Skip to content
arrow_back
search
ISM-1588 policy ASD Information Security Manual (ISM)

Annual Review of Standard Operating Environments

Standard Operating Environments must be reviewed and updated once every year.

record_voice_over

Plain language

Standard Operating Environments (SOEs) are like a set of rules for the software and systems used across your organisation. This annual review is important because it ensures everything is up-to-date and secure. If these rules are outdated, your organisation could be more vulnerable to cyber attacks, resulting in data breaches or loss of important information.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

SOEs are reviewed and updated at least annually.
policy ASD Information Security Manual (ISM) ISM-1588
priority_high

Why it matters

Outdated SOEs can expose systems to emerging threats, increasing the risk of breaches and compromising sensitive information.

settings

Operational notes

Conduct an annual SOE baseline review: validate patch levels, security hardening, and approved software; document changes and re-issue the SOE.

Mapping detail

Mapping

Direction

Controls