Skip to content
arrow_back
search
ISM-1879 policy ASD Information Security Manual (ISM)

Timely Patching of Critical Driver Vulnerabilities

Critical driver vulnerabilities must be fixed within 48 hours to prevent exploits.

record_voice_over

Plain language

This control is about fixing known problems in software drivers, which are bits of code that help your computer talk to its hardware, as soon as possible. If these problems aren't fixed quickly, hackers might find a way to exploit them, which could lead to data breaches or system shutdowns.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in drivers are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1879
priority_high

Why it matters

Delaying critical driver patches can allow rapid exploitation, leading to privilege escalation, data theft, or service disruption.

settings

Operational notes

Apply driver mitigations within 48 hours when vendors rate issues critical or exploits exist; automate alerts and track deployment to completion.

Mapping detail

Mapping

Direction

Controls