Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0735CISO Oversees the Cyber Security Awareness Training Program

The CISO oversees the development, implementation and maintenance of the organisation's cyber security awareness training program.

record_voice_over

Plain language

This control ensures that the Chief Information Security Officer (CISO) is accountable for the organisation's cyber security awareness training program. The CISO guides how the training is designed, rolled out to staff, and kept up to date over time. Clear ownership at a senior level keeps the training relevant, makes sure it reaches everyone, and helps people recognise and avoid cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2022

Control Stack last updated

10 Aug 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
policyASD Information Security Manual (ISM)ISM-0735
priority_high

Why it matters

Without clear CISO oversight, awareness training can become outdated, inconsistent or neglected, leaving staff ill-equipped to recognise cyber threats and increasing the risk of successful attacks.

settings

Operational notes

The CISO should schedule periodic reviews of the training program to keep content aligned with emerging threats and organisational changes.

build

Implementation tips

  • Formally assign the CISO accountability for the cyber security awareness training program in a role description, governance charter or terms of reference.
  • Have the CISO approve a training plan that sets learning objectives, target audiences, delivery methods and a schedule covering all personnel.
  • Direct the CISO to work with content owners to develop training material covering current threats, organisational security policies and staff responsibilities.
  • Deliver the training to all personnel through the organisation's learning platform and record completion so the CISO can confirm coverage.
  • Task the CISO with reviewing and updating the training at least annually, and after significant incidents or changes to the threat landscape.
fact_check

Audit / evidence tips

  • AskAsk who is accountable for the cyber security awareness training program.GoodDocumentation clearly assigns the CISO oversight of developing, implementing and maintaining the program.
  • AskAsk to see the current cyber security awareness training program and its plan.GoodA CISO-approved plan covering objectives, target audiences, content and delivery cadence.
  • AskAsk how the training material was developed and who approved it.GoodEvidence the CISO reviewed and approved the training content before release.
  • AskAsk how the training has been delivered to personnel.GoodRecords showing personnel have completed the current training, with coverage monitored by the CISO.
  • AskAsk how the training is kept current.GoodRegular reviews at least annually, with dated updates authorised by the CISO.
link

Cross-framework mappings

How ISM-0735 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 7.3ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, focusing on facility-level...
sync_altPartially overlaps(4)expand_less
Annex A 7.1ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, which typically depends on...
Annex A 7.5ISM-0735 addresses keeping classified systems in secure locations suitable for their classification, which includes ensuring the environm...
Annex A 7.6ISM-0735 requires classified systems to be housed in secure locations commensurate with their classification, implying controlled environ...
Annex A 7.8ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, addressing the physical pr...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls