Skip to content
arrow_back
search
ISM-1694 policy ASD Information Security Manual (ISM)

Timely Application of Non-Critical Security Patches

Apply patches for non-critical vulnerabilities on internet-facing devices within two weeks if no known exploits are available.

record_voice_over

Plain language

This control means that if there's a known weakness in the software of your devices that connect to the internet, you need to fix it within two weeks if it isn't a major issue and no one is trying to exploit it yet. This matters because even smaller weaknesses can become big problems if left unaddressed, potentially allowing cybercriminals to access your systems and compromise your data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1694
priority_high

Why it matters

Delaying non-critical patching on internet-facing systems increases exposure to compromise, enabling unauthorised access and data breaches.

settings

Operational notes

Track vendor releases; when rated non-critical and no working exploit exists, patch internet-facing servers/devices within 14 days.

Mapping detail

Mapping

Direction

Controls