Skip to content

Evidence request lists

ASIC Cyber Resilience Good Practices

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Asset Management

ASIC-CR-AM-1
Centralised asset management system

Maintain a centralised asset management system covering hardware, software and data inventories for visibility of critical assets.

Artefacts an auditor will ask for
  • Centralised hardware/software/data inventory
  • Identification of critical assets
Where this commonly fails
  • Incomplete or decentralised inventories
  • Critical assets not identified
ASIC-CR-AM-2
Configuration management

Apply configuration management to ensure visibility and control of critical assets across the organisation.

Artefacts an auditor will ask for
  • Configuration baselines/standards
  • Configuration monitoring records
Where this commonly fails
  • No configuration baselines
  • Configuration drift unmanaged

Collaboration and Information Sharing

ASIC-CR-CO-1
Confidential information sharing

Maintain confidential information-sharing arrangements with other financial institutions, security agencies and law enforcement.

Artefacts an auditor will ask for
  • Membership of information-sharing arrangements
  • Records of shared threat information
Where this commonly fails
  • No external information sharing
  • Threat insights not shared or received
ASIC-CR-CO-2
Specialist threat-intelligence providers

Use specialist third-party providers for threat intelligence gathering.

Artefacts an auditor will ask for
  • Threat-intelligence service contracts
  • Use of external intelligence in defence
Where this commonly fails
  • No external threat intelligence
  • Intelligence not operationalised

Cyber Awareness and Training

ASIC-CR-AT-1
Staff awareness and training

Run organisation-wide programs for staff awareness, education and active vigilance against cyber threats.

Artefacts an auditor will ask for
  • Awareness/training programme and completion records
  • Coverage across staff and contractors
Where this commonly fails
  • No structured awareness programme
  • Training not tracked or incomplete coverage
ASIC-CR-AT-2
Continuous development

Use continuous development strategies to maintain active staff vigilance over time.

Artefacts an auditor will ask for
  • Ongoing/refresher training schedule
  • Updated content reflecting current threats
Where this commonly fails
  • One-off training only
  • Content not refreshed
ASIC-CR-AT-3
Random staff testing

Conduct random testing (e.g. phishing simulations) to measure the effectiveness of the awareness programme.

Artefacts an auditor will ask for
  • Phishing/simulation test results
  • Trend of click/report rates
  • Follow-up training for failures
Where this commonly fails
  • No simulation testing
  • Results not measured or acted upon

Cyber Risk Management and Threat Assessment

ASIC-CR-RM-1
Intelligence-led cyber risk management

Use intelligence-led approaches with near real-time processes through automation to manage cyber risk.

Artefacts an auditor will ask for
  • Threat-intelligence feeds into risk processes
  • Automation of near real-time risk monitoring
Where this commonly fails
  • Risk assessment static/periodic only
  • No threat intelligence integration
ASIC-CR-RM-2
Fusion centres for real-time monitoring

Establish specialist 'fusion' centres for real-time monitoring and correlation of threats and risks.

Artefacts an auditor will ask for
  • Fusion-centre or SOC function
  • Real-time threat correlation outputs
Where this commonly fails
  • No central real-time monitoring capability
  • Threat data not correlated
ASIC-CR-RM-3
Third-party and supply chain risk management

Apply risk-based assessment of third-party suppliers and partners, obtaining visibility through contract transparency and managing vendor cyber risk on an ongoing basis.

Artefacts an auditor will ask for
  • Risk-based third-party assessments
  • Contractual transparency/security requirements
  • Ongoing supplier monitoring
Where this commonly fails
  • Suppliers not risk-assessed
  • No contractual security clauses
  • No ongoing supplier oversight

Cyber Security Strategy and Governance

ASIC-CR-GOV-1
Board engagement and periodic review of cyber strategy

The board takes ownership of cyber strategy and reviews it periodically to assess progress against success measures such as time to detection, speed of response and recovery process.

Artefacts an auditor will ask for
  • Board-approved cyber strategy with success measures
  • Periodic board review minutes
  • Metrics for time-to-detect / response / recovery
Where this commonly fails
  • Cyber strategy not owned at board level
  • No periodic review against measures
  • No defined success metrics
ASIC-CR-GOV-2
Treat cyber resilience as a management and investment tool

Treat cyber resilience as a critical management tool for understanding risk and informing investment decisions.

Artefacts an auditor will ask for
  • Cyber risk inputs into investment decisions
  • Risk-based budget/resourcing records
Where this commonly fails
  • Cyber spend not risk-informed
  • Cyber treated as IT-only, not management concern
ASIC-CR-GOV-3
Board cyber fluency

Enhance board fluency in cyber threat language and the capability to ask relevant questions of management.

Artefacts an auditor will ask for
  • Board cyber briefings/training
  • Evidence of board challenge/questioning on cyber
Where this commonly fails
  • Board unable to interrogate cyber risk
  • No cyber education for directors
ASIC-CR-GOV-4
End-to-end assurance processes

Assurance processes focus on testing end-to-end business processes rather than isolated controls.

Artefacts an auditor will ask for
  • End-to-end process assurance reports
  • Scope statements covering business processes
Where this commonly fails
  • Assurance limited to point controls
  • No end-to-end testing
ASIC-CR-GOV-5
Responsive, event-driven governance

Adopt responsive governance models that adjust to events and incidents rather than keeping to a fixed review period.

