Skip to content
arrow_back
ISM-1163policyASD Information Security Manual (ISM)

Continuous Monitoring Plan to Find and Fix Vulnerabilities

Each system must have a written continuous monitoring plan that covers three things: (1) running security assessment activities to find vulnerabilities (weaknesses an attacker could exploit), (2) analysing each vulnerability found to work out its potential impact, and (3) putting fixes (mitigations) in place, choosing which ones based on risk, how effective they are, and how much they cost. The goal is an ongoing cycle of find, assess, and fix, rather than a one-off security check.

record_voice_over

Plain language

Your systems need an ongoing routine for spotting and closing security holes, written down as a plan. The plan has to do three jobs. First, it keeps looking for weaknesses (this is called a security assessment, and includes things like vulnerability scans). Second, when a weakness is found, someone works out how bad it could be if a criminal used it, for example what data or services it puts at risk. Third, you fix the weaknesses, deciding what to fix first by weighing up the risk, whether the fix actually works, and what it costs. This matters because attackers constantly look for unpatched weaknesses, so a single yearly check is not enough. A continuous loop of finding, judging, and fixing keeps your defences current and stops small holes from turning into a major breach.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Systems have a continuous monitoring plan that includes: - conducting security assessment activities to identify vulnerabilities - analysing identified vulnerabilities to determine their potential impact - implementing mitigations based on risk, effectiveness and cost.
policyASD Information Security Manual (ISM)ISM-1163
priority_high

Why it matters

Without continuous monitoring, vulnerabilities go undetected and unfixed, giving attackers an open path to breach data, disrupt services, and cause costly damage.

settings

Operational notes

Treat finding, analysing, and fixing as one repeating loop, not three one-off tasks. Keep the plan and its assessment schedule current as systems and threats change.

build

Implementation tips

  • System owners should write a continuous monitoring plan for each system and have it cover all three required activities: finding vulnerabilities, analysing their impact, and implementing mitigations.
  • IT or security staff should schedule regular security assessment activities, such as automated vulnerability scans and periodic manual reviews, so new weaknesses are found on an ongoing basis rather than once a year.
  • Whoever runs the assessments should analyse each vulnerability found to determine its potential impact, recording what system, data, or service is at risk and how serious the consequences would be.
  • Decision makers should choose which mitigations to apply by weighing three factors together: the risk the vulnerability poses, how effective the proposed fix is, and how much it costs to implement.
  • System owners should keep the plan current by reviewing it on a set cadence and updating the schedule, scan coverage, and mitigation priorities as systems and threats change.
fact_check

Audit / evidence tips

  • AskCan you show me the documented continuous monitoring plan for this system?Look atA written plan that names all three activities (security assessments, impact analysis, risk-based mitigation). GOOD-ANSWER: A current, system-specific plan covering all three, with named owners and a schedule
  • AskHow and how often do you run security assessment activities to find vulnerabilities?Look atScan schedules, scan reports with dates, and records of manual reviews. GOOD-ANSWER: Regular, recurring assessments with dated evidence, not a single point-in-time check
  • AskHow do you analyse a vulnerability once it is found to determine its impact?Look atImpact ratings or notes recording affected systems, data, and severity for each finding. GOOD-ANSWER: A consistent method that records potential impact for every vulnerability identified
  • AskHow do you decide which mitigations to implement?Look atRecords showing decisions weighed risk, effectiveness, and cost together. GOOD-ANSWER: Prioritisation that visibly balances all three factors, with high-risk items addressed first
  • AskCan you show evidence that planned mitigations were actually implemented?Look atPatch logs, change records, or remediation tickets tied to specific findings. GOOD-ANSWER: Completed fixes traceable back to the vulnerabilities they address, done in a timely way
link

Cross-framework mappings

How ISM-1163 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 8.8ISM-1163 requires continuous monitoring including regular vulnerability assessments
handshakeSupports(1)expand_less
Annex A 5.7Annex A 5.7 requires organisations to collect and analyse threat information to produce threat intelligence that informs security decisions

E8

ControlNotesDetails
layersPartially meets(5)expand_less
sync_altPartially overlaps(4)expand_less
handshakeSupports(5)expand_less

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for cyber security documentation controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls