Skip to content
arrow_back
search
ISM-2035 policy ASD Information Security Manual (ISM)

Document Security Roles and Knowledge for Development

Define and document roles and skills needed for secure software development.

record_voice_over

Plain language

This control is about making sure everyone involved in software development knows their specific security roles and has the necessary skills. It's important because if people aren't clear on their responsibilities or don't have the right knowledge, software could become vulnerable to cyber threats, leading to data breaches or financial losses.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Security roles, responsibilities and knowledge requirements required to support the software development life cycle are identified and documented.
policy ASD Information Security Manual (ISM) ISM-2035
priority_high

Why it matters

Without clearly defined security roles in software development, vulnerabilities may go unnoticed, risking breaches and financial losses.

settings

Operational notes

Review and update documented SDLC security roles and knowledge needs regularly, and maintain role-based training so developers meet the defined requirements.

Mapping detail

Mapping

Direction

Controls