Skip to content
arrow_back
search
ISM-2002 policy ASD Information Security Manual (ISM)

Ensure Board Cyber Security Literacy for Compliance

Executive leaders must understand cyber security to meet legal and regulatory responsibilities.

record_voice_over

Plain language

This control means that the board of directors or top executives need to understand enough about cyber security to make informed decisions and ensure the company complies with laws and regulations. If they don’t, the organisation could face legal penalties, financial losses, or damage to its reputation if a cyber attack occurs.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee maintains a sufficient level of cyber security literacy to fulfil both their fiduciary duties and any legislative or regulatory obligations.
policy ASD Information Security Manual (ISM) ISM-2002
priority_high

Why it matters

Lack of board cyber literacy can lead to uninformed decisions, resulting in regulatory breaches and severe reputational and financial harm.

settings

Operational notes

Provide quarterly board briefings on cyber risk, regulatory duties and incidents; record attendance and actions to evidence literacy.

Mapping detail

Mapping

Direction

Controls