Skip to content
arrow_back
search
ISM-1999 policy ASD Information Security Manual (ISM)

Align Cyber Security with Business Strategy

Leadership ensures cyber security strategy aligns with the company's overall business direction.

record_voice_over

Plain language

Aligning your cyber security strategy with your business goals is like making sure your seatbelt matches your speed. If the two aren't in sync, you could end up with serious problems, like breaches that cost you money, damage your reputation, or even halt your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee ensures the cyber security strategy for their organisation is aligned with the overarching strategic direction and business strategy for their organisation.
policy ASD Information Security Manual (ISM) ISM-1999
priority_high

Why it matters

Without board/executive alignment, cyber security strategy may not support business priorities, leading to misdirected investment, unmanaged risk and delivery delays.

settings

Operational notes

At least annually, have the board/executive committee approve a cyber security strategy mapped to business objectives, risk appetite and major programs; track KPIs and reprioritise funding as strategy changes.

Mapping detail

Mapping

Direction

Controls