Skip to content
arrow_back
search
ISM-1998 policy ASD Information Security Manual (ISM)

Integrate Cyber Security Across Business Functions

Leaders ensure cyber security is a part of every business area.

record_voice_over

Plain language

This control is about making sure cyber security is part of every part of the business. If cyber security isn't considered everywhere, small mistakes can lead to big problems like data breaches, financial loss, and damage to the business's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee ensures that cyber security is integrated throughout all business functions within their organisation.
policy ASD Information Security Manual (ISM) ISM-1998
priority_high

Why it matters

Without board-driven integration across business functions, security becomes siloed, creating inconsistent risk decisions and higher breach likelihood.

settings

Operational notes

Set executive-owned security KPIs for each business unit and review progress quarterly to keep security embedded in business planning and delivery.

Mapping detail

Mapping

Direction

Controls