Skip to content
arrow_back
search
ISM-1565 policy ASD Information Security Manual (ISM)

Annual Training for Privileged Users

Privileged users receive yearly customised cyber security training.

record_voice_over

Plain language

Privileged users, like IT administrators, need to get special security training every year. This is important because these users can access sensitive parts of systems, and without proper training, they could accidentally or unintentionally expose the organisation to cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Tailored privileged user training is undertaken annually by all privileged users.
policy ASD Information Security Manual (ISM) ISM-1565
priority_high

Why it matters

If privileged users skip annual training, misconfiguration and misuse of elevated access increases, raising likelihood of insider incidents and major compromise.

settings

Operational notes

Update privileged user training yearly for new threats/tools; record completion for all admin accounts and follow up on non-completions before access review.

Mapping detail

Mapping

Direction

Controls