CISO Manages and Verifies System Register
The CISO keeps and checks a list of all the systems the organisation uses.
Plain language
The Chief Information Security Officer (CISO) needs to have and regularly check a complete list of all computer systems the organisation uses. This is important because without an accurate list, systems could go unmanaged and become susceptible to security threats or failures without anyone knowing.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
The CISO develops, implements, maintains and regularly verifies a register of systems used by their organisation.
Why it matters
Without a verified system register, vulnerabilities may remain unnoticed, leading to cybersecurity breaches, data loss, or system failures.
Operational notes
Keep the system register updated continuously through regular communication between departments, HR, and IT to uphold cybersecurity standards.
Implementation tips
- The CISO should assign someone to compile a list of every system the organisation uses. Work with IT and department heads to identify systems used across various departments and ensure the list is thorough.
- The IT team should maintain and update the system list regularly. Designate a team member to check the list every month for any changes like new systems being added or old ones being removed.
- Department managers should inform the IT team about any new systems they start using. Create a simple form for managers to fill out any time they add or plan to retire a system.
- HR should ensure any employee onboarding or offboarding includes a review of the systems they may have access to. This helps keep the system register accurate and up-to-date.
- The CISO should review the system register with security staff quarterly. This review ensures every system on the list complies with security policies and any necessary updates or precautions are in place.
Audit / evidence tips
- Askthe current system register: Ensure it contains a comprehensive list of all systems used by the organisation, with details like system name, purpose, and department
- Look atupdate logs for the system register: Check these logs to see how frequently updates occur and if they note changes such as newly added systems or decommissioned ones
- Askrecords of quarterly review meetings: Verify there is a documented meeting between the CISO and the security team about the system register and any resulting actions
- Look atthe communication logs: Confirm departments report new systems to IT through established forms or emails. Good communication logs show consistent and timely updates
- Request audit reports to ensure the register matches real-world use: Inspect reports comparing the system register against actual systems in use to see if they align accurately.
Cross-framework mappings
How ISM-1966 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 5.9 | Annex A 5.9 requires maintaining an inventory of information and associated assets, including ownership | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| E8-PA-ML1.1 | ISM-1966 requires the CISO to maintain and regularly verify a register of organisational systems | |
| E8-PO-ML1.1 | ISM-1966 requires the CISO to maintain and regularly verify a register of organisational systems | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.