Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 0735CISO Oversees the Cyber Security Awareness Training Program

Official control statement

The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
policyASD Information Security Manual (ISM)ISM-0735

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

The CISO oversees the development, implementation and maintenance of the organisation's cyber security awareness training program.

NCOSPASD Information Security ManualGuidelines for cyber security roles
record_voice_over

What this means in practice

This control ensures that the Chief Information Security Officer (CISO) is accountable for the organisation's cyber security awareness training program. The CISO guides how the training is designed, rolled out to staff, and kept up to date over time. Clear ownership at a senior level keeps the training relevant, makes sure it reaches everyone, and helps people recognise and avoid cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2022

Control Stack last updated

29 Sept 2026

E8 maturity levels

N/A

Topic

Overseeing cyber security awareness training

priority_high

Why it matters

Without clear CISO oversight, awareness training can become outdated, inconsistent or neglected, leaving staff ill-equipped to recognise cyber threats and increasing the risk of successful attacks.

settings

Operational notes

The CISO should schedule periodic reviews of the training program to keep content aligned with emerging threats and organisational changes.

build

Implementation tips

  • Formally assign the CISO accountability for the cyber security awareness training program in a role description, governance charter or terms of reference.
  • Have the CISO approve a training plan that sets learning objectives, target audiences, delivery methods and a schedule covering all personnel.
  • Direct the CISO to work with content owners to develop training material covering current threats, organisational security policies and staff responsibilities.
  • Deliver the training to all personnel through the organisation's learning platform and record completion so the CISO can confirm coverage.
  • Task the CISO with reviewing and updating the training at least annually, and after significant incidents or changes to the threat landscape.
fact_check

Audit / evidence tips

  • AskAsk who is accountable for the cyber security awareness training program.Look atRole descriptions, governance charter or terms of reference that name the CISO.GoodDocumentation clearly assigns the CISO oversight of developing, implementing and maintaining the program.
  • AskAsk to see the current cyber security awareness training program and its plan.Look atThe documented training plan, syllabus or program schedule.GoodA CISO-approved plan covering objectives, target audiences, content and delivery cadence.
  • AskAsk how the training material was developed and who approved it.Look atContent development records and CISO review or sign-off.GoodEvidence the CISO reviewed and approved the training content before release.
  • AskAsk how the training has been delivered to personnel.Look atCompletion records, learning platform reports or attendance logs.GoodRecords showing personnel have completed the current training, with coverage monitored by the CISO.
  • AskAsk how the training is kept current.Look atVersion history, review dates and change logs for the training material.GoodRegular reviews at least annually, with dated updates authorised by the CISO.
link

Cross-framework mappings

How ISM-0735 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(2)expand_less
Annex A 5.4ISM-0735 requires the CISO to oversee the development, implementation and maintenance of the organisation's cyber security awareness trai...
Annex A 6.3ISM-0735 requires the CISO to oversee the development, implementation and maintenance of the organisation's cyber security awareness trai...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls