Back to Frameworks

ASIC Cyber Resilience Good Practices

Australia
v2022
8 domains
29 controls

The Australian Securities and Investments Commission sets expectations for cyber resilience of regulated entities in the financial services sector. Based on ASIC Report 429 (2015) and Report 716 (2022), it outlines good practices for boards and management in managing cyber security risks. Applies to Australian financial services licensees, credit licensees, and market operators.

Verified

ASIC Cyber Resilience Good Practices is a compliance framework from Australia with 8 domains and 29 controls that map to 8 other frameworks. The largest domains are Cyber Security Strategy and Governance (6 controls), Protective Measures and Controls (5 controls), Response and Recovery Planning (5 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated Published standard

Get the official standard — this page is an AI-assisted companion tool, not a replacement for the authoritative text.

Visit asic.gov.au

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (8)

Asset Management

2 controls

Centralised asset and configuration management.

Controls in the Asset Management domain of ASIC Cyber Resilience Good Practices2 controls
CodeTitle
ASIC-CR-AM-1Centralised asset management system
ASIC-CR-AM-2Configuration management

Collaboration and Information Sharing

2 controls

Information sharing with peers, agencies and threat-intel providers.

Controls in the Collaboration and Information Sharing domain of ASIC Cyber Resilience Good Practices2 controls
CodeTitle
ASIC-CR-CO-1Confidential information sharing
ASIC-CR-CO-2Specialist threat-intelligence providers

Cyber Awareness and Training

3 controls

Staff awareness, training and testing.

Controls in the Cyber Awareness and Training domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-AT-1Staff awareness and training
ASIC-CR-AT-2Continuous development
ASIC-CR-AT-3Random staff testing

Cyber Risk Management and Threat Assessment

3 controls

Intelligence-led cyber risk management and third-party risk.

Controls in the Cyber Risk Management and Threat Assessment domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-RM-1Intelligence-led cyber risk management
ASIC-CR-RM-2Fusion centres for real-time monitoring
ASIC-CR-RM-3Third-party and supply chain risk management

Cyber Security Strategy and Governance

6 controls

Board ownership, responsive governance and alignment of cyber strategy.

Controls in the Cyber Security Strategy and Governance domain of ASIC Cyber Resilience Good Practices6 controls
CodeTitle
ASIC-CR-GOV-1Board engagement and periodic review of cyber strategy
ASIC-CR-GOV-2Treat cyber resilience as a management and investment tool
ASIC-CR-GOV-3Board cyber fluency
ASIC-CR-GOV-4End-to-end assurance processes
ASIC-CR-GOV-5Responsive, event-driven governance
ASIC-CR-GOV-6Align cyber governance with enterprise governance

Detection Systems and Processes

3 controls

Continuous monitoring, analytics and red teaming.

Controls in the Detection Systems and Processes domain of ASIC Cyber Resilience Good Practices3 controls
CodeTitle
ASIC-CR-DE-1Continuous monitoring with SIEM
ASIC-CR-DE-2Data analytics for threat integration
ASIC-CR-DE-3Red teaming

Protective Measures and Controls

5 controls

Essential Eight and additional protective controls.

Controls in the Protective Measures and Controls domain of ASIC Cyber Resilience Good Practices5 controls
CodeTitle
ASIC-CR-PR-1Implement the ASD Essential Eight
ASIC-CR-PR-2Security Development Lifecycle
ASIC-CR-PR-3Encryption of data at rest and in transit
ASIC-CR-PR-4Outbound email filtering and monitoring
ASIC-CR-PR-5Restricted removable media / USB access

Response and Recovery Planning

5 controls

Scenario-based response, recovery and stakeholder communication.

Controls in the Response and Recovery Planning domain of ASIC Cyber Resilience Good Practices5 controls
CodeTitle
ASIC-CR-RR-1Scenario planning and response exercising
ASIC-CR-RR-2War gaming
ASIC-CR-RR-3Proactive board reporting during incidents
ASIC-CR-RR-4Customer and breach notification
ASIC-CR-RR-5Stakeholder communication plan

Your Compliance Coverage

If you comply with ASIC Cyber Resilience Good Practices, you already cover:

Maps to 8 other frameworks

29 total controls
NIST Cybersecurity Framework 2.0
27 source controls mapped|32 target controls covered
93%
NIST SP 800-53 Rev 5
8 source controls mapped|9 target controls covered
28%
ASD Strategies to Mitigate Cyber Security Incidents
7 source controls mapped|14 target controls covered
24%
APRA CPS 234
3 source controls mapped|4 target controls covered
10%
ACSC Essential Eight
1 source controls mapped|8 target controls covered
3%
ISO 27002:2022
1 source controls mapped|1 target controls covered
3%
ISO 10007:2017
1 source controls mapped|1 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%

What is ASIC Cyber Resilience Good Practices and who does it apply to?

ASIC Cyber Resilience Good Practices is a compliance framework from Australia with 8 domains and 29 controls. The Australian Securities and Investments Commission sets expectations for cyber resilience of regulated entities in the financial services sector. Based on ASIC Report 429 (2015) and Report 716 (2022), it outlines good practices for boards and management in managing cyber security risks. Applies to Australian financial services licensees, credit licensees, and market operators. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does ASIC Cyber Resilience Good Practices actually require?

ASIC Cyber Resilience Good Practices has 29 controls organised across 8 domains. The largest domains are Cyber Security Strategy and Governance (6 controls), Protective Measures and Controls (5 controls), Response and Recovery Planning (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of ASIC Cyber Resilience Good Practices do I already cover?

ASIC Cyber Resilience Good Practices maps to 8 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (93% coverage), NIST SP 800-53 Rev 5 (28% coverage), ASD Strategies to Mitigate Cyber Security Incidents (24% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement ASIC Cyber Resilience Good Practices?

Start your ASIC Cyber Resilience Good Practices compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about ASIC Cyber Resilience Good Practices requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required