Skip to content
arrow_back
search
ISM-1407 policy ASD Information Security Manual (ISM)

Ensure Use of Current OS Versions

Use the latest or previous operating system version to keep systems up-to-date.

record_voice_over

Plain language

Keeping your computer systems up-to-date by using the latest or just the previous release of an operating system is like ensuring that your team has the best tools available. It matters because outdated systems can have vulnerabilities that are not fixed, making it easier for cybercriminals to break in and potentially cause damage or steal information.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

The latest release, or the previous release, of operating systems are used.
policy ASD Information Security Manual (ISM) ISM-1407
priority_high

Why it matters

Using outdated OS versions leaves known vulnerabilities unpatched, increasing the likelihood of compromise and data breaches.

settings

Operational notes

Maintain OS currency by standardising on the latest or previous release, tracking vendor lifecycle dates, and scheduling upgrades before end-of-support.

Mapping detail

Mapping

Direction

Controls