Skip to content
arrow_back
search
ISM-0298 policy ASD Information Security Manual (ISM)

Centralised System Patch and Update Management

Ensure patches and updates are applied correctly using a centralised system for better security.

record_voice_over

Plain language

This control means that all your computers and systems should get updated in a systematic way from a central point. It's important because if these updates aren't managed properly, your business could be open to attacks that could harm your sensitive data or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Feb 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A centralised and managed approach that maintains the integrity of patches or updates, and confirms that they have been applied successfully, is used to patch or update applications, operating systems, drivers and firmware.
policy ASD Information Security Manual (ISM) ISM-0298
priority_high

Why it matters

Without a centralised patch and update process, patching becomes inconsistent, leaving unpatched OS, apps, drivers or firmware exposed to known vulnerabilities and outages.

settings

Operational notes

Use a centralised patch service to source trusted updates, verify integrity/signatures, deploy to OS, apps, drivers and firmware, and centrally confirm success and exceptions.

Mapping detail

Mapping

Direction

Controls