Skip to content
arrow_back
search
ISM-2005 policy ASD Information Security Manual (ISM)

Understand Critical Systems and Their Security

Board members must know their systems' importance, what they protect, and how well they're secured.

record_voice_over

Plain language

This control means that top leaders, like board members, need to understand which of their organisation's systems are most crucial and how they're being protected. This matters because if these key systems aren't well-protected, the organisation could face data breaches, financial losses, or damage to its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee understands the business criticality of their organisation's systems, including at least a basic understanding of what exists, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.
policy ASD Information Security Manual (ISM) ISM-2005
priority_high

Why it matters

If the board lacks visibility of critical systems, location, access and assurance, key assets may go unprotected or unverified, increasing breach, loss and reputational risk.

settings

Operational notes

Provide the board a current critical-system register (value, hosting, owners), key access/threat summaries, and evidence of control effectiveness (assurance reports, test results) each quarter.

Mapping detail

Mapping

Direction

Controls