Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1526Continuously Monitor System Security and Manage Risks

System owners continuously monitor the security of each system and manage the associated cyber threats, security risks and controls.

record_voice_over

Plain language

This control ensures the person responsible for each system keeps a constant eye on its security instead of checking it once and moving on. System owners watch for new cyber threats, keep track of the security risks facing the system, and make sure the controls protecting it are working and still adequate. This matters because threats and system changes appear all the time, so a control that was enough last month may no longer be enough today.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Mar 2026

Control Stack last updated

10 Aug 2026

E8 maturity levels

N/A

Official control statement

System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.
policyASD Information Security Manual (ISM)ISM-1526
priority_high

Why it matters

Without continuous monitoring, emerging cyber threats, changing risks and failing controls can go unnoticed until they are exploited, leading to system compromise or prolonged undetected breaches.

settings

Operational notes

Treat monitoring as a continuous cycle, reviewing threats, risks and control effectiveness on a set cadence rather than only at audit or accreditation time.

build

Implementation tips

  • System owners assign clear ownership for every system and schedule regular reviews of its security posture, threats and risks.
  • Configure security monitoring and logging tools so events and alerts for each system flow into a central place the system owner reviews.
  • Maintain a per-system risk register and update it whenever new threats, vulnerabilities or business changes are identified.
  • Track the status and effectiveness of each control, and remediate or replace any control that is failing or no longer adequate.
  • Establish a recurring cadence (for example monthly) where system owners review monitoring output, reassess risks and record the decisions and actions taken.
fact_check

Audit / evidence tips

  • AskAsk who the system owner is for each system and how they continuously monitor its security.GoodEvery system has a named owner with clearly assigned, documented monitoring duties.
  • AskAsk to see evidence of ongoing security monitoring for a sample of systems.GoodLive monitoring is in place and reviewed on a regular cadence, with dated records showing it happens.
  • AskAsk how cyber threats affecting each system are identified and managed.GoodThreats are tracked against specific systems and lead to recorded assessment and action.
  • AskAsk how security risks for each system are assessed and kept current.GoodRisk registers are current and dated, showing ongoing reassessment rather than one-off entries.
  • AskAsk how the effectiveness of controls is checked and maintained over time.GoodControls are periodically verified, and any failing control has a recorded remediation action and timeline.
link

Cross-framework mappings

How ISM-1526 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(3)expand_less
Annex A 5.7ISM-1526 requires system owners to monitor each system and its associated cyber threats, security risks and controls on an ongoing basis
Annex A 8.15ISM-1526 requires system owners to continuously monitor system security and manage cyber threats, risks and controls for each system
Annex A 8.16ISM-1526 requires continuous monitoring of each system’s security and ongoing management of cyber threats, risks and controls based on sy...

E8

ControlNotesDetails
handshakeSupports(5)expand_less
E8-AC-ML2.8ISM-1526 requires system owners to continuously monitor system security and manage cyber threats and risks for each system
E8-MF-ML2.9ISM-1526 requires system owners to continuously monitor each system’s security and manage associated threats, risks and controls within d...
E8-RA-ML2.9ISM-1526 requires system owners to continuously monitor system security and manage cyber threats, security risks and controls within defi...
E8-RA-ML2.10ISM-1526 requires system owners to monitor systems and associated cyber threats and risks on an ongoing basis
E8-AH-ML2.15ISM-1526 requires ongoing monitoring of systems and associated cyber threats, security risks and controls by system owners

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls