Skip to content
arrow_back
search
E8-PO-ML3.3 bolt ASD Essential Eight

Apply critical patches to non-internet-facing OS within 48 hours

Quickly install critical updates on internal systems to fix security vulnerabilities.

record_voice_over

Plain language

This control is about making sure we quickly update the computer systems inside our organisation that aren't directly connected to the internet. This is crucial because if there's a known weakness, hackers could use it to break into our system. By fixing these vulnerabilities quickly, we prevent bad actors from exploiting them and causing harm.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
bolt ASD Essential Eight E8-PO-ML3.3
priority_high

Why it matters

Delaying patches on non-internet-facing operating systems can leave known critical flaws exploitable, enabling lateral movement and internal data compromise.

settings

Operational notes

Track vendor advisories and prioritise critical/actively exploited OS fixes; deploy to non-internet-facing servers, workstations and devices within 48 hours.

Mapping detail

Mapping

Direction

Controls