Maintain and Verify Software Registers
Ensure software lists for all IT equipment are up-to-date and regularly checked.
Plain language
This control is about keeping a detailed and accurate list of all the software running on your computers and other devices. It's important because if you don't know what software you have, you're likely to miss important updates and patches, which can leave your systems open to attacks.
Framework
ASD Information Security Manual (ISM)
Control effect
Proactive
Classifications
NC, OS, P, S, TS
ISM last updated
June 2026
Control Stack last updated
18 June 2026
E8 maturity levels
N/A
Official control statement
Software registers for workstations, servers, network devices and networked IT equipment are developed, implemented, maintained and regularly verified.
Why it matters
Without an accurate software register, your company might miss critical updates, increasing the risk of hacking or data breaches.
Operational notes
Regularly review and update the software register. Consistent monitoring ensures new software is correctly documented and validated.
Implementation tips
- System owners should compile a list of all software currently installed on company devices. Use basic inventory tools, checking regularly to add or remove software as it changes.
- The IT team should coordinate regular updates of this list. This might involve setting reminders in their calendars to check for new installations or removals once a month.
- Managers should ensure there is a policy in place that requires any new software to be reported before installation. This can be a simple form or email notification to the IT department.
- An office manager should consider establishing a process for verifying software updates are applied. This can involve checking a sample of computers every few weeks and confirming with users.
- Procurement should maintain records of all software licenses purchased. This ensures that the list is consistent with current licenses and helps control costs.
Audit / evidence tips
- Askthe software register document: Verify that it includes software names, versions, and installation dates. Good track: a comprehensive list without gaps
- Request records of monthly updates to the register: Check these for consistency and dates of updates. Good result: regular and timely updates noted.
- Askevidence of a review process for new software installationsLook atdocumented requests or approvals for new softwareGoodincludes a reliable approval trail
- Look atany discrepancies noted and actions takenGoodwould show proactive management of software changes
- Aska list of software licences: Check this against the software register for unauthorised softwareGoodno discrepancies between the lists
Cross-framework mappings
How ISM-1493 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(2)expand_less | ||
| Annex A 5.9 | Annex A 5.9 requires developing and maintaining an inventory of information and associated assets, including owners | |
| Annex A 8.19 | ISM-1493 requires organisations to develop, maintain and verify software registers, ensuring installed software is known and can be check... | |
handshakeSupports(1)expand_less | ||
| Annex A 8.9 | ISM-1493 requires organisations to maintain and regularly verify software registers so they can evidence what software exists across thei... | |
E8
| Control | Notes | Details |
|---|---|---|
handshakeSupports(4)expand_less | ||
| E8-AC-ML1.1 | ISM-1493 requires organisations to maintain and regularly verify software registers across devices, creating visibility of what executabl... | |
| E8-PO-ML1.1 | E8-PO-ML1.1 focuses on discovering assets automatically at least fortnightly to enable effective vulnerability scanning coverage | |
| E8-AC-ML3.1 | ISM-1493 requires organisations to maintain and regularly verify software registers for servers and other networked equipment, identifyin... | |
| E8-PA-ML3.3 | ISM-1493 requires organisations to maintain and verify software registers so they can reliably identify installed applications and their ... | |
ISO 42001
| Control | Notes | Details |
|---|---|---|
sync_altPartially overlaps(1)expand_less | ||
| Annex A 4.4 | Annex A 4.4 requires the organisation to document information about the tooling resources utilised for an AI system as part of identifyin... | |
handshakeSupports(1)expand_less | ||
| Annex A 4.5 | Annex A 4.5 requires documenting the system and computing resources used by an AI system | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in System management
See all Guidelines for system management controls, or browse the full ASD ISM library.