Skip to content
arrow_back
search
ISM-1997 policy ASD Information Security Manual (ISM)

Define Cyber Security Roles for Leadership

The board sets specific cyber security roles and duties for themselves and the whole organisation.

record_voice_over

Plain language

It's essential for the board of directors or top executives to clearly define who is responsible for different aspects of cyber security within the company. If this isn't done, responsibilities can fall through the cracks, meaning potential security threats might not be managed properly, leading to data breaches or financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee defines clear roles and responsibilities for cyber security both within the board of directors or executive committee and broadly within their organisation.
policy ASD Information Security Manual (ISM) ISM-1997
priority_high

Why it matters

Undefined cyber security roles at board/executive level create governance gaps, weakening oversight and increasing risk of strategic security incidents.

settings

Operational notes

Maintain a board/executive RACI for cyber security; assign named owners for oversight, risk appetite, reporting cadence, and major security decisions, and review quarterly.

Mapping detail

Mapping

Direction

Controls