Patch and Vulnerability Management Procedure
Purpose
This procedure defines how the company identifies and fixes vulnerabilities in devices, applications, servers, cloud systems, websites, and network equipment.
Step 1: Know What Needs Updating
Use the Asset Inventory and Applications and Services Inventory to identify:
- Endpoints
- Servers
- Network devices
- Firewalls
- VPN appliances
- Websites
- CMS systems and plugins
- Cloud workloads
- Business applications
- SaaS configurations
Step 2: Monitor for Updates and Vulnerabilities
Use vendor notifications, security tools, vulnerability scanners, MSP reports, and trusted security advisories to identify security issues.
Step 3: Prioritize
Do not treat every vulnerability equally.
Prioritize based on:
- Known exploitation
- Internet exposure
- Severity
- Business criticality
- Sensitive data access
- Privilege level
- Availability of patches
- Compensating controls
Step 4: Apply Updates
Security updates should be installed within timeframes appropriate to the risk.
A practical internal target might be:
-
Critical or actively exploited: Emergency treatment.
-
High risk: As soon as reasonably practical.
-
Normal security updates: Routine scheduled cycle.
Exact timeframes should reflect the company’s environment and operational constraints.
Step 5: Test Where Necessary
For important production systems, test significant updates where practical before broad deployment.
Do not use testing as an excuse for indefinite delay.
Step 6: Verify
Confirm that:
- The update installed successfully.
- The vulnerability is no longer present where appropriate.
- The service still works.
- Failed deployments are investigated.
Step 7: Manage Exceptions
If a vulnerability cannot be fixed:
- Document the reason
- Record the risk
- Apply compensating controls
- Assign an owner
- Set a review or expiry date
Examples include:
- Restricting network access
- Disabling the vulnerable service
- Increasing monitoring
- Removing internet exposure
Step 8: Replace Unsupported Technology
Unsupported systems should be treated as a security risk.
Create a plan to:
- Upgrade
- Replace
- Isolate
- Retire
Or formally accept the risk temporarily.
Patch and Vulnerability Record
Record where appropriate:
- System
- Vulnerability or update
- Severity
- Internet-facing status
- Known exploitation
- Owner
- Required action
- Due date
- Status
- Exception
- Verification
- Evidence
Practical Rule
Patch the vulnerabilities that attackers can realistically use against the company first.