Skip to content
arrow_back
search
ISM-2020 policy ASD Information Security Manual (ISM)

Ensure Adequate Cyber Security Personnel Are Acquired

The CISO must recruit qualified cyber security staff to support the organisation's activities.

record_voice_over

Plain language

This control is about making sure there are enough people with the right skills to protect your organisation's computer systems and data. Without enough cyber security staff, your organisation might be vulnerable to attacks, putting sensitive information at risk and potentially harming your reputation or operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.
policy ASD Information Security Manual (ISM) ISM-2020
priority_high

Why it matters

Insufficient cyber security staff can delay monitoring and incident response, weaken controls, and increase the likelihood of successful attacks and outages.

settings

Operational notes

Review cyber security headcount and skills quarterly against workload and threat changes; address gaps via hiring, uplift training, or specialist support.

Mapping detail

Mapping

Direction

Controls