Australian Information Security Manual
Guidelines for cyber security incidents

Australian Information Security Manual ISM-0123: Reporting incidents to the CISO

Cyber security incidents are reported to the chief information security officer, or one of their delegates, as soon as possible after they occur or are discovered.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 9 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

ACSC Essential Eight · 4 controls

  • E8-ADMIN-ISM-0123 Restrict administrative privileges (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-APP-ISM-0123 Application control (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-MFA-ISM-0123 Multi-factor authentication (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered
  • E8-UAH-ISM-0123 User application hardening (ISM-0123): Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered

CIS Controls v8 · 1 control

  • CIS-17.3 Establish and Maintain an Enterprise Process for Reporting Incidents

ISO 27002:2022 · 1 control

  • 6.8 Information security event reporting

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Guidelines for cyber security incidents

Query this from an agent

The graph holds this control, the 9 it maps to, and the evidence behind each claim, over MCP and REST.