Skip to content
arrow_back
search
ISM-0300 policy ASD Information Security Manual (ISM)

Apply System Security Patches with Approval

Security patches for critical IT must be approved and applied as directed by ASD.

record_voice_over

Plain language

This control is about making sure that important security updates for IT systems are properly approved and applied. This matters because if critical systems don't get timely updates, they could be exposed to cyber attacks or data breaches, leading to significant business disruption and loss.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in high assurance IT equipment are applied only when approved by ASD, and in doing so, using methods and timeframes prescribed by ASD.
policy ASD Information Security Manual (ISM) ISM-0300
priority_high

Why it matters

Applying patches to high assurance equipment without ASD approval or prescribed timeframes can cause outages, weaken assurance and leave critical vulnerabilities exploitable.

settings

Operational notes

Coordinate with ASD for patch/mitigation approval for high assurance equipment; implement changes only via ASD-prescribed methods and within mandated timeframes.

Mapping detail

Mapping

Direction

Controls