Skip to content
arrow_back
search
ISM-2000 policy ASD Information Security Manual (ISM)

Regular Cyber Security Briefings for Executives

Executives receive regular updates on cyber security and threats from experts.

record_voice_over

Plain language

This control is about making sure that the leaders of an organisation get regular updates from cyber security experts about the current risks and how well the organisation is protected. This is important because without these updates, executives might not realise emerging threats or weaknesses, which could lead to significant financial loss, reputational damage, or legal issues if a cyber attack occurs.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee seeks regular briefings or reporting on the cyber security posture of their organisation, as well as the threat environment in which they operate, from internal and external subject matter experts.
policy ASD Information Security Manual (ISM) ISM-2000
priority_high

Why it matters

Without regular board/executive cyber briefings, leaders may miss posture and threat trends, delaying decisions and increasing breach, loss, and reputational damage risk.

settings

Operational notes

Schedule board/executive committee briefings (e.g., quarterly) covering security posture, key incidents, risk metrics and current threat environment, using internal and external SMEs.

Mapping detail

Mapping

Direction

Controls