Skip to content
arrow_back
search
ISM-1903 policy ASD Information Security Manual (ISM)

Rapid Application of Critical Firmware Patches

Install critical firmware updates within 48 hours to protect systems from known vulnerabilities.

record_voice_over

Plain language

This control is about updating the tiny programs inside computer hardware, like routers or servers, called firmware, very quickly—within 48 hours—when there's a known security issue. It's important because if you don't fix these issues, hackers can break in and cause serious damage, like stealing information or making your systems crash.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1903
priority_high

Why it matters

Failure to apply critical firmware fixes within 48 hours can enable rapid exploitation, leading to device compromise, data theft and outages.

settings

Operational notes

Track vendor advisories and exploit intel for firmware; assess criticality and deploy patches or mitigations within 48 hours, with change logging.

Mapping detail

Mapping

Direction

Controls