Skip to content
arrow_back
search
ISM-1071 policy ASD Information Security Manual (ISM)

Assign System Ownership for Better Oversight

Every system should have a specific person responsible for managing it.

record_voice_over

Plain language

Every system in your organisation needs someone in charge of it. Think of it like assigning a captain for each ship. This matters because when no one is responsible, issues like security holes can slip through the cracks, leading to data loss or costly downtime.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2018

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Each system has a designated system owner.
policy ASD Information Security Manual (ISM) ISM-1071
priority_high

Why it matters

Without a designated system owner, accountability falters, leaving systems vulnerable to unchecked security gaps and unmanaged incidents.

settings

Operational notes

Maintain a system ownership register and review it quarterly; update the named owner and delegations when staff or responsibilities change.

Mapping detail

Mapping

Direction

Controls