Patch operating systems
Patching operating systems, often just called OS patches, means keeping Windows, macOS and the firmware on servers, firewalls and routers up to date with security fixes. It also means replacing systems so old they no longer get updates. Internet-facing devices matter most, because attackers can probe them directly.
It is control 6 of the eight in the Australian Signals Directorate's Essential 8 (Essential Eight) baseline, assessed at maturity Levels 0–3.
Why this Essential 8 control comes up with insurers
Unsupported or unpatched operating systems come up often in claims, so insurers commonly ask about OS patch timeframes and end-of-life systems like Windows 7. This is a separate Essential 8 control from application patching, so each one needs its own documented timeframe.
Maturity Level 1: the baseline
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
If a critical security fix is released for your internet-facing servers, firewalls or routers, is it applied within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of internet-facing servers and internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are operating system updates (Windows, macOS) installed on staff computers and internal servers within one month of release?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within one month of release.”
Have you replaced devices running operating systems that no longer get security updates (for example Windows 7 or 8)?
ACSC requirement: “Operating systems that are no longer supported by vendors are replaced.”
Do you use a tool that automatically checks, at least fortnightly, for missing operating system updates on staff computers and internal servers?
ACSC requirement: “A vulnerability scanner is used at least fortnightly to identify missing patches or updates for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices.”
Maturity Level 3: advanced
Ask yourself these. Under each is the ACSC requirement (November 2023 model) it comes from:
If a critical operating system fix comes out, is it installed on staff computers and internal servers within 48 hours?
ACSC requirement: “Patches, updates or other vendor mitigations for vulnerabilities in operating systems of workstations, non-internet-facing servers and non-internet-facing network devices are applied within 48 hours of release when vulnerabilities are assessed as critical by vendors or when working exploits exist.”
Are your devices running the latest (or previous) release of their operating system?
ACSC requirement: “The latest release, or the previous release, of operating systems are used.”
These are the criteria our free self-assessment checks. They are a representative subset of the full ACSC model, which has more requirements at each level. You can read the full model at cyber.gov.au.
This is a self-assessment based on your own answers. It is not a certification, audit, or guarantee of security or insurance outcomes, and is not legal or insurance advice. Results are indicative, reflect the information you provided, and are assessed against a representative subset of the ASD Essential Eight Maturity Model (November 2023).