Skip to content
arrow_back
ISM-1966policyASD Information Security Manual (ISM)

CISO Manages and Verifies System Register

The CISO keeps and checks a list of all the systems the organisation uses.

record_voice_over

Plain language

The Chief Information Security Officer (CISO) needs to have and regularly check a complete list of all computer systems the organisation uses. This is important because without an accurate list, systems could go unmanaged and become susceptible to security threats or failures without anyone knowing.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.
policyASD Information Security Manual (ISM)ISM-1966
priority_high

Why it matters

Without a verified system register, vulnerabilities may remain unnoticed, leading to cybersecurity breaches, data loss, or system failures.

settings

Operational notes

Keep the system register updated continuously through regular communication between departments, HR, and IT to uphold cybersecurity standards.

build

Implementation tips

  • The CISO should assign someone to compile a list of every system the organisation uses. Work with IT and department heads to identify systems used across various departments and ensure the list is thorough.
  • The IT team should maintain and update the system list regularly. Designate a team member to check the list every month for any changes like new systems being added or old ones being removed.
  • Department managers should inform the IT team about any new systems they start using. Create a simple form for managers to fill out any time they add or plan to retire a system.
  • HR should ensure any employee onboarding or offboarding includes a review of the systems they may have access to. This helps keep the system register accurate and up-to-date.
  • The CISO should review the system register with security staff quarterly. This review ensures every system on the list complies with security policies and any necessary updates or precautions are in place.
fact_check

Audit / evidence tips

  • Askthe current system register: Ensure it contains a comprehensive list of all systems used by the organisation, with details like system name, purpose, and department
  • Look atupdate logs for the system register: Check these logs to see how frequently updates occur and if they note changes such as newly added systems or decommissioned ones
  • Askrecords of quarterly review meetings: Verify there is a documented meeting between the CISO and the security team about the system register and any resulting actions
  • Look atthe communication logs: Confirm departments report new systems to IT through established forms or emails. Good communication logs show consistent and timely updates
  • Request audit reports to ensure the register matches real-world use: Inspect reports comparing the system register against actual systems in use to see if they align accurately.
link

Cross-framework mappings

How ISM-1966 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 5.9Annex A 5.9 requires maintaining an inventory of information and associated assets, including ownership

E8

ControlNotesDetails
handshakeSupports(2)expand_less
E8-PA-ML1.1ISM-1966 requires the CISO to maintain and regularly verify a register of organisational systems
E8-PO-ML1.1ISM-1966 requires the CISO to maintain and regularly verify a register of organisational systems

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls