ISM-0105 Removed History Priority should 2010 Agencies should undertake and document vulnerability assessments of their systems at least annually. 2008 Agencies should undertake and document ICT security reviews of their systems.