Skip to content
arrow_back
search
ISM-1690 policy ASD Information Security Manual (ISM)

Timely Application of Non-Critical Vulnerability Patches

Apply non-critical patches to online services within two weeks to prevent unexploited vulnerabilities.

record_voice_over

Plain language

This control is about making sure we update our software with non-critical security patches within two weeks after they're available. Even if a vulnerability isn't currently being exploited, leaving it unpatched can give hackers an opportunity to find and use it, which could lead to data breaches or service disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1690
priority_high

Why it matters

Delaying non-critical online-service patches beyond two weeks increases exposure, raising the risk of compromise, data loss, or service disruption.

settings

Operational notes

Track non-critical online-service advisories and confirm no working exploits; apply vendor mitigations within 14 days of release.

Mapping detail

Mapping

Direction

Controls