### Purpose

This procedure defines how the company identifies and fixes vulnerabilities in devices, applications, servers, cloud systems, websites, and network equipment.

### Step 1: Know What Needs Updating

Use the Asset Inventory and Applications and Services Inventory to identify:

- Endpoints
- Servers
- Network devices
- Firewalls
- VPN appliances
- Websites
- CMS systems and plugins
- Cloud workloads
- Business applications
- SaaS configurations

### Step 2: Monitor for Updates and Vulnerabilities

Use vendor notifications, security tools, vulnerability scanners, MSP reports, and trusted security advisories to identify security issues.

### Step 3: Prioritize

Do not treat every vulnerability equally.

**Prioritize based on:**

- Known exploitation
- Internet exposure
- Severity
- Business criticality
- Sensitive data access
- Privilege level
- Availability of patches
- Compensating controls

### Step 4: Apply Updates

Security updates should be installed within timeframes appropriate to the risk.

**A practical internal target might be:**

- **Critical or actively exploited:** Emergency treatment.

- **High risk:** As soon as reasonably practical.

- **Normal security updates:** Routine scheduled cycle.

Exact timeframes should reflect the company’s environment and operational constraints.

### Step 5: Test Where Necessary

For important production systems, test significant updates where practical before broad deployment.

Do not use testing as an excuse for indefinite delay.

### Step 6: Verify

**Confirm that:**

- The update installed successfully.
- The vulnerability is no longer present where appropriate.
- The service still works.
- Failed deployments are investigated.

### Step 7: Manage Exceptions

**If a vulnerability cannot be fixed:**

- Document the reason
- Record the risk
- Apply compensating controls
- Assign an owner
- Set a review or expiry date

**Examples include:**

- Restricting network access
- Disabling the vulnerable service
- Increasing monitoring
- Removing internet exposure

### Step 8: Replace Unsupported Technology

Unsupported systems should be treated as a security risk.

**Create a plan to:**

- Upgrade
- Replace
- Isolate
- Retire

Or formally accept the risk temporarily.

### Patch and Vulnerability Record

**Record where appropriate:**

- System
- Vulnerability or update
- Severity
- Internet-facing status
- Known exploitation
- Owner
- Required action
- Due date
- Status
- Exception
- Verification
- Evidence

### Practical Rule

Patch the vulnerabilities that attackers can realistically use against the company first.
