Skip to content
arrow_back
ISM-2006policyASD Information Security Manual (ISM)

Board Plans for Major Cyber Security Incidents

The board prepares for major cyber attacks by joining practice drills and knowing their responsibilities.

record_voice_over

Plain language

This control ensures that the board of directors or executive committee are actively involved in planning for significant cyber security incidents. It matters because if they are caught unprepared, a major cyber attack could lead to severe business disruptions and damage to the organisation's reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.
policyASD Information Security Manual (ISM)ISM-2006
priority_high

Why it matters

Without board involvement, a major cyber incident may be poorly managed, leading to prolonged downtime, data loss, and reputational damage.

settings

Operational notes

Regularly update and rehearse the incident response plan with the board's involvement to maintain preparedness and effective communication.

build

Implementation tips

  • Board members should participate in scheduled cyber security incident drills. Coordinate these with the IT and security teams to simulate potential breach scenarios and determine appropriate responses.
  • The executive committee should review and understand the organisation's incident response plan. This should involve a meeting with the cyber security manager to walk through the plan's key steps and ensure clarity on the roles and responsibilities.
  • Appoint a board member to take the lead on cyber security issues. This person can regularly liaise with the organisation's security experts to stay updated on potential threats and response strategies.
  • The CEO should organise regular briefings for the board on cyber security trends and risks. Invite external experts to present and provide insights on emerging threats and mitigation strategies.
  • Create a clear communication plan involving the board for use during a cyber incident. The communication officer should draft this plan, detailing who needs to be informed about incidents and how information is disseminated swiftly and accurately.
fact_check

Audit / evidence tips

  • Askrecords of board meeting minutes related to cyber security drillsLook atdetailed notes of attendance and actions agreed upon. Good evidence includes documented participation and decision-making on incident handling
  • Request the organisation's cyber incident response plan. Check that it includes board and executive involvement in various scenarios. A strong plan will outline clear roles for board members.
  • Look atthe agenda and list of topics covered. Good evidence includes regularity and detailed coverage of emerging threats
  • Aska list of board members and their designated security roles. Verify that one member is clearly assigned responsibility for cyber security issues. Confirmation of this designation, with clear responsibilities, is ideal
  • Goodplan will detail communication workflows and responsible parties
link

Cross-framework mappings

How ISM-2006 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 5.2ISM-2006 requires the board/executive committee to understand their duties in relation to major cyber security incidents and to participa...
Annex A 5.24ISM-2006 requires the board/executive committee to plan and practise for major cyber security incidents (e.g
handshakeSupports(2)expand_less
Annex A 5.26ISM-2006 requires executives to plan for major cyber incidents and practise their response so they understand their duties
Annex A 5.29Annex A 5.29 requires the organisation to plan for maintaining information security at an appropriate level during disruptions

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls