Skip to content
arrow_back
search
ISM-1754 policy ASD Information Security Manual (ISM)

Timely Resolution of Identified Software Vulnerabilities

Software vulnerabilities should be fixed quickly to prevent potential security risks.

record_voice_over

Plain language

This control means that any weaknesses found in your software should be addressed quickly to keep your organisation safe. If you don't fix these vulnerabilities in a timely manner, hackers might exploit them to steal data, disrupt operations, or cause other harm.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Vulnerabilities identified in software are resolved in a timely manner.
policy ASD Information Security Manual (ISM) ISM-1754
priority_high

Why it matters

Delaying vulnerability fixes can lead to exploits, with attackers gaining access to sensitive data or disrupting critical operations.

settings

Operational notes

Run regular vulnerability scans and patch promptly; prioritise remediation by severity, exploitability and asset criticality to reduce the likelihood of compromise.

Mapping detail

Mapping

Direction

Controls