Skip to content
arrow_back
policyASD ISM

Guidelines for cyber security roles

42 controls in this part of the Australian Government Information Security Manual. Each control links to plain-English guidance, audit tips and cross-framework mappings.

Board of directors and executive committee

ISM-1997
Define Cyber Security Roles for Leadership
ISM-1998
Integrate Cyber Security Across Business Functions
ISM-1999
Align Cyber Security with Business Strategy
ISM-2000
Regular Cyber Security Briefings for Executives
ISM-2001
Championing Cyber Security at an Executive Level
ISM-2002
Ensure Board Cyber Security Literacy for Compliance
ISM-2003
Monitor Cyber Security Workforce and Skill Gaps
ISM-2004
Enhancing Cyber Security Skills and Experience
ISM-2005
Understanding Business Criticality of Organisation Systems
ISM-2006
Board Plans for Major Cyber Security Incidents

Chief information security officer

ISM-0714
Appoint a CISO to Lead Cyber Security Across IT and OT
ISM-0717
CISO Oversight of Cyber Security Personnel
ISM-0718
CISO Reporting to Board on Cyber Security
ISM-0720
Develop and Maintain a Cyber Security Communication Strategy
ISM-0724
Implement Cyber Security Metrics and KPIs
ISM-0725
Cyber Security Steering Committee Coordination
ISM-0726
Coordinate Security Risk Management Activities
ISM-0731
CISO Oversight of Cyber Supply Chain Risks
ISM-0732
Manage and Allocate Cyber Security Budget
ISM-0733
Ensure CISO Awareness of Cyber Incidents
ISM-0734
CISO Role in Disaster Recovery Planning
ISM-0735
CISO Oversees the Cyber Security Awareness Training Program
ISM-1478
CISO Management of Cyber Security Compliance
ISM-1617
Regular Review of Cyber Security Program
ISM-1618
CISO's Role in Cyber Security Incident Response
ISM-1918
Regular Cyber Security Reporting to Audit Committee
ISM-1966
CISO Manages and Verifies System Register
ISM-2020
Ensure Adequate Cyber Security Personnel Are Acquired

System owners

ISM-0009
System Owners Identify Supplementary Controls With Authorising Officer
ISM-0027
Mandatory Authorisation for System Operation
ISM-1071
Assign System Ownership for Better Oversight
ISM-1203
Risk Assessment for System Security
ISM-1525
Register Systems with Authorising Officers
ISM-1526
System Owners Continuously Monitor Security and Manage Threats, Risks and Controls
ISM-1587
Annual Security Status Reporting for Systems
ISM-1633
Determine System Boundary, Criticality and Security Objectives
ISM-1634
System Owners Select and Tailor Controls in Consultation with Authorising Officer
ISM-1635
System Owners Implement Security Controls for Each System and Environment
ISM-1636
Security Control Assessment of Systems by Own or IRAP Assessors
ISM-1967
ASD Assessor Security Control Assessment of TOP SECRET Systems
ISM-1968
Obtain Authorisation for TOP SECRET Systems
ISM-2021
Implement and Maintain Data Minimisation Practices

Back to the full Information Security Manual (ISM) control list, or browse the complete control library.