Skip to content
arrow_back
search
ISM-2022 policy ASD Information Security Manual (ISM)

Develop and Maintain Cyber Security Training Register

Maintain a record of all cyber security awareness training activities within an organisation.

record_voice_over

Plain language

This control is about keeping track of who in your organisation has been trained on cyber security awareness. It's important because if you don't know who's been trained, your staff might miss out on vital information, leading to mistakes that could harm your business, such as data breaches or loss of customer trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A cyber security awareness training register is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-2022
priority_high

Why it matters

Without a cyber security training register, staff training gaps go untracked, increasing phishing success and accidental data disclosure.

settings

Operational notes

Update the training register for new starters and completions; track overdue training and run refreshers when threat guidance changes.

Mapping detail

Mapping

Direction

Controls