ISM-2121 says software developers who lack the cyber security knowledge and skills their project or task needs are not used for that work. In practice an organisation decides what security knowledge each kind of development work requires, checks everyone who writes its code against that, contractors and AI coding tools included, and closes any gap before the work starts rather than after the code ships. The control is new in the June 2026 ISM and works with ISM-2037, which asks for training or upskilling, and ISM-2038, a register of developers' security knowledge and skills.
Read on its own, the control can sound like a ban. Read with the controls around it, it is a matching rule: the security skills a developer brings have to be enough for the work they are given. Three points carry the meaning.
The control applies at every classification ASD marks, from non-classified systems to TOP SECRET, wherever an organisation develops software. It is not part of the Essential Eight.
Many software vulnerabilities start as an ordinary coding decision: a database query built from user input, a permission check left off one page, a password written into a configuration file, a library added without a look at its history. Security testing catches some of these. A developer who knows the safe pattern does not write them in the first place, and is better placed to notice what testing misses.
ASD's Secure by Design guidance puts the responsibility on the organisation: "All organisations must invest in the skills and knowledge of their employees, whilst supporting them through the implementation of technical controls, safety nets and guard rails" (ASD). NIST's Secure Software Development Framework, which the ISM points to for this section, makes the same point in its practice on roles and responsibilities: "Ensure that everyone inside and outside of the organization involved in the SDLC is prepared to perform their SDLC-related roles and responsibilities throughout the SDLC" (NIST SP 800-218).
AI coding assistants make the control more pressing, not less. They produce plausible code quickly, and the person who accepts it is often the last check before it ships. GitHub's documentation for its own assistant says: "You should be careful when using Copilot to generate code for security-sensitive applications and always review and test the generated code thoroughly" (GitHub). That review is only as good as the reviewer's security knowledge. And because ASD counts AI as a software developer, the tool itself has to be suitable for the task it is given, as well as the people directing and checking it.
ISM-2121 is one step in a short sequence within ASD's secure software development controls:
The controls that follow in the same section describe the skills themselves: Secure by Design principles (ISM-0401), threat modelling (ISM-1238), secure programming practices for the language in use (ISM-2040) and memory-safe programming languages (ISM-2041). Together they are a sensible first list of what "cyber security knowledge and skills" means in practice.
| Ask | Look at | Good looks like |
|---|---|---|
| What security knowledge does each kind of work need? | Documented roles, responsibilities and knowledge (ISM-2035, ISM-2036) | Written for each role or type of work, not one generic sentence |
| Who has it? | The developer knowledge and skills register (ISM-2038) | Every developer listed, contractors included, with when and how they were assessed |
| What happens when someone falls short? | Training and upskilling records (ISM-2037) | Gaps closed, or the work reassigned, before the work starts |
| Does the register decide who does what? | A sample of recent higher-risk changes, compared with the register | Each one done or reviewed by someone with the skills the task needed |
| How is AI-assisted development governed? | The secure software development policy (ISM-2120) and review records | Approved tools, defined uses, and review by a developer with the right skills |
| What about contractors and partners? | Contracts and the evidence they supplied | A skills requirement in the contract, and evidence received |
Skills are hard to measure. Certificates and years of experience are easy to record and say little about whether someone writes safe code in your stack. Short practical exercises and the findings of real code reviews are better evidence, and cheaper than they sound.
A register nobody consults. The register is only useful if someone looks at it when work is allocated. A spreadsheet that is filled in once a year and never read is evidence of a document, not of the control.
Contractors and development partners. Organisations that outsource development often cannot see who is writing their code. Ask the partner how it assesses and trains its developers, and ask for the evidence in the table above.
AI changes the volume. AI coding assistants can produce more code than a team can review well. If the reviewers lack the skills for the task, the extra speed is extra risk.
Smaller and larger organisations. A smaller organisation may have one or two developers or rely on an agency. Its register can be a single page; the hard part is depth, so it may need an outside security review for its riskiest work, such as authentication or payments. A larger organisation has many teams, languages and contractors, so it needs a skills framework, a training platform, security champions in each team and a way to keep the register current as people move between projects.
The business case. The cost is training time and a little process. What it buys is fewer vulnerabilities written in the first place, rather than found, fixed and sometimes disclosed later, and a clear answer when a customer, an auditor or a government buyer asks how you know your developers can build secure software.
Which of the products you already pay for help here? The free coverage check shows which ISM and Essential Eight controls your current products can reach, in about three minutes. To see ISM-2121 among the other software development controls, open it in our sample coverage report, or read what an ISM assessment involves.
ISM-2121 is new: ASD added it in the June 2026 release, at revision 0, together with ISM-2120, the secure software development policy. The same release changed ISM-2037 from "training" to "training or upskilling" and tidied the wording of ISM-2035. In the September 2026 release ISM-2038 changed from a register that "is implemented and maintained" to one that "is developed, implemented and maintained", the same wording ASD uses for the new policy control. Our ISM September 2026 summary covers the rest of the latest release.