ASD ISM 0735CISO Oversees the Cyber Security Awareness Training Program
The CISO oversees the development, implementation and maintenance of the organisation's cyber security awareness training program.
Plain language
This control ensures that the Chief Information Security Officer (CISO) is accountable for the organisation's cyber security awareness training program. The CISO guides how the training is designed, rolled out to staff, and kept up to date over time. Clear ownership at a senior level keeps the training relevant, makes sure it reaches everyone, and helps people recognise and avoid cyber threats.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2022
Control Stack last updated
10 Aug 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
Why it matters
Without clear CISO oversight, awareness training can become outdated, inconsistent or neglected, leaving staff ill-equipped to recognise cyber threats and increasing the risk of successful attacks.
Operational notes
The CISO should schedule periodic reviews of the training program to keep content aligned with emerging threats and organisational changes.
Implementation tips
- Formally assign the CISO accountability for the cyber security awareness training program in a role description, governance charter or terms of reference.
- Have the CISO approve a training plan that sets learning objectives, target audiences, delivery methods and a schedule covering all personnel.
- Direct the CISO to work with content owners to develop training material covering current threats, organisational security policies and staff responsibilities.
- Deliver the training to all personnel through the organisation's learning platform and record completion so the CISO can confirm coverage.
- Task the CISO with reviewing and updating the training at least annually, and after significant incidents or changes to the threat landscape.
Audit / evidence tips
- AskAsk who is accountable for the cyber security awareness training program.GoodDocumentation clearly assigns the CISO oversight of developing, implementing and maintaining the program.
- AskAsk to see the current cyber security awareness training program and its plan.GoodA CISO-approved plan covering objectives, target audiences, content and delivery cadence.
- AskAsk how the training material was developed and who approved it.GoodEvidence the CISO reviewed and approved the training content before release.
- AskAsk how the training has been delivered to personnel.GoodRecords showing personnel have completed the current training, with coverage monitored by the CISO.
- AskAsk how the training is kept current.GoodRegular reviews at least annually, with dated updates authorised by the CISO.
Cross-framework mappings
How ISM-0735 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 7.3 | ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, focusing on facility-level... | |
sync_altPartially overlaps(4)expand_less | ||
| Annex A 7.1 | ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, which typically depends on... | |
| Annex A 7.5 | ISM-0735 addresses keeping classified systems in secure locations suitable for their classification, which includes ensuring the environm... | |
| Annex A 7.6 | ISM-0735 requires classified systems to be housed in secure locations commensurate with their classification, implying controlled environ... | |
| Annex A 7.8 | ISM-0735 requires classified systems to be kept in secure locations appropriate to their classification level, addressing the physical pr... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.