Skip to content
arrow_back
search
ISM-0888 policy ASD Information Security Manual (ISM)

Annual Review of Cyber Security Documentation

Cyber security documents are checked yearly to ensure they are up-to-date.

record_voice_over

Plain language

This control is all about making sure your business's cyber security documents are kept up-to-date. It's like checking your pantry every year to toss expired items and restock essentials. If you don't do this, you might accidentally be following outdated advice, which could leave your organisation vulnerable to cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Cyber security documentation is reviewed at least annually and includes a 'current as at [date]' or equivalent statement.
policy ASD Information Security Manual (ISM) ISM-0888
priority_high

Why it matters

If cyber security documentation is not reviewed at least annually, staff may follow outdated guidance, raising security risk and audit non-compliance.

settings

Operational notes

Set an annual review cadence for all cyber security documents and add a “current as at [date]” line on each; track ownership and evidence of review.

Mapping detail

Mapping

Direction

Controls