Skip to content
arrow_back
search
ISM-1697 policy ASD Information Security Manual (ISM)

Apply Non-Critical Patches Within One Month

Apply updates for driver vulnerabilities within a month if they are non-critical and have no known exploits.

record_voice_over

Plain language

Applying patches within a month for non-critical issues in your computer drivers is like fixing a small leak in a roof before it rains heavily. While these updates may not seem urgent, ignoring them can lead to bigger problems like system slowdowns or even data loss if vulnerabilities are exploited later.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1697
priority_high

Why it matters

If non-critical driver patches (no known working exploits) aren’t applied within 1 month, exposure to privilege escalation or device compromise increases.

settings

Operational notes

Track vendor driver advisories; when rated non-critical and no working exploit exists, test then deploy within 1 month and record evidence of completion.

Mapping detail

Mapping

Direction

Controls