular, formal executive steering committee/advisor...
Annex A 5.4Annex A 5.4 requires management to ensure personnel apply information security in line with organisational policies and procedures
Annex A 5.35ISM-0725 requires the CISO to coordinate cyber security and business alignment via a formal, regularly meeting cyber security steering co...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls