Skip to content
arrow_back
search
ISM-1901 policy ASD Information Security Manual (ISM)

Timely Application of Non-Critical Security Patches

Apply non-critical software patches within two weeks to maintain system security.

record_voice_over

Plain language

This control is about making sure any updates to your software that aren't urgent are still applied in a timely manner. It's important because even if a security risk isn't immediately dangerous, leaving it unpatched could allow someone to eventually find a way to exploit it, potentially putting your data and systems at risk.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF applications, and security products are applied within two weeks of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1901
priority_high

Why it matters

Delaying non-critical patches beyond two weeks can expose browsers, email/PDF and security tools to emerging exploits, risking compromise and data integrity.

settings

Operational notes

Track vendor advisories for browsers, office/email/PDF and security products; confirm “non-critical” and no known exploits, then deploy updates within 14 days.

Mapping detail

Mapping

Direction

Controls