Skip to content
arrow_back
search
ISM-1904 policy ASD Information Security Manual (ISM)

Apply Firmware Patches for Non-Critical Vulnerabilities

Install patches for minor firmware issues within a month if there're no immediate threats.

record_voice_over

Plain language

Think of firmware as the basic software that lets your hardware work correctly. If we don't regularly update it, even for non-critical issues, those small problems can turn into bigger ones, like security holes that hackers might try to exploit later. By keeping this up to date, we're preventing minor issues from becoming major headaches down the line.

Framework

ASD Information Security Manual (ISM)

Control effect

Proactive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML3

Official control statement

Patches, updates or other vendor mitigations for vulnerabilities in firmware are applied within one month of release when vulnerabilities are assessed as non-critical by vendors and no working exploits exist.
policy ASD Information Security Manual (ISM) ISM-1904
priority_high

Why it matters

Delaying non-critical firmware patches beyond a month can leave known flaws unmitigated, increasing risk of compromise and device instability over time.

settings

Operational notes

Track vendor firmware advisories; if rated non-critical and no working exploit exists, schedule and apply patches within 30 days, recording assessment and completion.

Mapping detail

Mapping

Direction

Controls