Skip to content
arrow_back
search
ISM-1655 policy ASD Information Security Manual (ISM)

Ensure .NET Framework 3.5 is Disabled or Removed

.NET Framework 3.5 should be turned off or uninstalled for security reasons.

record_voice_over

Plain language

.NET Framework 3.5 might seem like just some software that helps run certain programs on your computer, but it's not supported for the newest security updates. This means it can leave your computer open to hackers, who could steal your data, mess up your system, or compromise your business operations if they're able to exploit these security holes.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2021

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

.NET Framework 3.5 (includes .NET 2.0 and 3.0) is disabled or removed.
policy ASD Information Security Manual (ISM) ISM-1655
priority_high

Why it matters

Leaving .NET Framework 3.5 enabled risks exploitation of unpatched vulnerabilities, leading to potential data breaches and business disruptions.

settings

Operational notes

Verify via Windows Features/PowerShell that .NET Framework 3.5 is disabled/removed on all hosts during quarterly reviews.

Mapping detail

Mapping

Direction

Controls