ASD ISM 1526System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
Official control statement
System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and security controls.
Quoted as published. Everything else on this page is written by Control Stack.
In plain English
Each system's owner keeps watching its security posture after go-live, and keeps its cyber threats, security risks and security controls under active management rather than reviewing them once.
What this means in practice
Every system has a named system owner, and this control makes that owner responsible for the system's security on an ongoing basis, not just at the point it was authorised to operate. The owner keeps watch over how secure the system actually is, and actively manages three linked things: the cyber threats that could target it, the security risks those threats create, and the security controls that are meant to keep those risks acceptable. It matters because a system's security does not stand still. New vulnerabilities are published, threat actors change their techniques, the system itself is patched, reconfigured and integrated with other things, and staff and suppliers come and go. A risk assessment and set of controls that were sound at authorisation can quietly stop being adequate within months. If nobody with authority over the system is watching, the gap between "what we think protects the system" and "what actually protects it" widens until an attacker finds it first. Putting this on the system owner, rather than only on a central security team, is deliberate. The owner is the person who understands the system's purpose, data and users, who can approve changes and spend money on it, and who carries accountability for its risk. Continuous monitoring gives that owner the facts; managing threats, risks and controls is what they do with those facts.
Framework
ASD Information Security Manual (ISM)
Control effect (Control Stack)
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
29 Sept 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesSection
System ownersTopic
Protecting systems and their resources
Why it matters
Without continuous monitoring and active management by the system owner, changes in the threat environment, newly disclosed vulnerabilities, configuration drift and control failures go unnoticed, so the system's real risk rises above what was accepted at authorisation. Attackers exploit the unmanaged gap, and the organisation is exposed to compromise, data loss and service disruption while still believing the system is adequately protected. Accountability also blurs: when an incident occurs, nobody can show who was watching the system or who decided its risks and controls remained acceptable.
Operational notes
In practice this control runs as a steady rhythm owned by each system owner rather than a one-off project. The owner receives and reviews security information about their system on a regular cadence: vulnerability scan results, patch status, control health, security events and alerts, audit findings and the output of any security testing. They also receive threat information relevant to the system, whether from a security team, government advisories or vendors, and consider what it means for their system specifically.
The system's risk register and control set are living documents. When a new threat emerges, a vulnerability is found, a control is found to be failing, or a significant change to the system is proposed, the owner updates the risk assessment, decides whether the current controls are still sufficient, and either accepts the residual risk within their authority, escalates it, or directs remediation. Decisions and their rationale are recorded so the security posture of the system can be explained at any point in time.
Where the owner does not do the technical monitoring personally, they still remain accountable. The usual arrangement is that operations, security operations or a managed provider does the monitoring and reports to the owner, with clear thresholds for what is escalated immediately and what is summarised periodically. The owner should periodically confirm that this monitoring actually covers their system and that reporting is reaching them.
Implementation tips
- The CISO or security governance lead assigns a named system owner to every system in the system inventory and records in the owner's role description that they are accountable for continuously monitoring the system's security and managing its cyber threats, security risks and security controls.
- Each system owner, working with the security operations team or managed provider, defines what security monitoring covers their system (vulnerability scanning, patch compliance, logging and alerting, control health checks, security testing) and agrees how often results are reported to them and what is escalated immediately.
- Each system owner sets a recurring review, for example monthly, in which they read the monitoring reports for their system, update the system's risk register with any new or changed risks, and record decisions on whether existing controls remain adequate.
- The security team establishes a threat intelligence feed (government advisories, vendor notices, internal incident learnings) and routes items relevant to each system to its owner, who assesses the threat against the system and records any change to risks or controls.
- Each system owner, through the change management process, requires that significant changes to their system trigger a reassessment of the system's risks and controls before approval, and updates the system security documentation accordingly.
Audit / evidence tips
- AskAsk for the system inventory showing the named system owner for each system, and the role description or appointment record for a sample of owners.Look atCheck that every in-scope system has a current, named owner and that the owner's responsibilities explicitly include ongoing security monitoring and management of threats, risks and controls.GoodNo systems without an owner, owners are current staff, and the accountability for continuous security management is written down rather than assumed.
- AskAsk a sample of system owners to show the security monitoring reports they receive for their systems over the last several months.Look atLook for regular, system-specific reporting on vulnerabilities, patch status, control health and security events, with evidence the owner actually reviewed it (sign-off, meeting minutes, actions raised).GoodReports exist for each period without gaps, are specific to the system rather than generic, and show the owner engaging with the content and raising actions where needed.
- AskAsk for the system's risk register or risk assessment and its change history.Look atCheck that risks have been added, updated or closed over time in response to monitoring results, new threats or system changes, and that each change has a date, an owner decision and a rationale.GoodThe register is clearly a living document with recent entries that trace back to real events, not a static document last touched at authorisation.
- AskAsk how threat information reaches the system owner and for examples of threats assessed in the last year.Look atLook for evidence that advisories or intelligence relevant to the system were received, assessed for their impact on that specific system, and resulted in a documented decision or action.GoodThreat assessments are recorded per system, show the owner's reasoning about applicability, and link to any resulting changes to risks or controls.
- AskAsk for records showing how a failed or degraded security control on the system was handled.Look atTrace from the point the failure was detected through to the owner's decision (remediate, accept, escalate) and the resulting action, checking timeliness and that the decision sat within the owner's authority.GoodControl failures are detected by monitoring, reach the owner promptly, and produce a recorded decision and completed remediation or a properly approved risk acceptance.
Cross-framework mappings
How ISM-1526 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 8.8 | ISM-1526 requires system owners to continuously monitor security and manage cyber threats, security risks and security controls over time | |
| Annex A 8.16 | ISM-1526 requires continuous monitoring of each system's security and ongoing management of cyber threats, risks and controls based on sy... | |
handshakeSupports(2)expand_less | ||
| Annex A 5.7 | ISM-1526 requires system owners to monitor each system and its associated cyber threats, security risks and controls on an ongoing basis | |
| Annex A 8.15 | ISM-1526 requires system owners to continuously monitor system security and manage cyber threats, risks and controls for each system | |
E8
| Control | Notes | Details |
|---|---|---|
open_in_fullBroader than(2)expand_less | ||
handshakeSupports(4)expand_less | ||
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.