Skip to content
arrow_back
search
ISM-1693 policy ASD Information Security Manual (ISM)

Timely Application of Patches to Mitigate Vulnerabilities

Apply updates to non-generic software within a month to keep systems secure.

record_voice_over

Plain language

Keeping your software up-to-date is like locking your doors at night. This control ensures that less common software is updated within a month of a security fix being released. If you don't apply these updates, attackers might exploit weaknesses in your software, which could lead to data breaches or disruptions to your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2, ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in applications other than office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within one month of release.
policy ASD Information Security Manual (ISM) ISM-1693
priority_high

Why it matters

Delaying patches for non-core applications beyond one month leaves known vulnerabilities exploitable, increasing breach and outage risk.

settings

Operational notes

Track vendor releases for non-core applications and apply patches, updates or mitigations within one month, with exceptions risk-assessed.

Mapping detail

Mapping

Direction

Controls