Understanding Business Criticality of Organisation Systems
Leaders need to know the importance, location, and protection of critical business systems.
Plain language
This control ensures that business leaders understand which systems are crucial to their operations, where they are located, and how they are protected. It's important because if executives aren't aware of these systems, they could miss key risks, leading to business disruptions or data breaches.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
The board of directors or executive committee understands the business criticality of their organisation's systems, including at least a basic understanding of what systems exist, their value, where they reside, who has access, who might seek access, how they are protected, and how that protection is verified.
Why it matters
If this control is not followed, critical business operations could be disrupted, leading to financial loss and reputational damage.
Operational notes
Regularly review and update who has access to critical systems to ensure that only necessary personnel have permissions.
Implementation tips
- The IT Manager should provide a regular brief to the board explaining which systems are most crucial for business operations. This can be done by listing key systems, their purpose, location, and any known risks in a simple report.
- Security personnel should organise a security audit to identify who has access to each critical system and ensure that only authorised personnel have entry. They can achieve this by reviewing access logs and updating access permissions as needed.
- The business continuity manager should develop clear documentation of where critical systems reside, whether on-site servers, cloud, or third-party providers. This should include contact details for vendors or third-party support.
- Risk management teams should assess the value of each system in terms of business impact if it were to fail, which can be done through an impact assessment workshop with department heads.
- Management should verify the security measures protecting critical systems by reviewing performance reports from security tools regularly. This helps ensure that measures are working and any breaches are quickly addressed.
Audit / evidence tips
- Askthe latest board briefing on critical systems: Request a copy of the report presented to the boardLook atthe completeness in terms of listed critical systems and the risks involvedGoodwill include detailed descriptions of key systems and identified risks
- Askaccess control logs: Request documentation showing who has access to critical systemsLook atthe last audit or update of permissionsGoodshows updated logs and limited access to authorised personnel only
- Asksecurity audit reports: Request the most recent audit conclusions on system protection measuresLook atthe scope of the audit covering critical systemsGoodwill have clear findings and actionable recommendations
- Askbusiness impact assessments: Request copies of recent assessments carried out on system failuresLook atdetailed analyses of potential impactsGoodshows clear understanding of consequences of system failures
- Asksecurity performance reports: Request reports from tools monitoring system protectionLook atmetrics on threat detection and response timesGoodshows steady monitoring with no major breaches
Cross-framework mappings
How ISM-2005 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(5)expand_less | ||
| Annex A 5.9 | Annex A 5.9 requires an accurate and maintained inventory of information and associated assets, including ownership | |
| Annex A 5.15 | ISM-2005 requires the board or executive committee to understand critical systems, where they reside, and who has access, including how c... | |
| Annex A 5.18 | ISM-2005 requires executives to understand who has access to critical systems and how that access is controlled and verified | |
| Annex A 5.35 | ISM-2005 requires executives to understand how critical systems are protected and how that protection is verified | |
| Annex A 8.2 | ISM-2005 requires the board or executive committee to understand critical systems and who has access, including the adequacy of protectio... | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.