Patch

Patch management is the practice of deploying software fixes in a timely, controlled way to remediate known vulnerabilities. It turns the steady stream of vendor updates into an organized workflow that closes weaknesses before they can be exploited, while avoiding disruption from changes applied carelessly.

Within the Preparation phase, patching is one of the most direct ways to reduce exposure. Many intrusions rely on weaknesses for which a fix already exists, so the gap between a patch being available and being applied is itself a risk. Managing that gap deliberately, and prioritizing by severity and exposure, keeps the most dangerous weaknesses from lingering.

In practice, patch management runs a repeatable cycle: identify applicable updates, assess their relevance and risk, test them where practical, deploy them on a schedule matched to urgency, and verify that systems are actually patched. Teams prioritize using severity ratings and real-world exposure, treating internet-facing and critical systems first. Patching connects closely to asset management, which supplies the inventory, and to change management, which governs how updates are rolled out and rolled back. A measured, well-tracked process keeps remediation reliable at scale.

References#

  • NIST SP 800-40, Guide to Enterprise Patch Management Planning
  • CISA, Known Exploited Vulnerabilities guidance

Cookie Consent

We use cookies to enhance your experience. Learn more