Skip to content
arrow_back
search
ISM-1752 policy ASD Information Security Manual (ISM)

Fortnightly Vulnerability Scanning for Non-Workstations

Check non-work devices every two weeks for missing security updates.

record_voice_over

Plain language

This control is about ensuring your non-work computers, like those used for special purposes or devices in key roles, are checked every two weeks for missing security updates. It's important because if there are gaps in security patches, these devices can become an easy target for cyber attacks, leading to data breaches or operational disruptions.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices.
policy ASD Information Security Manual (ISM) ISM-1752
priority_high

Why it matters

Without fortnightly scanning of non-workstation IT equipment OSs, missing patches may persist and be exploited, causing compromise or service disruption.

settings

Operational notes

Schedule vulnerability scans at least every 14 days for non-workstation IT equipment operating systems (excluding servers/network devices); track missing patches and verify remediation.

Mapping detail

Mapping

Direction

Controls