Skip to content
arrow_back
search
ISM-1876 policy ASD Information Security Manual (ISM)

Apply Critical Patches Within 48 Hours

Install critical patches for online services within 48 hours when notified by the vendor or if exploits are present.

record_voice_over

Plain language

This control is all about being quick to fix critical issues in your online services. When a vendor releases an important update or a security hole has been found, it's crucial to patch it within 48 hours. This prevents hackers from exploiting known weaknesses, which could lead to data breaches, financial loss, or damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in online services are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1876
priority_high

Why it matters

Failure to apply critical patches within 48 hours can allow rapid exploitation of known flaws in online services, causing breaches and outage.

settings

Operational notes

Monitor vendor alerts for critical or exploited flaws and use an emergency change process to deploy patches to online services within 48 hours.

Mapping detail

Mapping

Direction

Controls