Skip to content
arrow_back
search
ISM-1478 policy ASD Information Security Manual (ISM)

CISO Management of Cyber Security Compliance

The CISO is responsible for managing the organisation's cyber security and ensuring compliance with relevant standards and laws.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) is like the captain of a ship when it comes to steering an organisation's cyber security. They are tasked with ensuring that the company follows all the rules and laws to protect its digital assets. If this isn't done correctly, the organisation risks facing fines, loss of customer trust, or even legal action if they fail to protect their information properly.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees their organisation's cyber security program and ensures their organisation's compliance with cyber security policy, standards, regulations and legislation.
policy ASD Information Security Manual (ISM) ISM-1478
priority_high

Why it matters

Without CISO oversight of cyber security compliance, policy and regulatory gaps persist, increasing breach likelihood, audit findings, and penalties.

settings

Operational notes

Define CISO accountability for compliance, keep a policy/standards compliance register, and require periodic CISO-led reviews and audit remediation reporting.

Mapping detail

Mapping

Direction

Controls