Skip to content
arrow_back
search
ISM-1525 policy ASD Information Security Manual (ISM)

Register Systems with Authorising Officers

System owners must register their systems with the designated authorising officer for oversight.

record_voice_over

Plain language

System owners must inform a designated authorising officer about each system they manage. This is important because it ensures the right person is aware and can provide oversight, reducing the risk of systems being mismanaged or neglected, which can lead to security breaches or operational failures.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

System owners register each system with its authorising officer.
policy ASD Information Security Manual (ISM) ISM-1525
priority_high

Why it matters

If systems aren’t registered with an authorising officer, they may operate without formal authorisation, oversight or accountability, increasing unmanaged security risk.

settings

Operational notes

Maintain a central system register and notify the authorising officer on onboarding, major changes, ownership transfer and decommissioning to keep authorisation current.

Mapping detail

Mapping

Direction

Controls