Board Plans for Major Cyber Security Incidents
The board prepares for major cyber attacks by joining practice drills and knowing their responsibilities.
Plain language
This control ensures that the board of directors or executive committee are actively involved in planning for significant cyber security incidents. It matters because if they are caught unprepared, a major cyber attack could lead to severe business disruptions and damage to the organisation's reputation.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for cyber security rolesOfficial control statement
The board of directors or executive committee plans for major cyber security incidents, including by participating in exercises, and understands their duties in relation to such cyber security incidents.
Why it matters
Without board involvement, a major cyber incident may be poorly managed, leading to prolonged downtime, data loss, and reputational damage.
Operational notes
Regularly update and rehearse the incident response plan with the board's involvement to maintain preparedness and effective communication.
Implementation tips
- Board members should participate in scheduled cyber security incident drills. Coordinate these with the IT and security teams to simulate potential breach scenarios and determine appropriate responses.
- The executive committee should review and understand the organisation's incident response plan. This should involve a meeting with the cyber security manager to walk through the plan's key steps and ensure clarity on the roles and responsibilities.
- Appoint a board member to take the lead on cyber security issues. This person can regularly liaise with the organisation's security experts to stay updated on potential threats and response strategies.
- The CEO should organise regular briefings for the board on cyber security trends and risks. Invite external experts to present and provide insights on emerging threats and mitigation strategies.
- Create a clear communication plan involving the board for use during a cyber incident. The communication officer should draft this plan, detailing who needs to be informed about incidents and how information is disseminated swiftly and accurately.
Audit / evidence tips
- Askrecords of board meeting minutes related to cyber security drillsLook atdetailed notes of attendance and actions agreed upon. Good evidence includes documented participation and decision-making on incident handling
- Request the organisation's cyber incident response plan. Check that it includes board and executive involvement in various scenarios. A strong plan will outline clear roles for board members.
- Look atthe agenda and list of topics covered. Good evidence includes regularity and detailed coverage of emerging threats
- Aska list of board members and their designated security roles. Verify that one member is clearly assigned responsibility for cyber security issues. Confirmation of this designation, with clear responsibilities, is ideal
- Goodplan will detail communication workflows and responsible parties
Cross-framework mappings
How ISM-2006 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.2 | ISM-2006 requires the board/executive committee to understand their duties in relation to major cyber security incidents and to participa... | |
| Annex A 5.24 | ISM-2006 requires the board/executive committee to plan and practise for major cyber security incidents (e.g | |
handshakeSupports(2)expand_less | ||
| Annex A 5.26 | ISM-2006 requires executives to plan for major cyber incidents and practise their response so they understand their duties | |
| Annex A 5.29 | Annex A 5.29 requires the organisation to plan for maintaining information security at an appropriate level during disruptions | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Cyber security roles
See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.