Use Latest Releases of User Applications
Ensure all user applications like email and web browsers are updated to their latest versions.
Plain language
Keeping user applications like email and web browsers updated to their latest versions is crucial because it protects against security flaws. If these apps are outdated, they can be an easy target for cybercriminals, potentially leading to breaches of sensitive business or personal information.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
User Application HardeningOfficial control statement
The latest release of email clients, office productivity suites, PDF applications, security products and web browsers, including their extensions, are used.
Why it matters
Neglecting to update applications invites cyber threats, risking data breaches that could harm business finances and reputation.
Operational notes
Regularly check for updates and set reminders to review application versions; engage staff on the importance of timely updates.
Implementation tips
- IT team should check regularly for updates to all user applications. This means setting up automatic updates where possible or tracking release notifications from application providers.
- System owner should ensure that all employees understand the importance of updates. They could organise a short workshop or send an informative email explaining the risks of using outdated applications.
- Managers should create a policy for regular updates. This involves drafting a simple document that outlines how often updates should occur and the responsibilities of staff.
- The IT team should use a centralised management tool to deploy updates. This helps to automate and streamline the installation of updates, ensuring no application is overlooked.
- System administrators should monitor compliance with the update policy. This can be achieved by generating regular reports that show what versions of applications are in use across the organisation.
Audit / evidence tips
- Askthe update policy document: Request to see the formal document that outlines the process for updating applicationsLook atthe schedule and responsibilities defined in the documentGoodis a comprehensive, clear policy that includes update frequency and roles
- Aska list of current application versions in use: Request a report or inventory showing the versions of important applications like email clients and web browsersLook atversions that are the latest availableGoodis a detailed list with version numbers matching the most recent releases
- Askupdate deployment logs: Request logs or records showing when updates were installed on applicationsLook atrecent entries coinciding with the release of new updatesGoodis logs showing timely updates following new releases
- Askstaff communication records: Request copies of any emails, memos, or training materials sent to staff about the importance of keeping applications updatedLook atexplanations of risks associated with outdated applicationsGoodis clear, targeted communication that reaches all relevant staff
- Askcompliance check reports: Request reports that summarise compliance with the updating policyLook atthe percentage of applications that are updated versus those that are notGoodis a high compliance rate with plans to address any non-compliance
Cross-framework mappings
How ISM-1467 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(3)expand_less | ||
| E8-PA-ML1.9 | ISM-1467 requires organisations to ensure the latest releases of office suites, web browsers and extensions, email clients, PDF applicati... | |
| E8-PA-ML3.1 | ISM-1467 requires organisations to use the latest releases of key user applications and security products to reduce exposure to known wea... | |
| E8-PA-ML3.2 | ISM-1467 requires organisations to use the latest releases of core user applications (office suites, browsers and extensions, email clien... | |
handshakeSupports(1)expand_less | ||
| E8-PA-ML1.4 | ISM-1467 requires organisations to ensure the latest releases of specified user applications and security products are used | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.