Back to Frameworks

ASIC Cyber Resilience Good Practices

Australia
v2022
8 domains
29 controls

The Australian Securities and Investments Commission sets expectations for cyber resilience of regulated entities in the financial services sector. Based on ASIC Report 429 (2015) and Report 716 (2022), it outlines good practices for boards and management in managing cyber security risks. Applies to Australian financial services licensees, credit licensees, and market operators.

Verified

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit asic.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Asset Management

2 controls

Centralised asset and configuration management.

Controls in the Asset Management domain of ASIC Cyber Resilience Good Practices2 controls
CodeTitle
ASIC-CR-AM-1Centralised asset management system
ASIC-CR-AM-2Configuration management

Collaboration and Information Sharing

2 controls

Information sharing with peers, agencies and threat-intel providers.

Controls in the Collaboration and Information Sharing domain of ASIC Cyber Resilience Good Practices2 controls
CodeTitle
ASIC-CR-CO-1Confidential information sharing
ASIC-CR-CO-2Specialist threat-intelligence providers

Cyber Awareness and Training

3 controls

Staff awareness, training and testing.

Controls in the Cyber Awareness and Training domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-AT-1Staff awareness and training
ASIC-CR-AT-2Continuous development
ASIC-CR-AT-3Random staff testing

Cyber Risk Management and Threat Assessment

3 controls

Intelligence-led cyber risk management and third-party risk.

Controls in the Cyber Risk Management and Threat Assessment domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-RM-1Intelligence-led cyber risk management
ASIC-CR-RM-2Fusion centres for real-time monitoring
ASIC-CR-RM-3Third-party and supply chain risk management

Cyber Security Strategy and Governance

6 controls

Board ownership, responsive governance and alignment of cyber strategy.

Controls in the Cyber Security Strategy and Governance domain of ASIC Cyber Resilience Good Practices6 controls
CodeTitle
ASIC-CR-GOV-1Board engagement and periodic review of cyber strategy
ASIC-CR-GOV-2Treat cyber resilience as a management and investment tool
ASIC-CR-GOV-3Board cyber fluency
ASIC-CR-GOV-4End-to-end assurance processes
ASIC-CR-GOV-5Responsive, event-driven governance
ASIC-CR-GOV-6Align cyber governance with enterprise governance

Detection Systems and Processes

3 controls

Continuous monitoring, analytics and red teaming.

Controls in the Detection Systems and Processes domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-DE-1Continuous monitoring with SIEM
ASIC-CR-DE-2Data analytics for threat integration
ASIC-CR-DE-3Red teaming

Protective Measures and Controls

5 controls

Essential Eight and additional protective controls.

Controls in the Protective Measures and Controls domain of ASIC Cyber Resilience Good Practices5 controls
CodeTitle
ASIC-CR-PR-1Implement the ASD Essential Eight
ASIC-CR-PR-2Security Development Lifecycle
ASIC-CR-PR-3Encryption of data at rest and in transit
ASIC-CR-PR-4Outbound email filtering and monitoring
ASIC-CR-PR-5Restricted removable media / USB access

Response and Recovery Planning

5 controls

Scenario-based response, recovery and stakeholder communication.

Controls in the Response and Recovery Planning domain of ASIC Cyber Resilience Good Practices5 controls
CodeTitle
ASIC-CR-RR-1Scenario planning and response exercising
ASIC-CR-RR-2War gaming
ASIC-CR-RR-3Proactive board reporting during incidents
ASIC-CR-RR-4Customer and breach notification
ASIC-CR-RR-5Stakeholder communication plan

Your Compliance Coverage

If you comply with ASIC Cyber Resilience Good Practices, you already cover:

Maps to 5 other frameworks

29 total controls
NIST Cybersecurity Framework 2.0
27 source controls mapped|32 target controls covered
93%
APRA CPS 234
11 source controls mapped|13 target controls covered
38%
NIST SP 800-53 Rev 5
8 source controls mapped|9 target controls covered
28%
ASD Strategies to Mitigate Cyber Security Incidents
7 source controls mapped|14 target controls covered
24%
ACSC Essential Eight
1 source controls mapped|8 target controls covered
3%

Frequently Asked Questions

What is ASIC Cyber Resilience Good Practices?

ASIC Cyber Resilience Good Practices is a compliance framework from Australia with 8 domains and 29 controls. The Australian Securities and Investments Commission sets expectations for cyber resilience of regulated entities in the financial services sector. Based on ASIC Report 429 (2015) and Report 716 (2022), it outlines good practices for boards and management in managing cyber security risks. Applies to Australian financial services licensees, credit licensees, and market operators. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does ASIC Cyber Resilience Good Practices have?

ASIC Cyber Resilience Good Practices has 29 controls organised across 8 domains. The largest domains are Cyber Security Strategy and Governance (6 controls), Protective Measures and Controls (5 controls), Response and Recovery Planning (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does ASIC Cyber Resilience Good Practices map to?

ASIC Cyber Resilience Good Practices maps to 5 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (93% coverage), APRA CPS 234 (38% coverage), NIST SP 800-53 Rev 5 (28% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with ASIC Cyber Resilience Good Practices compliance?

Start your ASIC Cyber Resilience Good Practices compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASIC Cyber Resilience Good Practices requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.

Get Started Free →

Free forever — no credit card required