Skip to content
arrow_back
search
ISM-1501 policy ASD Information Security Manual (ISM)

Replace Unsupported Operating Systems

Replace operating systems that are no longer supported to maintain security.

record_voice_over

Plain language

This control is about making sure your computers and devices are running up-to-date, supported versions of their operating systems, like Windows or MacOS. If you're using software that's no longer supported by the maker, your systems are more vulnerable to viruses and hackers because they don't get security updates. It's like leaving your home with the doors unlocked; you're inviting trouble that could cost you time, money, or more importantly, data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Operating systems that are no longer supported by vendors are replaced.
policy ASD Information Security Manual (ISM) ISM-1501
priority_high

Why it matters

Unsupported operating systems remain unpatched, increasing exposure to known exploits, malware and unauthorised access across the network.

settings

Operational notes

Maintain an OS register, track vendor end-of-support dates, and replace or upgrade systems before support ends; isolate exceptions and manage risk.

Mapping detail

Mapping

Direction

Controls