Skip to content
arrow_back
search
ISM-2003 policy ASD Information Security Manual (ISM)

Monitor Cyber Security Workforce and Skill Gaps

Executives should stay informed on hiring and skills gaps in their cyber security team.

record_voice_over

Plain language

This control is about making sure that the people at the top of an organisation, like the board of directors, are aware of what's happening with the cyber security team. They need to know if there are enough qualified people, if those people have the right skills, and if they are staying with the company. If the leaders aren't paying attention, the organisation might not have the right people to protect it from cyber threats, leading to potential data breaches or financial loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee maintains awareness of key cyber security recruitment activities, retention rates for cyber security personnel, and cyber security skills and experience gaps within their organisation.
policy ASD Information Security Manual (ISM) ISM-2003
priority_high

Why it matters

Without executive oversight of cyber security recruitment, retention and skill gaps, key roles may remain unfilled and capability erodes, increasing breach likelihood and business impact.

settings

Operational notes

Provide quarterly board/executive reporting on cyber recruitment pipelines, retention metrics and skills-gap analysis, with actions, owners and dates to close capability shortfalls.

Mapping detail

Mapping

Direction

Controls