Skip to content
arrow_back
search
ISM-1691 policy ASD Information Security Manual (ISM)

Timely Vulnerability Patching in Software Tools

Apply patches to major software tools like browsers and email clients within two weeks to prevent vulnerabilities.

record_voice_over

Plain language

This control is about making sure that updates for important software like web browsers and email programs are applied within two weeks of their release. This is crucial because failing to update these tools can leave your business open to cyber attacks, where hackers exploit these vulnerabilities to steal data or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release.
policy ASD Information Security Manual (ISM) ISM-1691
priority_high

Why it matters

Unchecked vulnerabilities in browsers, email clients, PDF apps and security tools can be exploited quickly, leading to compromise, data loss, and outages.

settings

Operational notes

Track vendor releases for listed apps and enforce patching within 14 days; use automation for rollout, but validate and expedite critical/high-risk fixes.

Mapping detail

Mapping

Direction

Controls