ASD ISM 1526Continuously Monitor System Security and Manage Risks
System owners continuously monitor the security of each system and manage the associated cyber threats, security risks and controls.
Plain language
This control ensures the person responsible for each system keeps a constant eye on its security instead of checking it once and moving on. System owners watch for new cyber threats, keep track of the security risks facing the system, and make sure the controls protecting it are working and still adequate. This matters because threats and system changes appear all the time, so a control that was enough last month may no longer be enough today.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
Mar 2026
Control Stack last updated
10 Aug 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesSection
System ownersOfficial control statement
System owners continuously monitor the security of each system, and manage associated cyber threats, security risks and controls.
Why it matters
Without continuous monitoring, emerging cyber threats, changing risks and failing controls can go unnoticed until they are exploited, leading to system compromise or prolonged undetected breaches.
Operational notes
Treat monitoring as a continuous cycle, reviewing threats, risks and control effectiveness on a set cadence rather than only at audit or accreditation time.
Implementation tips
- System owners assign clear ownership for every system and schedule regular reviews of its security posture, threats and risks.
- Configure security monitoring and logging tools so events and alerts for each system flow into a central place the system owner reviews.
- Maintain a per-system risk register and update it whenever new threats, vulnerabilities or business changes are identified.
- Track the status and effectiveness of each control, and remediate or replace any control that is failing or no longer adequate.
- Establish a recurring cadence (for example monthly) where system owners review monitoring output, reassess risks and record the decisions and actions taken.
Audit / evidence tips
- AskAsk who the system owner is for each system and how they continuously monitor its security.GoodEvery system has a named owner with clearly assigned, documented monitoring duties.
- AskAsk to see evidence of ongoing security monitoring for a sample of systems.GoodLive monitoring is in place and reviewed on a regular cadence, with dated records showing it happens.
- AskAsk how cyber threats affecting each system are identified and managed.GoodThreats are tracked against specific systems and lead to recorded assessment and action.
- AskAsk how security risks for each system are assessed and kept current.GoodRisk registers are current and dated, showing ongoing reassessment rather than one-off entries.
- AskAsk how the effectiveness of controls is checked and maintained over time.GoodControls are periodically verified, and any failing control has a recorded remediation action and timeline.
Cross-framework mappings
How ISM-1526 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(3)expand_less | ||
| Annex A 5.7 | ISM-1526 requires system owners to monitor each system and its associated cyber threats, security risks and controls on an ongoing basis | |
| Annex A 8.15 | ISM-1526 requires system owners to continuously monitor system security and manage cyber threats, risks and controls for each system | |
| Annex A 8.16 | ISM-1526 requires continuous monitoring of each system’s security and ongoing management of cyber threats, risks and controls based on sy... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(5)expand_less | ||
| E8-AC-ML2.8 | ISM-1526 requires system owners to continuously monitor system security and manage cyber threats and risks for each system | |
| E8-MF-ML2.9 | ISM-1526 requires system owners to continuously monitor each system’s security and manage associated threats, risks and controls within d... | |
| E8-RA-ML2.9 | ISM-1526 requires system owners to continuously monitor system security and manage cyber threats, security risks and controls within defi... | |
| E8-RA-ML2.10 | ISM-1526 requires system owners to monitor systems and associated cyber threats and risks on an ongoing basis | |
| E8-AH-ML2.15 | ISM-1526 requires ongoing monitoring of systems and associated cyber threats, security risks and controls by system owners | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.