Skip to content
arrow_back
search
ISM-1703 policy ASD Information Security Manual (ISM)

Regular Vulnerability Scanning for Missing Patches

A scanner checks every two weeks to find missing security patches for drivers.

record_voice_over

Plain language

Every two weeks, it’s crucial for someone to run a check on computers and other devices to see if any important updates or patches are missing. If these checks aren’t done, devices might have security holes that cybercriminals could exploit to access sensitive information.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in drivers.
policy ASD Information Security Manual (ISM) ISM-1703
priority_high

Why it matters

Without fortnightly vulnerability scans, missing driver patches can go undetected, increasing exposure to known exploits and potential compromise.

settings

Operational notes

Run vulnerability scans at least every fortnight, review findings quickly, and track missing driver patches to remediation based on risk and exposure.

Mapping detail

Mapping

Direction

Controls