Skip to content
arrow_back
search
ISM-1909 policy ASD Information Security Manual (ISM)

Perform Root Cause Analysis for Vulnerabilities

Analyse the cause of issues and fix related vulnerabilities completely.

record_voice_over

Plain language

When you find a security problem, it's important to dig deep to understand the root cause and not just patch it up. If you only fix part of the issue, there's a risk similar problems will keep happening, potentially compromising sensitive information or your systems' functionality.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

In resolving vulnerabilities, root cause analysis is performed and, to the greatest extent possible, entire vulnerability classes are remediated.
policy ASD Information Security Manual (ISM) ISM-1909
priority_high

Why it matters

Without root cause analysis, fixes are patchy and the same vulnerability class reappears across systems, enabling repeat exploitation and possible breaches.

settings

Operational notes

For each vulnerability, document the underlying cause (e.g. coding pattern, misconfiguration) and remediate the whole class via standards, templates and regression tests.

Mapping detail

Mapping

Direction

Controls