Skip to content
arrow_back
ISM-2020policyASD Information Security Manual (ISM)

Ensure Adequate Cyber Security Personnel Are Acquired

The CISO must recruit qualified cyber security staff to support the organisation's activities.

record_voice_over

Plain language

This control is about making sure there are enough people with the right skills to protect your organisation's computer systems and data. Without enough cyber security staff, your organisation might be vulnerable to attacks, putting sensitive information at risk and potentially harming your reputation or operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2025

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

The CISO ensures sufficient cyber security personnel, with the right skills and experience, are acquired to support cyber security activities within their organisation.
policyASD Information Security Manual (ISM)ISM-2020
priority_high

Why it matters

Insufficient cyber security staff can delay monitoring and incident response, weaken controls, and increase the likelihood of successful attacks and outages.

settings

Operational notes

Review cyber security headcount and skills quarterly against workload and threat changes; address gaps via hiring, uplift training, or specialist support.

build

Implementation tips

  • Management should identify the skills and number of cyber security employees needed for their organisation. This involves consulting with team leads and reviewing current security tools and systems to determine gaps or needs.
  • HR should develop job descriptions for the necessary cyber security roles. These should be based on identified skills and responsibilities, and align with industry standards and the organisation's strategic goals.
  • The CISO should coordinate with recruitment teams to actively source and attract qualified candidates. This could involve attending industry events, using specialised job boards, or partnering with universities offering cyber security programs.
  • The IT team should establish an onboarding and ongoing training program for new recruits. This includes an introduction to the organisation's systems, security policies, and regular upskilling opportunities to keep staff updated with the latest cyber security threats and tools.
  • Management should review the cyber security staffing plan annually to ensure it meets current and future needs. This involves conducting interviews with current staff and assessing any new threats or technologies impacting security needs.
fact_check

Audit / evidence tips

  • AskThe cyber security staffing plan: Request a document that outlines current staff levels and future hiring needsGoodIncludes clear links between identified security needs and staffing plans
  • AskJob descriptions and qualifications: Review the roles and required qualifications for cyber security positionsGoodShows that job descriptions accurately reflect necessary skills and responsibilities
  • AskRecruitment and hiring records: Request data on recent hiring activities for cyber security rolesGoodShows a proactive approach to recruiting qualified candidates
  • AskTraining and development programs: Request details of cyber security training provided to staffGoodIncludes relevant and regular training content that addresses current and emerging threats
  • AskAnnual reviews of cyber staffing needs: Request reports or minutes from meetings where staffing needs were discussedGoodReflects consideration of both current needs and future challenges
link

Cross-framework mappings

How ISM-2020 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 6.2Annex A 6.2 requires employment contractual agreements to clearly state the information security responsibilities of both personnel and t...
extensionDepends on(1)expand_less
Annex A 5.2ISM-2020 requires the CISO to acquire sufficient cyber security personnel with the right skills and experience

ISO 42001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 4.6Annex A 4.6 requires the organisation to document human resources and competences used throughout the AI system lifecycle

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security roles controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls