Skip to content
arrow_back
search
ISM-2024 policy ASD Information Security Manual (ISM)

Utilise Authoritative Sources in Software Development

Use only official sources for all software development tasks to ensure accuracy and reliability.

record_voice_over

Plain language

When developing software, it’s crucial to use official and trusted sources to avoid errors and ensure safety. This is important because relying on unofficial sources can lead to software bugs, data breaches, or other technical issues that might harm your business or customer's trust.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

The authoritative source for software is used for all software development activities.
policy ASD Information Security Manual (ISM) ISM-2024
priority_high

Why it matters

Using non-authoritative sources can introduce malicious code or defective components into builds, undermining software integrity and user trust.

settings

Operational notes

Maintain an approved list of authoritative repositories and vendor sites, and periodically revalidate access paths, signatures and ownership to avoid compromised or stale sources.

Mapping detail

Mapping

Direction

Controls