Skip to content
arrow_back
search
ISM-1704 policy ASD Information Security Manual (ISM)

Remove Unsupported Software to Ensure Security

Unsupported software like browsers, productivity tools, and security apps should be removed to maintain security.

record_voice_over

Plain language

This control is about getting rid of software that's no longer supported by its maker. It matters because unsupported software doesn't get security updates, so it can be an easy target for hackers who might steal your data or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Office productivity suites, web browsers and their extensions, email clients, PDF applications, Adobe Flash Player, and security products that are no longer supported by vendors are removed.
policy ASD Information Security Manual (ISM) ISM-1704
priority_high

Why it matters

Unsupported software can harbour vulnerabilities, exposing organisations to data breaches or operational disruptions from malware or cyber attacks.

settings

Operational notes

Regularly audit for vendor end-of-support software (browsers/extensions, email, PDF, office suites, Flash and security tools) and remove or replace it promptly.

Mapping detail

Mapping

Direction

Controls