Skip to content
arrow_back
search
ISM-1523 policy ASD Information Security Manual (ISM)

Regular Assessment of Security Events in CDS

Every three months, security events are reviewed to ensure CDS are working correctly and follow data transfer policies.

record_voice_over

Plain language

This control is about checking every three months that the systems used to securely transfer data are working as they should and following the rules set out for them. If this isn't done, mistakes or security issues in data transfers may go unnoticed, potentially leading to data breaches or unauthorised access to sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A sample of security-relevant events relating to data transfer policies are taken at least every three months and assessed against security policies for CDSs to identify any operational failures.
policy ASD Information Security Manual (ISM) ISM-1523
priority_high

Why it matters

Without quarterly sampling and assessment of CDS data-transfer events, policy failures may go unnoticed, enabling unauthorised data exfiltration or disclosure.

settings

Operational notes

At least every 3 months, sample CDS data-transfer events/logs and compare against transfer policies; record findings, investigate deviations, and remediate failures.

Mapping detail

Mapping

Direction

Controls