Skip to content
arrow_back
search
ISM-1698 policy ASD Information Security Manual (ISM)

Daily Vulnerability Scanning for Missing Updates

Online services are checked daily for missing updates to prevent vulnerabilities.

record_voice_over

Plain language

Every day, businesses should check their online services to make sure they have all the latest updates. These updates fix weaknesses that hackers could use to cause harm. If you skip these checks, your business might be left open to cyber attacks that could disrupt operations or steal sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in online services.
policy ASD Information Security Manual (ISM) ISM-1698
priority_high

Why it matters

Without daily vulnerability scans for missing updates, online services may remain unpatched and quickly exploited, causing compromise, service disruption and data exposure.

settings

Operational notes

Run vulnerability scans at least daily across all online services, review findings promptly, and prioritise remediation of missing patches/updates. Track exceptions and rescan after patching.

Mapping detail

Mapping

Direction

Controls