Skip to content
arrow_back
search
ISM-1784 policy ASD Information Security Manual (ISM)

Annual Testing of Cyber Incident Response Plan

The organisation tests its cyber incident response plan every year to ensure it's effective.

record_voice_over

Plain language

This control means your organisation needs to test its plan for handling cyber incidents every year. It's important because if you don't check your response plan, you might be unprepared when a data breach or cyber attack happens, which could result in lost data, downtime for your business, and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The cyber security incident management policy, including the associated cyber security incident response plan, is exercised at least annually.
policy ASD Information Security Manual (ISM) ISM-1784
priority_high

Why it matters

An untested incident response plan may lead to prolonged downtime and chaos during real cyber attacks, increasing recovery costs and reputational damage.

settings

Operational notes

Exercise the incident response plan at least annually; capture lessons learned, update playbooks and contacts, and confirm each role is understood.

Mapping detail

Mapping

Direction

Controls