Skip to content
arrow_back
search
ISM-1699 policy ASD Information Security Manual (ISM)

Weekly Vulnerability Scanning for Software Updates

Every week, a scanner checks for software updates to fix security issues in commonly used applications.

record_voice_over

Plain language

Every week, a system checks our software to see if there are any updates we need to install. This process is important because missing updates can leave our computers open to attacks, potentially exposing private information and harming our operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

A vulnerability scanner is used at least weekly to identify missing patches or updates for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products.
policy ASD Information Security Manual (ISM) ISM-1699
priority_high

Why it matters

Without weekly vulnerability scanning, missing patches in browsers, email clients, PDF apps and security tools can be exploited, causing breaches and outages.

settings

Operational notes

Run the scanner at least weekly across endpoints; review reports, prioritise missing patches for browsers, office suites and security products, and track remediation to closure.

Mapping detail

Mapping

Direction

Controls