Use Latest Release of Internet-Facing Server Applications
Ensure that internet-facing server applications always use the latest software version.
Plain language
Always using the latest version of software on servers that face the internet is like having the latest lock for your front door. It keeps out cyber criminals who take advantage of outdated software to break into systems.
Framework
ASD Information Security Manual (ISM)
Control effect
Preventative
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Guideline
Guidelines for system hardeningSection
Server Application HardeningOfficial control statement
The latest release of internet-facing server applications is used.
Why it matters
Old software on internet-facing servers can be an entry point for cyber attacks, potentially resulting in data breaches or downtime.
Operational notes
Regularly review upcoming vendor updates and coordinate with teams to minimise disruption during patching.
Implementation tips
- IT team should regularly check for updates from software vendors. They can do this by subscribing to the vendor's notification service and scheduling periodic reviews of available updates.
- System administrator should test updates in a controlled environment before deploying them. This involves setting up a test server that mirrors the production server to ensure updates don't impact other services.
- Procurement manager should ensure software maintenance agreements are up-to-date. Verify contracts include clauses for regular updates and patches as part of the service.
- The IT team should schedule monthly maintenance windows for updates. This ensures that patches can be applied without interrupting regular business operations, keeping servers secure.
- Managers should regularly communicate with the IT team to confirm updates are applied. This can be done through monthly meetings where the progress on updates and any issues are discussed.
Audit / evidence tips
- Askthe server software update log: Request documentation showing recent updates applied to internet-facing servers
- Look atupdate dates and version numbers in logs: Check that updates are recent and versions are the latest available
- Goodincludes a log with dates less than a month old and version numbers matching the latest vendor release
- Aska list of server applications with descriptions of current versions and vendors: Confirm each application is accounted for
- Look atconsistency with vendor release notes: Verify that listed versions are supported and latest
- Goodincludes documentation with each server application listed, version numbers, and cross-referenced with recent vendor release notes
Cross-framework mappings
How ISM-1483 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(1)expand_less | ||
| Annex A 8.8 | ISM-1483 requires internet-facing server applications to be kept on their latest release to address known vulnerabilities | |
E8
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(3)expand_less | ||
| E8-PA-ML1.5 | ISM-1483 requires internet-facing server applications to use the latest release, reducing risk from vulnerabilities addressed in newer ve... | |
| E8-PA-ML3.3 | ISM-1483 requires that internet-facing server applications are kept on their latest release to reduce exposure to known vulnerabilities | |
| E8-PO-ML3.9 | ISM-1483 requires internet-facing server applications to be kept at their latest release | |
handshakeSupports(2)expand_less | ||
| E8-PA-ML1.6 | E8-PA-ML1.6 requires applying non-critical security patches for online services within two weeks when vendors rate them non-critical and ... | |
| E8-AC-ML2.1 | ISM-1483 requires the latest release of internet-facing server applications to be used to reduce exploitation risk | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System hardening
See all Guidelines for system hardening controls, or browse the full ASD ISM library.