Skip to content
arrow_back
ISM-2005policyASD Information Security Manual (ISM)

Understanding Business Criticality of Organisation Systems

Leaders need to know the importance, location, and protection of critical business systems.

record_voice_over

Plain language

This control ensures that business leaders understand which systems are crucial to their operations, where they are located, and how they are protected. It's important because if executives aren't aware of these systems, they could miss key risks, leading to business disruptions or data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee understands the business criticality of their organisation's systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.
policyASD Information Security Manual (ISM)ISM-2005
priority_high

Why it matters

If this control is not followed, critical business operations could be disrupted, leading to financial loss and reputational damage.

settings

Operational notes

Regularly review and update who has access to critical systems to ensure that only necessary personnel have permissions.

build

Implementation tips

  • The IT Manager should provide a regular brief to the board explaining which systems are most crucial for business operations. This can be done by listing key systems, their purpose, location, and any known risks in a simple report.
  • Security personnel should organise a security audit to identify who has access to each critical system and ensure that only authorised personnel have entry. They can achieve this by reviewing access logs and updating access permissions as needed.
  • The business continuity manager should develop clear documentation of where critical systems reside, whether on-site servers, cloud, or third-party providers. This should include contact details for vendors or third-party support.
  • Risk management teams should assess the value of each system in terms of business impact if it were to fail, which can be done through an impact assessment workshop with department heads.
  • Management should verify the security measures protecting critical systems by reviewing performance reports from security tools regularly. This helps ensure that measures are working and any breaches are quickly addressed.
fact_check

Audit / evidence tips

  • Askthe latest board briefing on critical systems: Request a copy of the report presented to the boardLook atthe completeness in terms of listed critical systems and the risks involvedGoodwill include detailed descriptions of key systems and identified risks
  • Askaccess control logs: Request documentation showing who has access to critical systemsLook atthe last audit or update of permissionsGoodshows updated logs and limited access to authorised personnel only
  • Asksecurity audit reports: Request the most recent audit conclusions on system protection measuresLook atthe scope of the audit covering critical systemsGoodwill have clear findings and actionable recommendations
  • Askbusiness impact assessments: Request copies of recent assessments carried out on system failuresLook atdetailed analyses of potential impactsGoodshows clear understanding of consequences of system failures
  • Asksecurity performance reports: Request reports from tools monitoring system protectionLook atmetrics on threat detection and response timesGoodshows steady monitoring with no major breaches
link

Cross-framework mappings

How ISM-2005 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
handshakeSupports(5)expand_less
Annex A 5.9Annex A 5.9 requires an accurate and maintained inventory of information and associated assets, including ownership
Annex A 5.15ISM-2005 requires the board or executive committee to understand critical systems, where they reside, and who has access, including how c...
Annex A 5.18ISM-2005 requires executives to understand who has access to critical systems and how that access is controlled and verified
Annex A 5.35ISM-2005 requires executives to understand how critical systems are protected and how that protection is verified
Annex A 8.2ISM-2005 requires the board or executive committee to understand critical systems and who has access, including the adequacy of protectio...

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls