Skip to content
arrow_back
search
ISM-0304 policy ASD Information Security Manual (ISM)

Remove Unsupported Applications for System Security

Applications no longer supported by vendors, except some key types, should be removed for security.

record_voice_over

Plain language

This control means we should get rid of any computer applications that the companies who made them no longer support, except for some essential ones like office software and security tools. This matters because unsupported applications no longer receive updates or bug fixes, which makes them a prime target for hackers and can lead to data breaches.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
policy ASD Information Security Manual (ISM) ISM-0304
priority_high

Why it matters

Unsupported applications have unpatched flaws attackers can exploit, increasing the likelihood of malware infection, data breaches and full system compromise.

settings

Operational notes

Maintain an application inventory; routinely check vendor support status and remove or replace any unsupported apps (including browsers, plugins and PDF tools) promptly.

Mapping detail

Mapping

Direction

Controls