Skip to content
arrow_back
search
ISM-0734 policy ASD Information Security Manual (ISM)

CISO Role in Disaster Recovery Planning

The CISO helps to ensure recovery plans are in place to maintain essential services during a disaster.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) plays a crucial role in creating and maintaining plans to keep your essential business services running if a disaster strikes, like a cyberattack or a natural event. If these plans aren't in place, an unexpected incident could stop the entire operation, leading to financial loss, data breaches, and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO contributes to the development, implementation and maintenance of business continuity and disaster recovery plans for their organisation to ensure that business-critical services are supported appropriately in the event of a disaster.
policy ASD Information Security Manual (ISM) ISM-0734
priority_high

Why it matters

If the CISO does not contribute to BCP/DR planning, recovery priorities may miss business-critical services, extending outages and increasing financial and reputational harm.

settings

Operational notes

Have the CISO review and sign off BCP/DR plans, ensure critical services and recovery objectives are defined, and run scheduled exercises to keep plans current.

Mapping detail

Mapping

Direction

Controls