Skip to content
arrow_back
search
ISM-0733 policy ASD Information Security Manual (ISM)

Ensure CISO Awareness of Cyber Incidents

The CISO should be informed about all cyber security incidents in the organisation.

record_voice_over

Plain language

This control means that the Chief Information Security Officer (CISO) must be kept in the loop about every cyber security issue that happens within the organisation. It matters because if incidents are kept hidden or not communicated promptly, the organisation could face bigger security risks, leading to data breaches, financial loss, or damage to its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO is fully aware of all cyber security incidents within their organisation.
policy ASD Information Security Manual (ISM) ISM-0733
priority_high

Why it matters

Unchecked cyber incidents can escalate threats, causing severe reputational damage and financial loss if the CISO is not promptly informed.

settings

Operational notes

Ensure incident reports are relayed to the CISO within 24 hours, enabling timely decision-making and effective response coordination.

Mapping detail

Mapping

Direction

Controls