Skip to content
arrow_back
search
ISM-1692 policy ASD Information Security Manual (ISM)

Quick Apply Critical Patches for Vulnerabilities

Apply crucial software patches within 48 hours to prevent security breaches from known vulnerabilities.

record_voice_over

Plain language

Applying critical software updates within 48 hours ensures your systems are protected from security gaps that malicious hackers might exploit. If these updates aren't applied quickly, your organisation could be exposed to cyber attacks that can steal sensitive information or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1692
priority_high

Why it matters

Not applying critical vendor patches within 48 hours for browsers, email, PDF and security tools increases likelihood of exploitation, data compromise and operational disruption.

settings

Operational notes

Track vendor advisories and exploit intel for browsers, office, email, PDF and security products; prioritise automated rollout and verification to meet the 48‑hour critical patch SLA.

Mapping detail

Mapping

Direction

Controls