Skip to content
arrow_back
search
ISM-1618 policy ASD Information Security Manual (ISM)

CISO's Role in Cyber Security Incident Response

The CISO is responsible for managing the organisation's reactions to cyber security threats.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) is like the safety manager for the digital side of a business. They make sure that the company knows how to handle any cyber security threats or issues. If this isn't done, the organisation might not respond quickly to a cyber attack, leading to data loss, financial damage, or reputational harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Sept 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO oversees their organisation's response to cyber security incidents.
policy ASD Information Security Manual (ISM) ISM-1618
priority_high

Why it matters

Without CISO oversight, incident response can be delayed or misdirected, increasing attack impact and risking regulatory, legal and financial consequences.

settings

Operational notes

Have the CISO review incident response plans and major response decisions, and ensure timely communication to executives and key stakeholders during incidents.

Mapping detail

Mapping

Direction

Controls