Patch management is the systematic process of acquiring, testing, prioritising, and deploying software updates across an organisation’s systems to remediate vulnerabilities and defects. It tracks asset inventory and known vulnerabilities, schedules and stages patches to balance risk against operational disruption, and verifies that fixes are applied. Effective patch management is a core control for reducing the window during which known exploits can be used.

Overview

  • Patch management closes the gap between a vulnerability becoming known and its fix being applied.
  • It depends on accurate asset inventory and vulnerability intelligence to prioritise.
  • Patches are tested and staged to avoid breaking production while reducing risk.
  • Automation and configuration management make patching repeatable at scale.

Mechanisms

  • Discovery: inventorying assets and the software they run.
  • Assessment: mapping vulnerabilities and severities to affected systems.
  • Prioritisation: ranking patches by exploitability and business impact.
  • Deployment: testing, staging, and rolling out updates with rollback plans.
  • Verification: confirming patches applied and vulnerabilities closed.

Applications

  • Remediating known CVEs across servers, endpoints, and devices.
  • Meeting compliance requirements for timely patching.
  • Reducing the attack surface exploited by malware and worms.
  • Coordinating maintenance windows with operational constraints.

Provenance