Skip to content
arrow_back
search
ISM-1143 policy ASD Information Security Manual (ISM)

Develop and Maintain Patch Management Procedures

Ensure patches for systems are regularly updated and processes are in place to manage this.

record_voice_over

Plain language

Patch management is about keeping all your software and systems up-to-date with the latest fixes or updates provided by the software maker. This matters because outdated software can have security weaknesses, which hackers can exploit to steal information or disrupt your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Patch management processes, and supporting patch management procedures, are developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1143
priority_high

Why it matters

Without structured patch management, known vulnerabilities remain exploitable, risking unauthorised access and potential data breaches.

settings

Operational notes

Document patch procedures: roles, asset scope, SLAs by severity, testing/rollback and exceptions. Track patch status and audit compliance; use vendor advisories to prioritise.

Mapping detail

Mapping

Direction

Controls