Skip to content
arrow_back
search
ISM-1587 policy ASD Information Security Manual (ISM)

Annual Security Status Reporting for Systems

System owners must annually report each system's security status to an authorising officer.

record_voice_over

Plain language

System owners have to check and report how secure their systems are at least once a year to the person in charge of approving them. This is important because it keeps everyone aware of any risks or weaknesses in the systems, so they can fix problems before they lead to data leaks or other issues that could damage the organisation's reputation or operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

System owners report the security status of each system to its authorising officer at least annually.
policy ASD Information Security Manual (ISM) ISM-1587
priority_high

Why it matters

Missing annual security status reports can conceal system risks, leaving issues unreported to the authorising officer and increasing breach likelihood.

settings

Operational notes

Schedule annual security status reports and submit them to the authorising officer; include changes, incidents, outstanding risks and remediation progress.

Mapping detail

Mapping

Direction

Controls