Skip to content
arrow_back
search
ISM-1900 policy ASD Information Security Manual (ISM)

Fortnightly System Vulnerability Scanning

Scan systems every two weeks to find and fix unpatched security flaws.

record_voice_over

Plain language

This control means that every two weeks, your business should scan its computer systems to look for software that needs updating. This is important because unpatched software can have security holes that hackers can exploit to steal data or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Detective

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in firmware.
policy ASD Information Security Manual (ISM) ISM-1900
priority_high

Why it matters

If firmware isn’t scanned at least fortnightly, missing patches can persist and be exploited, causing service disruption or data compromise.

settings

Operational notes

Run an authenticated vulnerability scan at least fortnightly and track firmware patch gaps; prioritise and remediate high/critical findings quickly.

Mapping detail

Mapping

Direction

Controls