Skip to content
arrow_back
search
ISM-2001 policy ASD Information Security Manual (ISM)

Championing Cyber Security at an Executive Level

Executives set a good example to promote a healthy cyber security culture in the organisation.

record_voice_over

Plain language

This control is about ensuring the leaders of an organisation promote good cyber security practices by setting a positive example. When executives actively support cyber security, it encourages everyone to follow suit, reducing risks like data breaches or other damaging cyber incidents.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee champions a positive cyber security culture within their organisation, including through leading by example.
policy ASD Information Security Manual (ISM) ISM-2001
priority_high

Why it matters

Without board/executive championing of cyber security, staff follow suit, weakening culture and increasing likelihood of incidents, breaches and losses.

settings

Operational notes

Executives/board should visibly lead by example (briefings, messaging, compliance), sponsor security initiatives, and fund priorities to reinforce a positive cyber security culture.

Mapping detail

Mapping

Direction

Controls