Document Security Roles for Software Development
Identify and document the roles and skills needed for secure software development.
Plain language
This control ensures that everyone involved in creating software knows their security roles and responsibilities. It matters because unclear roles can lead to security gaps, exposing your software to cyber attacks or data breaches.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
Security roles, responsibilities and knowledge required to support the software development life cycle are identified and documented.
Why it matters
Without documented security roles, software projects can suffer from unclear responsibilities, leading to vulnerabilities and potential breaches.
Operational notes
Regularly update role descriptions and ensure training stays current with emerging security threats and technologies.
Implementation tips
- The project manager should identify all the different roles needed for software development and note their security responsibilities. This can be done by building a list of roles like developer, tester, and system administrator, and outlining what security tasks each should be responsible for.
- HR and team leads must ensure that new hires have the necessary skills for their security roles. They can do this by cross-referencing the skills needed with the candidates' résumés and arranging training sessions where needed.
- IT managers should regularly update role descriptions to include security responsibilities as the software and risks evolve. This means reviewing descriptions at least annually and after any major software update or security incident.
- Team leads should organise workshops or training sessions to refresh team members on security best practices. This can be done by inviting security experts to share insights or using online courses tailored to their roles.
- The compliance officer should document all identified security roles and responsibilities in a central repository accessible to the team. This involves keeping a written record that can be quickly checked and updated when roles or requirements change.
Audit / evidence tips
- Askthe organisation's security roles documentation: Request the list of documented security roles and responsibilitiesLook atthe clarity and current relevance of the described rolesGoodall roles are up-to-date with clear security responsibilities
- Asktraining records related to security roles: Request records of security-related training attended by each personLook atcompletion dates and relevance to rolesGoodeveryone has completed necessary and recent training
- Aska skills matrix for security roles: Request a document showing the skills required for each security roleLook atcomprehensive lists that match the actual job tasksGooddetailed skills aligned with role responsibilities
- Askevidence of security reviews for role updates: Request records showing when and why roles were reviewed and updatedLook atregular and incident-triggered reviewsGoodreviews are conducted annually or after significant incidents
- Askdocumentation of role assignment in recent projects: Request role assignments for the latest software projectsLook atalignment with documented security responsibilitiesGoodclear role allocation aligns with expected responsibilities
Cross-framework mappings
How ISM-2035 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 5.2 | ISM-2035 requires organisations to identify and document security roles, responsibilities and knowledge requirements specifically to supp... | |
sync_altPartially overlaps(2)expand_less | ||
| Annex A 6.2 | Annex A 6.2 requires that employment contractual agreements state personnel and organisational responsibilities for information security | |
| Annex A 6.3 | ISM-2035 requires security roles, responsibilities and knowledge requirements to be identified and documented to support the software dev... | |
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 4.6 | Annex A 4.6 involves documenting people and competences for AI systems including operational and decommissioning activities | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.