Skip to content
arrow_back
search
ISM-2038 policy ASD Information Security Manual (ISM)

Maintain Developer Cyber Security Skills Register

Keep a record of software developers' cybersecurity skills and knowledge.

record_voice_over

Plain language

This control is about keeping track of the cybersecurity skills and knowledge of the software developers in your organisation. This is important because if developers aren't up to speed on security, they might create software that is vulnerable to attacks, putting your business and customer data at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A software developer cyber security knowledge and skills register is implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-2038
priority_high

Why it matters

Without a developer cyber security skills register, skills gaps go unnoticed, increasing the likelihood of insecure code and missed secure development practices.

settings

Operational notes

Maintain a central register of each developer’s cyber security skills, training and certifications, and review/update it after courses, onboarding and role changes.

Mapping detail

Mapping

Direction

Controls