Skip to content
arrow_back
search
ISM-1616 policy ASD Information Security Manual (ISM)

Implementing a Vulnerability Disclosure Program

Create a program to find and fix software issues to keep products secure.

record_voice_over

Plain language

A vulnerability disclosure program is like having a feedback mechanism for your software, where users can report any security issues they find. This is important because if nobody reports these vulnerabilities, bad actors might exploit them, leading to data breaches or other security incidents.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

July 2020

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A vulnerability disclosure program is implemented to assist with the secure development and maintenance of products and services.
policy ASD Information Security Manual (ISM) ISM-1616
priority_high

Why it matters

Without a vulnerability disclosure program, researchers lack a safe reporting path, so flaws stay hidden or are exploited, leading to breaches and loss.

settings

Operational notes

Triage and validate disclosures, set severity and fix SLAs, acknowledge reporters promptly, and publish a clear reporting channel and safe-harbour rules.

Mapping detail

Mapping

Direction

Controls