Skip to content
arrow_back
search
ISM-1918 policy ASD Information Security Manual (ISM)

Regular Cyber Security Reporting to Audit Committee

The CISO reports cyber security updates directly to the organisation's risk committee.

record_voice_over

Plain language

This control is about the Chief Information Security Officer (CISO) keeping the organisation's audit and risk committee updated on cyber security matters. It's important because regular updates help ensure that top decision-makers are aware of cyber risks and can make informed decisions to protect the organisation from cyber threats.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO regularly reports directly to their organisation's audit, risk and compliance committee (or equivalent) on cyber security matters.
policy ASD Information Security Manual (ISM) ISM-1918
priority_high

Why it matters

Without regular CISO reporting to the audit committee, cyber risk oversight weakens, delaying decisions on threats and increasing likelihood and impact of a breach.

settings

Operational notes

Schedule CISO updates to the audit/risk committee with a standing agenda: current threats, incidents, control gaps, and risk acceptance decisions with owners and due dates.

Mapping detail

Mapping

Direction

Controls