Skip to content
arrow_back
search
ISM-1696 policy ASD Information Security Manual (ISM)

Apply Critical Patches Within 48 Hours

Apply critical security patches to certain systems within 48 hours to prevent exploits.

record_voice_over

Plain language

This control is about making sure that important security updates, known as critical patches, are installed on certain computer systems within two days of their release. This is crucial because if you delay these updates, it can leave your systems vulnerable to hackers who can exploit these weaknesses and potentially cause damage or loss by accessing sensitive data.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1696
priority_high

Why it matters

Failure to apply critical OS patches within 48 hours can allow rapid exploitation, leading to compromise of workstations and internal servers, data loss, and downtime.

settings

Operational notes

Track vendor advisories and exploit intel; prioritise critical OS patches for workstations and non-internet-facing servers/devices and enforce automated deployment to meet the 48-hour window.

Mapping detail

Mapping

Direction

Controls