Skip to content
arrow_back
search
ISM-1739 policy ASD Information Security Manual (ISM)

Approve Security Architecture Before System Development

Ensure system security plans are approved before starting system development.

record_voice_over

Plain language

Before starting on system development, it's important to get approval for the system's security plans. This ensures that security is built into the system right from the start, reducing the risk of data breaches or cyber attacks that could cost you money and harm your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A system's security architecture is approved prior to the development of the system.
policy ASD Information Security Manual (ISM) ISM-1739
priority_high

Why it matters

If security architecture isn’t approved before development, insecure design choices may be built in, causing rework, delays and exploitable vulnerabilities.

settings

Operational notes

Require documented security architecture approval (e.g., design review sign-off) before build starts and before major changes or new development phases proceed.

Mapping detail

Mapping

Direction

Controls