Skip to content
arrow_back
search
ISM-2004 policy ASD Information Security Manual (ISM)

Enhancing Cyber Security Skills and Experience

The board supports cyber security training for all staff using internal and external opportunities.

record_voice_over

Plain language

This control is about ensuring everyone in your organisation gets proper training on cyber security. It's important because if your staff aren't aware of the latest security threats and how to handle them, your organisation could be at risk of data breaches, financial losses, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee supports the development of cyber security skills and experience for all personnel via internal and external cyber security awareness raising and training opportunities.
policy ASD Information Security Manual (ISM) ISM-2004
priority_high

Why it matters

Without executive-backed cyber security training and awareness, staff are more likely to make avoidable errors, enabling breaches and data loss.

settings

Operational notes

Have executives sponsor role-based cyber security training and awareness, track completion, and fund external courses to build staff skills and experience.

Mapping detail

Mapping

Direction

Controls