Skip to content
arrow_back
search
E8-PO-ML3.4 bolt ASD Essential Eight

Non-critical OS patches applied within one month if no exploits exist

Apply OS patches on internal devices within a month if they aren't critical and have no known exploits.

record_voice_over

Plain language

This control is about making sure your computers and devices are kept up-to-date with the latest patches, but only for non-critical issues. If there are no known ways hackers can exploit these issues, you have up to a month to apply these updates. Not updating could mean leaving your systems more vulnerable to new threats.

Framework

ASD Essential Eight

Control effect

Preventative

E8 mitigation strategy

PO

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
bolt ASD Essential Eight E8-PO-ML3.4
priority_high

Why it matters

Delaying non-critical OS patches beyond one month can let attackers chain low-severity flaws into compromise, disrupting workstations and internal services.

settings

Operational notes

Monitor vendor OS advisories weekly; confirm severity is non-critical and that no working exploits exist, then schedule deployment to all scoped assets within 30 days.

Mapping detail

Mapping

Direction

Controls