Skip to content
arrow_back
search
ISM-1755 policy ASD Information Security Manual (ISM)

Develop and Maintain a Vulnerability Disclosure Policy

Organisations create and sustain a policy for reporting software vulnerabilities securely.

record_voice_over

Plain language

A vulnerability disclosure policy is like an invitation for people to let you know about weaknesses in your software in a safe and organised way. This is crucial because if these vulnerabilities are not reported and fixed, they could be exploited by malicious people, potentially leading to data breaches or system failures.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

A vulnerability disclosure policy is developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1755
priority_high

Why it matters

Without a vulnerability disclosure policy, external researchers may not report flaws, leaving vulnerabilities unaddressed and increasing likelihood of compromise or data breach.

settings

Operational notes

Publish a clear disclosure policy with reporting channels, triage/response timeframes and safe-harbour; review and update it regularly as systems and contacts change.

Mapping detail

Mapping

Direction

Controls