Skip to content
arrow_back
search
ISM-0732 policy ASD Information Security Manual (ISM)

Manage and Allocate Cyber Security Budget

The CISO is responsible for handling the organisation's dedicated cyber security funds.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) needs to oversee and manage a dedicated budget specifically for cyber security. This is important because having allocated funds ensures that the organisation can proactively protect its data and systems from cyber threats, rather than reacting only after an attack occurs.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO receives and manages a dedicated cyber security budget for their organisation.
policy ASD Information Security Manual (ISM) ISM-0732
priority_high

Why it matters

If the CISO does not manage a dedicated cyber security budget, risk treatments and key security initiatives may not be funded, increasing the likelihood and impact of incidents and data loss.

settings

Operational notes

Maintain a CISO-owned dedicated cyber security budget; review quarterly and reallocate to priority risk treatments, capability uplift, and emerging threats, with clear approvals and tracking of spend.

Mapping detail

Mapping

Direction

Controls