Skip to content
arrow_back
policyASD Information Security Manual (ISM)

ASD ISM 1905Remove Online Services No Longer Supported by Vendors

Official control statement

Online services that are no longer supported by vendors are removed.
policyASD Information Security Manual (ISM)ISM-1905

Quoted as published. Everything else on this page is written by Control Stack.

In plain English

Online services that are no longer supported by their vendors are decommissioned and removed from use.

ML1ML2ML3NCOSPASD Information Security ManualGuidelines for system management
Control Stack classificationPreventativePatch management
record_voice_over

What this means in practice

This control ensures that any online service your organisation uses is removed once its vendor stops supporting it. When a vendor ends support, the service no longer receives security patches, so known weaknesses stay open for attackers to exploit. By retiring these services promptly and moving to supported alternatives, you avoid running software that can no longer be kept safe.

Framework

ASD Information Security Manual (ISM)

Control effect (Control Stack)

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

Dec 2023

Control Stack last updated

29 Sept 2026

E8 maturity levels

ML1, ML2, ML3

Topic

Cessation of support

priority_high

Why it matters

If unsupported online services remain in use, they stop receiving security patches and leave known vulnerabilities open for attackers to exploit.

settings

Operational notes

Review the online service inventory on a regular schedule so services are retired promptly as soon as vendor support ends.

build

Implementation tips

  • IT and asset owners maintain an inventory of all online services in use, recording each vendor's support status and end-of-life date.
  • Administrators subscribe to vendor product lifecycle notifications so the organisation learns when a service is approaching end of support.
  • The service owner plans and completes a migration to a supported alternative before the current service reaches its end-of-support date.
  • Administrators decommission each unsupported online service by disabling access and deprovisioning its associated accounts and data.
  • IT teams schedule periodic reviews of the service inventory to identify and remove any services that have since lost vendor support.
fact_check

Audit / evidence tips

  • AskAsk for the inventory of online services in use and each service's vendor support status.Look atThe service register showing vendor support and end-of-life dates for every online service.GoodA current inventory that clearly flags any service that is at or past its vendor support end date.
  • AskAsk how the organisation is alerted when an online service reaches end of vendor support.Look atVendor lifecycle notification subscriptions or the documented process for tracking support end dates.GoodReliable notification arrangements that surface upcoming end-of-support dates before they arrive.
  • AskAsk for evidence that online services no longer supported by vendors have been removed.Look atDecommissioning records, change tickets, or removal confirmations for retired services.GoodRecords showing each unsupported service was decommissioned and its access fully disabled.
  • AskAsk whether any online services currently in use are past their vendor support end date.Look atThe list of active online services compared against vendor support end dates.GoodNo active online services remain in use beyond their vendor support end date.
  • AskAsk how often the online service inventory is reviewed for unsupported services.Look atThe review schedule and the most recent review records.GoodRegular, dated reviews that identify services losing support and drive their removal.
link

Cross-framework mappings

How ISM-1905 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.

ISO 27001

ControlNotesDetails
layersPartially meets(1)expand_less
Annex A 8.8ISM-1905 requires removal of vendor-unsupported online services to reduce risk from vulnerabilities that can no longer be remediated

E8

ControlNotesDetails
equalEquivalent(1)expand_less
E8-PA-ML1.8E8-PA-ML1.8 requires organisations to remove online services that are no longer supported by vendors

These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.

See all Guidelines for system management controls, or browse the full ASD ISM library.

Mapping detail

Mapping

Direction

Controls