Skip to content
arrow_back
search
ISM-1702 policy ASD Information Security Manual (ISM)

Regularly Scan for Missing Security Patches

Regular checks detect missing updates on devices to fix security gaps.

record_voice_over

Plain language

Think of your computer systems like a car that needs regular servicing. If you don't check for and fix missing updates, security holes might let in online attackers, much like leaving your car doors unlocked in a busy parking lot. Regular scanning can prevent these potential threats from becoming real problems.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.
policy ASD Information Security Manual (ISM) ISM-1702
priority_high

Why it matters

Unpatched internal workstations, servers and network devices can be exploited, causing data compromise, lateral movement and service outages.

settings

Operational notes

Run vulnerability scans at least fortnightly across internal workstations, servers and network devices; prioritise missing OS patches and track remediation to closure.

Mapping detail

Mapping

Direction

Controls