Skip to content
arrow_back
search
ISM-1756 policy ASD Information Security Manual (ISM)

Develop and Maintain Vulnerability Disclosure Processes

Organisations must create and maintain procedures for reporting software vulnerabilities.

record_voice_over

Plain language

This control is about setting up a system for people to report problems in your software, like bugs that hackers could exploit. It's important because if you know about these issues early, you can fix them before someone uses them to steal data or disrupt your operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2022

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Vulnerability disclosure processes, and supporting vulnerability disclosure procedures, are developed, implemented and maintained.
policy ASD Information Security Manual (ISM) ISM-1756
priority_high

Why it matters

Without a defined vulnerability disclosure process, flaws may not be reported or coordinated, leaving them exploitable and increasing breach and service disruption risk.

settings

Operational notes

Maintain public reporting channels and internal procedures to triage, validate and coordinate fixes, tracking acknowledgements, timelines and remediation to closure.

Mapping detail

Mapping

Direction

Controls