Skip to content
arrow_back
search
ISM-1701 policy ASD Information Security Manual (ISM)

Daily Vulnerability Scanning for Internet-Facing Systems

Use a daily scanner to find missing security updates on internet-facing systems to keep them secure.

record_voice_over

Plain language

This control is about scanning the systems that are connected to the internet every day to check for any missing security updates. It’s crucial because hackers often look for weaknesses in your systems, and without these updates, those weaknesses can be easily exploited. This could lead to data breaches or allow malware to disrupt your business operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

A vulnerability scanner is used at least daily to identify missing patches or updates for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices.
policy ASD Information Security Manual (ISM) ISM-1701
priority_high

Why it matters

Ignoring daily scans on internet-facing systems can leave severe vulnerabilities open for attackers, risking data theft or operational disruption.

settings

Operational notes

Run vulnerability scans at least daily on all internet-facing servers and network devices; review findings and prioritise patching or mitigation of critical OS issues.

Mapping detail

Mapping

Direction

Controls