ASD ISM 0735CISO Oversees the Cyber Security Awareness Training Program
Official control statement
The CISO oversees the development, implementation and maintenance of their organisation's cyber security awareness training program.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
The CISO oversees the development, implementation and maintenance of the organisation's cyber security awareness training program.
What this means in practice
This control ensures that the Chief Information Security Officer (CISO) is accountable for the organisation's cyber security awareness training program. The CISO guides how the training is designed, rolled out to staff, and kept up to date over time. Clear ownership at a senior level keeps the training relevant, makes sure it reaches everyone, and helps people recognise and avoid cyber threats.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
Dec 2022
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesTopic
Overseeing cyber security awareness training
Why it matters
Without clear CISO oversight, awareness training can become outdated, inconsistent or neglected, leaving staff ill-equipped to recognise cyber threats and increasing the risk of successful attacks.
Operational notes
The CISO should schedule periodic reviews of the training program to keep content aligned with emerging threats and organisational changes.
Implementation tips
- Formally assign the CISO accountability for the cyber security awareness training program in a role description, governance charter or terms of reference.
- Have the CISO approve a training plan that sets learning objectives, target audiences, delivery methods and a schedule covering all personnel.
- Direct the CISO to work with content owners to develop training material covering current threats, organisational security policies and staff responsibilities.
- Deliver the training to all personnel through the organisation's learning platform and record completion so the CISO can confirm coverage.
- Task the CISO with reviewing and updating the training at least annually, and after significant incidents or changes to the threat landscape.
Audit / evidence tips
- AskAsk who is accountable for the cyber security awareness training program.Look atRole descriptions, governance charter or terms of reference that name the CISO.GoodDocumentation clearly assigns the CISO oversight of developing, implementing and maintaining the program.
- AskAsk to see the current cyber security awareness training program and its plan.Look atThe documented training plan, syllabus or program schedule.GoodA CISO-approved plan covering objectives, target audiences, content and delivery cadence.
- AskAsk how the training material was developed and who approved it.Look atContent development records and CISO review or sign-off.GoodEvidence the CISO reviewed and approved the training content before release.
- AskAsk how the training has been delivered to personnel.Look atCompletion records, learning platform reports or attendance logs.GoodRecords showing personnel have completed the current training, with coverage monitored by the CISO.
- AskAsk how the training is kept current.Look atVersion history, review dates and change logs for the training material.GoodRegular reviews at least annually, with dated updates authorised by the CISO.
Cross-framework mappings
How ISM-0735 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| Annex A 5.4 | ISM-0735 requires the CISO to oversee the development, implementation and maintenance of the organisation's cyber security awareness trai... | |
| Annex A 6.3 | ISM-0735 requires the CISO to oversee the development, implementation and maintenance of the organisation's cyber security awareness trai... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.