Skip to content
arrow_back
ISM-1493policyASD Information Security Manual (ISM)

Maintain and Verify Software Registers

Ensure software lists for all IT equipment are up-to-date and regularly checked.

record_voice_over

Plain language

This control is about keeping a detailed and accurate list of all the software running on your computers and other devices. It's important because if you don't know what software you have, you're likely to miss important updates and patches, which can leave your systems open to attacks.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

June 2026

Control Stack last updated

18 June 2026

E8 maturity levels

N/A

Official control statement

Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.
policyASD Information Security Manual (ISM)ISM-1493
priority_high

Why it matters

Without an accurate software register, your company might miss critical updates, increasing the risk of hacking or data breaches.

settings

Operational notes

Regularly review and update the software register. Consistent monitoring ensures new software is correctly documented and validated.

build

Implementation tips

  • System owners should compile a list of all software currently installed on company devices. Use basic inventory tools, checking regularly to add or remove software as it changes.
  • The IT team should coordinate regular updates of this list. This might involve setting reminders in their calendars to check for new installations or removals once a month.
  • Managers should ensure there is a policy in place that requires any new software to be reported before installation. This can be a simple form or email notification to the IT department.
  • An office manager should consider establishing a process for verifying software updates are applied. This can involve checking a sample of computers every few weeks and confirming with users.
  • Procurement should maintain records of all software licenses purchased. This ensures that the list is consistent with current licenses and helps control costs.
fact_check

Audit / evidence tips

  • Askthe software register document: Verify that it includes software names, versions, and installation dates. Good track: a comprehensive list without gaps
  • Request records of monthly updates to the register: Check these for consistency and dates of updates. Good result: regular and timely updates noted.
  • Askevidence of a review process for new software installationsLook atdocumented requests or approvals for new softwareGoodincludes a reliable approval trail
  • Look atany discrepancies noted and actions takenGoodwould show proactive management of software changes
  • Aska list of software licences: Check this against the software register for unauthorised softwareGoodno discrepancies between the lists
link

Cross-framework mappings

How ISM-1493 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
sync_altPartially overlaps(2)expand_less
Annex A 5.9Annex A 5.9 requires developing and maintaining an inventory of information and associated assets, including owners
Annex A 8.19ISM-1493 requires organisations to develop, maintain and verify software registers, ensuring installed software is known and can be check...
handshakeSupports(1)expand_less
Annex A 8.9ISM-1493 requires organisations to maintain and regularly verify software registers so they can evidence what software exists across thei...

E8

ControlNotesDetails
handshakeSupports(4)expand_less
E8-AC-ML1.1ISM-1493 requires organisations to maintain and regularly verify software registers across devices, creating visibility of what executabl...
E8-PO-ML1.1E8-PO-ML1.1 focuses on discovering assets automatically at least fortnightly to enable effective vulnerability scanning coverage
E8-AC-ML3.1ISM-1493 requires organisations to maintain and regularly verify software registers for servers and other networked equipment, identifyin...
E8-PA-ML3.3ISM-1493 requires organisations to maintain and verify software registers so they can reliably identify installed applications and their ...

ISO 42001

ControlNotesDetails
sync_altPartially overlaps(1)expand_less
Annex A 4.4Annex A 4.4 requires the organisation to document information about the tooling resources utilised for an AI system as part of identifyin...
handshakeSupports(1)expand_less
Annex A 4.5Annex A 4.5 requires documenting the system and computing resources used by an AI system

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system management controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls