Skip to content
arrow_back
search
ISM-1606 policy ASD Information Security Manual (ISM)

Apply Timely Updates to Isolation Mechanisms

Keep server hardware isolation software and OS updated to fix vulnerabilities promptly.

record_voice_over

Plain language

Keeping your server's software and its operating system updated is crucial because it protects your systems from new vulnerabilities that hackers might exploit. If you don't apply these updates promptly, someone could potentially steal data, disrupt your services, or even lock you out of your own systems.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

When using a software-based isolation mechanism to share a physical server's hardware, patches, updates or vendor mitigations for vulnerabilities are applied to the isolation mechanism and underlying operating system in a timely manner.
policy ASD Information Security Manual (ISM) ISM-1606
priority_high

Why it matters

Delayed hypervisor/container and host OS patching can enable isolation escape or host compromise, exposing multiple tenants’ data and workloads.

settings

Operational notes

Track vendor advisories for the hypervisor/container runtime and host OS; prioritise isolation-escape CVEs and apply patches/mitigations promptly.

Mapping detail

Mapping

Direction

Controls