Skip to content
arrow_back
search
ISM-1908 policy ASD Information Security Manual (ISM)

Responsible Disclosure of Software Vulnerabilities

Software weaknesses must be reported openly and quickly, using standard classification systems.

record_voice_over

Plain language

This control is about making sure software flaws are reported responsibly and quickly so they can be fixed before causing harm. If vulnerabilities are not disclosed properly, hackers could exploit them to steal information or disrupt operations.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Vulnerabilities identified in software are publicly disclosed in a responsible and timely manner, including with Common Weakness Enumeration and Common Platform Enumeration information.
policy ASD Information Security Manual (ISM) ISM-1908
priority_high

Why it matters

Failure to responsibly disclose vulnerabilities can lead to exploitation by attackers, causing data breaches and operational disruptions.

settings

Operational notes

Disclose identified vulnerabilities responsibly and promptly, including CWE/CPE details, and coordinate release timelines with vendors and affected parties.

Mapping detail

Mapping

Direction

Controls