Patch and Vulnerability Management Procedure

Purpose

This procedure defines how the company identifies and fixes vulnerabilities in devices, applications, servers, cloud systems, websites, and network equipment.

Step 1: Know What Needs Updating

Use the Asset Inventory and Applications and Services Inventory to identify:

  • Endpoints
  • Servers
  • Network devices
  • Firewalls
  • VPN appliances
  • Websites
  • CMS systems and plugins
  • Cloud workloads
  • Business applications
  • SaaS configurations

Step 2: Monitor for Updates and Vulnerabilities

Use vendor notifications, security tools, vulnerability scanners, MSP reports, and trusted security advisories to identify security issues.

Step 3: Prioritize

Do not treat every vulnerability equally.

Prioritize based on:

  • Known exploitation
  • Internet exposure
  • Severity
  • Business criticality
  • Sensitive data access
  • Privilege level
  • Availability of patches
  • Compensating controls

Step 4: Apply Updates

Security updates should be installed within timeframes appropriate to the risk.

A practical internal target might be:

  • Critical or actively exploited: Emergency treatment.

  • High risk: As soon as reasonably practical.

  • Normal security updates: Routine scheduled cycle.

Exact timeframes should reflect the company’s environment and operational constraints.

Step 5: Test Where Necessary

For important production systems, test significant updates where practical before broad deployment.

Do not use testing as an excuse for indefinite delay.

Step 6: Verify

Confirm that:

  • The update installed successfully.
  • The vulnerability is no longer present where appropriate.
  • The service still works.
  • Failed deployments are investigated.

Step 7: Manage Exceptions

If a vulnerability cannot be fixed:

  • Document the reason
  • Record the risk
  • Apply compensating controls
  • Assign an owner
  • Set a review or expiry date

Examples include:

  • Restricting network access
  • Disabling the vulnerable service
  • Increasing monitoring
  • Removing internet exposure

Step 8: Replace Unsupported Technology

Unsupported systems should be treated as a security risk.

Create a plan to:

  • Upgrade
  • Replace
  • Isolate
  • Retire

Or formally accept the risk temporarily.

Patch and Vulnerability Record

Record where appropriate:

  • System
  • Vulnerability or update
  • Severity
  • Internet-facing status
  • Known exploitation
  • Owner
  • Required action
  • Due date
  • Status
  • Exception
  • Verification
  • Evidence

Practical Rule

Patch the vulnerabilities that attackers can realistically use against the company first.