Skip to content
arrow_back
search
ISM-1617 policy ASD Information Security Manual (ISM)

Regular Review of Cyber Security Program

The CISO ensures the cyber security program stays relevant to combat threats and seize opportunities.

record_voice_over

Plain language

The cybersecurity boss needs to frequently check and update the company's plan for dealing with online threats. This is important because if they fall behind, the company could become vulnerable to new types of cyber attacks, leading to potential data breaches or financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO regularly reviews and updates their organisation's cyber security program to ensure its relevance in addressing cyber threats and harnessing business and cyber security opportunities.
policy ASD Information Security Manual (ISM) ISM-1617
priority_high

Why it matters

Without regular reviews and updates, the cyber security program can drift from current threats and business priorities, increasing likelihood of incidents and reputational harm.

settings

Operational notes

Run biannual CISO-led program reviews; update the security roadmap, priorities and metrics using recent incidents, threat intel and business changes, and track actions to closure.

Mapping detail

Mapping

Direction

Controls