Skip to content
arrow_back
search
ISM-0726 policy ASD Information Security Manual (ISM)

Coordinate Security Risk Management Activities

The CISO ensures business and security teams work together effectively on managing security risks.

record_voice_over

Plain language

This control ensures that the Chief Information Security Officer (CISO) makes sure everyone in the organisation understands the potential risks to their digital systems. It's like having a designated person who gets everyone to work together on spotting any security threats and figuring out how to deal with them. If these teams don't communicate well, things can slip through the cracks, increasing the chance of data leaks or cyber attacks.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO coordinates security risk management activities between cyber security and business teams.
policy ASD Information Security Manual (ISM) ISM-0726
priority_high

Why it matters

Without CISO-led coordination between cyber security and business teams, risk decisions can be inconsistent, leaving gaps in treatment and slower incident response.

settings

Operational notes

Have the CISO run recurring cyber/business risk forums, maintain a shared risk register, and agree escalation paths so priorities and treatments stay aligned across teams.

Mapping detail

Mapping

Direction

Controls