Skip to content
arrow_back
search
ISM-1877 policy ASD Information Security Manual (ISM)

Timely Application of Critical Security Patches

Apply critical patches to online systems within 48 hours to prevent vulnerability exploits.

record_voice_over

Plain language

This control is about quickly fixing critical weaknesses in your online systems by updating them within two days of the patch being available. It matters because if you don’t update in time, hackers can exploit these vulnerabilities to steal information or cause significant harm to your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Aug 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML1, ML2, ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1877
priority_high

Why it matters

Delaying critical patching can expose online systems to known exploits, leading to data breaches and severe operational disruptions.

settings

Operational notes

Automate patch workflows for internet-facing servers/devices; prioritise, test and deploy critical fixes within 48 hours, and record evidence.

Mapping detail

Mapping

Direction

Controls