Artefacts an auditor will ask for
  • Governance triggers tied to events/incidents
  • Evidence of out-of-cycle reviews after incidents
Where this commonly fails
  • Governance only on a fixed calendar
  • No mechanism to respond to emerging threats
ASIC-CR-GOV-6
Align cyber governance with enterprise governance

Ensure clear alignment between cyber security governance and the organisation's overall governance framework.

Artefacts an auditor will ask for
  • Mapping of cyber governance to enterprise governance
  • Integrated risk/governance committee terms of reference
Where this commonly fails
  • Cyber governance siloed from enterprise governance
  • Conflicting or duplicate governance structures

Detection Systems and Processes

ASIC-CR-DE-1
Continuous monitoring with SIEM

Implement organisation-wide continuous monitoring using SIEM technologies to detect and alert on anomalous behaviour against a baseline of normal activity.

Artefacts an auditor will ask for
  • SIEM deployment and coverage
  • Baseline of normal activity
  • Alerting and triage records
Where this commonly fails
  • No SIEM/continuous monitoring
  • No behavioural baseline
  • Alerts not triaged
ASIC-CR-DE-2
Data analytics for threat integration

Use data analytics to integrate threat sources into a single real-time view of the threat landscape to move towards predicting malicious activity.

Artefacts an auditor will ask for
  • Integrated threat analytics platform
  • Correlation of internal and shared threat data
Where this commonly fails
  • Threat data siloed
  • No predictive/correlation analytics
ASIC-CR-DE-3
Red teaming

Employ technical specialists to attempt to break into the organisation's networks (red teaming) to test defences.

Artefacts an auditor will ask for
  • Red-team / penetration-test reports
  • Remediation of findings
Where this commonly fails
  • No offensive security testing
  • Findings not remediated

Protective Measures and Controls

ASIC-CR-PR-1
Implement the ASD Essential Eight

Implement the Australian Signals Directorate's Essential Eight strategies to mitigate targeted cyber incidents, and self-assess maturity using the Essential Eight Maturity Model.

Artefacts an auditor will ask for
  • Essential Eight implementation evidence
  • Essential Eight Maturity Model self-assessment
  • Remediation plan to target maturity
Where this commonly fails
  • Essential Eight not implemented
  • No maturity self-assessment
  • Maturity gaps not remediated
ASIC-CR-PR-2
Security Development Lifecycle

Integrate security as an integral part of the systems development lifecycle (Security Development Lifecycle).

Artefacts an auditor will ask for
  • Secure SDLC policy and gates
  • Security testing in development pipeline
Where this commonly fails
  • Security bolted on after development
  • No secure-development gates
ASIC-CR-PR-3
Encryption of data at rest and in transit

Apply encryption for stored data and data in transit based on a risk assessment of the assets in question.

Artefacts an auditor will ask for
  • Encryption standards for data at rest and in transit
  • Risk assessment driving encryption scope
  • Key management records
Where this commonly fails
  • Sensitive data unencrypted
  • Encryption not risk-based
  • Key management weak
ASIC-CR-PR-4
Outbound email filtering and monitoring

Filter and monitor outbound email to ensure data is not transmitted outside the network in error or through intent.

Artefacts an auditor will ask for
  • Outbound email filtering/DLP configuration
  • Monitoring/alerting on outbound data
Where this commonly fails
  • No outbound email controls
  • DLP not monitored
ASIC-CR-PR-5
Restricted removable media / USB access

Highly restrict use of USB ports on computer equipment to minimise data leakage or introduction of unauthorised software.

Artefacts an auditor will ask for
  • USB/removable media restriction policy and enforcement
  • Exceptions register
Where this commonly fails
  • USB ports unrestricted
  • No control over removable media

Response and Recovery Planning

ASIC-CR-RR-1
Scenario planning and response exercising

Conduct routine, detailed scenario planning to predict incidents based on the risk profile, and implement and exercise response processes.

Artefacts an auditor will ask for
  • Documented scenarios tied to risk profile
  • Incident response plan
  • Exercise records and lessons learned
Where this commonly fails
  • No scenario planning
  • Response plan untested
  • Exercises not run
ASIC-CR-RR-2
War gaming

Use war gaming techniques to better understand and plan defence against malicious cyber activities.

Artefacts an auditor will ask for
  • War-gaming exercise records
  • Outcomes feeding defensive improvements
Where this commonly fails
  • No war gaming
  • Exercise outcomes not actioned
ASIC-CR-RR-3
Proactive board reporting during incidents

Provide proactive reporting to the board on changing threats and the countermeasures in place.

Artefacts an auditor will ask for
  • Board threat/countermeasure reports
  • Escalation criteria to the board
Where this commonly fails
  • Board not informed of changing threats
  • No incident escalation to board
ASIC-CR-RR-4
Customer and breach notification

Actively determine when and how to notify customers in the event of a data breach.

Artefacts an auditor will ask for
  • Breach notification criteria and procedure
  • Records of notification decisions
Where this commonly fails
  • No breach notification procedure
  • Notification ad hoc or delayed
ASIC-CR-RR-5
Stakeholder communication plan

Maintain a well-defined communication plan for managing stakeholders and public relations during and after an incident.

Artefacts an auditor will ask for
  • Stakeholder/PR communication plan
  • Pre-drafted communications and spokesperson roles
Where this commonly fails
  • No communication plan
  • Stakeholder messaging improvised during crisis
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASIC Cyber Resilience Good Practices framework page.