Train Software Developers Lacking Cyber Security Skills
Developers without cyber security skills need training in secure software practices.
Plain language
This control ensures that developers who don't know much about cyber security get the training they need to build secure software. If they don't, software could be vulnerable to cyber attacks, which can lead to data breaches and financial loss.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for software developmentOfficial control statement
Software developers that lack sufficient cyber security knowledge and skills required for their projects or tasks undertake suitable training or upskilling on secure software development and programming practices.
Why it matters
Without proper training, developers might write insecure code, potentially leading to vulnerabilities and cyber breaches in the software.
Operational notes
Regularly update training content to keep pace with emerging threats and involve developers in security discussions to reinforce learning.
Implementation tips
- Look atcourses that cover secure coding practices and common vulnerabilities
- IT manager should partner with a reputable provider to deliver cyber security training to developers. Prioritise hands-on workshops where developers can practice secure coding.
- Development team leaders should hold regular review sessions where developers can discuss what they've learned and ask questions. Use real-world examples to make the learning more relatable.
- HR should incorporate cyber security skill assessments into the hiring process for developers. Use these assessments to determine ongoing training needs as part of professional development.
- IT security lead should provide developers with resources like coding standards and guides that focus on secure software development. Ensure these are easily accessible and updated regularly.
Audit / evidence tips
- Askcopies of the training schedule and curriculum: Check whether the content covers essential secure coding practicesGooda well-documented calendar and detailed syllabus reflecting cyber security topics
- Goodsigned attendance sheets showing the participants' names and dates
- Look atcourse completion certificates or credentials: Ensure developers completed the training satisfactorilyGoodvalid certificates for all developers needing training
- Askto review internal communications regarding training opportunities: See if these were clearly communicatedGoodemails or notices showing details and encouragement for attendance
- Look atparticipant feedback or test results to evaluate training effectivenessGoodrecords showing improvement or satisfaction ratings
Cross-framework mappings
How ISM-2037 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
layersPartially meets(1)expand_less | ||
| Annex A 6.3 | ISM-2037 requires that software developers who lack sufficient cyber security knowledge and skills undertake suitable training in secure ... | |
extensionDepends on(1)expand_less | ||
| Annex A 8.28 | Annex A 8.28 requires secure coding principles to be applied in software development | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Software development
See all Guidelines for software development controls, or browse the full ASD ISM library.