ASIC Cyber Resilience Good Practices
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Asset Management
Maintain a centralised asset management system covering hardware, software and data inventories for visibility of critical assets.
- Centralised hardware/software/data inventory
- Identification of critical assets
- Incomplete or decentralised inventories
- Critical assets not identified
Apply configuration management to ensure visibility and control of critical assets across the organisation.
- Configuration baselines/standards
- Configuration monitoring records
- No configuration baselines
- Configuration drift unmanaged
Collaboration and Information Sharing
Maintain confidential information-sharing arrangements with other financial institutions, security agencies and law enforcement.
- Membership of information-sharing arrangements
- Records of shared threat information
- No external information sharing
- Threat insights not shared or received
Use specialist third-party providers for threat intelligence gathering.
- Threat-intelligence service contracts
- Use of external intelligence in defence
- No external threat intelligence
- Intelligence not operationalised
Cyber Awareness and Training
Run organisation-wide programs for staff awareness, education and active vigilance against cyber threats.
- Awareness/training programme and completion records
- Coverage across staff and contractors
- No structured awareness programme
- Training not tracked or incomplete coverage
Use continuous development strategies to maintain active staff vigilance over time.
- Ongoing/refresher training schedule
- Updated content reflecting current threats
- One-off training only
- Content not refreshed
Conduct random testing (e.g. phishing simulations) to measure the effectiveness of the awareness programme.
- Phishing/simulation test results
- Trend of click/report rates
- Follow-up training for failures
- No simulation testing
- Results not measured or acted upon
Cyber Risk Management and Threat Assessment
Use intelligence-led approaches with near real-time processes through automation to manage cyber risk.
- Threat-intelligence feeds into risk processes
- Automation of near real-time risk monitoring
- Risk assessment static/periodic only
- No threat intelligence integration
Establish specialist 'fusion' centres for real-time monitoring and correlation of threats and risks.
- Fusion-centre or SOC function
- Real-time threat correlation outputs
- No central real-time monitoring capability
- Threat data not correlated
Apply risk-based assessment of third-party suppliers and partners, obtaining visibility through contract transparency and managing vendor cyber risk on an ongoing basis.
- Risk-based third-party assessments
- Contractual transparency/security requirements
- Ongoing supplier monitoring
- Suppliers not risk-assessed
- No contractual security clauses
- No ongoing supplier oversight
Cyber Security Strategy and Governance
The board takes ownership of cyber strategy and reviews it periodically to assess progress against success measures such as time to detection, speed of response and recovery process.
- Board-approved cyber strategy with success measures
- Periodic board review minutes
- Metrics for time-to-detect / response / recovery
- Cyber strategy not owned at board level
- No periodic review against measures
- No defined success metrics
Treat cyber resilience as a critical management tool for understanding risk and informing investment decisions.
- Cyber risk inputs into investment decisions
- Risk-based budget/resourcing records
- Cyber spend not risk-informed
- Cyber treated as IT-only, not management concern
Enhance board fluency in cyber threat language and the capability to ask relevant questions of management.
- Board cyber briefings/training
- Evidence of board challenge/questioning on cyber
- Board unable to interrogate cyber risk
- No cyber education for directors
Assurance processes focus on testing end-to-end business processes rather than isolated controls.
- End-to-end process assurance reports
- Scope statements covering business processes
- Assurance limited to point controls
- No end-to-end testing
Adopt responsive governance models that adjust to events and incidents rather than keeping to a fixed review period.
- Governance triggers tied to events/incidents
- Evidence of out-of-cycle reviews after incidents
- Governance only on a fixed calendar
- No mechanism to respond to emerging threats
Ensure clear alignment between cyber security governance and the organisation's overall governance framework.
- Mapping of cyber governance to enterprise governance
- Integrated risk/governance committee terms of reference
- Cyber governance siloed from enterprise governance
- Conflicting or duplicate governance structures
Detection Systems and Processes
Implement organisation-wide continuous monitoring using SIEM technologies to detect and alert on anomalous behaviour against a baseline of normal activity.
- SIEM deployment and coverage
- Baseline of normal activity
- Alerting and triage records
- No SIEM/continuous monitoring
- No behavioural baseline
- Alerts not triaged
Use data analytics to integrate threat sources into a single real-time view of the threat landscape to move towards predicting malicious activity.
- Integrated threat analytics platform
- Correlation of internal and shared threat data
- Threat data siloed
- No predictive/correlation analytics
Employ technical specialists to attempt to break into the organisation's networks (red teaming) to test defences.
- Red-team / penetration-test reports
- Remediation of findings
- No offensive security testing
- Findings not remediated
Protective Measures and Controls
Implement the Australian Signals Directorate's Essential Eight strategies to mitigate targeted cyber incidents, and self-assess maturity using the Essential Eight Maturity Model.
- Essential Eight implementation evidence
- Essential Eight Maturity Model self-assessment
- Remediation plan to target maturity
- Essential Eight not implemented
- No maturity self-assessment
- Maturity gaps not remediated
Integrate security as an integral part of the systems development lifecycle (Security Development Lifecycle).
- Secure SDLC policy and gates
- Security testing in development pipeline
- Security bolted on after development
- No secure-development gates
Apply encryption for stored data and data in transit based on a risk assessment of the assets in question.
- Encryption standards for data at rest and in transit
- Risk assessment driving encryption scope
- Key management records
- Sensitive data unencrypted
- Encryption not risk-based
- Key management weak
Filter and monitor outbound email to ensure data is not transmitted outside the network in error or through intent.
- Outbound email filtering/DLP configuration
- Monitoring/alerting on outbound data
- No outbound email controls
- DLP not monitored
Highly restrict use of USB ports on computer equipment to minimise data leakage or introduction of unauthorised software.
- USB/removable media restriction policy and enforcement
- Exceptions register
- USB ports unrestricted
- No control over removable media
Response and Recovery Planning
Conduct routine, detailed scenario planning to predict incidents based on the risk profile, and implement and exercise response processes.
- Documented scenarios tied to risk profile
- Incident response plan
- Exercise records and lessons learned
- No scenario planning
- Response plan untested
- Exercises not run
Use war gaming techniques to better understand and plan defence against malicious cyber activities.
- War-gaming exercise records
- Outcomes feeding defensive improvements
- No war gaming
- Exercise outcomes not actioned
Provide proactive reporting to the board on changing threats and the countermeasures in place.
- Board threat/countermeasure reports
- Escalation criteria to the board
- Board not informed of changing threats
- No incident escalation to board
Actively determine when and how to notify customers in the event of a data breach.
- Breach notification criteria and procedure
- Records of notification decisions
- No breach notification procedure
- Notification ad hoc or delayed
Maintain a well-defined communication plan for managing stakeholders and public relations during and after an incident.
- Stakeholder/PR communication plan
- Pre-drafted communications and spokesperson roles
- No communication plan
- Stakeholder messaging improvised during crisis
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ASIC Cyber Resilience Good Practices framework page.