Skip to content
arrow_back
search
ISM-1695 policy ASD Information Security Manual (ISM)

Timely Application of System Security Patches

Ensure non-internet-facing systems are updated within a month to protect against known vulnerabilities.

record_voice_over

Plain language

This control means you need to update software on computers and devices that aren't directly connected to the internet within a month of a fix being available. This is important because if you don't, you leave these systems open to attacks from hackers who take advantage of known weaknesses, which can lead to data theft or disruption of business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.
policy ASD Information Security Manual (ISM) ISM-1695
priority_high

Why it matters

Delaying patches on non-internet-facing systems leaves known OS vulnerabilities exploitable, increasing the likelihood of compromise and service disruption.

settings

Operational notes

Track vendor patch releases and apply OS patches to workstations, non-internet-facing servers and network devices within 1 month, after compatibility testing.

Mapping detail

Mapping

Direction

Controls