Skip to content
arrow_back
search
ISM-2006 policy ASD Information Security Manual (ISM)

Executive Planning for Cyber Incident Preparedness

Executives must plan and practice handling major cyber incidents to know their responsibilities.

record_voice_over

Plain language

Planning and practising for potential cyber attacks is crucial for executives, as this ensures they know exactly what to do when a serious threat occurs. Without a plan, the organisation risks confusion and delayed responses, which can lead to significant losses or damage to its reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understand their duties in relation to such cyber security incidents.
policy ASD Information Security Manual (ISM) ISM-2006
priority_high

Why it matters

If the board/executive committee does not plan and rehearse for major cyber incidents, critical decisions may be delayed or wrong, worsening legal, financial and operational impacts.

settings

Operational notes

Schedule executive-led cyber incident exercises; document board/executive duties, delegations and decision thresholds, then update plans and playbooks after each exercise.

Mapping detail

Mapping

Direction

Controls