Skip to content
arrow_back
search
ISM-2061 policy ASD Information Security Manual (ISM)

Conduct Security-Focused Peer Reviews on Software

Developers review important software to ensure it is secure.

record_voice_over

Plain language

This control means that software developers need to have a close look at critical pieces of software to ensure they're safe and secure before they're used. This is important because if there are security holes or weaknesses, it could lead to bad actors accessing sensitive information or disrupting operations, which can seriously affect a business or organisation.

Framework

ASD Information Security Manual (ISM)

Control effect

Preventative

Classifications

NC, OS, P, S, TS

ISM last updated

May 2025

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Software developer-supported security-focused peer reviews are conducted on all critical and security-focused software components.
policy ASD Information Security Manual (ISM) ISM-2061
priority_high

Why it matters

Without security-focused peer reviews of critical components, vulnerabilities can slip into production, enabling breaches or data theft.

settings

Operational notes

Perform developer-supported security peer reviews on all critical/security code; use a checklist and assign independent reviewers.

Mapping detail

Mapping

Direction

Controls