Skip to content
arrow_back
search
ISM-1878 policy ASD Information Security Manual (ISM)

Apply Critical Patches Within 48 Hours

Critical system updates must be installed within 48 hours to prevent security risks.

record_voice_over

Plain language

Critical security updates for your IT systems should be installed within 48 hours when deemed critical by vendors. This is crucial because failing to act quickly could leave your systems vulnerable to cyber attacks, which can lead to data breaches, financial losses, and damage to your reputation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2024

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in operating systems of IT equipment other than workstations, servers and network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1878
priority_high

Why it matters

If critical OS patches are not applied within 48 hours, known or exploited vulnerabilities may be rapidly abused, causing outages, data compromise and financial loss.

settings

Operational notes

Monitor vendor advisories and exploit intel, prioritise critical OS patches for non-workstation/server/network devices, and automate deployment to meet the 48-hour window.

Mapping detail

Mapping

Direction

Controls